Most HOA boards discover the Telephone Consumer Protection Act (TCPA) the wrong way: a resident threatens to sue, an attorney sends a demand letter, or the management company's SMS provider suddenly suspends the account "pending consent verification." None of these end well. The good news is that TCPA compliance for an HOA is conceptually simple: four rules, a recordkeeping practice, and a willingness to say "no" when someone wants to add a phone number you have not opted in.
This is not legal advice. It is an operational primer that boards can use to set up their messaging program correctly the first time, then cite when a resident or auditor asks how the system works.
What the TCPA actually says
The TCPA (47 U.S.C. § 227) is a 1991 federal statute amended several times, most consequentially by the Federal Communications Commission's 2012 ruling and the 2015 Omnibus Order. The relevant provisions for HOA messaging:
- You must have prior express consent before sending any non-emergency text to a residential or wireless number.
- "Prior express written consent" is required for any message that is "telemarketing", which the FCC has interpreted broadly. To be safe, treat all HOA messages as requiring written consent.
- You must honor opt-out requests immediately. The CTIA Short Code Monitoring Handbook makes "STOP" universal.
- Statutory damages are $500 per violation, trebled to $1,500 if the violation is "knowing or willful." There is no harm requirement; a single un-consented text is a complete cause of action.
Does the TCPA really apply to HOAs?
Yes. This is a frequent source of confusion because HOA messages are "informational" rather than "marketing." But the FCC's 2003 ruling and subsequent enforcement makes clear that the TCPA applies to any "automated or prerecorded" messages to a wireless number, regardless of content. Mass texting from a platform is automated. The only narrow exception is genuine emergencies, life-safety alerts where time is critical.
There is a partial defense for "informational" (non-telemarketing) messages: oral consent may suffice. But because boards rotate, paper records get lost, and oral consent is hard to prove three years later, the safe practice is to capture written consent for everything. The handful of extra clicks costs nothing; a TCPA defense costs $20,000+ in legal fees even if you win.
The four pillars of TCPA compliance for an HOA
1. Express written consent before the first message
Express written consent is a clear statement, signed (electronically or on paper) by the resident, that authorizes the HOA to send messages to a specific phone number. The consent statement must:
- Identify the sender ("Maple Hills HOA") and what kinds of messages will be sent (announcements, reminders, emergency alerts)
- State the phone number being authorized
- Disclose that consent is not a condition of any service or membership
- Include the standard opt-out language ("Reply STOP to unsubscribe; reply HELP for help")
- Mention message and data rates may apply
2. Audit-grade recordkeeping
Every consent action must produce a record. Treat the consent log like the meeting minutes: append-only, never edited, retained for at least five years (the statute of limitations for TCPA claims is four years; one year of buffer is reasonable). For each record, capture:
- Member ID and phone number
- Action: granted, declined, revoked, reinstated
- Method: paper form, portal opt-in, SMS keyword reply, email link
- Timestamp (UTC, with original timezone preserved)
- IP address (for portal opt-ins) or signature image (for paper)
- Version of the consent language shown to the resident
- Who recorded it (board member, automated system, the resident themselves)
Why all of this? Because in TCPA litigation, the defendant has the burden of proving consent. "We assumed they consented because the previous board did" is not a defense. A timestamped record showing the exact consent text the resident agreed to, the IP address it came from, and the version of the language displayed. That is.
3. Honor opt-outs immediately
When a resident replies STOP, STOP-ALL, UNSUBSCRIBE, CANCEL, END, or QUIT, every major SMS platform automatically suppresses future sends. But the legal bar is higher than that. You must:
- Suppress the number across every messaging program from your community (announcements, reminders, violations, polls)
- Send exactly one confirmation reply ("You have been unsubscribed from Maple Hills HOA messages") and no more
- Treat any plain-English opt-out request the same way ("please stop texting me," "remove me," "I don't want these"). Do not require the magic word STOP.
- Keep the opt-out record forever: re-adding a number after opt-out without a fresh consent is itself a TCPA violation
4. Identify the sender, every time
The CTIA Messaging Principles require sender identification on the first message of any new conversation. Practically, that means:
- First broadcast of the year: "Maple Hills HOA: pool closed today for repairs. Reply STOP to unsubscribe."
- New resident's first message: same identification, same opt-out reminder
- Follow-up messages in the same thread: identification optional but never harmful
The emergency exemption (and its limits)
The TCPA carves out a narrow exception for "calls made for emergency purposes": life-safety messages where waiting for consent would cause harm. Examples: gas leak in Building C evacuate now, boil-water advisory, severe weather shelter-in-place. Counter-examples: meeting reminder, dues delinquency notice, "the pool will close at 5 PM today."
Use the emergency exemption sparingly. Every emergency message should be logged with: the nature of the emergency, who authorized the send, the time, and a copy of the message. If a board uses "emergency" to send routine reminders, the entire defense collapses.
What happens when you get sued
TCPA litigation is a cottage industry. Plaintiffs' attorneys actively monitor SMS traffic for non-compliant patterns. A typical HOA case looks like this:
- Resident receives an HOA text. They claim they never opted in.
- They file a putative class action covering all residents who received the same message.
- Discovery requests every consent record and the technical configuration of your messaging system.
- If consent records are sloppy or missing, the case settles for $50,000–$300,000+ depending on the message volume.
- If consent records are clean (version-controlled, timestamped, IP-logged), the case is dismissed at the motion-to-dismiss stage for a few thousand dollars in legal fees.
Practical compliance checklist
- Use a platform that defaults to sms_consent_status = "not_requested" until consent is captured. No "consent assumed" toggles.
- Require a fresh opt-in for every imported phone number, even from a previous management company that "always had consent."
- Display a clear consent statement before any portal opt-in. Version the language and store the version with each consent record.
- Send the first broadcast of the year with sender identification and a STOP reminder. Save it as a template.
- Suspend any number that opts out, immediately, across all programs. Do not re-add without a new consent action.
- Train new board members on consent before giving them broadcast permissions.
- Review consent logs at the annual meeting. The treasurer reviews finances; the secretary should review consent.
- Retain consent records for five years minimum, indefinitely if storage is cheap.
How TextHOA handles compliance for you
A platform built for HOAs handles the TCPA scaffolding automatically:
- Consent log per member, append-only, with IP and language version baked in
- Default sms_consent_status of "not_requested": opt-in is a deliberate action, not an assumption
- STOP / START / HELP keywords processed natively, with audit entries
- A2P 10DLC registration handled by the platform, including the brand and campaign vetting carriers require
- Sender identification injected into the first message of any new thread
- Annual consent review prompts so the board does not forget
You still own the policy, the consent language, and the decision about who to add to the system. The platform makes sure the underlying records are bulletproof, which, when a TCPA case lands on your desk, is the only thing that actually matters.
Compliance that runs on autopilot
TextHOA logs every consent, opt-out, and broadcast automatically. Audit-ready records, no spreadsheets, no surprises.