TCPA Class Actions Doubled in a Year. Can You Prove Consent?
A plaintiff's attorney does not need to prove you're a bad operator. They need to prove one text went to one number that hadn't agreed to receive it. That's the whole case. And right now, a small army of those attorneys is running that play at a pace nobody in this industry has seen before.
Here's the number that should reorganize your week. TCPA class-action filings surged 112% year-over-year into 2025, jumping from 239 filings in Q1 2024 to 507 in Q1 2025, and blowing past 2,128 cases by September, up 50% for the year (ActiveProspect, 2025). This is no slow drift. It's a wave, and it's still building.
The math that makes it a business problem
Statutory damages under the TCPA run $500 to $1,500 per violation (ActiveProspect, 2025). Read that as a per-text or per-call price tag, then remember the second number: nearly 80% of all TCPA suits today are class actions, against just 2 to 5% for other consumer cases (ActiveProspect, 2025).
So you're not paying for one bad text. You're paying for one bad practice, multiplied by every record it touched. A list of 4,000 contacts you couldn't prove consent for, at the floor rate of $500, is a $2 million exposure before anyone argues willfulness. The penalties stack from there. LeadCompliant cites figures of $23,727+ per violation on the FCC side and $50,120+ on the FTC side (LeadCompliant, 2025). One sloppy campaign can outrun a year of deals. Verify your own exposure with counsel, but the shape of it is not subtle.
What's actually getting people sued
The spike isn't random bad luck. ActiveProspect attributes it to aggressive plaintiff firms, misinterpretation of FCC revocation rules, and plain old non-compliance, and names the top triggers: missing or invalid consent, poor lead data quality, failure to honor opt-outs, and weak oversight on purchased leads (ActiveProspect, 2025).
Notice what's on that list and what isn't. Intent is nowhere on it. Nobody's getting sued for being aggressive on purpose. They're getting sued because when the demand letter arrived, they couldn't reach into their system and produce the receipt. The consent existed, probably. They just couldn't prove it existed. In a courtroom, those are the same thing.
That's the trap for real estate operators specifically. You're texting tenants, leads, sellers, agents, often fast, often through whatever tool was handy that quarter. The consent might be real. The proof usually isn't. And proof is the only thing that survives contact with a plaintiff's firm.
The receipt is the product
If the lawsuit turns on whether you can produce a record, then the fix is a system that produces the record automatically, every time, without anyone remembering to. That's the whole idea behind a compliance-first intake CRM. The audit trail is the point, not a feature bolted on the side.
What that system logs, per the compliance spec LeadCompliant lays out (LeadCompliant, 2025):
Timestamped consent at the moment of capture. Not "they agreed sometime." The exact language shown, the timestamp, the source URL and IP (ActiveProspect, 2025). When a number gets challenged, you pull the receipt in seconds instead of reconstructing a story.
Rolling 31-day DNC scrubs. You scrub against the National Do Not Call Registry and applicable state lists before every campaign, on a 31-day window, because a scrub older than 31 days loses safe-harbor protection (LeadCompliant, 2025). The system runs it on a clock so a stale list never goes out the door.
Five-year retention. Every consent verification, every scrub, every opt-out event, every compliance decision, held for at least five years (LeadCompliant, 2025). The suit that lands in 2028 is about something you sent in 2026. If the record's already gone, you've lost before you've read the complaint.
Honored opt-outs. The single fastest way to manufacture a violation is to text someone who already said stop. The system catches the revocation, processes it, and logs that it did, so an unhonored opt-out can't slip through on a busy Tuesday.
Independent proof is the belt-and-suspenders layer here. Third-party certificates like TrustedForm create an outside record of consent that doesn't depend on your own logs (ActiveProspect, 2025). When it's your word against theirs, an independent timestamp is worth more than a confident memory.
What to do before the wave reaches you
None of this is legal advice, and your situation deserves a real lawyer's eyes. But the operational move is clear enough to act on now. Find every place you're contacting people, ask whether you could produce dated proof of consent for each one, and assume the answer is no until a system proves otherwise.
The operators who sleep through this year are the ones who can hit export and watch the receipts print. The ones who can't are running a company whose downside is set by how motivated the next plaintiff's attorney happens to be. Consent you can't prove is consent you don't have. The lawyers already know that. The only question is whether your system does.
