Go to main content

TruStage Cyber Incident

 

 

menu logo
Home

  • September 18, 2026
    All on Boards: Directors' Symposium
  • October 21, 2026
    Contact & Connect: Leadership Conference
  • November 4, 2026
    Developing Future Leaders Webinar

  • Sponsor an Event
  • Speaker Proposals

Take A Second: CU Legal Insights

"Take A Second: CU Legal Insights" offers weekly updates and legal analysis tailored for credit unions, helping navigate regulatory landscapes and stay informed on industry trends.

masthead banner

The Next Evolution of TCPA Compliance: Understanding “Revoke All”

9/15/2026

In December, I wrote an article about the Telephone Consumer Protection Act (TCPA), covering some of its nuances and how it is, in fact, alive and well.  

Since then, the TCPA has continued to evolve. This article examines the upcoming changes to the "revoke all" rule, including updates expected to be considered at the Federal Communications Commission (FCC)'s September board meeting and the recently released Further Notice of Proposed Rulemaking (FNPRM). Buckle up, because this one might take more than a "second." 

Quick Background on TCPA 

The Telephone Consumer Protection Act (TCPA) was enacted in 1991 under President George H.W. Bush to curb abusive telemarketing practices, including unsolicited calls, automated messages and faxes. The law specifically targeted automatic telephone dialing systems (ATDS) and prerecorded or artificial voice messages. 

Despite being created at a time when cell phones were far less common than they are today, the TCPA has withstood the test of time. The FCC is the primary agency responsible for the implementation and regulation of the TCPA, and over time, it has updated the rules to reflect changes in how consumers communicate.  

Which is precisely where this latest round of modernizations came from. The FCC states that “the Commission receives more complaints about illegal robocalls that defraud and annoy consumers than any other issue…”1  

What Was Modernized in this Order? 

The Order which will be considered at the FCC’s Sept. 30 meeting of the commission will make four key changes: 

  1. 1. It will allow callers (for our purposes credit unions) to interpret a members revocation request to apply only to the specific category of informational robocalls in which the member stated they did not want to be contacted for. Previously, this revocation by the member was to be extended to all informational communications not just a category of informational communications. Narrowing the scope of the revocation; 
     
  2. It will allow callers (for our purpose credit unions) to designate the means of revoking that consent; 
     
  3. It modifies the exemption from the consent requirement for financial institutions to allow us to more easily alert our members about fraudulent activity on their accounts; and  
     
  4. It delegates authority to the Consumer Governmental Affairs Bureau to review the rules that are implemented by the TCPA to ensure that those rules are clear and easily understood.  
How Do these Changes Impact Us? 

These changes make the “revoke all” rule easier on credit union operations and provide additional flexibility that the prior Report and Order did not.  

This means that as credit unions we don’t have to stop all informational communications with members because they revoked consent to receive, for instance “marketing” communications. If the member revokes their consent to receive marketing communications, then that revocation only applies to that type of communication and not fraud alerts, for instance. This added flexibility is particularly important as fraud continues to rise and credit unions need reliable ways to communicate urgent account and security information to members. 

Additionally, previously the Order required credit unions (and others) to accept a member’s revocation by any “reasonable means,” creating uncertainty and increasing the burden of tracking and processing opt-out requests across multiple channels. Now, credit unions can designate an exclusive means by which their members may revoke prior express consent. Keep in mind that if the credit union does not designate an exclusive means to revoke that members can exercise their right to revoke in any reasonable manner. Ensuring your credit union designates an exclusive means of revocation is important.  

The final and major relevant change is an exemption for financial institutions that removes the requirement that phone calls regarding fraud alerts and security breach notices must only go to numbers directly provided by members. It allows financial institutions to call numbers that they have obtained from other reliable sources, such as others authorized on accounts and/or spouses.  

These updates create some relief for credit unions and other financial institutions prior to what was the original deadline for implementation. 

That All Sounds Great, So What’s the Catch? 

Yes, these updates are a welcome improvement to the Order that was originally scheduled to take effect on Jan. 31, 2027. However, they also accelerate the implementation timeline. 

Rather than having until Jan. 31, 2027 to comply, credit unions and other covered entities will need to comply 30 days after the Order is published in the Federal Register, which is expected to occur following the Sept. 30 FCC meeting. If that timeline holds, compliance could be required as early as Oct. 30, 2026. 

As a result, credit unions should start reviewing current systems to make sure they can meet these new opt-out/revocation requirements.  

What’s Next?  

The FCC also published a Further Notice of Proposed Rulemaking (FNPRM) to the TCPA. This FNPRM “seeks comments on updating various TCPA-related rules including revisiting the timeline for callers to honor revocation requests, requiring two-way texting functionality to allow for revocation via reply text, requiring callers to provide a method to revoke consent to all robocalls, and the treatment of affiliates.”2  

The areas covered in the FNPRM have the potential to impact credit union operations and place additional burden if we do not add our voices to this conversation. Our team will continue to keep an eye on this FNPRM and provide additional information once it is available.  

To sum it up… 

The updated Order, which is expected to be approved at the Sept. 30 FCC meeting, is a significant improvement over the previous version. However, credit unions will need to move quickly to prepare for compliance. 

Assuming the Order is published in the Federal Register shortly after the meeting, compliance could be required as early as Oct. 30, 2026. The shortened timeline is not ideal, but the relief provided was much needed.  

The FNPRM that the FCC announced is a great opportunity to ensure that our voices are heard on any additional changes to the TCPA, several of which have the opportunity to impact daily credit union operations. We will want, as an industry, to make sure we are reviewing the FNPRM and making relevant comments. As mentioned above, the FNPRM has not been published in the Federal Reserve yet, so we will continue to monitor this one and provide updates once it has been published. 

As always, this article is intended for general information only and does not constitute legal advice. If you have any questions about this topic and/or possible implications, you should contact your attorney for advice.  

Hope to see you next time when we take a second to break down another trending legal topic! 

 

1 Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991, Report and Order & Further Notice of Proposed Rulemaking, CG Docket No. 02-278, FCC-CIRC 2609-05, ¶ 1 (circulated Sept. 9, 2026). 

 

2 Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991, Report and Order & Further Notice of Proposed Rulemaking, CG Docket No. 02-278, FCC-CIRC 2609-05, ¶ 3 (circulated Sept. 9, 2026). 



« Return to "Take a Second CU Legal Insights"
Go to main navigation