Compliance Guides
What the rules require now, with the dates. This area has moved repeatedly since 2024 — several widely-circulated guides describe a rule that no longer exists.
In short
US outbound calling is governed mainly by the TCPA (FCC-enforced, with private suits and statutory damages of $500–$1,500 per violation and no aggregate cap) and the Telemarketing Sales Rule (FTC-enforced, setting calling hours, abandonment caps and recordkeeping).
Two 2025 changes matter most: the FCC's one-to-one consent rule was vacated and never took effect, while new consent revocation rules did. A growing patchwork of state mini-TCPAs now carries much of the litigation risk.
This is general information, not legal advice
Written for contact center operators to know what to ask about. It is not a substitute for counsel, and it does not create a professional relationship. Several dates in this area have shifted more than once and sources disagree on some of them — where that is true below, we say so rather than picking one.
TCPA
The Telephone Consumer Protection Act is a 1991 federal statute restricting autodialed calls, prerecorded and artificial-voice messages, and texts. It requires prior consent, adherence to do-not-call requests, and compliance with calling-time limits.
What makes the TCPA unusual is the damages structure: $500 per violation, rising to $1,500 for wilful or knowing violations, with no cap on aggregate damages and a four-year limitations period. A single non-compliant campaign to a few thousand numbers can therefore produce existential liability, which is why the TCPA generates more class-action volume than most federal statutes combined.
The practical consequence for an operator: consent provability is the whole game. Not consent — provable consent, retained, timestamped, tied to a specific disclosure the consumer actually saw.
One-to-one consent: vacated
The FCC adopted a rule in December 2023 that would have required consumer consent to be given to one identified seller at a time, aimed at lead-generation forms that obtained consent for dozens of partners at once.
It never took effect. The FCC postponed its effective date in January 2025 pending judicial review, and on January 24, 2025 the Eleventh Circuit vacated it in Insurance Marketing Coalition Ltd. v. FCC, holding that the Commission had exceeded its TCPA authority and departed from the ordinary meaning of prior express consent. The FCC formally removed the nullified rule in July 2025.
Why operators still build to it anyway
Seller-specific consent is easier to prove in litigation and it removes the lead-source ambiguity that causes most disputes. Several state statutes already impose a similar standard. So the rule is gone as a federal requirement, and a great deal of the industry has kept the practice — not out of caution about the rule returning, but because provable consent is the only defence that works.
If your compliance programme is built around a one-to-one federal requirement, it is built around a rule that does not exist. If it is built around provable, seller-identified consent, it is in good shape.
Consent revocation
This is the change that did take effect, and it is the one most operators under-implement. As of April 11, 2025:
- A consumer may revoke consent by any reasonable means — replying STOP, saying it on a call, sending an email, telling an agent. You cannot require a specific keyword or channel.
- Revocation must be honoured within a reasonable time, not exceeding 10 business days.
- It applies to informational messages as well as marketing.
The operational implication is significant: a revocation can arrive anywhere. In an SMS reply that is not a keyword, mid-call to an agent who has no field to record it, in a reply to a no-reply inbox. If those paths do not reach your suppression list, you are non-compliant regardless of what your web form says.
A broader "revoke-all" provision from the 2024 TCPA Consent Order — under which a single revocation would stop all robocalls and robotexts from a sender, including across unrelated business units — has been delayed more than once, and reported effective dates differ between sources. Confirm the current date with counsel rather than relying on any published guide, including this one.
Telemarketing Sales Rule
The FTC's rule governs telemarketing practice directly:
- Calling hours — 8am to 9pm in the called party's local time, which makes timezone-aware dialing a requirement rather than a nicety.
- Abandoned calls — capped. A call answered by a live person where no agent connects within two seconds of the greeting counts as abandoned, which is what pacing ratios are really tuned against.
- Registry calls — most calls to numbers on the National Do Not Call Registry are prohibited.
- Disclosures — prompt, truthful identification of the seller and the purpose of the call.
- Recordkeeping — specified records must be retained, with broader five-year retention now applying in several categories.
TSR civil penalties are assessed per violation and the maximum is adjusted for inflation annually, so check the current figure rather than quoting an older one.
DNC scrubbing
Scrubbing is not a one-time import step. It is a pre-dial check, run before every campaign, against several lists at once:
- National DNC Registry — the federal list.
- State DNC registries — several states maintain their own, with their own rules.
- Your internal DNC list — every revocation and opt-out you have ever received, permanently. This is the list that gets neglected and the one plaintiffs check.
- Litigator and complainer lists — commercially available; screens numbers associated with serial TCPA plaintiffs.
- Reassigned number data — consent does not travel with a phone number to its new subscriber.
The failure mode is almost always the internal list: a suppression that lived in a spreadsheet, a CRM field nobody synced, or an agent note that never became a record.
STIR/SHAKEN
STIR/SHAKEN is the caller ID authentication framework US voice providers use to cryptographically attest that a calling number is legitimately associated with the caller. Attestation comes in levels, and calls with weak or absent attestation are substantially more likely to be labeled or blocked before they ever ring.
This has moved from a telecom concern into a compliance and deliverability concern for two reasons. First, attestation level now materially affects connect rate. Second, the FCC has been removing providers from the Robocall Mitigation Database for non-compliant filings — over a thousand in 2025 — and when a provider is removed, downstream carriers must stop accepting its traffic. A perfectly compliant campaign can lose deliverability overnight because of something that happened at a carrier.
Ask your provider directly what attestation level your traffic receives and whether their RMD filing is current. It is a reasonable question and a straight answer should be easy.
Reassigned Numbers Database
Phone numbers get disconnected and reassigned. Consent obtained from the previous subscriber does not transfer to the new one, and calling the new subscriber can create liability even though your consent record is genuine.
The FCC administers a database that lets callers check whether a number has been permanently disconnected since a given date. Correct use provides a limited safe harbour — limited being the operative word. It protects you where the database returned no evidence of reassignment; it does not protect you from calling a number you never checked, and it does not cure a consent record that was defective to begin with.
State mini-TCPAs
This is where the risk has migrated. Florida's FTSA, Maryland's Stop the Spam Calls Act, Oklahoma's statute and Washington's provisions all impose consent standards resembling the vacated federal rule, and several write their own damages arithmetic — Texas's model of treble damages plus attorney's fees is the version other legislatures are most likely to copy.
Because federal preemption is weak in this area, plaintiffs' attorneys have pivoted toward state-law claims. The practical planning consequence: a programme designed only to the federal floor may still be exposed in the states where your list is densest. Know which states your list actually concentrates in.
AI voice and the TCPA
In February 2024 the FCC confirmed that AI-generated voices fall under the existing TCPA rules for artificial or prerecorded voice calls. There is no separate, lighter regime for synthetic speech.
So a consumer telemarketing campaign using an AI voice generally requires the same prior express written consent as a prerecorded telemarketing call. And the seller remains responsible for the campaign regardless of what the vendor contract says — no platform removes your legal exposure. See the voice AI guide for the operational side.
HIPAA and PCI in the contact center
Two obligations that sit alongside the calling rules rather than inside them.
HIPAA applies wherever protected health information passes through the contact center. The pressure points are call recording and storage, agent access scoping, retention limits, and whether recordings containing PHI are encrypted at rest and restricted by role. A recording archive that every supervisor can search is a problem waiting to be found.
PCI DSS applies wherever card data is spoken aloud. The standard approach is to keep card numbers out of the recording entirely — pause-and-resume recording, or DTMF suppression so the agent never hears or sees the digits. Redacting after the fact is worse than never capturing.
Operating checklist
Not a legal opinion — a list of things that should be demonstrably true of your operation.
- Consent records are retained with timestamp, source, and the exact disclosure text shown.
- Revocation can be captured from SMS replies, agent notes, email and inbound calls, and all four paths reach one suppression list.
- Suppression is honoured well inside 10 business days, and you can prove the interval.
- Every campaign is scrubbed pre-dial against federal, state, internal, litigator and reassigned-number data.
- Dialing is timezone-aware, enforced by the platform rather than by policy.
- Abandonment is monitored against a ceiling set below the regulatory limit.
- You know your STIR/SHAKEN attestation level and your provider's RMD status.
- Recordings are encrypted, role-scoped, retention-limited, and card data never enters them.
- Someone owns quarterly re-review of all of the above, by name.
Deep-dive guides in progress
Each of these expands one topic into a full page with the primary sources cited and the effective dates stated on the page.
- TCPA: a compliance programme from scratchIn progress
- Consent capture and retention that survives discoveryIn progress
- Consent revocation: capturing it from every channelIn progress
- Telemarketing Sales Rule: an operator's readingIn progress
- DNC scrubbing: building the pre-dial gateIn progress
- STIR/SHAKEN and attestation: questions for your carrierIn progress
- State mini-TCPAs: a state-by-state summaryIn progress
- HIPAA in the contact center: recording and accessIn progress
- PCI DSS: keeping card data out of recordingsIn progress
These are listed without links on purpose — we would rather show you what is coming than send you to a page that does not exist yet.
Frequently asked questions
Is the FCC one-to-one consent rule still in effect in 2026?
No. The Eleventh Circuit vacated it on January 24, 2025 in Insurance Marketing Coalition Ltd. v. FCC, holding that the FCC exceeded its TCPA authority, and the Commission formally removed the nullified rule in July 2025. It never took effect.
Many operators still capture seller-specific consent because it is easier to prove in litigation and several state statutes impose a similar standard. General information, not legal advice.
What are the TCPA consent revocation rules?
Since April 11, 2025, a consumer may revoke consent by any reasonable means — not a keyword or channel you choose — and you must honour it within a reasonable time not exceeding 10 business days. It covers informational messages as well as marketing.
A broader "revoke-all" provision has been delayed more than once and reported effective dates differ between sources; confirm the current date with counsel.
What are the legal calling hours for outbound calls in the US?
The federal window under the Telemarketing Sales Rule is 8am to 9pm in the called party's local time, not yours. Several states impose narrower windows and some restrict weekend calling.
Because the window follows the consumer's timezone, a national list requires timezone-aware dialing enforced by the platform.
How much can a TCPA violation cost?
$500 per violation, rising to $1,500 for wilful or knowing violations, with no cap on aggregate damages and a four-year limitations period.
The absence of a cap is what makes this a business-threatening exposure rather than a cost of doing business: one non-compliant campaign to a few thousand numbers scales directly into seven figures.
Do AI voice agents need the same consent as prerecorded calls?
Generally yes. In February 2024 the FCC confirmed that AI-generated voices fall under the existing TCPA rules for artificial or prerecorded voice calls, so consumer telemarketing with an AI voice needs the same prior express written consent.
The seller remains responsible for the campaign whatever the vendor contract says.
How often should compliance guidance be re-checked?
Quarterly at minimum, and this area deserves it more than most — the one-to-one rule was postponed, vacated and removed inside seven months, and the revocation timetable has shifted repeatedly.
Any guide that does not state when it was last reviewed cannot be relied on. That includes this one, which is why the review date is at the top.
Compliance controls built into the dialer
Timezone-aware calling windows, pre-dial scrubbing, abandonment ceilings and suppression handling enforced by the platform rather than by policy documents.