Strategy
Stop TCPA Risk: 8 Steps to Do Not Call Compliance for Telemarketers
By Nick Georgalos · 14 min read · Updated 2026-09-03
Stop TCPA Risk: 8 Steps to Do Not Call Compliance for Telemarketers ! Specialist reviewing a telemarketing compliance scrub No, you cannot call a number on the National Do Not Call Registry unless a narrow exception applies, and if you're not sure your scrubbing process actually catches every listed number, stop dialing until you check.

No, you cannot call a number on the National Do Not Call Registry unless a narrow exception applies, and if you’re not sure your scrubbing process actually catches every listed number, stop dialing until you check. Verify your last scrub date, confirm your consent records, and document what you find today.
TL;DR:
- Regularly update and document your last scrubbing date to ensure phone numbers are not on the registry for more than 31 days.
- Maintain and verify explicit, signed consent records or established business relationships for every call outside the registry.
- Conduct internal audits of call records and consent proof regularly to identify and fix compliance gaps before enforcement actions occur.
- Use written procedures, agent training logs, and scrub timestamps as part of your safe-harbor defense to prove compliance during inspections.
- Transition to lead generation with documented consent to reduce the compliance burden and reliance on outdated or bought lists.
Table of Contents
- What Do Not Call Compliance Actually Requires
- Quick Compliance Checklist: 8 Steps To Get Compliant Today
- The Legal Framework: TCPA, TSR, FTC, and FCC, Who Enforces What
- How the Registry Works: Access, Fees, Scrubbing, and Exemptions
- Operational Requirements: Disclosures, Timing, and Revocation
- Vendor Liability: Contracts and Controls That Limit Your Exposure
- Penalties and Enforcement: What a Violation Actually Costs
- Safe Harbor and Documentation: The Records That Protect You
- Reducing Outbound Dependence Through Consent-Based Lead Generation
- The Gap Between Compliance Advice and Compliance Reality
- A Lower-Risk Path to Life Insurance Leads
- Sources
What Do Not Call Compliance Actually Requires
Do not call compliance means your organization checks every phone number against the National Do Not Call Registry before dialing, unless you can prove one of two exceptions: an established business relationship or prior express written consent. That’s the entire concept in one sentence, but the mechanics behind it trip up more agencies than you’d expect.
The registry itself is simple to access. Telemarketers and sellers subscribe to the area codes they intend to call and pay the required fees, then certify they’re using the registry only for compliance purposes, not for building marketing lists. What’s harder is treating that scrub as a living process rather than a one-time checkbox. A number can be clean on Monday and land on the registry by Wednesday. If your last scrub was six weeks ago, you’re not compliant anymore, no matter how careful you were the day you ran it.
Most agencies that get burned aren’t running rogue operations. They’re running outdated ones: a scrub cadence set up two years ago that nobody revisited after a vendor change, or a lead list bought from a broker who swore the numbers were “opted in” with no actual documentation to back it up. Compliance with do not call rules isn’t about intent. Regulators and courts care about what you can prove, not what you meant to do.
Quick Compliance Checklist: 8 Steps To Get Compliant Today
You don’t need a six-month overhaul to reduce your exposure. You need these eight things done, in roughly this order, starting now.
- Subscribe to the registry and run an immediate scrub against every number in your active calling list.
- Maintain an internal do-not-call list and honor opt-out requests the moment they come in, not at the end of the shift.
- Confirm EBR or written consent documentation exists for every number you plan to call outside the registry.
- Lock in mandatory disclosures and calling-hour rules so every agent opens calls the same compliant way.
- Require scrub certification from any vendor supplying leads or dialing on your behalf.
- Archive scrub timestamps and consent proof somewhere retrievable, tied to each phone number.
- Audit 1,000 recent calls against your DNC list and consent records, then fix whatever gaps surface.
- Retrain agents on instant opt-out handling so “please stop calling” ends the conversation immediately.
Pro Tip: Run your audit before a regulator or plaintiff’s attorney does it for you. A self-caught gap is a training issue. A complaint-triggered gap is a liability issue.
The Legal Framework: TCPA, TSR, FTC, and FCC, Who Enforces What
Four acronyms govern almost everything about outbound calling, and conflating them is where a lot of compliance programs go wrong.
The Telephone Consumer Protection Act (TCPA) is the statute that gives consumers the right to sue over unwanted calls, robocalls, and texts, and it’s the one most often cited in private litigation. In 2024, the FCC strengthened consent and revocation rules under the TCPA, codifying that a consumer can revoke consent through any reasonable method, not just the process the caller prefers, and that callers must honor revocation requests within a reasonable time not exceeding 10 business days. That single change reshaped how compliance teams have to think about opt-outs: you can no longer point to a narrow revocation channel and call anything outside it invalid.
The Telemarketing Sales Rule (TSR), enforced by the Federal Trade Commission, is where the actual Do Not Call mechanics live: registry access requirements, call disclosures, time-of-day restrictions, recordkeeping, and the safe-harbor defense. The TSR is the rulebook; the TCPA is the courtroom weapon consumers use when the rulebook gets ignored.
The National Do Not Call Registry itself is jointly implemented by the FTC and the Federal Communications Commission, with the FTC handling most enforcement against sellers and telemarketers and the FCC handling carrier-level rules, robocall restrictions, and TCPA rulemaking. It’s not a single database owned by one office. It’s a shared enforcement mechanism, and both agencies bring cases.

State attorneys general add another layer entirely. Many states enforce the federal registry directly and layer on their own registration requirements or calling-frequency limits, which means a multistate campaign that’s clean under federal rules can still trigger a state-level violation. Callers running campaigns across several states need to check state-specific requirements in addition to the federal framework, because assuming national coverage equals full coverage is a common and costly mistake.
Then there’s private TCPA litigation, which has become its own enforcement arm almost independent of the agencies. A single unwanted call can trigger a lawsuit with statutory damages, and plaintiff’s firms actively monitor complaint databases for patterns worth pursuing. Agency action and private lawsuits aren’t alternatives to each other. They run in parallel, and a company can face both from the same underlying call.
How the Registry Works: Access, Fees, Scrubbing, and Exemptions
Accessing the registry isn’t complicated, but the details of how often and under what conditions you’re allowed to skip it are where most violations originate.
Telemarketers and sellers must subscribe to the registry for every area code they intend to call and pay the associated access fees. That subscription isn’t permanent. It has to be renewed, and more importantly, your call list has to be rescrubbed against it on a regular cadence, not just once when the campaign launches.
The FTC recommends scrubbing no more than 31 days before calling, and treating that as a hard ceiling rather than a target is the safer approach. Numbers get added to the registry constantly, and a list that was clean 45 days ago is not a defensible list today.
Two exemptions let you call a registered number anyway, and both require documentation, not just a good-faith belief:
- Established business relationship (EBR): generally within a conservative period after the consumer’s last purchase, payment, or transaction, or a shorter period from an inquiry or application, if no purchase followed.
- Prior express written consent: a signed agreement, which can be electronic, specifically authorizing calls to that number, tied to the calling party and the type of call being made.
Neither exemption is self-certifying. If you’re relying on an EBR, you need a transaction date on file. If you’re relying on consent, you need the signed record itself, not a vendor’s assurance that the lead was “opt-in.” Buying a list labeled as consented does not transfer the burden of proof. You still have to be able to produce the actual consent record if asked, tied to the specific phone number in question.
Operational Requirements: Disclosures, Timing, and Revocation
Every outbound call has to open with specific disclosures: the caller’s identity, the name of the seller on whose behalf the call is made, a contact number or address, and the purpose of the call. Skipping this at the top of the call is one of the easiest violations to spot in a recorded-call audit, and one of the easiest to fix with a script.
Calling hours are restricted to reasonable daytime and evening hours in the consumer’s local time zone, and abandoned call rates (calls where a live agent doesn’t connect within a set window) are capped under predictive dialer rules. If your dialing system routinely drops calls before an agent picks up, that’s a compliance problem hiding inside what looks like a technology problem.
Revocation handling changed meaningfully under the FCC’s 2024 order. Consumers can revoke consent through any reasonable method, a verbal statement, a text reply, an email, and callers must honor that request within a reasonable time not exceeding 10 business days. The order also permits a one-time confirmation text after an opt-out, but only one, and it can’t be used as a backdoor re-engagement attempt.
Internal, company-specific do-not-call lists sit alongside the national registry, not underneath it. A consumer who asks your company specifically to stop calling goes on your internal list permanently, separate from whatever the national registry says, and that request has to be honored across every campaign and every agent, not just the one who took the call.

Vendor Liability: Contracts and Controls That Limit Your Exposure
Sellers stay liable for the telemarketers they hire, full stop. Outsourcing the dialing doesn’t outsource the risk, which means your vendor contracts need to do real work, not just check a compliance box.
- Require scrub certification with timestamps, not a verbal assurance the list was cleaned.
- Build in audit rights so you can pull sample call logs and API records on demand, not just at renewal.
- Add indemnity language that puts financial responsibility back on the vendor if their scrub process fails.
- Run periodic testing against your own internal DNC list to confirm the vendor’s numbers actually match.
Pro Tip: Ask a vendor for their scrub log before you sign, not after a complaint lands. If they can’t produce one on request, that tells you everything about what happens under real enforcement pressure.
Penalties and Enforcement: What a Violation Actually Costs
Violations of the TSR may lead to civil penalties that accumulate with each call to a registered number, and enforcement agencies have pursued significant penalties against telemarketing operations with systemic scrubbing failures, and state attorneys general regularly bring parallel actions on top of federal cases.
Complaints typically arrive through consumer reports to the FTC, traceback requests run through industry consortiums, or direct state AG investigations, any of which can escalate into civil litigation. Private TCPA suits add another channel entirely, often triggered by a single documented call.
The most common enforcement triggers are stale scrub dates, vendors calling off unverified “opt-in” lists, and agents ignoring verbal opt-out requests mid-call. If you find one of these gaps internally, document the discovery, fix the process, and preserve the audit trail. That paper trail is what separates a defensible mistake from a pattern of disregard.
Safe Harbor and Documentation: The Records That Protect You
The safe-harbor defense under the TSR isn’t automatic. It’s an affirmative defense you have to prove with specific records, and the FTC lays out exactly what counts.
- Written procedures for DNC compliance, not an informal understanding among staff.
- Ongoing agent training logs showing the procedures were actually taught.
- Monitoring reports confirming agents follow the procedures in practice.
- A maintained internal DNC list, updated in real time as requests come in.
- Scrub timestamps proving the list was checked within 31 days of calling.
- An errant-call log documenting any calls made to registered numbers as good-faith mistakes, not policy failures.
| Safe-harbor element | What it proves |
|---|---|
| Written procedures | Compliance was designed, not improvised |
| Training logs | Staff were actually taught the rules |
| Monitoring reports | Procedures are followed, not just written |
| Internal DNC list | Company-specific opt-outs are honored |
| Scrub timestamps | The registry check was current, not stale |
| Errant-call log | Violations were isolated mistakes, not patterns |
Keep every one of these records in a retrievable format tied to the specific phone number and call date, not just a general compliance folder. When an inquiry comes in, whether from the FTC, a state AG, or opposing counsel in a TCPA suit, the speed at which you can produce this documentation often determines whether the conversation stays administrative or turns into litigation.
Reducing Outbound Dependence Through Consent-Based Lead Generation
The compliance burden above exists because cold outbound calling starts from zero consent and has to build a legal case for every single number. Lead generation built around explicit, timestamped consent flips that structure. When a consumer fills out a lead form with their phone number, that timestamp and the matching form data become part of your consent record, not an afterthought you scramble to document later.
Passing that consent metadata directly into your telephony or CRM system means agents can verify EBR or consent status before they ever dial, rather than relying on a scrub run weeks earlier. Agents working exclusive leads generated in their own ad account, with consent already attached to each contact, spend far less time worrying about registry exposure and far more time actually selling.
The Gap Between Compliance Advice and Compliance Reality
Most compliance content treats the Do Not Call Registry like it’s the whole job. It isn’t. The registry is the floor, not the ceiling, and agencies that stop there are the ones getting hit with TCPA suits over consent issues the registry never touched.
The bigger failure I see is treating documentation as an afterthought instead of the actual product of a compliance program. A scrub you can’t prove happened is functionally the same as a scrub you never ran. An “opt-in” lead list without a retrievable consent record is a liability sitting in your CRM, not an asset.
If you take one thing from this: stop treating vendor-supplied leads as pre-cleared. Verify them the same way you’d verify your own list. And if your business model still leans heavily on cold outbound dialing to numbers with no prior relationship, that dependence is itself the risk, regardless of how tight your scrub cadence is. The agencies moving away from that model aren’t doing it for marketing reasons. They’re doing it because owned consent is easier to defend than a scrub log.
— Nick
A Lower-Risk Path to Life Insurance Leads
Cold dialing a purchased list will always carry more compliance overhead than working leads where consent is already documented at the point of capture. Fexads is the alternative to rented, DNC-exposed lead lists for final expense, IUL, and mortgage protection agents. It generates exclusive leads directly inside your own Facebook ad account, with consent metadata attached to each contact the moment they submit a lead form, so you’re not relying on a third-party scrub you can’t audit.

Because the leads are exclusive and generated with a documented opt-in, you own the data and the consent trail, not a broker who resold the same number to five other agents. That ownership means continuous audience optimization over time instead of starting from a cold, unverified list every cycle. If you want to see what compliance-focused lead generation looks like state by state, check Fexads’ state-specific Facebook ad programs and get a quote on a custom campaign built around your licensed lines of business.
Sources
- Complying with the Telemarketing Sales Rule | Federal Trade Commission
- REPORT AND ORDER AND FURTHER NOTICE OF PROPOSED RULEMAKING | FCC (FCC-24-24A1)
- National Do Not Call Registry
Recommended
Want us to run your FE ads?
$700 to launch, custom website included. $500 a month flat after that.
Apply now