Compliance failure is the most common way a functioning, revenue-generating call center is destroyed. Not slowly — a single class action or a carrier-level block can end an operation in weeks. The rules are also not especially complicated once laid out.
The governing principle: the law of the country you are calling into applies, regardless of where your agents sit. An operation in Manila calling US consumers is subject to US rules, and "we are offshore" is not a defence.
United States
The highest-risk market to call into, and the one with the most developed enforcement.
TCPA — Telephone Consumer Protection Act
The dominant risk. Key provisions for outbound operations:
- Prior express written consent is required for autodialed or prerecorded marketing calls to mobile numbers. Written consent means a signed agreement identifying the seller and authorising calls, not a pre-ticked box buried in terms.
- Prerecorded/artificial voice calls to residential lines for marketing require prior express written consent.
- Statutory damages are $500 per violation, trebled to $1,500 for wilful or knowing violations.
- There is a private right of action, which is why TCPA class actions are an industry in themselves.
The definition of "autodialer" (ATDS) has narrowed since Facebook v. Duguid (2021), but relying on that narrowing as a compliance strategy is unwise — the FCC continues to issue interpretations and state-level analogues have filled gaps.
TSR — Telemarketing Sales Rule
Administered by the FTC. Applies to most telemarketing:
| Requirement | Rule |
|---|---|
| DNC scrubbing | Every 31 days against the National Registry |
| Calling hours | 8:00am - 9:00pm in the called party's time zone |
| Abandoned calls | Maximum 3% of answered calls, per campaign, per 30 days |
| Connection time | Agent must be connected within 2 seconds of the greeting |
| Abandonment message | If abandoned, a recorded ID message must play |
| Disclosure | Identify seller and that it is a sales call, promptly |
| Record keeping | 24 months of specified records |
Do Not Call
Two layers, and you must honour both:
- National DNC Registry — scrub every 31 days, retain proof.
- Internal DNC list — anyone who asks you not to call again, honoured immediately and indefinitely. This applies even where the national registry does not.
Many state registries also exist with their own requirements.
Caller ID and STIR/SHAKEN
Transmitting inaccurate or misleading caller ID with intent to defraud or cause harm violates the Truth in Caller ID Act. Separately, STIR/SHAKEN call authentication now governs how US calls are attested and displayed:
- Calls originating with proper attestation are less likely to be labelled "Spam Likely."
- Calls with poor attestation increasingly get blocked outright by carriers.
- Using a caller ID number you do not legitimately control will hurt attestation and can result in your traffic being blocked.
United Kingdom
- PECR (Privacy and Electronic Communications Regulations) governs marketing calls, alongside UK GDPR.
- TPS / CTPS — the Telephone Preference Service registers for consumer and corporate numbers. Screening against them is mandatory for unsolicited marketing calls.
- Ofcom policy sets an abandoned call rate ceiling of 3% per campaign per 24-hour period, with an information message required on abandonment.
- Silent calls are specifically targeted; an answer machine detection false positive that produces silence counts.
- The ICO issues monetary penalties, and directors can be held personally liable for nuisance-call breaches.
European Union
- GDPR applies to every piece of personal data in your dialer — names, numbers, recordings, notes.
- You need a lawful basis. For direct marketing this is usually consent or legitimate interests, and the analysis differs by member state.
- Controller vs processor matters commercially. If a client supplies the list and directs the campaign, they are typically controller and you are processor — which requires a Data Processing Agreement under Article 28. Do not run EU campaigns without one.
- Data subject rights — access, erasure, objection to direct marketing. Objection to marketing is absolute; there is no balancing test.
- Transfers outside the EEA need a valid mechanism such as Standard Contractual Clauses. This directly affects offshore centers processing EU data.
- Breach notification within 72 hours.
Several member states add national rules — Germany in particular treats unsolicited marketing calls to consumers strictly.
Canada, Australia, India
Canada — CRTC Unsolicited Telecommunications Rules, National DNCL registration and scrubbing, plus CASL for electronic messages. Calling hours and identification requirements apply.
Australia — Do Not Call Register, administered by ACMA. Calling hours restricted, and the Telecommunications (Do Not Call Register) Act carries substantial penalties.
India — TRAI's TCCCPR regime requires registration of telemarketers and headers on a DLT (Distributed Ledger Technology) platform, with scrubbing against subscriber preferences. Operating unregistered is a fast route to disconnection.
Call recording consent
The rule that most often catches small centers out, because it varies within the United States.
| Jurisdiction | Requirement |
|---|---|
| US federal | One-party consent |
| California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Washington | All-party consent |
| Other US states | Generally one-party |
| UK | Must inform; lawful basis required under UK GDPR |
| EU | Must inform; lawful basis required; retention limits apply |
| Canada | Must inform under PIPEDA |
| Australia | State-based; generally must inform |
Because a single US campaign routinely crosses one-party and all-party states, the practical answer for almost everyone is: announce recording at the start of every call, and configure the dialer to play the announcement automatically rather than relying on agents.
Retention is a separate question. Keeping recordings indefinitely is a GDPR problem and a breach-exposure problem. Set a retention period, document it, and actually enforce it.
A compliance checklist for a small center
Before the first campaign:
- Business registered, and any telemarketing registration required in your jurisdiction obtained.
- Written contract with the client covering lead provenance, consent records, and compliance responsibility.
- DNC scrubbing process in place, with retained logs, running at required frequency.
- Internal DNC list implemented in the dialer and honoured immediately.
- Calling hours configured per destination time zone in the campaign, not per your local clock.
- Abandon rate monitored against the applicable ceiling, with dialer tuned accordingly.
- Caller ID set to a DID you legitimately control and have registered.
- Recording announcement automated at call start.
- Recording retention period defined and enforced.
- Agent scripts include mandatory identification and disclosure.
- DPA signed where EU or UK personal data is processed.
- Complaint log maintained, with a defined escalation path.
The client-supplied list problem
The most common way a well-intentioned center acquires liability: a client hands over a list and says it is clean.
Under the TCPA and most equivalent regimes, the party placing the call carries liability. That is you. A client's verbal assurance is not a defence.
Insist on:
- A written warranty that the data was lawfully obtained and lawfully callable.
- The actual consent records, or the ability to obtain a specific record on demand.
- Indemnification for claims arising from the data.
- Your own right to scrub the list independently before dialing.
A client who declines all four is asking you to absorb a risk they understand better than you do.
Where to go next
- How to find call center processes and clients — contract terms that protect you.
- ViciDial installation guide — configuring calling hours, abandon limits, and recording.
- DIDs and caller ID reputation — keeping your numbers out of spam labelling.
- How to start a call center with $200 — the wider startup picture.
CloudyVoice requires traffic review and lawful-use confirmation before activating outbound routes. That is not a formality — it protects your account and our routes from the carrier-level blocking that follows non-compliant traffic.
Frequently asked questions
What is the fine for a TCPA violation?
Statutory damages under the US TCPA are 500 dollars per violation, rising to 1,500 dollars per violation for wilful or knowing breaches. Because each individual call is a separate violation and the statute carries a private right of action, class actions routinely reach seven and eight figures. This is the single largest legal risk in outbound calling to the United States.
How often must I scrub against the US Do Not Call registry?
Telemarketers covered by the FTC Telemarketing Sales Rule must scrub their lists against the National Do Not Call Registry at least every 31 days. Keeping proof of when each scrub occurred is part of the safe-harbour defence, so retain the logs.
Do I need consent to record calls?
It depends on jurisdiction. Some US states require only one party to consent, meaning your agent's knowledge suffices; others including California, Florida, Illinois, Pennsylvania, and Washington require all parties to consent. The UK and EU require you to inform the caller and have a lawful basis under GDPR. Because a single campaign often crosses these lines, most centers simply announce recording on every call.
What is the maximum abandoned call rate?
Under the US FTC Telemarketing Sales Rule the limit is 3 percent of answered calls, measured per campaign over a 30-day period, with a two-second connection requirement. UK Ofcom policy applies a comparable 3 percent ceiling. Predictive dialers must be tuned against these limits, not just against agent utilisation.