Avoid $1,500 Fines: DNC Compliance Rules for U.S. Compliance Officers

U.S. businesses making outbound sales calls must scrub every calling list against the National Do Not Call Registry at least once every 31 days, maintain an internal Do Not Call list, and honor opt-out requests immediately. Calls must stay inside the 8 a.m. to 9 p.m. local-time window, and every scrub, registry download, and consent record needs a timestamp. Skip any of that, and Safe Harbor protection disappears. Do it right, and one habit matters more than any other: run the scrub, log it, and prove it happened.
TL;DR:
- Businesses must run automated 31-day scrubs against the national DNC list, log each action, and retain proof of compliance for audit readiness.
- Opt-out requests must be enforced immediately with automated suppression, not manual updates, to ensure Safe Harbor protection.
- DNC compliance and TCPA consent verification are separate processes requiring parallel checks, especially for mobile numbers and vertical-specific rules.
- Multi-state callers need to scrub both federal and applicable state DNC lists, as different states maintain their own registries without obsolescence.
- Integrated, automated platforms that unify scrubs, consent records, and suppression logs reduce legal risk and support scalable compliance during business growth.
Table of Contents
- What Are the Core DNC Compliance Rules for Businesses?
- What Do the TSR and TCPA Actually Require?
- How Often Must You Scrub the National DNC List for Safe Harbor?
- When Can You Legally Call a Number on the DNC List?
- Which States Run Their Own DNC Lists?
- How Much Can DNC and TCPA Violations Cost You?
- How Do You Build Operational Controls That Actually Hold Up?
- What Should You Demand From a Compliance Technology Vendor?
- What Scaling a Compliant Calling Program Actually Looks Like
- Why Most Compliance Programs Fail Before the Fine Ever Arrives
- Get DNC Compliance Built Into Your Calling Infrastructure, Not Bolted On
- Sources
- FAQ
What Are the Core DNC Compliance Rules for Businesses?
Compliance officers rarely fail because they don’t know the rules exist. They fail because the rules live in three different places (the Federal Trade Commission, the Federal Communications Commission, and a patchwork of state registries) and nobody owns the full picture. Here’s the short list to fix that today.
- Get registry access and automate the 31-day scrub. Register through Donotcall and certify your lawful use, then schedule scrubs on a recurring cycle. This is not optional. The Federal Trade Commission requires telemarketers and sellers to check the National DNC Registry at least once every 31 days for any campaign selling goods or services by phone.
- Suppress opt-outs the moment they happen. A consumer who says “take me off your list” goes into your internal Do Not Call list instantly, not at end of shift.
- Lock down consent and EBR records. Every number you call outside the registry needs a documented reason, timestamped and tied to a specific consumer.
- Enforce calling windows and disclosure scripts. Train agents on hours, required identification, and the prohibition on collecting certain payment types over the phone.
- Log everything. Registry downloads, scrub outputs, and internal suppression timestamps are the only evidence that will hold up in an audit.
Pro Tip: Don’t treat the 31-day scrub as a calendar reminder for someone to “get to.” Automate it as a system job with a confirmation log, the same way you’d treat a payroll run. Manual reminders are the single most common reason mid-size telemarketing operations lose Safe Harbor protection.
What Do the TSR and TCPA Actually Require?
Two federal frameworks govern outbound calling, and they overlap just enough to confuse most operations teams. The Telemarketing Sales Rule (TSR) is enforced by the Federal Trade Commission and governs any plan, program, or campaign to sell goods or services through interstate telephone calls. If your business dials consumers to pitch a product, the TSR applies to you, full stop.
The TSR’s core mechanism is the National Do Not Call Registry. Once a consumer’s number is on it, calling that number for sales purposes is illegal unless a specific exemption applies. The rule also dictates caller ID transmission requirements, mandatory identification disclosures early in the call, and restrictions on collecting payment through certain methods (wire transfers and cash reload cards, for instance) that regulators associate with fraud.
The Telephone Consumer Protection Act (TCPA) is a different statute with a different regulator. The Federal Communications Commission enforces TCPA rules covering robocalls, autodialed texts, and prerecorded messages, with a sharp focus on mobile numbers. Under the TCPA, robocalls that sell goods or services are illegal without prior express written consent from the recipient. That consent requirement is stricter than anything in the TSR, and it applies whether or not the number is on the DNC Registry.
Here’s where the confusion starts. A business can be fully DNC compliant and still violate the TCPA, because the TCPA cares about how the call is placed (autodialer, prerecorded voice, text) and what consent exists, independent of registry status. A live agent manually dialing a number not on the DNC list can still violate the TCPA if that number is a mobile line called without consent using an autodialer configuration the FCC considers automated. Conversely, a business can hold valid TCPA consent for texting a customer and still violate the TSR if that same customer’s number is on the DNC Registry and no exemption covers the sales call.
Practically, this means your compliance program needs two separate checks running in parallel: a DNC scrub and a consent verification. Treating them as one system is where most gaps open up. If your outbound calling program touches insurance, real estate, or healthcare lead generation, the stakes compound because these industries already sit under additional consent frameworks. RevRing’s own guidance on TCPA compliance for insurance calling programs breaks down how licensed agents in regulated verticals typically structure that dual check.

The operational obligations that flow from both rules are concrete: transmit accurate caller ID, disclose your business identity and purpose within the opening seconds, offer a live connection when required, and never solicit payment through prohibited methods. None of these are judgment calls. They are pass/fail items on any FTC or FCC review.
How Often Must You Scrub the National DNC List for Safe Harbor?
Every 31 days, without exception, for any interstate telemarketing campaign. That’s the number regulators check first, and it’s non-negotiable for businesses that want Safe Harbor protection against inadvertent violations.
Safe Harbor doesn’t erase mistakes. It excuses them, but only for businesses that can prove the mistake was genuinely accidental despite a functioning compliance program. To claim it, the FTC requires four specific elements:
- A written DNC policy available to staff, not a verbal understanding passed down from a manager.
- Documented training for anyone involved in telemarketing calls, with records of when and how that training occurred.
- An internal DNC list that captures every opt-out request your business receives, separate from the national registry.
- Records of registry access, meaning proof you downloaded and applied the National DNC Registry data at least every 31 days.
Regulators don’t accept “we usually scrub monthly” as evidence. They want the file. That means time-stamped registry download files, scrub output logs showing which numbers were suppressed and when, and internal DNC timestamps showing the exact moment an opt-out request was processed. One industry review puts it bluntly: Safe Harbor is defensive, and it only protects you if you can produce dated records of the download and scrub process, not just an assertion that one happened.
The most common failure mode isn’t a missing policy. It’s a policy that exists on paper but relies on agents manually logging opt-outs into a CRM note field. Manual opt-out logging without automated verification is a frequent cause of inadvertent violations, because notes get skipped during busy shifts, misspelled numbers slip through, and there’s no audit trail proving the suppression happened at the moment the consumer asked for it. Automated suppression, where a verbal opt-out triggers an immediate system-level block rather than a manual entry, closes that gap and gives you the evidence chain regulators actually want to see.
When Can You Legally Call a Number on the DNC List?
A handful of narrow exceptions let you call a registered number, and every one of them depends on documentation you need to produce on demand.
The established business relationship (EBR) exemption is the one most companies rely on and most companies misapply. It allows a call if the consumer made a purchase, rental, or lease from your business within the last 18 months, or made an inquiry or application within the last 3 months. The FTC’s own guidance confirms this EBR window applies as long as the consumer hasn’t separately asked to be placed on your internal DNC list, which overrides the EBR regardless of how recent the transaction was.
Beyond EBR, a short list of call categories fall outside DNC rules entirely:
- Political calls on behalf of candidates or campaigns.
- Charitable solicitations from nonprofits (though some states still apply their own restrictions here).
- Debt collection calls tied to an existing obligation.
- Purely informational calls with no sales pitch, such as appointment reminders or service notifications.
- Business-to-business calls, which generally sit outside TSR coverage when there’s no consumer transaction involved.
Every exemption has the same trap: the moment a call shifts from informational to promotional, the exemption disappears. A reminder call that pivots into an upsell pitch is now a telemarketing call subject to the full DNC framework.
For robocalls and texts specifically, the bar is higher. The TCPA requires prior express written consent, meaning a signed or electronically signed agreement that clearly discloses the consumer is authorizing automated calls or texts for marketing purposes, and that consent isn’t a condition of purchase. A checkbox buried in fine print won’t survive a challenge. As one industry compliance review notes, documented consent with a retained audit trail is the strongest defense a business can build, because ignoring an opt-out request even once is enough to trigger TCPA penalties.
Which States Run Their Own DNC Lists?
Eleven states maintain DNC registries separate from the national one, and calling a number that’s clear on the federal list but registered at the state level is still a violation. Businesses running multi-state campaigns need to check both layers every time.
| State | Notable compliance detail |
|---|---|
| Colorado | Maintains its own No-Call list alongside the national registry |
| Florida | Governed by the Florida Telemarketing Act with separate registration rules |
| Indiana | State-specific registry requires separate compliance checks |
| Louisiana | Operates its own Do Not Call list |
| Massachusetts | State registry layers on top of federal requirements |
| Missouri | Maintains a distinct No-Call database |
| Oklahoma | Separate state-level registry applies |
| Pennsylvania | State DNC list operates independently of the national registry |
| Tennessee | Requires checks against its own No-Call database |
| Texas | Maintains a state registry with distinct registration steps |
| Wyoming | Operates its own Do Not Call list |
These state registries exist because several states built their own DNC lists before or alongside the national registry, and none of them were retired once the federal system launched. For a business calling into any of these eleven states, the national scrub is necessary but not sufficient.
Operationalizing this means geo-tagging every number in your calling list by state before a campaign launches, running the applicable state-list scrub in addition to the federal one, and retaining proof that each check occurred, not just that it was scheduled. Where a state rule is stricter than the federal rule (shorter registry-check intervals, tighter calling hours, or additional registration requirements for the callers themselves) the stricter rule wins. Multi-state compliance isn’t one system with an add-on. It’s two systems that both have to pass.
How Much Can DNC and TCPA Violations Cost You?
Regulatory fines for DNC violations run into the tens of thousands of dollars per call under FTC enforcement authority, and TCPA private lawsuits carry statutory damages of $500 to $1,500 per call when a violation is found willful. A single bad campaign, dialing a suppressed list of a few thousand numbers, can generate liability that dwarfs the cost of the compliance program that would have prevented it.
The mechanics matter here: each individual call to a number that should have been suppressed counts as a separate violation, not one blanket infraction. That’s how enforcement actions and class-action suits reach eye-watering totals from what started as one flawed list upload or one skipped scrub cycle.
Common enforcement triggers include:
- Consumer complaints filed directly with the FTC after receiving a sales call despite DNC registration.
- Patterns of complaints against a specific caller ID or campaign flagged by state attorneys general.
- Plaintiff’s attorneys running number audits against public DNC status specifically to build TCPA class actions.
- Vendor or lead-source failures, where a purchased list wasn’t properly scrubbed before use, and the buyer still bears liability.
Enforcement comes from four directions: the FTC pursuing TSR violations, the FCC pursuing TCPA and robocall violations, state attorneys general enforcing their own registries, and private plaintiffs filing individual or class-action TCPA suits. Outcomes range from civil monetary penalties and consent decrees to court-ordered injunctions halting a calling program entirely. Regulators also lean on consumer complaint volume to prioritize which companies get investigated first, since the registry itself only prevents lawful companies from calling and depends on complaint reporting to catch violators.
How Do You Build Operational Controls That Actually Hold Up?
Policies on paper don’t stop violations. Systems do. Here’s the operational sequence that separates businesses with a real compliance program from businesses with a compliance document nobody follows.
- Automate scrubs on a fixed schedule, not a reminder. Set the 31-day cycle as a system job that produces a confirmation log every time it runs, with the file retained for audit purposes.
- Standardize consent capture at the point of collection. Every signed or e-signed consent record needs to map to a specific phone number, a specific campaign, and a specific date, stored in a searchable consent repository rather than scattered across spreadsheets.
- Build agent scripts around disclosure requirements, not around sales optimization alone. The opening seconds of a call need business identification and purpose before anything else.
- Push compliance clauses into vendor contracts. Any third party supplying leads or making calls on your behalf should be contractually required to provide registry access logs and sample audit exports on request.
- Monitor complaint volume and escalation paths. Track compliance KPIs the same way you’d track conversion rate, and route consumer complaints to a compliance owner immediately, not to a general support queue.
Pro Tip: Run a quarterly internal audit as if a regulator were about to ask for it. Pull a random sample of 20 calls, trace each one back to its consent record or EBR justification, and time how long it takes your team to produce that evidence. If it takes more than a few minutes per call, your recordkeeping system has a gap that a real investigation would expose fast.
Vendor management deserves special attention because outsourced calling is where a lot of DNC exposure actually originates. A partner resource on compliance in regulated communications makes a point that applies directly here: regulated businesses that outsource customer-facing communication still carry the compliance liability, even when the vendor made the mistake. The same logic applies to third-party dialing vendors and purchased lead lists. If your provider can’t hand you a scrub log, that’s a contract problem waiting to become a legal one. For internal teams managing this directly, tracking how quickly leads move from capture to first contact also matters for consent timing, and speed-to-lead benchmarks offer a useful reference point for where that response window typically sits.
What Should You Demand From a Compliance Technology Vendor?
Not every dialer platform that claims “DNC compliant” actually gives you the audit trail regulators expect. Before you trust a vendor’s compliance claims, verify the specific technical capabilities that back them up.
The essentials to require:
- Automated 31-day scrub cycles with a visible confirmation log, not a manual trigger someone has to remember to click.
- Time-stamped registry download records that show exactly when the National DNC Registry data was pulled and applied.
- Integrated internal DNC suppression, meaning an opt-out during a live call triggers immediate system-level blocking, not a manual CRM note that gets processed later.
- A centralized consent repository that ties written consent records to specific phone numbers and campaigns, addressing the dual-scrub problem where a number is DNC-registered but has separate documented consent, or vice versa. This overlap is exactly why compliance programs need both a DNC scrub and a consent database running independently rather than conflating the two.
- Exportable audit logs that a compliance officer can pull on demand, not a report that requires a support ticket to generate.
Before signing with any vendor, ask for a sample audit export, not a sales deck description of one. Confirm the actual scrub cadence in writing, verify how long consent and suppression records are retained, and talk to an existing customer if possible. An employer resources guide on recordkeeping practices makes the broader point well: documentation systems only earn trust when they’ve been stress-tested by an actual audit request, not when they look clean in a demo.
The practical advantage of an integrated platform over a stitched-together stack of point tools is straightforward: fewer handoff points means fewer places for a suppression record to get lost between systems. When your dialer, your CRM, and your consent database are three separate vendors, a number suppressed in one system doesn’t automatically suppress in the others unless someone builds and maintains that connection manually.
What Scaling a Compliant Calling Program Actually Looks Like
Compliance programs get tested hardest during growth, not during steady state. RevRing built its compliance infrastructure around that exact pressure point, working with clients scaling outbound teams from roughly 12 agents to 180 while keeping every scrub, consent record, and suppression event auditable across that entire growth curve.
The lesson from that kind of scaling isn’t a single feature. It’s sequencing. Automation has to come before headcount, not after. A business that adds 50 new agents before automating its opt-out suppression is multiplying its manual-error surface by 50. Get the automated scrub, the consent repository, and the suppression triggers running first, and new agents plug into a system that already enforces the rules instead of a system that depends on them remembering the rules.
The gap between a compliance program that works at 12 seats and one that survives at 180 seats is never the written policy. It’s whether suppression and consent checks run automatically, before a single dial goes out, regardless of how many agents are dialing at once.
RevRing’s clients report faster lead response times and cleaner lead management once that automation layer is in place, precisely because agents stop spending time on manual suppression checks and start spending it on the call itself. Training cadence still matters. So does evidence retention. But neither one scales without the automated backbone underneath it.
Why Most Compliance Programs Fail Before the Fine Ever Arrives
The conventional advice on DNC compliance treats it as a documentation exercise: write the policy, train the staff, check the box. That framing misses the actual failure point, which is almost always operational, not procedural. Businesses that get fined usually had a written policy. They just didn’t have a system that enforced it in real time.
The checklist approach this guide leads with matters because it forces the sequencing question: what has to happen automatically, before a human can forget to do it? A 31-day scrub that depends on someone remembering to run it isn’t a control. It’s a hope. The same goes for opt-out logging that lives in a manual CRM note instead of triggering an instant suppression event.
If there’s one place readers should focus first, it’s the gap between DNC registry status and TCPA consent, because that’s where dual-compliant, well-intentioned businesses still get sued. Treating those as one check instead of two independent systems is the single most underestimated risk in this entire framework. Fix the automation gap before worrying about the paperwork. The paperwork is easy once the system is doing the work.
— Marc
Get DNC Compliance Built Into Your Calling Infrastructure, Not Bolted On
Most compliance fixes get bolted onto an existing dialer setup after a near miss, which means the suppression logic, the consent records, and the calling engine all live in different systems that don’t talk to each other reliably. Revring built the opposite: automated 31-day registry scrubs, an internal DNC suppression layer that triggers the moment an agent logs an opt-out, and a consent repository tied directly to your calling campaigns, all inside one platform instead of stitched across three.

That integration is what lets growing teams scale their agent count without multiplying their compliance risk at the same rate. If you’re evaluating whether your current stack can actually produce a clean audit export on demand, that’s the question worth answering before your next campaign launch, not after a complaint lands. Explore the Predictive Dialer platform to see how scrub automation and suppression work at the call level, or check out ZinCRM for how consent records and audit logs stay tied to every contact. Ready to see it running against your own lists? Request a demo and ask for a sample audit export as part of the walkthrough.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Q&A for Telemarketers & Sellers About DNC Provisions in TSR | Federal Trade Commission
- Consumer
- Donotcall
- Federal Communications Commission
FAQ
What Calls Are Exempt From the DNC Registry?
Political calls, charitable solicitations, debt collection calls, purely informational calls with no sales pitch, and business-to-business calls generally fall outside DNC rules, along with calls covered by an established business relationship or documented consent.
What Are Three Rules Telemarketers Have to Follow?
Telemarketers must scrub their calling lists against the National DNC Registry at least once every 31 days, disclose their business identity and purpose early in the call, and honor opt-out requests immediately by adding the number to an internal Do Not Call list.
Is It Illegal to Call Someone on the DNC List?
Yes, unless a specific exemption applies, such as an established business relationship within the required time window, documented prior consent, or one of the exempt call categories like political or charitable calls.
What Is TCPA and DNC Compliance?
DNC compliance means honoring the National Do Not Call Registry and any applicable state lists for sales calls, while TCPA compliance covers the separate requirement for prior express written consent before placing robocalls or automated texts, especially to mobile numbers. A fully compliant program, like the dual-scrub approach RevRing’s platform is built to support, checks both systems independently rather than treating them as one requirement.