ColdCalls.ai
All posts
Compliance

Do Not Call List Rules for Businesses: A 2026 Compliance Guide

Do Not Call rules for businesses in 2026: federal and state DNC registries, the TCPA, calling hours, the EBR exception, B2B vs consumer, penalties and how to stay compliant.

By the ColdCalls.ai team

July 2026 · 10 min read

Businesses that make telemarketing calls to consumers must scrub every number against the National Do Not Call Registry at least every 31 days, call only between 8 a.m. and 9 p.m. in the recipient's local time, honor any opt-out request, and keep records for five years. Business-to-business calls are generally exempt from the National Registry, but the TCPA still governs calls to cell phones and calls that use an autodialed or artificial or prerecorded voice, including AI voices. Penalties are steep: up to $53,088 per violation under the FTC's rule and $500 to $1,500 per call under the TCPA.

This is general information for United States businesses, not legal advice. Do Not Call and TCPA rules carry real financial exposure, and state laws add requirements on top of the federal ones, so confirm your specific obligations with counsel before running a calling campaign.

What are the Do Not Call rules for businesses?

The core Do Not Call rules come from two federal sources: the FTC's Telemarketing Sales Rule, which runs the National Do Not Call Registry, and the FCC's rules under the Telephone Consumer Protection Act, or TCPA. Together they require a telemarketer to check the National Registry, maintain an internal do-not-call list, disclose who is calling and why, restrict calling hours, and get the right kind of consent before using automated technology. The rules apply to the company on whose behalf the call is made, not just the vendor dialing, so you cannot outsource away liability.

RequirementWhat it meansSource
Scrub the National RegistryRemove registered numbers, re-scrub at least every 31 daysFTC Telemarketing Sales Rule
Calling hours8 a.m. to 9 p.m. in the called party's local time zoneTCPA / TSR
Internal do-not-call listHonor any opt-out and never call that number againTCPA / TSR
Consent for autodialed / artificial-voice callsPrior express written consent for telemarketing to cell phonesTCPA (FCC)
Caller identificationTruthful caller ID and identify the seller and purposeTCPA / TSR
Record retentionKeep call and consent records for five yearsAmended FTC TSR

Does the Do Not Call list apply to B2B calls?

The National Do Not Call Registry generally does not apply to business-to-business calls, only to calls made to consumers about personal goods and services. Calling a business line to sell an office product is largely outside the National Registry. That exemption is narrower than it sounds, though. If you call a sole proprietor or a small operator on a number that doubles as a personal cell, courts have treated those as consumer calls, and the TCPA's separate restrictions on autodialed and artificial-voice calls to wireless numbers still apply regardless of whether the call is B2B. Do not treat "it's B2B" as blanket permission to skip compliance.

What is the established business relationship exception?

The established business relationship exception, or EBR, lets you call a consumer on the National Registry if they recently did business with you. Under the FTC's rule, an EBR exists if the person made a purchase from you within the last 18 months, or made an inquiry or application within the last 3 months. The exception covers the National Registry only. It does not override an internal opt-out: if that same customer has told you to stop calling, you must stop, EBR or not. And the EBR does not by itself satisfy the TCPA's separate consent requirement for autodialed or artificial-voice calls.

Do state Do Not Call laws add requirements?

Yes. A number of states run their own do-not-call registries and telemarketing statutes that are often stricter than federal law, so scrubbing only the National Registry is not enough. Florida's Telephone Solicitation Act, for example, is a well-known state "mini-TCPA" with its own consent rules and private right of action, and states including Oklahoma, Texas and others have passed similar laws in recent years. The safe practice is to scrub against both the National Registry and any applicable state registry, apply the strictest calling-hour and consent rule among the jurisdictions involved, and treat a lead's location, not your own, as the controlling law. When a specific statute or a recent ruling matters to your situation, it is worth researching the exact rule in plain English before you rely on a summary.

What are the penalties for Do Not Call violations?

Penalties come from two directions and stack. The FTC can seek civil penalties of up to $53,088 per violation under the Telemarketing Sales Rule, an amount adjusted for inflation and current for 2026. Separately, the TCPA gives the person you called a private right of action worth $500 per violation, rising to $1,500 per violation for willful or knowing conduct, with no cap on the number of calls. Because damages are per call, a single bad list dialed at scale can turn into a class action with exposure in the millions. That is why the discipline below is not optional.

How do businesses stay compliant when cold calling?

Staying compliant comes down to a short, repeatable checklist applied to every campaign. None of it is complicated, but all of it has to happen before the first dial, because a violation is created the moment the call connects.

  • Scrub every list against the National Registry and any applicable state registry, and re-scrub at least every 31 days.
  • Maintain and honor an internal do-not-call list the instant anyone opts out.
  • Call only between 8 a.m. and 9 p.m. in the prospect's local time zone.
  • Get prior express written consent before using an autodialer or an artificial or prerecorded voice to telemarket to a cell phone.
  • Identify who is calling and why, with truthful caller ID.
  • Keep call and consent records for five years.

How does AI cold calling handle Do Not Call compliance?

A well-built AI cold calling system enforces these rules automatically on every call, which is where automation actually reduces legal risk rather than adding to it. The FCC clarified in February 2024 that AI-generated voices are "artificial" under the TCPA, so an AI calling tool has to meet the same consent and disclosure standards as any prerecorded telemarketing, and updated 2025 rules require honoring an opt-out within a reasonable time, not to exceed 10 business days. A compliant agent scrubs DNC in real time, respects calling hours by the prospect's time zone, discloses that it is an AI, suppresses any number that says stop, and logs every outcome for the record.

That is exactly how TCPA-compliant AI calling is designed to work here: disclosure on every call, real-time registry scrubbing, consent-aware dialing and calling hours you control, with a full audit trail. If you want the deeper legal breakdown, our guide to whether AI cold calling is legal walks through the TCPA, the DNC framework and the AI-voice disclosure rules in more detail.

Compliance is not a reason to avoid outbound calling. It is a reason to run it on a system that treats scrubbing, consent and calling hours as defaults rather than as settings a rushed rep has to remember. Handle the rules correctly and the phone stays one of the most direct, profitable channels a business has.

See ColdCalls.ai book meetings

The AI SDR calls every lead, discloses it is an AI, qualifies, handles objections and books meetings into your calendar and CRM. Flat fee, no per-meeting cut, compliance built in.

Put your outbound on autopilot

ColdCalls.ai calls every lead, discloses it is an AI, qualifies, handles objections and books meetings into your calendar and CRM. Flat fee, no per-meeting cut, compliance built in.

AI disclosed & DNC scrubbed · Call, qualify, book · No per-meeting cut

AI disclosed on every call · real-time DNC scrubbing · TCPA and consent-aware.