DNC, calling windows and consent: the operational version
Most compliance advice for outbound is either a legal disclaimer or a scare story. This is the operational version: which controls belong in your dialer rather than in a rep's memory, and why that distinction is the whole game.
A note before anything else: this is not legal advice, and outbound calling rules vary by jurisdiction and change often. Talk to a lawyer about your specific situation. What follows is the operational layer — how teams that stay out of trouble actually configure things.
The single most useful idea here is this: every compliance control you implement as a rule a rep has to remember is a control you do not have. Reps are fast, tired, and incentivised on dials. Anything left to their judgement at 4:55pm on a Friday will eventually go the wrong way. The controls that work are the ones enforced by the system, where breaking them is not possible rather than merely discouraged.
Everything below is organised around that.
Do-not-call is more than one list
Most teams think of DNC as a single national registry. In practice you are reconciling several lists at once, and the one that causes the most trouble is the one you maintain yourself.
The national registry. In the US this is the FTC's Do Not Call registry. Access requires registration, and the practical point is that scrubbing against it cannot be an annual chore — the registry changes continuously and stale scrubbing is close to no scrubbing.
State registries. Several states run their own, with their own rules. If you dial nationally you are scrubbing against more than one list.
Your internal list. This is the one that bites. When someone tells your rep "take me off your list," that is a request you are obliged to honour, and it has to persist — across reps, across lists, across CRM re-imports, and across the day six months from now when someone uploads a purchased list that happens to include that person again.
That last scenario is the classic failure. The suppression was recorded as a CRM note, or a disposition, or in a rep's head. Then a fresh list lands, the number comes back in, and you call someone who explicitly asked you not to. Nobody decided to do that. The system just had no memory.
The fix is structural: internal suppression has to live at the account level and be applied at dial time to every list, permanently, with no path for an import to override it.
Calling windows, and the timezone trap
The general rule in the US is calling between 8am and 9pm, and the detail that catches people is that those hours are the prospect's local time, not yours.
This sounds obvious and is routinely got wrong, because area code is a poor proxy for location. Mobile numbers keep their area code when people move. A 212 number can sit in California. If you calculate calling windows from the area code you will confidently dial people at 6am.
Several states also impose tighter windows than the federal default, and some restrict calling on Sundays or holidays. Again: these are not things to put on a wiki page for reps to consult. They are things your dialer should enforce by refusing to place the call.
The practical test for any dialer you are evaluating: can a rep dial a number outside its permitted window if they really want to? If the answer is yes, the control is advisory.
Consent, and knowing which rules you are under
Consent is where the rules diverge most sharply by jurisdiction and by what you are doing.
The distinctions that matter operationally:
Manual versus automated dialing is treated differently, and the definitional boundary has been actively litigated. If your dialer uses any automated technology, assume the stricter interpretation applies to you until a lawyer tells you otherwise.
Existing business relationships can change what is permitted, which means your system needs to know which category a given contact falls into — and that has to come from data, not from a rep's recollection.
Mobile numbers generally attract stricter treatment than landlines, so knowing which you are dialing is not a nice-to-have.
Recording consent is its own separate question, and it is the one teams most often miss. Some jurisdictions require all parties to consent to a call being recorded, others only one. If you record everything by default and dial nationally, you need to know which rule applies to each call and handle it accordingly.
What this means practically is that consent state has to be a field you can act on, with a recorded basis and a date, rather than an assumption baked into a list you bought.
Recording and retention
If you record calls — and most teams do, for coaching — you have taken on a data obligation alongside the compliance one.
Decide your retention period deliberately and enforce it automatically. "We keep everything forever" is a decision, and usually the wrong one: every recording you hold is something you may have to produce, secure, and delete on request. Recordings contain personal data, which brings privacy regimes into scope depending on who you called.
The operational shape is: a retention period set at account level, deletion that happens on schedule without anyone remembering to run it, and access controls so that recordings are not casually browsable by the whole floor.
What good configuration looks like
If you are auditing your own setup, these are the questions worth asking:
- Can a rep dial a number on any suppression list? If yes, that is your highest-priority gap.
- Does an internal do-not-call request survive a CRM re-import?
- Are calling windows computed from the prospect's actual location or from their area code?
- Can a rep dial outside a permitted window?
- Do you know, per contact, whether you are dialing a mobile and what your consent basis is?
- Is there a retention period on recordings, and does deletion actually happen?
- Could you reconstruct, for a specific call six months ago, why you were permitted to make it?
That last one is the real test. Compliance is much less about intent than about being able to demonstrate the basis for what you did, after the fact, without relying on anyone's memory.
The short version
Cold calling is legal and most teams doing it are doing it legitimately. The teams that get into trouble rarely set out to break a rule — they had a control that depended on a person remembering something, and one day the person did not.
Move the controls into the system. Then the compliance question stops being "did everyone behave correctly today" and becomes "is the configuration right," which is a question you can actually answer.