Call Center Regulations: TCPA, Do Not Call, and PCI Compliance

Call center regulations are the set of federal rules, industry standards, and state laws that govern how businesses can place outbound calls, handle consumer data, and record conversations. The two federal statutes doing most of the work are the Telephone Consumer Protection Act (TCPA), which controls autodialing and prerecorded messages, and the Federal Trade Commission’s Telemarketing Sales Rule (TSR), which governs sales conduct, do-not-call compliance, and required disclosures. Layered on top are caller ID authentication requirements, federal and state recording-consent laws, payment card security standards, and, for health-related calls, HIPAA. Penalties run from $500 per unwanted call to more than $50,000 per deceptive sales practice, and the math compounds quickly when a dialer places thousands of calls a day.

Autodialer and Prerecorded Message Rules

The TCPA, codified at 47 U.S.C. § 227, makes it illegal to call or text someone using an automatic telephone dialing system or a prerecorded voice without the right kind of consent. The statute defines an autodialer as equipment that can store or produce phone numbers using a random or sequential number generator and then dial them.1Office of the Law Revision Counsel. 47 USC 227 – Restrictions on Use of Telephone Equipment

The consent standard depends on the call’s purpose. Non-marketing calls such as appointment reminders, shipping updates, and account alerts require “prior express consent,” which is generally satisfied when a customer provides their number during a transaction. Telemarketing calls placed with an autodialer or prerecorded message require the higher standard of “prior express written consent”: a signed agreement (electronic signatures count) in which the consumer specifically authorizes your company to contact them using automated technology for marketing. You cannot make that signature a condition of buying your product.2Federal Communications Commission. One-to-One Consent Rule for TCPA Prior Express Written Consent

The FCC has moved to tighten this further under a one-to-one consent framework, which redefines written consent as authorization for a single, specifically named seller rather than a blanket agreement covering a list of marketing partners. Each company would need its own consent, and the product marketed would have to be logically related to what the consumer was looking at when they opted in. The FCC postponed the effective date pending a legal challenge in the Eleventh Circuit, so the timeline remains uncertain into 2026.3Federal Communications Commission. FCC Postpones Effective Date of One-to-One Consent Rule Call centers that rely on purchased leads should still restructure their consent flows now, because old-style multi-seller forms will be worthless once the rule takes effect.

Damages under the TCPA are $500 per violation, tripled to $1,500 if the court finds the violation willful or knowing.1Office of the Law Revision Counsel. 47 USC 227 – Restrictions on Use of Telephone Equipment Per call, that reads modest. In class actions covering millions of calls, settlements routinely land in eight or nine figures, which is why TCPA exposure is the single highest-stakes issue for most outbound operations.

Calling Hours and Abandoned Calls

The TSR prohibits outbound telemarketing calls to a residence before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone.4eCFR. 16 CFR 310.4 – Abusive Telemarketing Acts or Practices Your dialing platform has to key on the called number’s time zone, not the agent’s location. A 6:00 p.m. call from a California floor lands in New York at 9:00 p.m., right at the cutoff. Some states impose tighter windows, and calls into those states have to honor the more restrictive rule.

The TSR also caps abandoned calls. When a predictive dialer connects a consumer to a line and no agent picks up within two seconds, the call is abandoned. Your abandonment rate cannot exceed 3 percent of calls answered by a live person, measured over a rolling 30-day window. When an agent isn’t available in that two-second window, the system must play a prerecorded message identifying the seller and giving a callback number. Exceed the 3 percent ceiling and each abandoned call becomes its own violation.

Do Not Call Compliance

Every call center placing outbound sales calls has to scrub its contact lists against the National Do Not Call Registry maintained by the FTC. The scrub has to happen at least every 31 days, and registry data older than that cannot be used to place a call.4eCFR. 16 CFR 310.4 – Abusive Telemarketing Acts or Practices

Access to the registry requires a paid annual subscription. For fiscal year 2026, the fee is $82 per area code, with the first five area codes free. The maximum fee for a single entity accessing all area codes nationwide is $22,626.5Federal Trade Commission. Telemarketer Fees to Access the FTCs National Do Not Call Registry to Increase in 2026

Separately, every seller must maintain a company-specific do-not-call list. When a consumer tells you to stop calling, you have to honor that request immediately and keep the number on your internal list indefinitely.6Federal Trade Commission. Q and A for Telemarketers and Sellers About DNC Provisions in TSR The internal list is independent of the national registry. A consumer who never registered nationally can still opt out from your company alone.

Safe Harbor for Good-Faith Errors

The TSR provides a safe harbor for accidental calls to numbers on the national registry or your internal list, but only if you can show all of the following:

  • Written compliance procedures for do-not-call obligations, established and implemented.
  • Training on those procedures for your agents and any third parties assisting with compliance.
  • A version of the national registry obtained no more than 31 days before the call.
  • Active monitoring and enforcement of your written procedures.
  • The violation resulted from a genuine mistake, not from a failure to collect or process an opt-out.

All five conditions must be satisfied. Miss one, such as letting your registry subscription lapse a few days too long, and the safe harbor is gone.4eCFR. 16 CFR 310.4 – Abusive Telemarketing Acts or Practices

Required Sales Disclosures

The TSR dictates what agents must say on an outbound telemarketing call and when they must say it. Before any sales pitch, the caller has to promptly disclose the identity of the seller, state that the purpose of the call is to sell something, and identify the specific product or service being offered. Skipping or burying those upfront disclosures is an unfair or deceptive practice under the rule.4eCFR. 16 CFR 310.4 – Abusive Telemarketing Acts or Practices

Before the consumer agrees to pay, the agent must also disclose every material term of the deal: total cost, any restrictions or conditions, and the refund or cancellation policy. Omitting a material term that would have changed the purchasing decision violates the FTC Act. Civil penalties for TSR violations exceed $50,000 per violation and are adjusted upward for inflation each year, so a single deceptive campaign touching thousands of consumers can produce penalties in the tens of millions.

Caller ID and STIR/SHAKEN

Federal law at 47 U.S.C. § 227(e) prohibits transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm, or obtain anything of value. Civil penalties run up to $10,000 per incident, with continuing violations capped at $1,000,000. Willful and knowing violations carry criminal fines at the same levels.1Office of the Law Revision Counsel. 47 USC 227 – Restrictions on Use of Telephone Equipment For call centers, the number a recipient sees has to be accurate and callable. Displaying a fake local number to lift answer rates, sometimes called “neighbor spoofing,” is exactly the conduct this law targets. Several states also mandate that the business name appear on the caller ID display.

The FCC now requires voice service providers to implement STIR/SHAKEN, a caller ID authentication framework that digitally verifies a call actually originates from the number shown. Most providers have been required to use the system since 2021, and those on older non-IP networks must either upgrade or develop an equivalent authentication solution.7Federal Communications Commission. Combating Spoofed Robocalls with Caller ID Authentication Call centers don’t implement STIR/SHAKEN directly; their carriers do. The practical effect is still significant. Calls that fail authentication are more likely to be labeled “Spam” or blocked outright by downstream carriers and phone apps. If your outbound numbers aren’t properly registered and authenticated through your carrier, answer rates will crater regardless of what else you’re doing right.

Recording and Monitoring Calls

Federal law allows you to record a phone call as long as at least one party consents, and in a call center the agent’s knowledge of the recording typically satisfies that one-party standard.8Office of the Law Revision Counsel. 18 USC 2511 – Interception and Disclosure of Wire, Oral, or Electronic Communications Prohibited

About 11 states go further and require all-party consent, meaning every person on the call must know about and agree to the recording. That group includes California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, and Washington, among others. When a call crosses state lines, the safe approach is to apply the stricter all-party rule. Most centers handle this with an automated announcement at the start of the call, such as “This call may be recorded for quality assurance,” and treat the consumer’s decision to stay on the line as implied consent.

Inadequate notice in an all-party state can support civil lawsuits and, in some jurisdictions, criminal charges. Recording systems should log that the disclosure played before the conversation began. If a caller objects to recording, agents need a clear protocol: either stop recording or end the call, depending on policy.

Customer Data and Payment Card Security

Call centers collect sensitive personal information on every interaction, from names and addresses to Social Security digits and payment credentials. The core obligation is straightforward: collect only what the transaction requires, restrict access to it, and dispose of it securely when there’s no longer a business reason to keep it. In practice, that means role-based access so agents see only the data relevant to their function, encryption for data in transit and at rest, and defined retention schedules.

PCI DSS

Any call center that processes, stores, or transmits credit card information falls under the Payment Card Industry Data Security Standard. PCI DSS isn’t a federal law. It’s a contractual requirement enforced by the major card brands, and the consequences of non-compliance (fines from your payment processor, loss of the ability to accept cards) can hit faster than a regulatory penalty.

Two PCI DSS requirements hit call centers especially hard. Cardholder data has to be encrypted when transmitted over public networks, and primary account numbers must be rendered unreadable anywhere they’re stored. Sensitive authentication data, including the CVV code, cannot be stored after a transaction is authorized, even in encrypted form.9PCI Security Standards Council. PCI DSS Quick Reference Guide

Call recordings create a specific problem here. If a customer reads their card number and CVV out loud, that data now sits in your recording. The common fixes are pause-and-resume technology that stops the recording while payment details are spoken, or automated systems that capture card data through the phone keypad so the numbers never pass through the agent or the recording.

HIPAA for Healthcare Call Centers

Call centers handling protected health information for healthcare providers, insurers, or their business associates face an additional layer of regulation under HIPAA. That includes encrypting voice and messaging channels, restricting the use of personal devices and unmanaged chat platforms, and providing initial and annual privacy training to every agent. Remote agents need VPN connections, disk encryption, and privacy screens. HIPAA compliance has to be built into the technology stack and training program from the start; it does not bolt on cleanly after the fact.

Recordkeeping

The TSR requires sellers and telemarketers to retain detailed records of their telemarketing activities for five years from the date the record is produced.10eCFR. 16 CFR 310.5 – Recordkeeping Requirements The scope is broad:

  • Every substantially different version of telemarketing scripts, brochures, and prerecorded messages, retained for five years after they’re last used.
  • For each call: calling number, called number, date, time, duration, disposition, caller ID information transmitted, and which scripts were used.
  • Customer records including name, phone number, address, goods purchased, purchase date, shipment date, and amount paid.
  • Name, contact information, and prize awarded for any prize valued at $25 or more.
  • Names and phone numbers of people who consented to receive calls, plus a copy of the consent request.

If no written contract between a seller and its telemarketer divides these responsibilities, both parties are independently on the hook for maintaining all of the records.11Federal Trade Commission. Mark Your Calendars, Telemarketers and Sellers – October 15 Is the Telemarketing Sales Rules Record Store Day Missing any individual record is itself a TSR violation. For TCPA consent specifically, the strongest defense in a dispute is a time-stamped record showing exactly when and how the consumer opted in, along with the exact language they agreed to.

State Telemarketing Registration

Federal rules don’t end the analysis. Many states require telemarketing companies to register or obtain a license before placing outbound sales calls to residents. Annual registration fees generally run from about $50 to $1,500 depending on the state, and some states also require a surety bond. Registration typically involves disclosing your business structure, the names of your principals, and the products or services you intend to sell. Operating without proper registration in a state that requires it can produce fines and injunctions independent of any federal violation, so a nationally operating call center has to check registration obligations in every state it calls into.