Call Center Compliance: The Whole Stack, Mapped

Call center compliance is the stack of federal statutes, trade rules, state laws, and data standards that govern how a calling operation dials, discloses, records, and stores information.

For a U.S. outbound floor in 2026, the stack has seven working layers: the TCPA and its FCC rules, the FTC’s Telemarketing Sales Rule, the National Do-Not-Call Registry, state telemarketing laws, calling-hours rules, call-recording consent laws, and the data standards — PCI DSS and HIPAA — that attach when payments or health information touch a call.

Get one layer wrong and exposure starts at $500 per call. This hub maps every layer, states what is in effect today, and links the dedicated guide for each — as of July 2026.

This page is education, not legal advice. A dialer is a tool — the dialer itself can be operated compliantly, but compliance depends on user behavior: your lists, consent records, schedules, and habits. Enzo does not scrub against national or state DNC registries; run every list through a third-party scrubbing service first. Have qualified telemarketing counsel review your program.

The Call Center Compliance Stack

The rules stack in layers, from federal statute down to the carrier network your calls ride on — each with its own regulator, its own failure mode, and its own dedicated guide on this site.

Layer What it governs The rule that bites Deep dive
Federal statute — TCPA Consent for autodialed, prerecorded, and AI-voice calls; do-not-call; quiet hours $500–$1,500 per call, private right of action under 47 U.S.C. § 227 TCPA for cold callers
Federal trade rule — TSR Disclosures, misrepresentation, call abandonment, payment rules, records Civil penalties up to $53,088 per violation (16 C.F.R. Part 310), as of 2026 Telemarketing Sales Rule
National DNC Registry Who you may solicit at all Registry data no more than 31 days old; per-seller subscription DNC registry for callers
State telemarketing laws Consent, hours, frequency, registration — state by state A growing list of mini-TCPA states, each with its own rules and penalties Telemarketing laws by state
Calling hours When you may dial Federal default 8 a.m.–9 p.m., called party’s local time; states go stricter Calling hours by state
Recording consent Whether and how you may record One-party default; 12 states plus Connecticut require all-party consent or notice Call recording consent states
Data standards Card data and health data on calls PCI DSS (contractual) and HIPAA (federal law) PCI compliance · HIPAA requirements
Carrier network Whether your calls complete at all STIR/SHAKEN and the Robocall Mitigation Database — your carrier files, not you Robocall Mitigation Database

Who Enforces What

Telemarketing law is enforced on four tracks at once — and the most active track is not a government agency.

Enforcer Authority What they can do
FCC 47 U.S.C. § 227; 47 C.F.R. § 64.1200 Writes the implementing rules; issues forfeitures
FTC Telemarketing Sales Rule, 16 C.F.R. Part 310 Civil penalties up to $53,088 per violation, as of 2026
State attorneys general 47 U.S.C. § 227(g) plus state mini-TCPAs Federal-court pattern-or-practice suits at $500 per violation, treble available; state-law actions on top
Private plaintiffs 47 U.S.C. § 227(b)(3) and (c)(5) $500–$1,500 per call, individually or as a class, with no proof of monetary injury required
HHS HIPAA (42 U.S.C. § 1320d-5, as adjusted) Tiered civil penalties up to $2,190,294 for calls and recordings involving PHI
Card networks and acquirers PCI DSS, via merchant agreements Contractual consequences under your processing agreements

Two details make the private track the one that fills dockets. First, no injury is required — statutory damages attach per call or text. Second, the clock is long: the TCPA states no limitations period of its own, so courts apply the federal four-year catch-all under 28 U.S.C. § 1658(a). One process failure, left running across a dialing floor, is a class action — according to press reports, Realogy’s $20 million settlement covering roughly 298,000 class members won final approval in January 2025.

The TCPA is the spine of the stack. Under federal law, a live, manually dialed sales call needs no prior consent — what triggers consent rules is technology: telemarketing with an autodialer or an artificial or prerecorded voice to a cell phone requires prior express written consent (PEWC) under 47 C.F.R. § 64.1200(a)(2), and the FCC’s unanimous February 2024 ruling holds that AI-generated and cloned voices count as artificial voices too.

The consent rules have been turbulent; here is where they stand today. The FCC’s one-to-one consent rule for lead-gen forms never took effect — the Eleventh Circuit vacated it on January 24, 2025 in Insurance Marketing Coalition v. FCC, and the FCC deleted the language effective August 29, 2025, restoring the pre-2023 PEWC standard.

The revocation rule did take effect, on April 11, 2025: consumers may revoke consent in any reasonable manner, and callers must honor it within ten business days. The related “revoke-all” provision is currently waived until January 31, 2027 and under active FCC reconsideration — the date and the rule itself could change again, so check FCC.gov before relying on it.

Whether a predictive dialer is an “autodialer” depends on the court, as of July 2026: after Facebook v. Duguid (2021), most federal courts hold that dialers calling stored lead lists are not an ATDS, but the Second Circuit has read stored-number capacity more broadly and the case law remains unsettled — ask a TCPA attorney before relying on this.

And there is no blanket B2B pass: a decision-maker’s personal cell is a wireless number regardless of business use. The full treatment — violations, consent records, and the five process failures that actually get callers sued — is in TCPA for cold callers.

Layer 2: The Telemarketing Sales Rule — the FTC’s Half of the Field

The TSR, 16 C.F.R. Part 310, covers campaigns involving more than one interstate call and regulates the conversation itself: agents must promptly disclose the seller’s identity, that the call is a sales call, and the nature of the goods or services (16 C.F.R. § 310.4(d)), and misrepresenting cost, performance, refund policy, or affiliation is prohibited outright. Its calling-hours rule at 16 C.F.R. § 310.4(c) mirrors the FCC’s 8 a.m.–9 p.m. window.

For predictive-dialer floors, the operative math is abandonment:

A call is abandoned if the person who answers is not connected to a live rep within two seconds of their completed greeting, and the safe harbor requires keeping abandonment to no more than 3% of calls answered by a person — measured per campaign over each 30-day period, not per day — letting unanswered calls ring at least 15 seconds or four rings, and playing a recorded message naming the seller with a phone number when no rep is free.

Two recent changes matter. The FTC’s 2024 amendments (effective May 16, 2024) extended record retention to five years and expanded required records to per-call detail. And B2B calls are no longer exempt from the TSR’s misrepresentation bans (§§ 310.3(a)(2) and (a)(4)) — though they remain exempt from most other TSR provisions.

The maximum civil penalty is $53,088 per violation: set January 17, 2025 and left unchanged for 2026 after OMB canceled the year’s inflation adjustments, with another adjustment expected in early 2027 — verify at FTC.gov. The complete rule, exemptions and all, is broken down in the Telemarketing Sales Rule guide.

Layer 3: Do-Not-Call — the National Registry and Your Internal List

Do-not-call is two separate systems. The National DNC Registry bars solicitations to registered numbers unless an exemption applies; the FCC’s safe harbor requires using registry data obtained no more than 31 days before any call, so scrubbing is a standing calendar entry.

Access runs on the FTC’s published fee schedule: for the fee year that began October 1, 2025, the first five area codes are free, each additional area code is $82 per year, capped at $22,626 for the whole country — fees change every October 1.

The main exemption is the established business relationship: a purchase or transaction within the prior 18 months, or an inquiry within the prior 3 months, ended the moment the person asks you to stop.

Your internal DNC list is separate: a written policy, trained personnel, opt-outs recorded when made and honored within ten business days, and each request kept for five years (47 C.F.R. § 64.1200(d)).

Where Enzo fits is deliberately narrow: campaign-level internal DNC — mark a contact DNC and they stay excluded from that campaign, but marks do not carry across campaigns, so keep your master suppression file outside the dialer and re-apply it to every new campaign.

Enzo does not scrub against the national or any state registry: run every list through a third-party scrubbing service, then import the clean file. Registry mechanics, SANs, and fees are covered in the DNC registry guide.

Layer 4: Calling Hours and State Telemarketing Laws

The federal default: no telephone solicitations before 8 a.m. or after 9 p.m., local time at the called party’s location — the caller bears the burden of determining that local time, and there is no weekend or holiday exception. Area code is not location.

Quiet-hours suits surged onto federal dockets in 2025, and whether the window applies to consented texts is still pending at the FCC. Unless you have verified a stricter state rule, schedule to the federal default window and confirm each state you dial in the calling hours by state table.

Federal law is the floor, not the ceiling. A growing list of states have their own mini-TCPA or telemarketing statutes — among them Florida’s Telephone Solicitation Act, Oklahoma’s Telephone Solicitation Act, Texas SB 140, Washington’s Robocall Scam Protection Act, and Maryland’s Stop the Spam Calls Act — each with its own consent, hours, frequency, and penalty rules.

The state-by-state picture lives in telemarketing laws by state, with the stricter-than-federal statutes profiled in state mini-TCPA laws.

Under the federal wiretap statute you may record a call you are a party to, and most states follow that one-party rule. Twelve states — plus Connecticut, through its civil statute — require all-party consent or notice for phone calls, and on interstate calls courts have applied the stricter state’s law.

The operational fix is one habit: announce the recording in the first line of every recorded call — the recognized consent path in the strictest states. The verified state list and announcement scripting are in call recording consent states. In Enzo, recording is optional — and if you record, the announcement belongs in the first line of your script.

Layer 6: PCI DSS and HIPAA — When Payments or Health Data Touch a Call

PCI DSS binds through card-brand and acquirer agreements, not statute. PCI DSS v4.0.1 has been the only active version since December 31, 2024, and the 51 future-dated requirements introduced with v4.0 became mandatory on March 31, 2025.

The rule phone floors trip on: card security codes may never be stored after authorization, even encrypted — if a recording captures one, that data must be rendered unrecoverable once the transaction is processed, which is why pause-and-resume recording and DTMF masking exist. Scope, SAQs, and the recording rules are in call center PCI compliance.

HIPAA attaches when a call center creates, receives, maintains, or transmits protected health information on behalf of a covered entity: that makes it a business associate under 45 C.F.R. § 160.103, a written business associate agreement is required before PHI is touched, and the Security Rule binds it directly — risk analysis, workforce training, access and audit controls included.

A business associate that discovers a breach must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery.

Penalties run $145 to $73,011 per violation by culpability tier, reaching $2,190,294 for uncorrected willful neglect with a matching calendar-year cap, per the January 28, 2026 inflation adjustment — though HHS has said it applies lower annual caps to the lower tiers as a matter of enforcement discretion. The safeguards, in workflow terms, are in HIPAA call center requirements.

Layer 7: The Carrier Network — Compliance You Inherit

One layer of the stack is filed by someone else. Every carrier in your call path must appear in the FCC’s Robocall Mitigation Database — end-user calling businesses never file, but under 47 C.F.R. § 64.6305(g), providers must stop accepting traffic from a carrier that is removed.

The FCC uses that lever: in August 2025 it ordered 185 companies removed and, per the order, directed providers to cease accepting their calls within two business days. If your dialer traffic rides on a delisted carrier, your calls stop completing — carrier selection is a deliverability decision, not a formality. The details for callers are in the Robocall Mitigation Database guide.

Running the Stack, Not Memorizing It

Nobody operates from statute citations. Compliance programs run on a short list of habits: scrub inside 31 days, document consent, schedule by the prospect’s actual location, honor opt-outs within ten business days, announce recordings, identify yourself on every call, and keep the records — five years for TSR call detail and internal DNC entries.

The call center compliance checklist turns that into a printable routine, and TCPA compliance software covers what tooling can and cannot take off your plate — including where Enzo helps (campaign-level internal DNC, optional recording, campaign scheduling) and where it deliberately does not (registry scrubbing, consent capture, legal review).

The stack looks heavier than it runs: each layer has one or two operational rules that generate nearly all of the exposure, and every one of them is a workflow fix. Build the habits, verify the states you actually call, and have counsel sanity-check the program once a year. To see how campaign-level DNC, recording controls, and scheduling work inside a real calling workflow, book a free discovery call — 20 minutes, and if Enzo isn’t the right fit, we’ll tell you.

Not legal advice. This guide is general information for outbound calling teams, not legal advice. Rules change and apply differently by state, industry, and call type — confirm your program with qualified telemarketing compliance counsel.

Statutes, rules, and figures from 47 U.S.C. § 227, 47 C.F.R. §§ 64.1200 and 64.6305, 16 C.F.R. Part 310, 45 C.F.R. Parts 160–164, the Federal Register, FCC and FTC orders, and PCI SSC publications, as of July 2026. Company names are trademarks of their owners.

FAQ

Common questions.

What is call center compliance?

Call center compliance is the set of laws, rules, and standards that govern how a calling operation dials, discloses, records, and stores data. For a U.S. outbound team it spans seven layers: the TCPA and its FCC rules (consent, quiet hours, do-not-call), the FTC's Telemarketing Sales Rule (disclosures, abandonment, records), the National DNC Registry and its 31-day scrub cycle, state telemarketing laws, calling-hours rules, state call-recording consent laws, and the PCI DSS and HIPAA standards that attach when card data or health information touches a call.

Getting a layer wrong exposes you to private lawsuits at $500 to $1,500 per call and regulator penalties up to $53,088 per violation as of 2026.

What are the main call center compliance standards?

Six standards cover most U.S. calling operations: the TCPA (47 U.S.C. § 227 and 47 C.F.R. § 64.1200) for consent, autodialers, prerecorded voice, and do-not-call; the FTC's Telemarketing Sales Rule (16 C.F.R. Part 310) for disclosures, misrepresentation, call abandonment, and recordkeeping; the National Do-Not-Call Registry with its 31-day scrub safe harbor;

state telemarketing statutes — a growing list of states have their own mini-TCPA or telemarketing statutes, among them Florida, Oklahoma, Texas, Washington, and Maryland; state call-recording consent laws, where twelve states plus Connecticut require all-party consent or notice; and, where relevant data is handled, PCI DSS v4.0.1 for phone payments and HIPAA for calls involving protected health information.

Who regulates call centers in the United States?

Telemarketing enforcement runs on four tracks. The FCC writes the TCPA implementing rules and issues forfeitures under 47 U.S.C. § 227. The FTC enforces the Telemarketing Sales Rule with civil penalties up to $53,088 per violation as of 2026. State attorneys general are expressly authorized by 47 U.S.C. § 227(g) to sue in federal court for pattern-or-practice violations at $500 per violation with treble damages available, on top of their own state statutes.

And private plaintiffs can sue directly under the TCPA — individually or as a class — for $500 to $1,500 per call with no proof of monetary injury required. Beyond telemarketing, HHS enforces HIPAA where calls involve health information, and card networks enforce PCI DSS through merchant agreements.

What regulations apply to outbound call centers specifically?

The rules that bite outbound floors day to day: prior express written consent for autodialed, prerecorded, or AI-voice marketing calls to cell phones; quiet hours of 8 a.m. to 9 p.m. at the called party's location with no weekend exception; scrubbing lists against the National DNC Registry with data no more than 31 days old; honoring opt-outs within ten business days and keeping internal DNC entries for five years; the TSR's prompt disclosure of who is calling and why, plus its 3%-of-answered-calls abandonment safe harbor for predictive dialing; state recording-consent laws when calls are recorded; and any stricter state mini-TCPA rules for the states you dial into.

How much do call center compliance violations cost?

TCPA statutory damages are $500 per call, or up to $1,500 per call for willful or knowing violations, and consumers can sue directly with no proof of monetary loss — a do-not-call claim requires more than one violating call by or for the same company within a 12-month period. Courts apply the federal four-year catch-all statute of limitations (28 U.S.C. § 1658(a)), so exposure accumulates.

The FTC can seek up to $53,088 per Telemarketing Sales Rule violation as of 2026, and HIPAA penalties run from $145 to $73,011 per violation across the three lower culpability tiers, and $73,011 up to $2,190,294 per violation for uncorrected willful neglect, with a $2,190,294 calendar-year cap, per the January 2026 inflation adjustment — though HHS has said it applies lower annual caps to the lower tiers as a matter of enforcement discretion.

Class actions scale the math: according to press reports, Realogy's $20 million TCPA settlement covering roughly 298,000 class members received final approval in January 2025.

Does dialer software make a call center compliant?

No. The dialer itself can be operated compliantly, but compliance depends on user behavior — the lists you load, the consent you documented, the hours you schedule, and how you honor opt-outs. Software covers pieces of the workflow: Enzo provides campaign-level internal DNC (marks do not carry across campaigns), optional call recording, and campaign scheduling, but it does not scrub lists against the national or state DNC registries — run every list through a third-party scrubbing service before uploading — and no vendor's tool substitutes for a written compliance program reviewed by qualified counsel.

Do call centers need to be PCI compliant or HIPAA compliant?

Only if they handle the relevant data. A call center that takes card payments by phone is bound to PCI DSS through its card-brand and acquirer agreements — PCI DSS is contractual, not a statute — and v4.0.1 has been the only active version since December 31, 2024. The hard rule for phone payments: card security codes may never be stored after authorization, even encrypted, so recordings that capture them must have that data rendered unrecoverable.

A call center that creates, receives, maintains, or transmits protected health information on behalf of a healthcare client is a HIPAA business associate under 45 C.F.R. § 160.103: a written business associate agreement is required before PHI is touched, and the Security Rule binds the call center directly.

Ready to have more conversations per hour?

Schedule Discovery Call
Schedule Discovery Call