Outbound Dialer Compliance Checklist for 2026
A compliance checklist for outbound dialing: DNC, calling hours, consent, recording, retry limits, caller ID, and abandon rates across US, EU, UAE, and KSA.
Outbound dialing compliance isn't a single regulation — it's a matrix of overlapping rules that vary by jurisdiction, channel, and use case. A collections call to a US mobile number is governed by different rules than a sales call to a UAE landline, which is different again from a survey call to a Saudi mobile.
This checklist covers the key compliance areas that every outbound dialing operation must address in 2026, with specific guidance for the US (TCPA/TSR/CFPB), EU (GDPR/ePrivacy), UAE (TDRA), and KSA (CITC). It's not legal advice — consult qualified counsel for your specific situation — but it is a practical operational guide for configuring your dialer and training your team.
1. Do Not Call (DNC) Lists
What's required: Before dialing any number, you must check it against all applicable DNC lists and suppress matching numbers.
US: The National Do Not Call Registry (managed by the FTC) is the primary federal list. Additionally, many states maintain their own DNC lists with separate registration requirements. Telemarketers must scrub against the national registry at least every 31 days. Internal DNC requests (where a consumer asks you directly to stop calling) must be honored immediately and indefinitely.
EU: DNC is handled through opt-out mechanisms under GDPR and member state ePrivacy implementations. The UK's TPS (Telephone Preference Service), Germany's Robinson List, and France's Bloctel are examples of national opt-out registers. You must honor opt-out requests within 28 days (UK) or immediately (GDPR best practice).
UAE (TDRA): The TDRA's Do Not Disturb (DND) registry allows UAE residents to opt out of unsolicited commercial calls. Operators must scrub against this registry before running campaigns. The TDRA can impose fines for violations.
KSA (CITC): The CITC maintains a DNC registry for Saudi numbers. Commercial calling to registered numbers without prior consent is prohibited. Penalties include fines and potential license suspension for repeat offenders.
Dialer requirement: Your dialer must support multiple simultaneous DNC lists, real-time scrubbing at the point of dialing (not just at list upload), immediate suppression when a number is added mid-campaign, and audit logging of every DNC check.
2. Calling Hours
What's required: Outbound calls must fall within permitted hours based on the recipient's local time zone.
US (TCPA): 8:00 AM to 9:00 PM, recipient's local time. Some states have narrower windows (e.g., certain states restrict to 9:00 AM to 8:00 PM).
EU: Varies by member state. Generally 9:00 AM to 9:00 PM. France restricts to 10:00 AM to 1:00 PM and 2:00 PM to 8:00 PM on weekdays, no weekends.
UAE (TDRA): Commercial calls are generally permitted between 9:00 AM and 9:00 PM local time. Stricter limits may apply during Ramadan.
KSA (CITC): Similar to UAE — calls should be placed during reasonable business hours. The CITC has indicated preferences for 9:00 AM to 9:00 PM, with additional restrictions during prayer times and Ramadan.
Dialer requirement: Automatic time zone resolution from phone number (using area code/prefix mapping), per-jurisdiction calling window configuration, automatic suppression of calls outside permitted hours, and handling of cross-timezone edge cases (e.g., a call center in Dubai dialing numbers in Riyadh with a 1-hour time offset).
3. Consent
What's required: The level of consent required depends on jurisdiction, call type, and whether you're calling a mobile or landline.
US (TCPA): Calls to mobile phones using an autodialer or prerecorded voice require prior express written consent for marketing calls. Prior express consent (can be oral) is sufficient for informational calls. The FCC's one-to-one consent rule (effective 2025) requires consent to be specific to a single seller — no more lead aggregators sharing consent across multiple companies.
EU (GDPR + ePrivacy): Direct marketing calls generally require opt-in consent. Legitimate interest may be sufficient for B2B calls in some member states, but the threshold varies. Consent must be freely given, specific, informed, and unambiguous. Pre-checked boxes don't count.
UAE (TDRA): Prior consent is required for commercial communications. Consent records must be maintained and producible on request.
KSA (CITC + PDPL): Saudi Arabia's Personal Data Protection Law (PDPL) requires consent for processing personal data for marketing purposes. Consent must be explicit and documented.
Dialer requirement: Per-number consent status tracking, consent type classification (written, oral, implied, none), consent timestamp and source recording, automatic suppression of numbers without required consent level, and consent audit trail for regulatory inquiries.
4. Call Recording Consent
What's required: If you record calls, you must comply with recording consent laws, which vary significantly by jurisdiction.
US: Federal law (18 U.S.C. 2511) requires one-party consent. However, 11 states require all-party consent (both parties must be informed). In practice, most contact centers play a recording disclosure at the start of every call.
EU (GDPR): Call recording requires a lawful basis. Consent is the most common basis. The recording disclosure must be clear and the customer must have the option to object. Recordings must be stored securely with defined retention periods.
UAE/KSA: Recording consent requirements are generally aligned with the principle of prior notice. Playing a recording disclosure at the start of the call is standard practice and recommended.
Dialer requirement: Configurable pre-call recording announcements (IVR), per-campaign recording consent settings, ability to pause/resume recording mid-call (for sensitive data like payment card numbers), secure recording storage with access controls, and configurable retention periods with automated deletion.
5. Retry Limits
What's required: Regulations limit how frequently you can attempt to reach the same person.
US (CFPB Reg F — debt collection): Maximum 7 call attempts per 7-day rolling period per debt. After a live conversation, no further attempts for 7 days (unless the consumer consents or initiates contact).
EU: No specific numeric limit in most jurisdictions, but excessive calling can constitute harassment under national consumer protection laws. Best practice: 3-5 attempts per week with varying times.
UAE/KSA: No published numeric limits, but the TDRA and CITC can act on complaints of excessive calling. Conservative limits (3-5 attempts per week) are recommended.
Dialer requirement: Per-number attempt counters with configurable rolling time windows, separate tracking of connected vs. unanswered attempts, per-campaign and per-jurisdiction limit configuration, automatic suppression when limits are reached, and cooldown timers after live conversations.
6. Caller ID (CLI) Presentation
What's required: You must present a valid, callable caller ID on outbound calls.
US (Truth in Caller ID Act): It's illegal to transmit misleading or inaccurate caller ID information with the intent to defraud. The displayed number must be a number assigned to you that a consumer can call back to reach your organization.
EU: CLI presentation rules vary by member state. Generally, a valid callback number must be displayed. Some countries require the displayed number to be a geographic or national-rate number.
UAE (TDRA): The TDRA requires valid CLI presentation. Spoofing or presenting unauthorized numbers can result in enforcement action. Carriers may block calls with invalid CLI.
KSA (CITC): Similar to TDRA. The CITC has implemented STIR/SHAKEN-like caller ID authentication requirements. Numbers that fail authentication may be blocked at the carrier level.
Dialer requirement: Per-campaign caller ID assignment with validation, DID health monitoring (to detect spam-labeled numbers), caller ID rotation capabilities, and integration with caller ID reputation services. DialerBee's caller ID intelligence system is designed to help manage these requirements.
7. Abandon Rate
What's required: Predictive dialers inherently produce some abandoned calls (calls answered by a human but disconnected because no agent is available). Regulations cap this rate.
US (FTC TSR): Maximum 3% abandon rate, measured over a single campaign per 30-day period. An abandoned call must play a prerecorded message identifying the caller and providing a callback number. The call must ring for at least 15 seconds before being considered unanswered.
UK (Ofcom): Maximum 3% abandon rate. Abandoned calls must deliver a brief information message. The same number cannot receive an abandoned call within 72 hours of a previous abandoned call.
UAE/KSA: While specific abandon rate regulations are less codified than in the US/UK, best practice is to maintain the 3% threshold. The TDRA and CITC can take enforcement action based on consumer complaints about repeated silent or abandoned calls.
Dialer requirement: Real-time abandon rate tracking per campaign, automatic pacing adjustment when approaching the threshold, abandoned call message playback, per-number abandon tracking (to avoid repeat abandons), and historical reporting for audit purposes.
8. Data Protection and Privacy
What's required: Contact data used for outbound calling is personal data subject to privacy regulations.
US: Sector-specific rules apply (GLBA for financial, HIPAA for health). State laws like CCPA/CPRA grant consumers rights to access and delete their data.
EU (GDPR): Full data protection regime: lawful basis for processing, data minimization, storage limitation, right to erasure, data portability, and mandatory breach notification within 72 hours.
UAE (Federal Decree-Law No. 45/2021): UAE's data protection law requires consent for personal data processing, data security measures, and breach notification.
KSA (PDPL): Saudi Arabia's Personal Data Protection Law requires explicit consent, data minimization, purpose limitation, and establishes data subject rights similar to GDPR.
Dialer requirement: Encrypted data storage and transmission, role-based access controls, data retention policies with automated enforcement, data export and deletion capabilities for privacy requests, and audit logging of all data access. DialerBee's compliance autopilot feature is designed to help automate many of these requirements.
Using This Checklist
Print this checklist or save it as your baseline compliance audit template. For each item, verify that your dialer platform supports the technical requirement, your operational procedures enforce the policy, your agents are trained on the relevant rules, and your compliance team reviews adherence monthly.
Compliance is not a one-time configuration. Regulations change, carrier requirements evolve, and operational drift happens. Build a quarterly compliance review into your operations calendar, and use your dialer's reporting tools to monitor adherence continuously.