TCPA Compliance in 2026: A Complete Guide for Outbound Calling
A practical 2026 guide to TCPA compliance for outbound calling: consent, the DNC registry, ATDS rules, revocation, calling hours, recording, and penalties.
Quick answer
TCPA compliance means following the Telephone Consumer Protection Act (1991), enforced by the FCC, when placing outbound calls and texts. For outbound calling it generally requires the right level of consumer consent, honoring the National Do Not Call Registry, respecting calling-hour limits, processing consent revocations, and following rules for autodialed and prerecorded calls to wireless numbers.
The Telephone Consumer Protection Act (TCPA) is one of the most consequential laws governing outbound calling in the United States. Enacted in 1991 and enforced primarily by the Federal Communications Commission (FCC), it shapes how businesses reach consumers by phone and text — and it carries some of the largest statutory penalties in consumer-protection law. For BPOs, collections agencies, telecom resellers, and any regulated contact center, understanding the TCPA is not optional. A single misconfigured campaign can trigger class-action exposure.
This guide walks through the core areas of TCPA compliance for outbound calling in 2026: consent standards, the Do Not Call registry, autodialer considerations after Facebook v. Duguid, revocation of consent, calling-hour restrictions, one-to-one consent trends, call recording, wireless numbers, and penalties. It closes with how a compliance-supporting dialer helps operators build the right controls into their workflow.
What the TCPA Covers
At a high level, the TCPA restricts certain categories of calls and texts to consumers. The rules are strictest for calls that use an automatic telephone dialing system (ATDS) or an artificial or prerecorded voice, and strictest of all when those calls reach wireless (cell phone) numbers. The statute also underpins the National Do Not Call Registry, imposes time-of-day calling restrictions, and requires businesses to maintain internal do-not-call policies.
Importantly, the TCPA is a federal law, but it operates alongside state telemarketing laws — several of which are stricter than the federal baseline. A campaign that satisfies federal TCPA rules may still violate a state mini-TCPA. Operators calling into multiple states should treat the TCPA as a floor, not a ceiling.
Consent: Prior Express Consent vs. Prior Express Written Consent
Consent is the foundation of TCPA compliance, and the type of consent required depends on the nature of the call. The two key standards are prior express consent and the higher bar of prior express written consent.
Prior express consent is generally understood to be established when a consumer provides their phone number in connection with a transaction or relationship, indicating they can be contacted about it. This standard has historically applied to certain non-telemarketing, informational calls — for example, appointment reminders or account notifications — where the consumer voluntarily shared their number.
Prior express written consent is a heightened standard that generally applies to telemarketing and advertising calls or texts placed with an autodialer or prerecorded voice to wireless numbers. It typically requires a signed written agreement (electronic signatures count) that clearly authorizes the specific caller to deliver marketing messages, discloses that consent is not a condition of purchase, and identifies the number to be called.
| Consent type | Typical use | What it generally requires |
|---|---|---|
| Prior express consent | Informational / transactional calls | Consumer voluntarily provided the number in connection with the relationship or transaction |
| Prior express written consent | Telemarketing / advertising via autodialer or prerecorded voice | Signed written agreement naming the caller, disclosing consent is not a purchase condition, and identifying the number |
| Established business relationship (EBR) | Narrow DNC exemptions in some contexts | A recent transaction or inquiry; treated cautiously and time-limited |
Because the correct consent standard depends on the call's purpose and the technology used, operators should document, for every contact, what type of consent was obtained, when, and in what context. Storing consent evidence — source, timestamp, and the exact language the consumer agreed to — is one of the most important defensive practices in TCPA compliance. Our compliance features are built around capturing and retaining this kind of consent metadata.
The National Do Not Call Registry
The National Do Not Call Registry, maintained by the FTC and referenced under TCPA rules, allows consumers to opt out of most telemarketing calls. Businesses making telemarketing calls must scrub their calling lists against the registry and suppress registered numbers. The registry is not a one-time check: lists change constantly, and numbers are added continuously.
- Regular scrubbing. Telemarketers are generally expected to scrub against the registry on a recurring basis rather than only at list import. A number added after your import must still be caught before you dial it.
- Internal do-not-call list. Separate from the national registry, businesses must maintain their own internal DNC list and honor consumer opt-out requests. The TCPA framework requires processing these requests promptly.
- Pre-dial checks. The strongest posture is to verify DNC status before each dial, using a default-deny approach that blocks a call when the number's status cannot be confirmed as callable.
For multi-tenant BPO operations, DNC handling gets more complex: an opt-out for one client's campaign may or may not extend to another, depending on your policies and the applicable rules. A dialer that supports both shared and per-tenant DNC lists gives operators the flexibility to configure this correctly.
Autodialer / ATDS After Facebook v. Duguid
For years, the definition of an "automatic telephone dialing system" was heavily litigated. In 2021, the U.S. Supreme Court decided Facebook v. Duguid, narrowing the ATDS definition. The Court held that, to qualify as an ATDS under the statute, a system must have the capacity to store or produce telephone numbers using a random or sequential number generator and to dial them.
This decision meant that many modern dialing systems — which call numbers from targeted, curated lists rather than randomly generated ones — may fall outside the strict ATDS definition. However, this is not a green light to ignore consent. Several critical points remain:
- Prerecorded and artificial voice rules are unaffected. The TCPA's separate restrictions on calls using a prerecorded or artificial voice still apply regardless of whether an ATDS is used.
- State laws may define autodialers more broadly. Some state mini-TCPA statutes use their own, broader definitions, so a system outside the federal ATDS definition can still trigger state-law obligations.
- The DNC registry and internal opt-out rules still apply to telemarketing regardless of the dialing technology.
- The legal landscape continues to evolve. The FCC has continued rulemaking on consent and revocation, and lower courts continue to interpret Duguid in varied ways.
The practical takeaway: Duguid narrowed one definition, but it did not dismantle the TCPA. Consent, DNC, calling windows, and revocation remain central.
Revocation of Consent
Consumers have the right to revoke consent to receive calls and texts, and the FCC has continued to strengthen and clarify revocation rules. Key principles operators should build for:
- Revocation can be made through any reasonable means. A consumer generally does not have to use a specific script or channel to revoke; a clear expression of intent to stop is enough.
- Prompt processing. Once a consumer revokes, callers are expected to honor the request within a reasonable, defined timeframe. Building revocation into an immediate suppression workflow is the safest approach.
- Scope of revocation. Recent FCC guidance has addressed how broadly a revocation applies across a caller's messages. Operators should treat a revocation conservatively and log it with a timestamp, source, and the campaigns it affects.
A defensible revocation process is auditable end to end: when the request arrived, how it was captured, when suppression took effect, and which campaigns were updated.
Calling-Hour Restrictions
The TCPA restricts telemarketing calls to consumers' local time between 8:00 a.m. and 9:00 p.m. Calling outside that window is a common and easily avoidable violation. The complication is that the relevant time zone is the consumer's, not the call center's. An agent dialing at 8:30 p.m. Eastern is calling at 5:30 p.m. Pacific — fine on the West Coast, but a violation if placed the other direction after 9:00 p.m. local.
State laws sometimes impose narrower windows or additional day-of-week restrictions. A dialer that enforces calling windows based on the destination number's time zone — and blocks dials that fall outside the permitted window — removes one of the most frequent sources of TCPA exposure.
One-to-One Consent Trends
A significant recent trend in TCPA rulemaking has focused on one-to-one consent — the idea that consent obtained on a lead-generation or comparison-shopping site should be specific to a single identified seller rather than blanket authorization for many unnamed "partners." The direction of regulation and litigation has pushed toward requiring clearer, more specific, seller-identified consent, and toward scrutinizing bundled or vague consent language.
The exact contours of one-to-one consent requirements have been the subject of ongoing rulemaking and legal challenge, so operators should confirm the current state of the rules with counsel. Regardless of the precise regulatory status at any moment, the defensible practice is the same: obtain and document consent that names the specific caller and clearly describes what the consumer is agreeing to.
Call Recording Consent
Call recording is governed by a separate body of law from the core TCPA calling rules, but it is a critical part of any outbound compliance program. U.S. states fall into two broad categories:
- One-party consent states, where only one party to the call (which can be the caller) needs to consent to recording.
- All-party (two-party) consent states, where every party on the call must consent before recording.
Because a single outbound campaign may reach consumers across many states, a common conservative approach is to obtain consent to recording from all parties — typically with a clear disclosure at the start of the call. Operators should configure recording announcements and consent capture to match the strictest applicable rule for their footprint.
Wireless Numbers and Penalties
Calls and texts to wireless numbers receive the strongest TCPA protections, which is why identifying whether a number is a cell phone matters. Contacting wireless numbers with an autodialer or prerecorded voice without the required consent is precisely the conduct the TCPA was designed to restrict.
Penalties are severe. The TCPA provides for statutory damages on a per-violation basis, and because campaigns involve large call volumes, exposure adds up quickly — willful or knowing violations can carry enhanced damages. Beyond private lawsuits and class actions, regulators can pursue enforcement. The financial and reputational stakes are why compliance-supporting controls, not ad-hoc processes, are essential for high-volume outbound operations. Teams calling into the United States can review our US region overview for a summary of the regulatory environment, and our contact center compliance checklist for 2026 for a broader operational review.
How DialerBee Supports TCPA-Aware Outbound
DialerBee provides compliance-supporting controls that help operators build TCPA-aware processes into their day-to-day calling — it does not, and cannot, guarantee compliance, because the operator remains responsible for how consent is obtained and how campaigns are run. Within that framework, DialerBee's compliance features and Compliance Autopilot help teams by:
- DNC scrubbing and pre-dial checks against national and internal do-not-call lists, with configurable default-deny behavior so calls that fail a check are blocked before they connect.
- Calling-window enforcement based on the destination number's local time zone, so dials outside permitted hours are suppressed automatically.
- Consent tracking that records the consent type, source, timestamp, and language for each contact, keeping consent evidence attached to the record.
- Revocation workflows that capture opt-out requests and suppress future dials across the relevant campaigns, with a timestamped audit trail.
- Recording policies configurable to your jurisdictional footprint, including recording announcements and consent capture.
- Audit logs covering DNC checks, calling-window decisions, consent, and revocation, so compliance actions can be demonstrated after the fact.
DialerBee's language-aware AI supports outbound campaigns across 9 languages, so multilingual BPOs and resellers can apply the same compliance-supporting controls across markets. In selected internal pilot conditions, teams have used these controls to reduce manual compliance steps, though results depend on how each operation configures and uses them.
Frequently Asked Questions
What is the difference between prior express consent and prior express written consent?
Prior express consent is generally established when a consumer voluntarily provides their phone number in connection with a transaction or relationship, and it has historically applied to certain informational or transactional calls. Prior express written consent is a higher standard that typically applies to telemarketing or advertising calls placed with an autodialer or prerecorded voice to wireless numbers; it generally requires a signed written agreement that names the caller, discloses that consent is not a condition of purchase, and identifies the number.
Did Facebook v. Duguid make the TCPA irrelevant for modern dialers?
No. The 2021 Supreme Court decision in Facebook v. Duguid narrowed the definition of an automatic telephone dialing system to systems that use a random or sequential number generator, which may place some list-based dialers outside that specific definition. However, the TCPA's rules on prerecorded and artificial voice calls, the Do Not Call registry, internal opt-outs, and calling hours still apply, and some state laws define autodialers more broadly.
How quickly must I honor a consumer's revocation of consent?
Consumers can revoke consent through any reasonable means, and callers are expected to honor revocation requests within a reasonable, defined timeframe. The safest practice is to process revocations promptly through an immediate suppression workflow and to log each request with a timestamp, source, and the campaigns it affects. Confirm current timeframes with legal counsel, as FCC rulemaking on revocation continues to evolve.
What are the TCPA calling-hour restrictions?
The TCPA restricts telemarketing calls to between 8:00 a.m. and 9:00 p.m. in the consumer's local time zone. Because the relevant time zone is the consumer's rather than the call center's, operators should enforce calling windows based on the destination number's location. Some state laws impose narrower windows or additional restrictions.
Do I need consent to record outbound calls?
Call recording is governed by state law separate from the core TCPA calling rules. Some states require only one party to consent to recording, while all-party consent states require every participant to agree. Because a single campaign may reach consumers in many states, a common conservative approach is to disclose recording and obtain consent from all parties at the start of the call.
What are the penalties for TCPA violations?
The TCPA provides statutory damages on a per-violation basis, and willful or knowing violations can carry enhanced damages. Because outbound campaigns involve large call volumes, total exposure can escalate quickly, and violations frequently lead to class-action litigation in addition to potential regulatory enforcement.
Can a dialer make my operation TCPA compliant?
No dialer can guarantee compliance. DialerBee provides compliance-supporting controls — such as DNC scrubbing, calling-window enforcement, consent tracking, revocation workflows, recording policies, and audit logs — that help operators build TCPA-aware processes. The operator remains responsible for obtaining valid consent and running campaigns lawfully, and should work with qualified legal counsel.
This article is for general informational purposes and is not legal advice. TCPA rules and case law evolve — consult qualified legal counsel for your specific situation.