Compliance

Cold calling laws in 2026: what actually applies to your calls

The TCPA, the Do Not Call Registry, the autodialer definition after Facebook v. Duguid, state mini-TCPA statutes and STIR/SHAKEN, explained for people who make calls rather than lawyers.

MNMRR Nerds Editorial TeamUpdated 12 min read

This page is orientation, not legal advice. It is written for people who make calls and need to know which questions to ask a lawyer. If you dial consumers at volume, get counsel.

The one distinction that determines everything

Calling a business line for a business purpose is lightly regulated in the US. The National Do Not Call Registry does not generally apply, and most of the TCPA's consent machinery is aimed elsewhere.

Calling a consumer, including a personal mobile, sits inside the TCPA, the Telemarketing Sales Rule and the DNC rules, with real damages attached.

The complication is that the line is blurry. A sole trader's mobile is both. A founder's cell number on a business card is both. Where you are unsure, apply the consumer rules.

The TCPA, briefly

The Telephone Consumer Protection Act is the statute that governs telemarketing calls in the US. The parts that matter to a sales team:

Damages. $500 per violating call or text. Trebled to $1,500 for willful or knowing violations. No cap. That is the fact that should govern everything else, because it means the exposure scales linearly with your dial volume.

Class actions. Roughly 80 percent of TCPA suits are filed as class actions. A single plaintiff's $500 claim is not the risk. Ten thousand calls at $500 is a five-million-dollar theoretical exposure, and that is why plaintiffs' firms specialise in it.

Calling hours. Telemarketing calls to consumers are restricted to 8am to 9pm in the called party's local time.

Identification. You must identify yourself and the entity on whose behalf you are calling.

Do-not-call requests. A request to stop must be honoured, and you must maintain an internal do-not-call list. This is the single most common source of complaints, and it is also the easiest thing to get right.

The autodialer question, after Duguid

For years the TCPA's definition of an automatic telephone dialing system was interpreted broadly enough to threaten ordinary sales dialers. In 2021 the Supreme Court resolved it unanimously in Facebook v. Duguid: equipment qualifies only if it uses a random or sequential number generator to store or produce the numbers it calls.

A dialer working from a list you uploaded does not do that. That holding is the reason power dialers and list-based parallel dialers exist as a mainstream product category.

Three caveats that matter more than the headline:

State mini-TCPA statutes. Florida, Oklahoma and other states have enacted their own telemarketing statutes with broader autodialer definitions than the federal standard. A dialer that is safe federally may not be safe in a call to Tampa. Anyone dialing nationally into consumer markets should have this specifically reviewed.

Prerecorded and artificial voice messages are regulated separately from autodialers and require prior express written consent to consumers regardless of the dialing equipment. Ringless voicemail sits in contested territory here.

The abandonment cap. Predictive dialers remain subject to the FCC rule limiting abandoned calls to three percent, measured over 30 days per campaign. Predictive pacing produces abandoned calls by design, so a team running one needs someone accountable for that percentage.

The Do Not Call Registry

If you make telemarketing calls to consumers:

  • Scrub against the National DNC Registry, and re-scrub regularly rather than once when the list was bought
  • Maintain your own internal do-not-call list and honour requests immediately
  • Know your state registries, several of which exist separately
  • Understand your exemptions properly. An established business relationship creates one, but it is narrower and shorter-lived than most salespeople assume, and a prior website visit is not one

The single most likely path to a complaint is calling someone who already asked you not to. That is an operational failure, not a legal grey area, and a dialer with proper internal suppression prevents it.

In 2023 the FCC adopted a rule that would have required separate, one-to-one consent for each seller named in a lead-generation form, effectively ending the practice of a single form consenting to dozens of buyers.

The Eleventh Circuit vacated it in January 2025 in IMC v. FCC, before it took effect, and it was formally removed in July 2025. Bundled consent therefore remains permissible under the federal rules.

The practical takeaway for anyone buying leads: the vacatur removed a specific rule, it did not lower the underlying standard that consent must be prior, express and written for the calls that require it. Diligence the consent chain on any purchased list, because the seller's compliance becomes your exposure.

STIR/SHAKEN, and why it does not save you

STIR/SHAKEN is a caller ID authentication framework the FCC required US carriers to implement by 30 June 2021 under the TRACED Act. It cryptographically signs calls with an attestation level:

  • A, full attestation: the carrier knows the customer and has verified their right to use the number
  • B, partial: the carrier knows the customer but not their right to the number
  • C, gateway: the call entered from elsewhere and the carrier can vouch for nothing

Two things are commonly misunderstood.

Attestation is not a spam score. It authenticates identity, not behaviour. An A-attested number that places 500 short unanswered calls a day will still be labelled Spam Likely, because the analytics engines score behaviour.

It is not the same system as the spam labels. Hiya for AT&T, TNS for Verizon and First Orion for T-Mobile each score numbers independently. Clearing a label with one does not clear it with the others, and there is no single place to fix it.

Outside the US, briefly

UK: the Privacy and Electronic Communications Regulations and the Telephone Preference Service. Business-to-business calls must be screened against the Corporate TPS, which is a real and frequently ignored obligation.

Canada: the National DNCL and CRTC rules, with distinct requirements for identification and calling hours.

EU: GDPR governs the lawful basis for processing the contact data, before you reach any telecoms rule. Legitimate interest is the usual basis for B2B and it requires an assessment you should actually document.

Australia: the Do Not Call Register Act, with a mandatory 30-day washing requirement.

A working checklist

  • Know whether each list is business or consumer, and treat ambiguous mobiles as consumer
  • Scrub the DNC before every campaign, not once at purchase
  • Keep an internal do-not-call list and honour requests on the call
  • Do not use a predictive dialer unless someone owns the abandonment rate
  • Identify yourself and your company on every call
  • Respect 8am to 9pm in the prospect's local time
  • Diligence the consent chain on every purchased list
  • Get state-specific advice before dialing consumers nationally
  • Record what you did and when, because the defence to a TCPA claim is documentation

Frequently asked questions

Is cold calling legal in 2026?
Yes. Cold calling businesses in the US is legal and lightly regulated. Cold calling consumers is legal but heavily regulated under the Telephone Consumer Protection Act, the Telemarketing Sales Rule and the National Do Not Call Registry, with statutory damages of $500 per call and $1,500 for willful violations. The regulatory burden depends almost entirely on whether you are calling a business line or a consumer.
Are power dialers legal under the TCPA?
Generally yes. In Facebook v. Duguid in 2021 the Supreme Court held unanimously that equipment only qualifies as an automatic telephone dialing system under the TCPA if it uses a random or sequential number generator to store or produce numbers. A power dialer or a parallel dialer working from an uploaded list does not do that. State mini-TCPA statutes define autodialers more broadly, so the federal analysis is not the whole picture. This is orientation, not legal advice.
What are TCPA damages?
The TCPA provides statutory damages of $500 per violating call or text, trebled to $1,500 for willful or knowing violations, with no cap on total damages. Roughly 80 percent of TCPA suits are filed as class actions, which is what turns a compliance lapse into a company-ending number: 10,000 improperly placed calls represents a theoretical exposure of five million dollars at the base rate.
Do I have to scrub the Do Not Call list before cold calling?
If you are calling consumers in the US for telemarketing purposes, yes. Registered numbers must be scrubbed and the registry must be re-checked regularly rather than once at list purchase. Calls to business lines for business purposes are generally outside the DNC rules, but the line between a business number and a personal mobile used for business is not always clean, and mobile numbers should be treated cautiously.
What is STIR/SHAKEN and does it stop spam labels?
STIR/SHAKEN is a caller ID authentication framework the FCC required US carriers to implement by 30 June 2021 under the TRACED Act. It assigns an attestation level: A means the carrier knows the customer and that they have the right to use the number, B is partial, C is gateway-level. It authenticates who you are, not how you behave, so an A attestation does not prevent a Spam Likely label if your calling pattern looks like a robocaller's to Hiya, TNS or First Orion.
What happened to the FCC one-to-one consent rule?
The FCC's one-to-one consent rule, which would have required separate consent for each seller in a lead-generation form, was vacated by the Eleventh Circuit in January 2025 in IMC v. FCC before it took effect, and was formally removed in July 2025. Bundled consent remains permissible under the federal rules as a result. Lead buyers should still diligence the consent chain, because the vacatur removed a rule rather than lowering the underlying consent standard.

Keep reading