Cold Calling Laws in 2026: The Complete Compliance Guide for B2B Sales Teams
Major Takeaways: Cold Calling Laws
No. Cold calling remains legal across the US, Canada, the UK, and the EU. What draws liability is calling the wrong type of number, using the wrong dialing technology, ignoring an opt-out, or running into a state where you were required to register and did not.
The first quarter of 2026 produced more TCPA class actions than any quarter in the statute’s history, and filings are up 34.3% year to date through June (WebRecon). Meanwhile the FCC repealed its one-to-one consent rule and pushed its “revoke-all” opt-out rule to January 31, 2027. Federal requirements are loosening while state legislatures tighten.
Not inherently. Using an AI-generated voice to place outbound calls without prior express written consent is illegal under the FCC’s February 2024 ruling, which treats synthetic speech as an artificial voice under the TCPA. Damages run $500 per call, or $1,500 if a court finds the violation willful. AI supporting a live rep sits in a different risk category entirely.
The federal window is 8 AM to 9 PM in the recipient’s local time zone. At least 15 states are stricter. Oregon narrowed to 8 AM–8 PM with a three-contact daily cap on January 1, 2026, and Texas moved to 9 AM–9 PM Monday through Saturday in September 2025. For national outbound, 11 AM to 8 PM Eastern, Monday through Friday, clears every state rule.
A wave of quiet-hours class actions has argued that any marketing contact outside 8 AM–9 PM is a separate violation, even where the recipient consented. In April 2026 a Delaware federal court held in King v. Bon Charge that someone who voluntarily hands over their number cannot bring a quiet-hours claim. That is the first reported decision on the question, and it is favorable to callers, but the FCC petition asking for the same clarification is still unresolved.
Manually dialed calls to cell phones during legal hours are generally fine, provided you scrub against the DNC and honor opt-outs. Autodialed or AI-voiced calls to any wireless number require prior express written consent, even when the number sits on a business contact list. The TCPA treats every wireless number as residential, and there is no federal B2B carve-out for mobile.
Statutory damages run $500 per call, trebled to $1,500 for willful or knowing violations, with no cap. FTC penalties for Telemarketing Sales Rule violations reach $53,088 per violation, adjusted annually for inflation. State mini-TCPAs stack on top, with Texas allowing up to $5,000 per violation and Oregon allowing actual damages or $200 minimum plus punitive damages.
Both permit it, on different consent frameworks. EU B2B outreach runs on legitimate interest, documented in a Legitimate Interest Assessment, with country-by-country opt-out registries. Canada allows B2B calling under CRTC rules but requires DNCL scrubbing and CASL compliance for any email that travels alongside the calls.
Introduction
If you run outbound, the question lands on your desk eventually, usually from legal, usually the week after someone forwards a demand letter: are we actually allowed to do this?
You are. Cold calling is legal in every market where we operate. But the distance between legal and defensible got noticeably wider over the past eighteen months, and most of the widening happened at the state level while everyone was watching the FCC.
Here is what shifted. The first quarter of 2026 set an all-time record for TCPA class action filings, and the pace has not slowed since. A new category of lawsuit built entirely around calling hours has pulled hundreds of ordinary companies into court. At least five states rewrote their telemarketing statutes in the past two years, several with private rights of action attached. And the FCC has been moving in the opposite direction, repealing rules rather than adding them, which sounds like relief until you realize it means the real constraints now live in fifty separate places instead of one.
This guide covers what is enforceable right now: federal TCPA and TSR rules, the state mini-TCPA wave, AI voice restrictions, the quiet-hours litigation surge, GDPR and PECR for European outreach, Canadian CRTC rules, and the operating model our teams use to run compliant campaigns across North America, Europe, and LATAM. If you want the broader playbook rather than the legal layer, our guide to B2B cold calling covers the execution side.
We built this by reviewing federal regulations, state legislation, recent FCC orders, and current litigation data, then reading it through what we see running outbound for clients since 2009. The goal is a clear picture of what is actually enforceable, without the jargon.
We are not lawyers, and this is general guidance rather than legal advice. These rules change frequently and vary by jurisdiction. Confirm with counsel before launching in a new region.
Cold Calling Laws at a Glance
- Cold calling is legal in the US, Canada, the UK, and the EU; what is regulated is who you call, when, with what technology, and how you handle an opt-out.
- The federal calling window is 8 AM to 9 PM in the recipient’s local time zone, and at least 15 states impose something stricter.
- Business landlines are largely exempt from the National Do Not Call Registry; personal cell phones used for work are not, because the TCPA treats every wireless number as residential.
- Any AI-generated or prerecorded voice on an outbound marketing call requires prior express written consent, with statutory damages of $500 to $1,500 per call.
- State mini-TCPAs in Texas, Oregon, Virginia, Florida, and Washington now carry broader autodialer definitions and private rights of action than federal law, which makes them the larger practical risk for multi-state campaigns.
- Federal DNC scrubbing is required at least every 31 days, and internal opt-out requests must be honored within 10 business days.
What Changed in 2026
- January 6, 2026: the FCC delayed its “revoke-all” rule a second time, to January 31, 2027. The rule would make a single opt-out apply to all of a caller’s communications, including unrelated ones. The Bureau tied the delay to its own pending review of whether to modify or scrap the rule (Wiley).
- Q1 2026 set a record for TCPA class actions, with March alone producing 283 filings and 220 class actions. Through June, TCPA filings are up 34.3% year to date, and putative class actions made up 76.4% of June’s filings (WebRecon).
- April 30, 2026: the first reported ruling on quiet-hours claims. In King v. Bon Charge, a Delaware federal court held that a consumer who voluntarily provides their number cannot bring a quiet-hours claim, because that act removes the message from the definition of a telephone solicitation (Nixon Peabody).
- January 1, 2026: Oregon’s HB 3865 took effect, narrowing the calling window to 8 AM–8 PM and capping solicitations at three per 24 hours, counting calls and texts together (Troutman Pepper Locke).
- The FCC formally repealed its one-to-one consent rule, following the Eleventh Circuit’s January 2025 decision vacating it, as part of the ongoing “Delete, Delete, Delete” deregulatory proceeding (Womble Bond Dickinson).
Terms Worth Knowing
- Cold call is a first-touch outbound call to someone who has not engaged with you and has not consented to contact. The TCPA treats it as a telephone solicitation.
- Robocall is any call placed with an automatic telephone dialing system or delivering a prerecorded or artificial voice. AI-generated voices fall in this category.
- ATDS is equipment that uses a random or sequential number generator to store or dial numbers. After Facebook v. Duguid, most dialers pulling from preloaded lists fall outside the federal definition.
- Prior express written consent (PEWC) is a signed agreement disclosing that the person will receive marketing calls placed with an autodialer or artificial voice, naming the specific company and the number being used. Pre-checked boxes do not count.
- Mini-TCPA is a state telemarketing statute modeled on the federal TCPA, usually with a broader autodialer definition, a narrower calling window, and its own private right of action.
- Reassigned Numbers Database (RND) is the FCC-operated database that tells you whether a number has been reassigned since consent was given. Scrubbing it earns a federal safe harbor.
- ECPA is the federal Electronic Communications Privacy Act, which sets the baseline rule for recording calls: one party to the conversation may consent, and stricter state laws override it.
- Quiet hours are the periods outside 8 AM–9 PM local time when telephone solicitations to residential subscribers are prohibited.
Is Cold Calling Illegal in 2026? The Honest Answer for B2B Teams
No. Cold calling is legal in the US, Canada, the UK, and the EU. What is illegal is a specific set of behaviors: calling a number you should have scrubbed, dialing a cell phone with technology that required consent you never got, continuing after someone asked you to stop, or operating in a state that required registration you never filed.
That distinction carries more weight in 2026 than it did a year ago, because of who is doing the enforcing. The class-action surge is not being driven by the FCC or the FTC. It is being driven by a small number of plaintiffs’ firms and repeat litigators who file routinely against any company whose calling practices show a procedural gap. Roughly 42% of consumers filing suit under these statutes have filed before, according to WebRecon’s litigation data. One non-compliant campaign can generate seven-figure exposure inside a month.
The numbers behind the exposure are straightforward. Under the Telemarketing Sales Rule, the FTC can seek civil penalties of up to $53,088 per violation, a figure indexed annually for inflation and applicable to conduct after January 13, 2025. Under the TCPA, calling someone who did not consent carries statutory damages of $500 per violation, trebled to $1,500 if a court finds the violation willful or knowing. There is no cap.
Run the arithmetic on your own list size and the picture gets uncomfortable fast. A 200-call campaign against an uncleaned list sits somewhere between $100,000 and $300,000 of theoretical liability. Ten thousand calls clears $15 million. Those are not hypothetical figures. They are how class-action settlements get calculated in the first place.
This is also the part most teams underestimate when they run outbound in-house. The rules themselves are learnable in an afternoon. Building the systems that enforce them on every dial, in every state, across every channel, is a different problem, and it is the reason a lot of teams hand the calling function to an outsourced cold calling partner rather than staffing the compliance layer internally.
The B2B vs. B2C Distinction (and the Cell Phone Trap)
Federally, there is no law against cold calling a business. The FTC’s Telemarketing Sales Rule generally exempts B2B solicitation calls from National Do Not Call Registry rules, so calling a company’s switchboard or a verified business landline does not require a federal DNC scrub.
That exemption is narrower than most teams assume, and the gap it leaves is the single largest compliance trap in B2B outbound.
The trap is the cell phone. The TCPA was written in 1991 to protect people from intrusive calls to wireless numbers, and it treats every wireless number as residential regardless of how the person uses it. There is no business-use carve-out. If your prospect is a CFO who hands out her personal mobile at conferences and uses it as her working line, a marketing call to that number is governed by consumer TCPA rules, not by any B2B exemption you thought you had.
What that means for how you dial:
- Manually dialed calls to cell phones during legal hours are generally lawful, as long as you scrub against the DNC and honor opt-outs.
- Autodialed or AI-voiced calls to cell phones require prior express written consent. Full stop, regardless of whether the number came off a business contact list.
- Power dialers and parallel dialers sit in the gray zone. Most modern dialers pull from preloaded lists rather than generating numbers, which keeps them outside the federal Duguid definition of an ATDS. Florida, Oklahoma, Texas, and several other states define autodialing far more loosely, so the same configuration can be compliant in California and actionable in Tampa. If you are evaluating your stack against this, the practical differences between cold call dialers matter more for compliance than for throughput.
Several states, including Arizona, Louisiana, New Jersey, Texas, and Wyoming, restrict even manually dialed sales calls in certain contexts. The B2B exemption you are operating on is a federal exemption. The states never signed up for it.
Who Is Exempt from the Telemarketing Sales Rule?
Some organizations sit outside the TSR entirely, and if you assume you are one of them without checking, you inherit somebody else’s exemption and none of the protection.
The FTC’s jurisdictional exemptions cover banks, federal credit unions, and federal savings and loans; common carriers such as long-distance carriers and airlines when they are acting as common carriers; and genuine nonprofit organizations. Certain call types are also outside the Rule regardless of who places them, including calls made solely to conduct a survey, political solicitations, and most calls placed in response to general media advertising.
Two catches matter far more than the list itself.
The exemption belongs to the entity, not to you. The FTC states plainly that the jurisdictional exemptions for banks and nonprofits do not extend to third-party telemarketers calling on their behalf. If you run outbound for a bank, the bank is exempt and you are not. Agencies and BPOs get caught by this regularly.
The B2B exemption is narrower than the shorthand suggests. Business-to-business calls fall outside the TSR unless they involve retail sales of nondurable office or cleaning supplies, or they solicit sales or charitable contributions from a company’s employees rather than from the company. Insurance telemarketing is treated differently again: unlike the bank and nonprofit exemptions, the TSR does not automatically apply to insurance campaigns simply because a third-party telemarketer is running them, because state insurance law may occupy the field.
Tax-exempt status under the Internal Revenue Code does not by itself make an organization exempt for Do Not Call purposes either. The FTC has successfully challenged entities claiming nonprofit status whose actual function was generating leads for fee-charging firms.
None of this touches the TCPA. A TSR exemption is not a TCPA exemption, and the consent rules for wireless numbers and artificial voices apply either way.
Europe and Canada: Lawful, But with Stricter Privacy Frameworks
Outside the US, legality turns on consent and purpose rather than on dialing technology.
Canada permits cold calling but requires registration and scrubbing through the CRTC’s National Do Not Call List, plus adherence to call curfew hours covered further down. Internal opt-outs must be honored within 14 days and retained for three years. CASL, Canada’s anti-spam legislation, governs any electronic outreach traveling alongside the calls, which is why teams targeting Canadian prospects generally weight the phone and LinkedIn more heavily than email. If you are deciding how to split effort between channels in a restricted market, the tradeoffs between cold calling and cold emailing look very different under CASL than they do in the US.
The EU’s GDPR does not outlaw cold calling, but it requires a lawful basis to process personal data for marketing. For B2B outreach that basis is typically legitimate interest, which has to be documented and balanced against the prospect’s privacy rights rather than simply assumed.
The UK’s PECR adds the Telephone Preference Service for consumers and the Corporate TPS for businesses, both opt-out registries that must be screened before you dial. Most EU member states run their own equivalents: Bloctel in France, Lista Robinson in Spain, the Registro Pubblico delle Opposizioni in Italy. Enforcement is real. Italy’s data protection authority has issued multi-million-euro penalties in recent marketing cases, and Germany’s UWG allows fines up to €300,000 per violation.
Germany is the strictest of the major markets. Unsolicited B2C calls require prior opt-in, and B2B calls require presumed consent, meaning a documented assumption that the business would want the offer based on its relevance. That is a high enough bar that some teams route their German pipeline toward cold calling alternatives rather than build the documentation trail.
Cold calling is lawful as a B2B method in every market we work in. But lawful does not mean automatic, and cross-border campaigns fail compliance most often when a team applies US assumptions to EU prospects or the reverse.
How This Plays Out in Practice
One example we point to often: a Stockholm-based IoT facilities and climate-control company came to us to build US pipeline. They could not run their own US outbound from Sweden. The dialing infrastructure, the time-zone coverage, the state registration requirements, and the DNC scrubbing all sat outside their domestic operations.
Over a 24-month engagement, our onshore North American team ran appointment setting campaigns that produced 203 SQLs and 139 booked meetings with US enterprise prospects, all through US-resident compliance infrastructure. For that kind of cross-border motion, the compliance work is not overhead layered on top of the campaign. It is the precondition that makes the campaign possible at all.
Is AI Cold Calling Illegal? (Robocalls, AI Voices & Autodialers)
The vendor pitches arrive constantly: AI voice agents promising 10,000 calls a day at a fraction of a rep’s cost, conversational agents that qualify end to end, dialers that book meetings without an SDR touching the phone.
The economics look excellent in a deck. The legal position is more complicated than most of those decks acknowledge.
Is AI Cold Calling Illegal?
Using an AI voice in a cold call without consent is illegal in the US. The technology itself is not.
In February 2024 the FCC ruled unanimously that calls made with AI-generated or prerecorded voices fall under the same rules as traditional robocalls, as Wilson Sonsini summarized at the time. Any artificial or prerecorded voice on a call triggers the TCPA’s consent requirement, and an AI voice clone speaking to a prospect is, as a legal matter, an artificial voice.
Call a cell phone or residential line with an AI voice and no prior express written consent, and you have violated the TCPA. Statutory damages run $500 per call for unintentional violations and $1,500 for willful or knowing ones. Courts have generally treated unconsented AI voice calls as willful, on the reasoning that deploying the technology is too deliberate an act to plead ignorance. A campaign of 10,000 AI-dialed calls without consent clears $15 million in exposure.
State attorneys general can pursue those damages directly under the same ruling, and they have started to. The enforcement posture through 2025 shifted from warning letters to filed actions.
What About “Is Voice AI Safe” — and AI Voice Scams?
Voice AI is safe enough as a technology. What made it a regulatory target is how quickly it got misused.
Through 2024 and 2025, AI voice fraud expanded quickly, with cloned voices used to impersonate executives, family members, government officials, and brand representatives. The FCC’s ruling was designed partly to give regulators a clean enforcement hook against that activity and to draw a hard line between consented AI voice use and unconsented use.
For your team, the implication is reputational as much as legal. Even if your AI voice call is technically permitted because you hold documented consent, the person answering has no way to know that. They experience it as another synthetic voice call and respond accordingly. Buyer tolerance for unannounced AI calling is moving in one direction, and it is not toward acceptance.
Our position is straightforward: AI does its best work amplifying a human rep rather than replacing one. A senior rep with AI-prepared context, live prompts, and post-call intelligence converts at multiples of a synthetic agent working the same list. The compliance advantage and the conversion advantage point the same way.
What About Autodialers, AI Dialers, and AI Power Dialers?
The legal answer depends on the technical definition of an ATDS. After the Supreme Court’s 2021 decision in Facebook v. Duguid, the federal definition narrowed to equipment using a random or sequential number generator to store or dial numbers. Most AI dialers and power dialers pull from preloaded contact lists instead, which means they often fall outside the federal definition and outside the strict consent rule for cell phone calls.
That federal carve-out is fragile, because state definitions are broader:
- Florida’s FTSA and Oklahoma’s OTSA both define autodialing systems far more loosely than Duguid, and both create private rights of action, as Manatt covered when Oklahoma’s statute took effect.
- Texas SB140, effective September 1, 2025, treats automated dialing equipment broadly and adds a $10,000 surety bond requirement for telemarketers reaching Texas residents (Morrison & Foerster).
- Arizona, Louisiana, New Jersey, Texas, and Wyoming restrict even manually dialed sales calls in certain contexts.
The rule our team operates under is a simple one. AI that supports a live rep by drafting context briefs, suggesting talk tracks, transcribing calls, and surfacing buying signals is compliant in every market we work in. AI that speaks on the call, dials autonomously across cell numbers, or replaces the rep requires consent that pure cold outbound almost never has. If you are evaluating tools in this category, the split between assisted dialing and autonomous voice is the first thing to establish, and our breakdown of AI cold calling software maps where each platform actually sits.
Abandoned Calls, Ring Time, and the Two-Second Rule
Most compliance guides stop at consent and calling hours. The rules that actually govern how your dialer behaves on each individual call are more specific than that, and they are the ones a plaintiff’s expert examines first when reviewing your call logs.
Under the TSR, an outbound call is legally abandoned if someone answers it and you fail to connect them to a live sales representative within two seconds of their completed greeting. Abandoning calls is itself an abusive telemarketing practice. The Rule then provides a safe harbor, codified at 16 CFR 310.4(b)(4), and you qualify only if you meet all four conditions:
- Stay under a 3% abandonment rate, measured across a single campaign if it runs under 30 days, or separately over each successive 30-day period if it runs longer. Put the other way, at least 97% of calls answered by a person have to reach a live rep inside two seconds.
- Let the phone ring at least 15 seconds or four rings before you disconnect an unanswered call.
- Play a recorded message when no rep is available, stating the name and telephone number of the seller the call was placed for.
- Keep records proving all three, which is the condition teams most often skip and the one that makes the other three unprovable.
Two practical consequences follow. First, the two-second rule is the reason a pure prerecorded sales pitch violates the TSR by default: the call never connects to a representative at all. Second, the abandonment ceiling is a hard constraint on how aggressively you can run parallel dialing. A four-line parallel dialer that connects a rep on every answer is fine. The same dialer configured for volume over pickup rate will breach 3% and lose the safe harbor, and the abandoned-call log is the evidence.
The FCC applies the same 3% threshold, so aligning to the stricter reading of either agency covers you for both.
Legal Compliance for Call Filtering: Spam Labeling, STIR/SHAKEN, and Caller ID
Legal compliance for call filtering is the layer almost no outbound team plans for and nearly every outbound team eventually collides with. Your calls can be blocked or labeled before a prospect ever sees them, and the rules governing that are separate from the TCPA and the TSR.
Caller ID authentication. Under the TRACED Act, the FCC mandated the STIR/SHAKEN caller ID authentication framework, requiring voice providers to implement it across the IP portions of their networks by June 30, 2021. Carriers cryptographically sign outbound calls and assign an attestation level: full attestation when the provider can verify both the caller’s identity and their right to use the number, partial or gateway attestation when it cannot. Your attestation rating drives whether your calls are delivered clean, labeled, or dropped. Since September 2025, rules limiting how third parties can sign calls on a caller’s behalf have tightened who can vouch for your traffic, which matters if you dial through a reseller.
Transmit accurate caller ID. The TSR requires telemarketers to transmit caller identification, and blocking or falsifying it is not an option. Spoofing another number with intent to defraud or cause harm violates the Truth in Caller ID Act. Presenting your main business number instead of a raw outbound trunk number is permissible, and it is generally the better choice for answer rates.
Spam labeling is a business problem before it is a legal one. Carrier analytics engines score numbers on dial volume, answer rate, average call duration, and complaint signals, then label or block accordingly. A legitimate campaign can get flagged “Spam Likely” without breaking a single law, and once a number is labeled, remediation takes weeks. The controllable inputs are number reputation management, keeping per-number dial volume within normal business ranges, registering your numbers, and adopting branded calling or Rich Call Data so your company name and call reason display on the handset.
States are now legislating this directly. Through the 2026 sessions, several states introduced caller ID authentication and anti-spoofing bills that go beyond the federal regime. Florida’s would require the state Public Service Commission to mandate STIR/SHAKEN in every telecommunications company’s IP network by July 1, 2027, with civil penalties reaching $250,000 per violation and a requirement that providers block calls whose caller ID does not match the originating number, while Missouri’s HB 564 would make knowingly entering false caller ID information a misdemeanor on first offense and a felony thereafter (The CommLaw Group). Most of these obligations land on carriers rather than on you, but they change what your carrier will accept from you.
The practical read: filtering compliance is not primarily about avoiding penalties. It is about whether your dials connect at all. A campaign that is perfectly lawful and universally labeled produces the same pipeline as a campaign that never ran.
What’s Changing in 2026: The Eleventh Circuit, the Revoke-All Delay, and “Delete, Delete, Delete”
Four developments reshaped this landscape, three settled and one still moving.
1. The one-to-one consent rule is gone. On January 24, 2025, the Eleventh Circuit vacated the FCC rule that would have required marketers to obtain consent one seller at a time, finding in Insurance Marketing Coalition Ltd. v. FCC that the agency exceeded its statutory authority. The FCC subsequently deleted the vacated language and reinstated the prior rule, as Womble Bond Dickinson reported. Bundled and marketing-partner consent is permitted again at the federal level, though documenting specific single-seller consent still gives you a stronger position against state-level claims.
2. The revoke-all rule is delayed to 2027. The requirement that a single opt-out apply across all of a caller’s communications, originally set for April 2025, was pushed to April 2026 and then, on January 6, 2026, to January 31, 2027 (Wiley). The Bureau cited operational concerns from financial institutions and its own pending review of whether to modify the rule at all.
3. The FCC opened a broad deregulatory proceeding. In October 2025, under new leadership, the Commission began evaluating whether a range of TCPA and DNC rules, including AI-call identification requirements, should be modified or eliminated, as Squire Patton Boggs detailed. The direction of federal travel is toward fewer restrictions.
4. States are moving the other way. Texas, Oregon, Virginia, Washington, and Maine all enacted or amended telemarketing laws in 2024 through 2026 that reach AI calling, autodialed texts, and broader dialing technology than Duguid permits federally.
The net effect is worth stating clearly, because it is counterintuitive. Federal AI calling rules are loosening, and your compliance burden is still rising, because the divergence between fifty state regimes now costs more to manage than federal enforcement ever did. A single national playbook no longer works.
The Operating Model That Works in 2026
Across the campaigns our teams run in AI/ML, cybersecurity, manufacturing, fintech, and adjacent verticals, the same pattern holds. AI handles preparation and post-call work. A senior human handles the conversation.
Every campaign we run is built on Landbase, the platform behind the account data, the buying signals, and the qualification layer. It generates ICP-aligned prospect intelligence, drafts outreach context, and surfaces intent signals. The dial itself, the conversation, and the qualification belong to an experienced onshore rep. That structure is a compliance choice and a conversion choice at the same time.
What to hold onto from this section:
- Treat any AI voice as a robocall. Consent has to be documented, specific, and tied to your company by name.
- Identify the caller and the AI, even as federal rules soften. The TCPA still requires caller identification and an opt-out mechanism on artificial-voice calls, and several states require more.
- Use AI as a copilot. Context briefs, live prompts, post-call analysis, and deliverability support are universally compliant. Autonomous speaking and dialing are not.
- Track state legislative sessions on a monthly cycle. That is where the constraints you have not seen yet are being written.
- Document everything. Consent records, opt-out timestamps, call logs, and dialer configurations are your defense if a class action arrives.
Cold Calling Times Allowed: Legal Time to Call Customers
Federal law caps US telemarketing at 8 AM to 9 PM in the recipient’s local time. Most teams get that part right and miss the state overrides, which is where enforcement risk has concentrated over the past two years.
The honest answer to “what time can telemarketers legally call” depends on three things: the federal rule, the recipient’s state, and whether any state registry overrides the default. Here is each layer, with a single safe-window heuristic at the end.
Federal US Rules
The Telemarketing Sales Rule limits telemarketing calls to between 8:00 AM and 9:00 PM in the recipient’s local time zone. That window governs consumer calls. B2B calls to verified business landlines are generally exempt federally, but personal cell phones used for business get treated as residential under the TCPA and fall inside the window regardless of how the number is labeled in your CRM.
The Quiet-Hours Lawsuit Wave
This is the development most compliance guides have not caught up with, and it is currently the single most active area of TCPA litigation.
Starting in late 2024 and accelerating through 2026, plaintiffs’ firms have filed hundreds of near-identical class actions alleging that any marketing message received before 8 AM or after 9 PM is a separate violation, even where the recipient had previously consented to the contact. The argument is narrow and effective: the plaintiff concedes consent to receive messages, then argues they never consented to receive them during quiet hours. A single Florida firm filed well over a hundred of these complaints in the first few months alone, recruiting plaintiffs through social media ads.
Most defendants settled rather than litigate, so for two years no court addressed the underlying question. That changed on April 30, 2026. In King v. Bon Charge, the District of Delaware held that a consumer who voluntarily provides their phone number for marketing purposes has given the prior express invitation that removes the communication from the definition of a telephone solicitation, and therefore cannot bring a quiet-hours claim. Nixon Peabody described it as a clear, defense-friendly answer to an open question.
Two caveats before you relax. The decision is one district court, not binding nationally. And a March 2025 industry petition asking the FCC to confirm that consent waives the quiet-hours restriction remains unresolved.
What this means operationally: keep enforcing recipient-local quiet hours on every marketing call and text, consented or not. The safe posture has not changed, and the cost of maintaining it is far lower than the cost of being the test case in another circuit.
State-Level Overrides
At least 15 states impose rules stricter than federal law:
- Oregon (HB 3865): effective January 1, 2026. Window narrowed to 8 AM–8 PM with a hard cap of three solicitations per 24 hours, counting calls and texts together. Violations are unlawful trade practices under Oregon’s UTPA, which carries civil penalties and a private right of action (Troutman Pepper Locke).
- Texas (SB140): effective September 1, 2025. Extends telemarketing rules to text messages, narrows hours to 9 AM–9 PM Monday through Saturday and noon–9 PM Sunday, requires a $10,000 surety bond, and creates a private right of action with statutory damages up to $5,000 per violation.
- Virginia: effective July 1, 2026. Requires companies to honor text opt-out requests for 10 years and adds tighter caller-identification requirements.
- Florida (FTSA): window of 8 AM–8 PM, three-call cap per 24 hours, a broader autodialer definition than Duguid, and a private right of action that has driven heavy class-action volume since 2021.
- Connecticut: no telemarketing calls before noon on Sundays.
- Rhode Island: window narrows to 8 AM–6 PM on weekdays.
- Maine: restricted weekday and Saturday windows with no Sunday calling, plus a Reassigned Numbers Database scrubbing mandate in effect since July 2024.
- Colorado, Mississippi, and Pennsylvania: all maintain state DNC lists that include some categories of business numbers, so the federal B2B exemption does not carry there.
- Arizona, Louisiana, New Jersey, and Wyoming: restrict even manually dialed sales calls in certain contexts.
The Practical Safe Window
If you are running national outbound and would rather not maintain fifty state-specific calling schedules, one window clears all of them:
11:00 AM to 8:00 PM Eastern Time, Monday through Friday.
That range respects the strictest state rules across the continental US, avoids nearly every Sunday and weekend prohibition, lands inside business hours for every domestic time zone, and gives you a defensible posture if a complaint arrives. Our teams running US campaigns default to it, then expand only where a specific state’s rules and a specific account profile justify it.
Worth separating from the legal question: the permissible window is wider than the effective one. Calls before 9 AM or after 5 PM rarely convert in B2B whether or not they are legal. Our strongest connect rates cluster in late morning and mid-afternoon, roughly 10 AM to noon and 3:00 to 4:30 PM in the prospect’s local time, which sit comfortably inside every regulatory window we work under. If you want to tune this against your own data rather than inherit our defaults, the best time to cold call varies meaningfully by vertical and seniority.
Canada
CRTC rules permit telemarketing from 9:00 AM to 9:30 PM Monday through Friday and 10:00 AM to 6:00 PM on weekends, in the recipient’s local time.
EU and UK
Member states largely cluster around 8 AM to 8 or 9 PM, with country-specific additions:
- United Kingdom: PECR guidance points to 8 AM–9 PM weekdays, with weekends and bank holidays generally avoided. Businesses registered with the Corporate Telephone Preference Service cannot be called for marketing.
- Germany: unsolicited B2C calls require prior opt-in under the UWG. B2B calls require presumed consent. Calls limited to standard business hours.
- France: Bloctel is the national consumer opt-out registry. No calls before 10 AM, after 8 PM, on weekends, or on holidays.
- Italy: maintains the Registro Pubblico delle Opposizioni and continues to issue substantial GDPR penalties for unauthorized marketing calls.
- Spain: operates Lista Robinson as the national opt-out service.
Australia
The Do Not Call Register Act prohibits unsolicited telemarketing on Sundays and national holidays, with weekday calls limited to 9 AM–8 PM and Saturday calls to 9 AM–5 PM.
Why This Matters in 2026
Calling outside permitted hours exposes you to federal TCPA and TSR liability, state mini-TCPA claims, and the quiet-hours class actions described above. Most state mini-TCPAs carry private rights of action with statutory damages between $200 and $5,000 per violation. One non-compliant campaign can generate exposure exceeding the revenue it was built to produce.
State Mini-TCPA Snapshot: The 2026 Compliance Map
Yes, there is almost certainly a new cold calling law you should know about, and probably more than one.
While federal rules stabilized or loosened through 2025 and 2026, state legislatures moved the other way. Mini-TCPAs, modeled on the federal statute but with broader autodialer definitions, narrower windows, registration requirements, and private rights of action, are now the larger compliance risk for any team running multi-state campaigns.
Texas — SB140 (Effective September 1, 2025)
- What changed: telemarketing rules extended to text messages; calling hours narrowed; surety bond requirement added; private right of action created.
- Calling window: 9 AM–9 PM Monday through Saturday, noon–9 PM Sunday.
- Damages: up to $5,000 per violation.
- Registration: $10,000 surety bond required for telemarketers reaching Texas residents.
- Why it matters: the most aggressive expansion of 2025. The bond requirement alone pushed several national outbound vendors to stop targeting Texas entirely (Morrison & Foerster).
Oregon — HB 3865 (Effective January 1, 2026)
- What changed: the Telemarketing Modernization Act tightened hours, capped contact frequency, and expanded “telephone solicitation” to cover text messages.
- Calling window: 8 AM–8 PM.
- Contact cap: three per 24-hour period, calls and texts combined.
- Damages: actual damages or $200 per violation, whichever is greater, plus punitive damages.
- Why it matters: violations are actionable as unlawful trade practices under Oregon’s UTPA, and the state Department of Justice can pursue enforcement independently.
Virginia — HB 2367 / SB 1148 (Effective July 1, 2026)
- What changed: text opt-out retention extended, caller identification tightened, state penalties aligned more closely with federal TCPA damages.
- Opt-out retention: 10 years, the longest in the country.
- Why it matters: the retention period creates a real data-management burden for anyone running ongoing nurture campaigns, because your suppression records now have to outlive most CRM migrations.
Florida — FTSA (Refined 2023, Active Litigation Through 2026)
- Calling window: 8 AM–8 PM.
- Contact cap: three per 24 hours.
- Autodialer definition: substantially broader than the federal Duguid standard.
- Why it matters: the original 2021 statute was scaled back in 2023 after class actions threatened to make the state unworkable for legitimate outbound. The private right of action survived, and Florida courts remain among the most plaintiff-friendly venues in the country (NatLawReview).
Maine — Reassigned Numbers Database Mandate (Effective July 2024)
- What changed: RND scrubbing became effectively required for telemarketers reaching Maine residents.
- Why it matters: the RND lets you verify whether a number was reassigned to a new subscriber after consent was given, which is a common source of inadvertent violations. Federal rules already offer a safe harbor for callers who scrub it; Maine made the scrub a practical requirement.
Washington — Updated UCPA (2025 Amendments)
- What changed: stricter caller identification requirements and expanded private rights of action for unlawful telemarketing.
- Why it matters: violations can be pursued under the state Consumer Protection Act and the federal TCPA in parallel.
Other States to Watch
Oklahoma’s OTSA maintains a broad autodialer definition similar to Florida’s, with its own private right of action. Colorado, Connecticut, Mississippi, and Pennsylvania all maintain state DNC lists covering some categories of business numbers, which means the federal B2B exemption is unavailable for residents there. Arizona, Louisiana, New Jersey, and Wyoming restrict manually dialed sales calls in certain contexts, so manual dialing is not automatically a safe harbor.
How This Plays Out for Multi-State B2B Campaigns
The burden is real, and it is manageable when the operating model is built for it.
We ran a 14-month outbound lead generation campaign for a manufacturing client in the industrial tools space, a US market entry from a non-US operating base, that produced 1,596 leads, 1,364 MQLs, and 203 SQLs across electrical and safety verticals. That campaign required state-by-state cadence variation, dialer configuration that toggled by recipient state, scrubbing against both the federal registry and Maine’s RND requirement, and a documented audit trail per call. None of it was optional. The campaign worked because the compliance infrastructure came first.
The rule we follow on any multi-state US campaign:
- Default the calling cadence to 11 AM–8 PM Eastern, Monday through Friday: the universal safe window from the previous section.
- Apply state-aware dialer rules: recipient state lookup at dial time, with the stricter rule applied automatically.
- Suppress autodialing for Florida, Oklahoma, and Texas residents: manual or click-to-dial only, regardless of your federal Duguid position.
- Enforce internal DNC universally: any opt-out is logged and propagated across every channel and state, indefinitely.
- Document every call: timestamp, channel, agent, recipient state, consent source, outcome.
Most teams do not want to build that in-house, which is part of why our sales outsourcing clients hand us the compliance layer along with the execution. The operational overhead is meaningful and the cost of getting it wrong is worse.
Cold Call Lists, DNC, and Consent: The Mechanics of Who You Can Call
The calling window is half of compliance. Your contact list is the other half, and it is the half that generates most of the litigation. Class actions rarely allege calls at the wrong hour. They allege calls to numbers that should never have been on the list: numbers on the federal registry, numbers where someone already asked to be removed, numbers reassigned to a person who never consented to anything.
Three questions come up constantly here. Each gets answered below.
“What Happens If You Cold Call Someone on the Do Not Call List?”
The National Do Not Call Registry is operated by the FTC and held about 258.5 million active registrations as of September 30, 2025, with more than 2.6 million consumer complaints filed during that fiscal year, per the FTC’s FY2025 Do Not Call Registry Data Book. It covers personal landlines and personal cell phones. It does not generally cover business landlines.
Calling a registered number without an applicable exemption can trigger:
- FTC penalties up to $53,088 per violation, indexed annually for inflation.
- Private TCPA claims of $500 per call, trebled to $1,500 for willful or knowing violations. A single uncleaned list of 5,000 numbers carries $7.5 million of theoretical exposure at the willful rate.
- Independent state attorney general enforcement under state statutes, with their own penalty structures.
The federal scrub requirement is every 31 days. Any list older than that cannot lawfully be used for telemarketing. Practically, scrub on every list load and every campaign launch rather than on a calendar, because campaign timing rarely lines up neatly with a 31-day clock. If you are assembling target accounts from scratch, the way you build a cold call list determines how much of this you are exposed to before a single dial goes out.
The Established Business Relationship Exemption
You can lawfully call a number on the National Do Not Call Registry if the seller has an established business relationship with that person, and this is the exemption teams most often either miss or overextend.
There are two kinds, and they run on different clocks:
- Purchase or transaction: 18 months. Formed by the person’s purchase, rental, or lease of your goods or services, or a financial transaction between you. The clock runs from the date of the last payment, transaction, or shipment, not from the date the account opened.
- Inquiry or application: 3 months. Formed when someone inquires about or applies for your product or service. It runs from the date of the inquiry, and it only covers calls about what they inquired about.
The FTC’s guidance for telemarketers and sellers sets out both windows and the record you have to keep to assert the relationship at all: the person’s name and last known number, the date of the inquiry or application, and the goods or services involved (FTC).
Four limits do most of the damage in practice:
- An entity-specific opt-out beats the exemption outright. If the person has asked to be on your internal do-not-call list, no established business relationship revives your right to call.
- It cannot be renewed by calling. Placing a call does not restart either clock. Only a fresh transaction or inquiry does.
- It does not cover autodialed or artificial-voice calls to a wireless number. Once either window closes, prior express written consent is required for any autodialed call, and the exemption never substituted for consent under the TCPA’s wireless rules in the first place.
- Termination ends it. A do-not-call request, a rescinded transaction, or the end of the relationship voids the exemption regardless of where the clock stood.
For B2B teams the honest application is narrow. A demo request three months ago is an inquiry-based relationship you can call about that product. A closed-won customer is an 18-month relationship. A scraped list of people who once downloaded a whitepaper from a partner is neither.
“How Often Can a Telemarketer Call You?” (Internal DNC Rules)
Federal DNC governs who you can call. Internal DNC governs what happens after you call.
Anyone who tells your company to stop calling goes on your internal list, and that request has to be honored across the entire organization rather than only on the campaign that generated it. Since April 11, 2025, revocation requests must be honored within 10 business days of receipt, and records retained for at least five years. Treat internal DNC entries as permanent. There is no upside to letting one expire.
State rules go further. Oregon caps total solicitations at three per 24 hours, calls and texts combined. Virginia requires text opt-out retention for 10 years. Florida and Texas both treat repeat contact after an opt-out as a per-call violation under their mini-TCPAs.
“Is Bundled Consent Still Allowed?”
Yes, at the federal level. The Eleventh Circuit vacated the FCC’s one-to-one consent rule in January 2025, and the Commission has since repealed it outright. Consent covering a defined list of marketing partners is permitted again, which restored the operating model for lead-generation networks and partner-marketing arrangements that looked unworkable in late 2024.
State laws do not follow that federal carve-out. Florida’s FTSA and several other mini-TCPAs apply their own consent standards regardless of what the FCC does. Document specific, single-seller consent wherever you can, even where bundled consent is technically sufficient federally.
Reassigned Numbers: The Quiet Risk Most Teams Underestimate
Numbers get reassigned. The original prospect consented; the current subscriber did not; the TCPA does not care that you had no way to know.
The FCC operates the Reassigned Numbers Database for exactly this problem. Scrub your consent records against it and you get a federal safe harbor, meaning that if the database returns no reassignment and you place the call, you are protected from liability for that call even if the database was wrong.
Maine made RND scrubbing effectively mandatory for telemarketers reaching its residents in July 2024, and other states are considering similar requirements. Treat it as standard procedure regardless of where your prospects sit. The safe harbor alone justifies the cost.
B2B Specifics: Where the Federal Exemption Holds and Where It Doesn’t
The federal B2B exemption from the DNC Registry covers calls to verified business landlines. It does not cover:
- Personal cell phones used for business, which the TCPA treats as residential regardless of use.
- Business numbers in states maintaining their own DNC lists that include business categories, including Colorado, Mississippi, and Pennsylvania.
- Calls using an artificial voice or autodialer to any wireless number, where federal robocall rules apply universally.
- Calls after an opt-out. The exemption covers scrubbing obligations, not your obligation to honor an individual revocation.
Can someone sue you over a cold call? Yes. The TCPA provides a private right of action worth $500 to $1,500 per call, and most state mini-TCPAs add their own on top. Class actions dominate the category: putative class actions made up 76.4% of TCPA filings in June 2026 and 80% in May. The plaintiffs’ bar here is organized, well-funded, and paying attention.
Canada — DNCL and CASL
Canada’s National Do Not Call List is operated by the CRTC and must be scrubbed by any telemarketer calling Canadian numbers. B2B calls are largely exempt from DNCL scrubbing, but internal opt-outs must still be honored within 14 days and retained for three years. Penalties reach CA$15,000 per call for corporations.
CASL governs electronic messaging, including most B2B email. Any email accompanying calls to Canadian prospects has to comply with its opt-in framework or fall within a documented exemption. CASL is among the strictest anti-spam regimes anywhere. Assume opt-in is required unless you can point to the specific exemption that applies.
UK and EU — Suppression Lists and Legitimate Interest
The UK runs two opt-out registries: the Telephone Preference Service for consumers and the Corporate TPS for businesses. Both must be screened before you dial. Calling a registered number triggers ICO enforcement under PECR, with fines up to £500,000 and up to 4% of global turnover under UK GDPR for serious data violations.
EU member states each maintain their own registries. Most must be scrubbed before any consumer outbound. For B2B, GDPR typically requires legitimate interest as the lawful basis, which means a documented Legitimate Interest Assessment weighing your commercial interest against the prospect’s privacy rights. A prospect’s objection has to be honored immediately and permanently.
LATAM and APAC
Most countries operate some form of DNC or consent regime. Brazil runs Não Me Perturbe for consumer marketing and Mexico runs REPEP. Australia’s Do Not Call Register is mandatory for B2C telemarketers, with B2B largely exempt. India operates DND under TRAI rules, Japan requires opt-out compliance, and Singapore’s PDPA combines opt-out registries with consent rules.
The Practical List Hygiene Standard
Across our appointment setting and outbound campaigns, the same standard applies before any call leaves our infrastructure:
- Federal DNC scrub: every list, every load, at minimum every 31 days.
- State DNC scrubs: for every state operating its own registry.
- Internal DNC scrub: universal, indefinite, propagated across every client and channel.
- Reassigned Numbers Database scrub: for the federal safe harbor.
- Cell phone identification: separate handling for any number flagged wireless or mixed-use.
- Audit trail per call: timestamp, consent source or exemption, agent, recipient state, dialer mode.
None of that is strategy. It is the baseline everything else sits on. Targeting, messaging, cadence, and qualification only produce results if the list underneath them is clean.
What Compliant Cold Calling Actually Looks Like in 2026
The legal landscape is one half of the story. What actually separates a defensible program from one that ends up on a complaint is usually operational rather than legal.
Here is the playbook our teams run across North America, Europe, and LATAM.
1. Treat Compliance as Engineering, Not Training
The standard advice is to train your reps. That is necessary and it is not the part that fails. Reps with good intentions still make mistakes when the systems around them permit mistakes. The real work is engineering the calling environment so violations are technically prevented.
In practice that means dialer rules that block calls outside the recipient’s permitted hours automatically. List-load processes that scrub federal DNC, state DNC, and the RND before a single call goes out. Consent records that propagate across your CRM, dialer, email platform, and LinkedIn outreach in real time. Audit logs capturing every dial attempt, channel touch, and opt-out request with timestamps.
The pattern we see in teams building outbound internally is compliance treated as a checklist the rep follows rather than infrastructure the system enforces. Every list load is manual. Every state lookup is the rep’s responsibility. Every internal DNC propagation lives in someone’s head. That model worked when TCPA enforcement was rare. With filings up 34.3% year to date and class actions running above three-quarters of them, it does not work now.
2. Use Technology That Prevents Violations
The right stack does most of the compliance work invisibly. Your dialer should automatically:
- Block calls outside the recipient’s local window, state-aware rather than federal-default.
- Refuse to dial federal DNC, state DNC, internal DNC, and RND hits.
- Distinguish cell phones from business landlines and route them to manual-dial workflows where required.
- Suppress AI voice and prerecorded messaging for any number without documented PEWC.
- Cap daily contacts per recipient to the strictest applicable rule.
Enforcement at the platform layer is harder to maintain than enforcement at the rep layer, and moving it to dedicated infrastructure removes a class of operational risk that internal teams routinely underestimate.
3. Open Every Call with Identity, Company, and Purpose
The TSR requires it. So does the TCPA. So do the state mini-TCPAs. And every plaintiff’s lawyer reviewing a complaint checks the recording for it.
Within the first ten seconds, give your first name, the company you represent, and the reason for the call, framed as the sales or marketing purpose it actually is.
The “courtesy call” euphemism is one of the most common and most legally dangerous patterns in outbound scripts. The TSR explicitly prohibits misrepresenting the purpose of a call. If you are calling to sell, say so. Connect rates are not materially different from the euphemistic version, and the exposure drops to nothing. Building this into cold call scripts at the template level is more reliable than trusting reps to remember it under pressure, and the same applies to your cold call opening lines, where the compliant version and the effective version turn out to be the same sentence more often than people expect.
4. Run Coordinated Omnichannel, Not Stacked Single Channels
Regulators, plaintiffs’ lawyers, and prospects all evaluate the same thing: frequency of unwanted contact. Someone hit with six calls, four emails, and three LinkedIn messages in a week experiences harassment regardless of whether each individual touch was technically lawful. State laws capping daily contact increasingly count texts alongside calls, and federal regulators have signaled the same direction.
The compliant model is coordinated omnichannel: one system running across email, phone, and LinkedIn outreach with cadence rules that prevent over-contact in any window. Three uncoordinated channels each running their own cadence is how teams generate harassment complaints while every individual touch was legal.
The conversion math points the same way. Spread, well-paced sequences outperform concentrated single-channel pressure. A prospect who gets a thoughtful connection request, a relevant email, and a well-timed call across three weeks responds at meaningfully higher rates than the same prospect hit with twelve calls in five days.
5. Document Consent, Opt-Outs, and Every Channel Touch
If a class action arrives, your audit trail is the defense. Specifically:
- Consent records: what was agreed to, by whom, on what date, through what channel, naming which company.
- Opt-out logs: when received, when processed, and confirmation it propagated everywhere.
- Call records: date, time, recipient state, channel, agent, dial mode, outcome, duration.
- List provenance: where the data came from, when it was last scrubbed, and any RND verification.
The same documentation discipline that satisfies a regulator also makes the campaign measurable. Connect rate, conversion rate, channel attribution: every cold calling metric your leadership asks about lives in the same audit layer that protects you legally.
For EU campaigns, GDPR adds a Legitimate Interest Assessment for B2B outreach plus subject-access-request handling within 30 days. CASL adds parallel obligations for Canada. None of it is optional, and none of it is burdensome if it is built into the workflow rather than retrofitted.
6. Get Call Recording Consent Right Under the ECPA
Recording is where a compliant calling program most often creates a second, entirely separate liability, because it is governed by wiretap law rather than telemarketing law.
The federal floor is the Electronic Communications Privacy Act, 18 U.S.C. § 2511, which permits any party to a conversation to record it without notifying the others, provided the recording is not made for a criminal or tortious purpose. Your rep counts as that consenting party. Civil exposure under the ECPA runs to the greater of actual damages or $100 per day of violation or $10,000 per violation, plus attorney’s fees, which is how a routine recording setting turns into class-action arithmetic.
States can be stricter, and a meaningful number are. Eleven require all-party consent for telephone calls by clear statute or controlling case law: California (Cal. Penal Code § 632), Delaware, Florida (Fla. Stat. § 934.03), Illinois (720 ILCS 5/14-2), Maryland (Cts. & Jud. Proc. § 10-402), Massachusetts (Gen. Laws ch. 272, § 99), Montana (Code Ann. § 45-8-213, which requires notification rather than agreement), Nevada, New Hampshire, Pennsylvania, and Washington.
Worth knowing, because most vendor guides hide it: published lists of these states disagree, ranging from eleven to fifteen. The variance comes from hybrid and unsettled jurisdictions. Connecticut is all-party for civil liability. Oregon applies all-party rules to in-person conversations but one-party to phone calls. Michigan’s statute reads all-party while courts have recognized a participant exception. Hawaii splits by medium. Vermont has no wiretap statute at all. If a guide hands you a clean number without that caveat, it has not read the statutes.
Penalties in the clear states are criminal, not just civil. Recording without consent is a misdemeanor escalating to a felony in California, a third-degree felony in Florida, and a Class 3 or 4 felony in Illinois.
Two rules resolve nearly all of it:
- The stricter state’s law governs. Courts generally apply the law of the state with the strongest privacy interest, so a rep in Texas calling a prospect in California complies with California. Kearney v. Salomon Smith Barney (Cal. 2006) is the case usually cited for it.
- Disclose on every call anyway. A single sentence at the top, before anything substantive, with the other party continuing the conversation, satisfies all-party consent in most jurisdictions and removes the state-lookup problem entirely. It costs you nothing in connect rate, and it is what our teams do on every recorded call regardless of geography.
Outside the US, the EU treats recording as personal data processing requiring a lawful basis and clear notice under GDPR, and several member states add explicit consent requirements. Canada requires notification under PIPEDA. Disclose there too.
7. Adjust for Regional Context
Cross-border outbound needs different playbooks, not just translated scripts.
- North America: direct, hypothesis-led calls with strong opening relevance. Federal window with state overrides. Manual dial first-touch for any cell or mixed-use number.
- Europe: more formal tone, longer nurture cycles, channel-aware sequencing. Cold calling works well paired with documented legitimate interest and a clear opt-out at every contact. Two-party consent for recording applies in many jurisdictions, so disclose at the start.
- LATAM: relationship-building openers outperform transactional ones. Local language proficiency matters more for the substance of the call than for the opening.
- APAC: highly relationship-driven. Direct cold outbound underperforms warm intro and account-based motions; where calls happen, keep them brief and aim at securing a meeting rather than qualifying in the call.
One example from our cross-border work: a London-based AI trust and safety company entering the US market found the playbook had to flip. UK norms favor formal, structured outreach with the value statement up front. US enterprise buyers in that vertical responded better to direct, hypothesis-driven openers naming a specific pain. Same product, same ICP, different voice, and the campaign ramped to 35 qualified leads per month in a narrow category.
8. Update the Playbook Quarterly
The 2025–2026 cycle is why annual compliance reviews stopped being adequate. In twelve months: the Eleventh Circuit vacated one-to-one consent, the FCC delayed the revoke-all rule twice, Texas and Oregon mini-TCPAs took effect four months apart, Virginia’s amendments landed, the FCC opened a sweeping deregulatory proceeding, quiet-hours litigation exploded, and class action filings hit record volume.
An annual review would have left your team operating on April 2025 rules well into 2026, and Texas SB140 alone could generate seven-figure liability in that window.
Our cadence:
- Federal monitoring: weekly, with changes pushed to dialer config and scripts within seven days of an effective date.
- State monitoring: monthly across all fifty states.
- EU and Canada: quarterly, with country-by-country LIA reviews refreshed annually.
- List hygiene: federal and state DNC every 31 days, internal DNC continuous, RND on every list load.
9. Treat Outbound as a Program, Not a Campaign
The clearest predictor of a non-compliant program is short-term thinking. A team launches a six-week push, dials hard, hits the quarter, and plans to revisit compliance later. That six-week push is exactly the operating mode that generates exposure: uncleaned lists, untested scripts, undertrained reps, no documentation discipline.
The engagements where compliance discipline compounds are the long ones. The Stockholm IoT company mentioned earlier ran with us for 24 months. A logistics and supply chain SaaS company ran 31 months and generated 1,491 leads, 225 SQLs, and 108 booked meetings. Neither would have been viable as a six-week push, and the infrastructure that made them sustainable is what made them perform.
The Bottom Line for B2B Sales Leaders in 2026
Cold calling is not getting harder. It is getting more particular.
The federal trajectory is toward fewer rules: one-to-one consent is repealed, revoke-all is pushed to 2027, and the “Delete, Delete, Delete” proceeding is actively reviewing what else to remove. The state trajectory is the opposite, with Texas, Oregon, Virginia, Maine, and Washington all expanding their statutes and attaching private rights of action. That divergence is the real story, and it means a single national playbook no longer covers you.
What to carry forward:
- Cold calling is legal everywhere we operate. What is illegal is calling the wrong number type, using the wrong technology, or ignoring an opt-out.
- The cell phone is the B2B trap. Manual dial your first touch to any mobile or mixed-use number.
- State mini-TCPAs outrank federal enforcement as your practical risk. Each has its own window, its own cap, and usually its own private right of action.
- Quiet-hours claims are the active litigation front. King v. Bon Charge helps, but it is one district court and the FCC has not weighed in. Keep enforcing recipient-local hours regardless of consent.
- Compliance belongs in the infrastructure, not the training deck. Reps with good intentions still make mistakes when the systems allow them.
Running this at scale across multiple states and regions is not a workflow most internal teams want to own. The dialer-level enforcement, the state-by-state rule mapping, the consent documentation, the RND scrubbing, the cross-channel cadence coordination: that is a full stack that has to run cleanly before the first call connects.
That stack is what we maintain. Since 2009 we have paired experienced onshore Sales Executives with the platform layer to run cold calling, cold emailing, and LinkedIn outreach as a coordinated omnichannel package across North America, Europe, and LATAM, delivering qualified pipeline for 2,000+ B2B brands across 50+ verticals. If cold calling is part of your motion and you would rather hand the compliance layer to a team that runs it daily across every major jurisdiction, book a consultation and we will review your current posture and the gaps worth closing first.
Disclaimer: This article is for informational purposes only. We are not attorneys, and nothing here should be taken as legal advice. Cold calling laws vary by country and change over time, so always check with a lawyer.
FAQs: Cold Calling Laws
Is cold calling illegal in 2026?
No. Cold calling itself is legal in the US, Canada, the UK, and the EU. What is regulated is how you do it: calling hours, dialing technology, consent for wireless numbers, scrubbing against Do Not Call registries, and state-level mini-TCPA requirements. A compliant program respects all of those. A non-compliant one risks $500 to $1,500 per call in TCPA damages plus state penalties reaching $5,000 per violation. The activity is not banned. Sloppy execution is what generates the exposure.
What is the 8 AM to 9 PM rule for cold calling?
The TSR and TCPA both restrict telemarketing calls to between 8:00 AM and 9:00 PM in the recipient’s local time zone. That is the federal default. At least 15 states are tighter: Oregon and Florida cap at 8 PM, Rhode Island ends at 6 PM on weekdays, Maine prohibits Sunday calling, and Texas requires a 9 AM start. National outbound teams should default to 11 AM–8 PM Eastern, Monday through Friday, which clears every state rule, then expand only where a specific state and account profile justify it.
Can I get sued for calling someone at 7 PM if they gave me their number?
Possibly, though the law is moving in your favor. A wave of quiet-hours class actions has argued that any marketing contact outside 8 AM–9 PM local time is a violation even where the recipient consented. In April 2026, a Delaware federal court held in King v. Bon Charge that someone who voluntarily provides their number cannot bring that claim. It is the first reported decision on the question and it favors callers, but it is one district court, and the FCC petition seeking the same clarification is unresolved. Keep enforcing recipient-local hours on every marketing call and text.
Do I need consent to cold call a business?
For verified business landlines in the US, federal law generally allows cold calling without prior consent, because the Telemarketing Sales Rule exempts most B2B solicitation from the National Do Not Call Registry. The exemption breaks in three places: calls to personal cell phones used for business, which the TCPA treats as residential; states like Colorado, Mississippi, and Pennsylvania that maintain DNC lists covering business numbers; and AI-voiced or autodialed calls to any wireless number, which require prior express written consent regardless.
Is AI cold calling illegal?
Using an AI-generated voice to place cold calls without prior express written consent is illegal in the US. The FCC ruled in February 2024 that AI voices count as artificial voices under the TCPA, which triggers robocall consent rules. Damages run $500 per call, or $1,500 if willful, and state attorneys general can pursue them directly. AI used as a copilot for a live rep, drafting context, suggesting talk tracks, transcribing calls, is fully compliant. AI used as the caller requires consent that pure cold outbound rarely has.
What is the difference between TCPA and TSR?
Both regulate US telemarketing, but they cover different ground. The TCPA, enforced by the FCC, governs dialing technology, prerecorded and AI voices, and consent requirements for wireless numbers. The TSR, enforced by the FTC, governs call timing, conduct, disclosure, and the National Do Not Call Registry. They overlap constantly, and a single non-compliant call can violate both. The TCPA carries a private right of action worth $500 to $1,500 per call. The TSR carries FTC civil penalties up to $53,088 per violation.
What are state mini-TCPAs and why do they matter?
Mini-TCPAs are state laws modeled on the federal statute but with broader autodialer definitions, stricter windows, extra registration requirements, and private rights of action. The most aggressive in 2026 are Texas SB140, Oregon HB 3865, Virginia’s July 2026 amendments, and Florida’s FTSA. A call that is compliant federally can still violate state law, and most mini-TCPAs let the recipient sue directly rather than waiting for a regulator.
If my rep is in Texas and the prospect is in California, whose call recording law applies?
California’s, in practice. Texas is a one-party consent state and California requires all-party consent, and courts generally apply the law of the state with the strongest privacy interest rather than the caller’s home state. That means a Texas rep who records without disclosing can face liability under California Penal Code § 632, where a violation is a misdemeanor on the first offense. The same logic applies to any call touching an all-party state. Because your reps cannot reliably know where a prospect is physically sitting when they answer a mobile, the workable policy is to disclose recording at the start of every call regardless of geography.