Written by: Matt Beucler, CEO, Plura AI
Key Takeaways
- TCPA is the federal umbrella statute that governs consent, technology, and calling hours for outbound calls and texts. DNC compliance focuses on screening numbers against the National Do Not Call Registry.
- Violations create significant financial exposure. TCPA statutory damages range from $500–$1,500 per call or text, and DNC violations can trigger FTC penalties up to $43,792 per call plus FCC forfeitures.
- High-volume operations need layered compliance that covers consent documentation, 31-day National DNC scrubbing, internal do-not-call list management, and time-zone-specific calling hour enforcement.
- State laws add complexity. More than 40 states maintain their own telemarketing rules, with some requiring more frequent scrubbing (Florida: every 10 days) and penalties up to $25,000 per violation.
- Plura AI delivers enterprise-grade compliance automation through real-time DNC scrubbing, TCPA-litigator screening, and immutable consent logging on every outbound contact. See the platform in action.
Updated September 2026
What Is TCPA Compliance? The Umbrella Statute
The Telephone Consumer Protection Act, enacted in 1991 and codified at 47 U.S.C. § 227, regulates telemarketing calls, robocalls, SMS and text messages, and unsolicited faxes to U.S. phone numbers.2 It applies to any organization making outbound sales calls or automated outreach, regardless of company size. There is no small-business exemption.
TCPA compliance centers on three operational requirement areas:
- Consent: 47 C.F.R. § 64.1200(a)(2) requires prior express written consent for autodialed or artificial voice calls to cell phones and for marketing texts. Informational calls such as appointment reminders and order updates require prior express consent, which is a lower standard. Written consent must be signed (electronic signatures qualify), must clearly authorize the specific seller, and cannot be a condition of purchase.
- Technology restrictions: The TCPA restricts automatic telephone dialing systems (ATDS) and prohibits prerecorded or artificial voice calls without appropriate consent. In February 2024, the FCC issued Declaratory Ruling 24-17. It confirmed that AI-generated voices qualify as “artificial voices” under the TCPA. This brings AI voice outbound campaigns under the same consent and disclosure framework as traditional autodialed calls.
- Calling hours: 47 C.F.R. § 64.1200(c)(1) restricts outbound telemarketing to 8:00 AM–9:00 PM local time at the called party’s location, not the caller’s location.
TCPA violations carry statutory damages of $500 to $1,500 per unsolicited call or text.4 TCPA class action settlements averaged $6.6M in 2023.3 A single campaign reaching 100,000 people with a systemic consent deficiency represents $50–$150 million in theoretical exposure. The FCC can also impose separate administrative forfeitures up to $23,727 per violation under 47 U.S.C. § 227(f).
Real settlement examples show the scale of exposure. UnitedHealthcare paid $2.5 million to resolve alleged TCPA violations. Capital One settled a TCPA class action for $75.5 million in 2014. Dish Network faced a $280 million judgment in 2017 for TCPA and TSR violations.
What Is DNC Compliance? The Subset That Screens Who You Call
DNC compliance operates under two parallel frameworks: the TCPA’s do-not-call provisions enforced by the FCC and the FTC’s Telemarketing Sales Rule (TSR), 16 C.F.R. Part 310.2 The National Do Not Call Registry, maintained by the FTC, holds more than 249 million active registrations covering both landline and wireless numbers.
DNC compliance involves three distinct obligations:
- National Registry scrubbing: 47 C.F.R. § 64.1200(c)(2) and 16 C.F.R. § 310.4(b)(3)(iv) require comparing calling lists against the National DNC Registry using a version no more than 31 days old. A list that was clean 32 days ago creates exposure from the first call. The entity making the call is responsible for its own scrub. Relying on a lead vendor’s claim that a list is “pre-scrubbed” does not satisfy this obligation.
- Internal do-not-call lists: Under 47 C.F.R. § 64.1200(d), companies must maintain a company-specific suppression list and honor opt-out requests within 30 days under the FCC standard. Internal DNC entries must be retained for at least 5 years and applied across the organization, not only to a single campaign.
- Opt-out honoring: Any consumer request to stop calls must be honored immediately and indefinitely, regardless of registry status or consent on file. As of April 2025, the FCC expects businesses to honor revocation requests within 10 business days across all channels.
Penalties for DNC violations include FTC civil penalties up to $43,792 per call under the TSR (as of 2024 inflation adjustments), FCC forfeitures up to $23,727 per violation, and private TCPA suits at the statutory range mentioned earlier under 47 U.S.C. § 227(c)(5). In 2023, the FTC and state attorneys general reached a $299 million settlement with a health insurance telemarketer for DNC and TSR violations.
Several states also maintain their own DNC registries separate from the federal list, including Colorado, Florida, Indiana, Louisiana, Massachusetts, Missouri, Oklahoma, Pennsylvania, Tennessee, Texas, and Wyoming. Florida requires DNC list scrubbing every 10 days versus the federal 31-day standard.
Key Differences Between TCPA and DNC Requirements
TCPA and DNC frameworks address different questions on each outbound contact. TCPA governs how you contact a consumer, while DNC rules govern whether you may place a telemarketing call to that number at all.
| Aspect | TCPA | DNC / TSR |
|---|---|---|
| Primary Focus | Consent, technology used, and calling hours | Whether a number can be called for telemarketing |
| Key Questions | Do you have the right level of consent for this technology and purpose? | Is this number on a federal or state DNC list or internal DNC list? |
| Scope | Autodialed, prerecorded, artificial voice calls, texts, and faxes | Telemarketing calls to residential and wireless numbers |
| Core Obligations | Obtain and document consent, follow technology limits, respect calling hours | Scrub against National and state DNC lists, maintain internal DNC, honor opt-outs |
| Primary Enforcers | FCC and private litigants | FTC, FCC, state attorneys general, and private litigants |
The Compliance Stack: How TCPA, DNC, TSR, and State Laws Fit Together
TCPA sets the umbrella rules. DNC requirements sit inside that structure. The full compliance picture for high-volume outbound operations also includes the Telemarketing Sales Rule (TSR) and a patchwork of state-specific laws. At least 40 states have their own telemarketing or do-not-call statutes4 that go beyond federal law, with state penalties reaching up to $25,000 per violation in some jurisdictions. Federal compliance sets a baseline and does not displace state claims.
A practical layered framework for outbound operations looks like this:
- Obtain consent (TCPA layer): Capture prior express written consent for autodialed or artificial voice calls and texts. Consent must name the specific seller, be signed (electronic qualifies), and remain separate from any purchase requirement.
- Scrub against DNC lists (DNC layer): Compare against the National Registry every 31 days plus applicable state lists. Florida requires every 10 days. The scrub date governs. A 32-day-old download creates exposure from the first call.
- Honor opt-outs (Internal DNC layer): Suppress numbers immediately upon request, apply suppression across the organization, and retain entries for at least 5 years. Any consumer request ends any Established Business Relationship (EBR) immediately.
- Follow calling hours and technology rules (Operational layer): Enforce 8 AM–9 PM local time at the called party’s location under federal rules. Florida restricts to 8 AM–8 PM. Maine bans weekend calls entirely. Apply STIR/SHAKEN authentication on every outbound voice call.
Teams that treat TCPA and DNC as separate checklists often leave gaps. A number can be on the National DNC Registry and also require TCPA consent for autodialed contact. A number can have valid consent on file and still be protected by a direct opt-out request. These frameworks interact on every outbound contact.
Watch a live outbound workflow to see how this compliance stack operates inside a single platform.
Penalties and Violations: Real Numbers and Examples
Penalty exposure for TCPA and DNC violations is concrete. The statutory structure allows consumers to recover damages without proving financial harm, which makes class actions in this space especially risky for defendants.
The following penalty figures illustrate the financial exposure across different enforcement mechanisms:
- TCPA statutory damages: $500–$1,500 per violation under 47 U.S.C. § 227(b)(3), with no cap. A campaign reaching 100,000 people with a systemic consent deficiency represents $50–$150 million in theoretical exposure.
- TCPA class action settlements: Averaged $6.6M in 2023.
- TSR civil penalties: Up to $53,088 per violation (FTC, 2024 adjustment) for TSR violations, including DNC Registry calls.
- DNC violations: Up to $43,792 per call under FTC enforcement as of 2024 inflation adjustments.
- FCC forfeitures: Up to $23,727 per TCPA violation, separate from any private lawsuit.
Recent enforcement actions reinforce these numbers. UnitedHealthcare paid $2.5 million. Capital One settled for $75.5 million in 2014. Dish Network faced a $280 million judgment in 2017. In 2023, the FTC and state attorneys general reached a $299 million settlement with a health insurance telemarketer for DNC and TSR violations.
What happens if you call a DNC number? The caller faces FTC civil penalties up to the $43,792 per-call figure noted earlier, potential FCC forfeitures, and private TCPA suits within the statutory range mentioned above. The caller also loses safe harbor protection, which requires a written DNC policy, trained personnel, and documented scrub records.
What are the penalties for TCPA violations? Statutory damages fall within the $500–$1,500 range per violation with no statutory cap. A 100,000-call campaign represents $50–$150 million in theoretical exposure before willfulness is alleged.
Exemptions: When Do TCPA and DNC Not Apply?
Several exemptions reduce compliance obligations in specific circumstances. Their limits matter as much as their availability.
- Prior Express Written Consent (PEWC): PEWC can override DNC registry restrictions for autodialed or artificial voice calls when properly documented. Consent must name the specific seller, be signed, and remain separate from any purchase requirement. PEWC is the most durable exemption and applies across channels including SMS.
- Established Business Relationship (EBR): Under 47 C.F.R. § 64.1200(f)(5), EBR exists for 18 months from the last purchase or transaction and 3 months from an inquiry or application. The EBR applies only to live-agent calls to residential landlines on the National DNC Registry. It does not cover autodialed cell calls, marketing texts, or prerecorded messages. A direct opt-out request ends the EBR immediately. The EBR cannot transfer from a lead generator to a downstream buyer.
- Informational calls: Non-telemarketing calls such as appointment reminders and order updates require prior express consent, not written consent. The FCC’s February 2024 Declaratory Ruling on AI voices applies the same framework to AI-generated informational calls.
- Non-profit and political calls: Many of these calls fall outside National DNC Registry rules because they do not meet the TCPA definition of “telephone solicitation,” which requires a commercial purpose. Third-party telemarketers hired to fundraise on behalf of charities may not qualify for this exemption.
What calls are exempt from DNC? Exempt categories generally include calls with prior express written consent, EBR calls within applicable time limits to residential landlines, informational calls with prior express consent, and calls from non-profit or political organizations calling on their own behalf. EBR does not override a consumer’s direct opt-out request under any circumstances.
Operational Checklist: How to Support Compliance
High-volume outbound operations need a repeatable process that runs continuously. The following checklist reflects the layered framework described above. Consult qualified legal counsel to confirm how these obligations apply to your specific operation.
- Scrub against the National DNC Registry at least every 31 days. Automate on a rolling cycle tied to call date, not list import date.
- Scrub against applicable state DNC lists on their required schedules, including Florida every 10 days.
- Maintain an internal do-not-call list. Honor opt-out requests within 10 business days and retain entries for at least 5 years.
- Obtain and document prior express written consent for autodialed or artificial voice calls and texts. Capture timestamp, IP address, form version, and exact disclosure language.
- Enforce calling hours (8 AM–9 PM local time at the called party’s location) with real-time time-zone detection. Apply state-specific windows where stricter.
- Re-scrub purchased lead lists before use. The entity making the call remains responsible for its own scrub regardless of vendor representations.
- Train staff on compliance procedures and document training. A written DNC policy is expected by both the FCC and FTC.
- Use compliant technology. Plura’s AI Predictive Dialer supports real-time DNC scrubbing and consent management on every outbound contact.
Common Scenarios and Mistakes
The following scenarios address nuanced questions that compliance teams encounter in practice. These descriptions are informational. Consult qualified legal counsel for guidance specific to your operation.
- Consent on file and number on the DNC Registry: Consent and DNC registry status operate as separate checks. For telemarketing calls to registered residential lines, DNC restrictions apply unless an exemption such as PEWC or a valid EBR applies. Properly documented prior express written consent can override DNC registry restrictions for autodialed or artificial voice calls.
- Customer asks to join your internal DNC list: The request must be honored immediately and indefinitely. It ends any EBR. The suppression must apply across the organization, not only to the campaign or representative that received the request.
- Scrub frequency decisions: Federal rules expect scrubbing at least every 31 days for the National DNC Registry. Florida requires every 10 days. The scrub must be tied to the call date. A list that was clean 32 days ago is not considered clean today.
- Buying leads labeled as pre-scrubbed: The entity making the call is responsible for its own compliance. Vendor representations do not satisfy the 31-day scrub obligation. Re-scrub purchased lists before use and retain scrub records for at least 4 years.
Why Plura AI for Compliance Support
Plura AI is an enterprise communications OS built on an FCC-licensed carrier. It covers the AI Predictive Dialer, AI voice agents, and AI SMS across 100% U.S. infrastructure. The platform’s compliance engine sits in the core architecture.
On every outbound contact, Plura supports compliance through:
- Real-time DNC scrubbing: Every number is checked against federal and state DNC registries before dial. Non-compliant numbers are blocked before the first attempt.
- TCPA-litigator screening: Screening is built into the platform on every outbound contact.
- Immutable consent logging: Consent records are timestamped and audit-ready, with one-click export for legal review or regulatory inquiries.
- Automated quiet hours: Time-zone detection enforces federal and state-specific calling windows on every campaign without manual configuration per state.
- STIR/SHAKEN authentication: Every outbound voice call is authenticated at the carrier level through Plura’s FCC-licensed infrastructure.
Plura holds SOC 2 and HIPAA certifications and enforces 50+ state rule sets on every outbound contact.1 The platform supports customer compliance. Customers remain responsible for their own regulatory obligations and the claims they make to their end users.
Plura’s compliance framework includes SOC 2 compliant infrastructure, TCPA and STIR/SHAKEN enforcement, DNC screening, and caller ID reputation management1, all enforced inside the platform before a call leaves the network.

See the compliance engine in a live demo and review a full outbound workflow.
Frequently Asked Questions
What Is the Difference Between TCPA and DNC?
The TCPA (Telephone Consumer Protection Act, 47 U.S.C. § 227) is the umbrella federal statute that regulates how you call. It governs the technology you use (autodialers, prerecorded or artificial voices), the consent you must obtain, and the hours during which you can call. DNC compliance is a subset of that framework. It governs who you can call based on whether a number appears on the National Do Not Call Registry, whether the consumer has submitted a direct opt-out request, and whether an exemption such as an Established Business Relationship applies. Both frameworks can apply to the same call at the same time, and a violation of DNC rules is also a TCPA violation under 47 U.S.C. § 227(c).
What Happens If You Call a DNC Number?
Calling a number registered on the National Do Not Call Registry without a valid exemption exposes the caller to FTC civil penalties up to the $43,792 per-call figure noted earlier under the Telemarketing Sales Rule, FCC forfeitures up to $23,727 per violation, and private TCPA suits within the statutory range mentioned above under 47 U.S.C. § 227(c)(5). The caller also loses safe harbor protection, which requires a written DNC policy, documented staff training, and dated scrub records. State attorneys general can bring independent enforcement actions under applicable state telemarketing statutes, with state penalties reaching up to $25,000 per violation in some jurisdictions.
What Are the Penalties for TCPA Violations?
TCPA statutory damages are $500 per violation for standard violations and up to $1,500 per violation for willful or knowing violations, with no statutory cap on total damages under 47 U.S.C. § 227(b)(3). Each call or text is a separate violation with its own four-year statute of limitations. Class action settlements in this space averaged $6.6M in 2023. The FCC can impose separate administrative forfeitures up to $23,727 per violation. A campaign with a systemic consent deficiency reaching 100,000 contacts represents $50–$150 million in theoretical statutory exposure before willfulness is alleged.
What Calls Are Exempt from DNC?
The following categories of calls are generally exempt from National Do Not Call Registry restrictions: calls made with prior express written consent from the specific consumer to the specific seller, calls to numbers where a valid Established Business Relationship exists (18 months from last transaction and 3 months from last inquiry) and the consumer has not submitted a direct opt-out request, informational calls with prior express consent that do not constitute telemarketing, and calls from non-profit organizations or political entities calling on their own behalf. These exemptions have specific conditions and limitations. The EBR exemption applies only to live-agent calls to residential landlines and does not cover autodialed cell calls or marketing texts. A direct opt-out request ends any EBR immediately and must be honored regardless of registry status or consent on file.
How Often Must You Scrub Against the National DNC Registry?
Under 47 C.F.R. § 64.1200(c)(2) and 16 C.F.R. § 310.4(b)(3)(iv), calling lists must be compared against a version of the National Do Not Call Registry that is no more than 31 days old before any call is placed. The 31-day window is measured from the date of the last scrub to the date of the call, not the date of list import. A list that was clean 32 days ago creates exposure from the first call placed against it. Florida requires scrubbing every 10 days under state law. Several other states maintain their own DNC registries with separate scrub requirements. Scrub records should be retained for at least 4 years, including the date of each scrub, the data set pulled, and the number of records suppressed.
What Are the 5 Major Types of TCPA Violations?
The five most common categories of TCPA violations in enforcement actions and litigation are: autodialed calls to cell phones without prior express written consent, prerecorded or artificial voice calls without the required consent level, calls to numbers registered on the National Do Not Call Registry without a valid exemption, calls placed outside the permitted 8 AM–9 PM local time window at the called party’s location, and failure to honor opt-out requests, including continuing to contact a consumer after they have revoked consent through any reasonable means. Each of these categories carries per-violation exposure within the statutory range mentioned earlier, and multiple categories can apply to the same call.
Conclusion: Build a Layered Outbound Compliance Program
TCPA compliance and DNC compliance work together as complementary layers. TCPA governs how you call. DNC governs who you call. High-volume outbound operations that align these frameworks build more durable compliance programs with fewer gaps at the intersections.
A durable compliance program requires consent management, National and state DNC scrubbing on the required schedules, immediate opt-out honoring, calling-hour enforcement by the called party’s local time, and technology that applies these rules before a call leaves the network. At least 40 states have telemarketing statutes stricter than federal rules, and state penalties can reach $25,000 per violation independently of federal exposure.
Plura’s AI Predictive Dialer supports real-time DNC scrubbing, TCPA-litigator screening, automated quiet hours, and immutable consent logging on every outbound contact, all enforced at the carrier level through Plura’s FCC-licensed infrastructure.
Compare plans and rates side by side on Plura’s pricing page. Run your numbers through Plura’s ROI calculator to check your savings in real time.
Schedule a personalized demo and see how the compliance stack operates on every outbound contact.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.