Written by: Matt Beucler, CEO, Plura AI
Updated September 2026
Key Takeaways
- TCPA safe harbor provisions can shield callers from liability for accidental DNC violations when they maintain documented compliance procedures as routine business practice.
- The DNC safe harbor requires five elements: written procedures, personnel training, internal DNC list maintenance, 31-day National Registry scrubbing, and proof that violations occurred despite these practices.
- Reassigned number and call-blocking safe harbors provide additional protections when callers query the FCC’s Reassigned Numbers Database and voice providers use reasonable analytics for blocking decisions.
- Documentation is critical. Records must be retained for at least five years and be producible in discovery, because the burden of proof falls on the caller.
- Plura AI’s compliance engine automates real-time DNC scrubbing, consent logging, and audit-ready reporting to help operators build defensible TCPA compliance programs at scale.
The Five Requirements For The DNC Safe Harbor
The Do-Not-Call safe harbor, codified at 47 C.F.R. § 64.1200(c)(2), can protect callers from liability for calls made to numbers on the National Do Not Call Registry when the violation results from an error despite the caller’s routine business practices.2 Congress designed this defense to protect callers that build and follow real compliance programs.

The five requirements under 47 C.F.R. § 64.1200(c)(2) are:
- Written Do-Not-Call Procedures. A documented policy must establish how the organization honors Do-Not-Call requests and complies with National DNC Registry rules. The policy should match day-to-day practice rather than sit unused in a shared drive.
- Training Of Personnel. All personnel engaged in telemarketing, plus any entity assisting in compliance, must be trained on the written procedures. Every training session should be documented with dates, attendee lists, and training materials so the organization can prove the training occurred.
- Maintenance Of A Company-Specific Do-Not-Call List. An internal list must track consumers who have requested not to be called. Internal opt-out requests never expire and must be honored permanently unless the consumer provides fresh written consent. Under the FCC’s revocation rules effective April 11, 2025, consent revocations must be honored within 10 business days.
- Access To The National Do Not Call Registry. Calling lists must be scrubbed against the National DNC Registry no more than 31 days before each call. A list that was clean on the first of the month is legally stale by the second. The FCC’s TCPA rules set a 31-day DNC scrub window for residential subscribers. The TSR allows a longer window, and callers that use the stricter 31-day standard can align with both frameworks.
- Proof The Violation Was An Error. The violation must have occurred despite routine business practices. Dated scrub confirmations, training logs, and the written policy must all be producible in discovery. If records cannot be produced, the safe harbor defense collapses regardless of actual compliance.
Evidence Burden And Record Retention. Safe harbor functions as an affirmative defense, so the burden is on the caller to produce records. The FTC’s business guidance recommends 24-month retention for DNC records, but the TCPA carries a four-year statute of limitations under 28 U.S.C. § 1658. Keeping records for five years creates a practical buffer. Some state laws require longer retention; Virginia requires 10-year retention for DNC opt-outs.
See Plura’s compliance engine in action with a live demo.
The Reassigned Number Safe Harbor
Roughly 35 million U.S. phone numbers are reassigned to new subscribers every year, which creates TCPA exposure when callers hold valid consent from the original subscriber but reach the new one.3 The FCC’s Reassigned Numbers Database (RND), live since November 2021 and accessible at icnd.us, provides a safe harbor for callers that query the database before placing a call.
Under 47 C.F.R. § 64.1200(m), the reassigned-number safe harbor requires four elements:
- The caller previously obtained prior express consent from the original subscriber.
- The caller queried the RND using the most recent numbering information.
- The database returned a “No” response, indicating the number had not been reassigned since the consent date.
- The call was placed in reliance on that response, which later proved erroneous.
The RND returns three practical outcomes: “Yes,” “No,” or “No Data.” Only a “No” response supports the safe harbor if that response later proves incorrect. A “Yes” response means the number has been reassigned and should be suppressed immediately. A “No Data” response does not qualify for the safe harbor and should be treated as moderate risk.
Practical Implementation. Most compliance teams batch RND queries 24 to 72 hours before dialing starts and re-query every 30 days for ongoing programs. Querying a list once at acquisition does not preserve the safe harbor for calls made weeks later. The query should occur before each campaign, not only before list purchase.
Plura integrates directly with the Reassigned Numbers Database as part of its pre-dial compliance stack and supports operators in building the query logs that make this defense viable.
The Call-Blocking Safe Harbor For Voice Providers
The TRACED Act (Pallone-Thune Telephone Robocall Abuse Criminal Enforcement and Deterrence Act, P.L. 116-105) was signed into law on December 30, 2019. It directed the FCC to combat illegal robocalls through a layered framework that includes STIR/SHAKEN caller ID authentication, the Robocall Mitigation Database (RMD), and the Industry Traceback Group (ITG).
Under FCC rules implementing the TRACED Act, terminating voice service providers (VSPs) may rely on a regulatory safe harbor to block calls they believe are illegal or unwanted, using reasonable analytics either directly or with third-party analytics engines. USTelecom’s Blocking and Labeling Working Group best practices, adopted April 15, 2026, confirm that this safe harbor covers blocking decisions made with reasonable analytics and does not create blanket immunity for all blocking.4
Key Distinction For High-Volume Callers. Database registration and STIR/SHAKEN compliance do not create a safe harbor from TCPA private litigation. TCPA exposure under 47 U.S.C. § 227 turns on consent and Do-Not-Call compliance, while the RMD governs carrier-level authentication and network delivery. For outbound callers, STIR/SHAKEN authentication and RMD registration function as table stakes for call deliverability and sit alongside consent-based compliance.
Plura operates as an FCC-licensed carrier and runs STIR/SHAKEN authentication on every outbound call, issuing branded caller ID at the carrier level rather than through a third-party reseller.
While STIR/SHAKEN and RND registration address network-level authentication, the DNC and reassigned-number safe harbors depend on documented, repeatable processes inside the contact center. The next section walks through how to build that program.
How To Implement A Safe Harbor Compliance Program
A defensible safe harbor program turns the five DNC requirements and reassigned-number screening into daily calling routines. The following checklist reflects the documentation and process standards described in the regulatory framework. Consult qualified counsel before finalizing any compliance program.
- Draft And Adopt A Written Do-Not-Call Policy. Document procedures for honoring opt-out requests, scrubbing against the National DNC Registry, and handling consent revocations. Update the policy when regulations change, including the FCC’s April 2025 revocation rules that cut the opt-out processing window from 30 to 10 business days.
- Train All Personnel. Conduct initial and recurring training for every employee involved in outbound calling. Document each session with dates, attendee signatures, and training materials so the organization can prove that training is routine.
- Maintain An Internal Do-Not-Call List. Log every opt-out request with timestamp and source. Internal DNC requests do not expire. Honor consent revocations within the 10-business-day window described earlier.
- Scrub Against The National DNC Registry Every 31 Days. The 31-day window functions as a hard deadline. Use the organization’s Subscription Account Number (SAN) to access the registry. If a third-party vendor scrubs on the organization’s behalf, share the SAN rather than relying on the vendor’s, because the safe harbor requires that the caller itself maintain access.
- Query The Reassigned Numbers Database Before Each Campaign. Submit phone numbers with the last-contact or consent date. Suppress any number returning “Yes” and treat “No Data” responses as moderate risk that may warrant additional controls.
- Document Everything. Maintain dated scrub confirmations, RND query logs, training records, consent records, and call logs for at least five years so the organization can substantiate its safe harbor defense.
- Automate Where Possible. Manual compliance processes often break under volume. Real-time DNC scrubbing, automated RND queries, and immutable consent logging work best when built directly into the dialing infrastructure.
Plura’s Compliance Engine enforces real-time DNC scrubbing against federal and state registries before every dial, maintains timestamped and immutable consent records, and automates quiet-hours enforcement through time-zone detection. The compliance dashboard exports audit-ready reports in one click and applies 50+ state rule sets on every outbound contact.

Compare plans and rates side by side.
Common Mistakes That Undercut The Safe Harbor Defense
Even well-documented compliance programs can fail when specific pitfalls weaken the safe harbor elements.
- Inconsistent Policy Enforcement. A written policy that is not followed undermines the defense. The safe harbor requires that procedures function as the caller’s routine business practice.
- Failure To Document Training. If training logs cannot be produced in discovery, the safe harbor defense collapses regardless of how often training actually occurred.
- Infrequent Registry Scrubbing. The 31-day window is a hard deadline. As noted earlier, the 31-day window defines when a list remains usable for safe harbor purposes.
- Ignoring Reassigned Numbers. Calling a number that has been reassigned without querying the RND removes access to the reassigned-number safe harbor. The Eleventh Circuit’s decision in Sartori v. Susan C. Little & Associates shows that courts treat the TCPA as close to strict liability for wrong-number calls.
- Relying Only On Vendor Scrubs. A third-party vendor’s scrub at the time of list sale does not protect a call made 45 days later. Re-scrubbing within 31 days of each call aligns with the safe harbor standard.
- No Audit Trail. Safe harbor operates as an affirmative defense, so the burden of proof sits with the caller. Without dated records, the defense is unavailable.
- Using The DNC Safe Harbor In Place Of Consent. The DNC safe harbor does not apply to text messages or robocalls to cell phones, which involve separate consent standards under 47 U.S.C. § 227(b) regardless of registry status. Scrubbing functions as a backstop that supports, rather than replaces, documented consent.
- Outdated Training Materials. Teams that never updated their training to reflect the FCC’s 2025 revocation rules are working from an outdated policy, which weakens the safe harbor claim even if the core conditions technically hold.
TCPA Safe Harbor Compared To TSR Safe Harbor
The TCPA safe harbor (47 C.F.R. § 64.1200(c)(2)) and the Telemarketing Sales Rule (TSR) safe harbor (16 C.F.R. § 310.4(b)(3)) are parallel frameworks that largely mirror each other, yet they differ in enforcement and exposure. The most consequential difference involves enforcement: the TCPA gives consumers a private right of action with statutory damages, while the TSR is enforced by the FTC and state attorneys general. The table below summarizes the key contrasts.
| Attribute | TCPA Safe Harbor | TSR Safe Harbor |
|---|---|---|
| Enforcing Agency | FCC | FTC |
| Private Right Of Action | Yes: $500-$1,500 per violation | No: FTC and state AGs enforce, with civil penalties up to $53,088 per violation (2024 inflation-adjusted) |
| Registry Scrub Window | 31 days (residential) | 31 days |
| Key Requirements | Written procedures, training, internal DNC list, registry access, proof of error | Written procedures, training, internal DNC list, registry access, proof of error |
Practical Difference. The TCPA allows private lawsuits with statutory damages of $500 per negligent violation or $1,500 per willful violation, and class actions can turn one plaintiff into millions in exposure. The TSR is enforced by the FTC and state attorneys general, with no private right of action under the TSR alone.
Key Nuance On Chain Liability. Both the seller and the telemarketer in the calling chain need their own documented compliance programs. A telemarketer cannot rely on a seller’s safe harbor program. Each party needs its own written procedures, trained staff, and registry scrub within 31 days to claim the defense independently.
Recent Regulatory And Court Developments (2025-2026)
The TCPA compliance landscape has shifted materially since 2024, and high-volume callers should factor these changes into any safe harbor strategy. Consult qualified counsel for guidance on how these developments may affect specific operations.
- McLaughlin Chiropractic Associates V. McKesson Corp. (June 2025). The U.S. Supreme Court held that district courts in private TCPA cases are not bound by FCC interpretations under the Hobbs Act, ending a three-decade regime of agency deference. Courts now independently interpret the TCPA, which increases the importance of compliance programs that can withstand direct judicial review.
- FCC Revocation Rules (Effective April 11, 2025). The opt-out processing window was cut from 30 business days to 10 business days. Consumers may revoke consent through any reasonable means, and keywords such as “stop,” “quit,” “revoke,” “opt out,” “cancel,” “unsubscribe,” and “end” are automatically effective.
- Steidinger V. Blackstone Medical Services (7th Cir., July 14, 2026). The Seventh Circuit held that text messages are not “telephone calls” under Section 227(c)(5) of the TCPA, eliminating the private right of action for unwanted text messages under federal Do-Not-Call rules in Illinois, Indiana, and Wisconsin. A circuit split with the Ninth Circuit remains unresolved.
- State Mini-TCPA Expansion. Texas Senate Bill 140 (effective September 1, 2025) broadened “telephone solicitation” to include texts and introduced a private right of action with statutory damages up to $5,000 per violation. Oregon House Bill 3865 (effective January 1, 2026) restricts contact hours to 8 a.m.-8 p.m. and limits daily calls to three per consumer.
Watch how Plura’s 50+ state rule sets adapt to new regulations in a live demo.
FAQ: TCPA Safe Harbor Provisions
What Are The Requirements For The TCPA Safe Harbor?
The DNC safe harbor under 47 C.F.R. § 64.1200(c)(2) requires five elements: written Do-Not-Call procedures, training of personnel, maintenance of a company-specific Do-Not-Call list, access to the National Do Not Call Registry within 31 days of calling, and proof that the violation was an error despite these routine business practices. All five elements must be met and documented. If any one element is missing or cannot be proven with records, the defense is unavailable regardless of the caller’s actual intent. Consult qualified counsel to evaluate whether a specific compliance program satisfies these requirements.
What Changed About The TCPA Safe Harbor In 2025 And 2026?
The TCPA safe harbor provisions themselves have not been rewritten, but the compliance environment around them has shifted significantly. The FCC’s April 2025 revocation rules cut the opt-out processing window from 30 to 10 business days, which requires faster updates to internal DNC lists. The Supreme Court’s June 2025 decision in McLaughlin Chiropractic Associates v. McKesson Corp. removed the requirement that district courts defer to FCC interpretations of the TCPA, so courts now independently evaluate the statute. This change makes a well-documented compliance program more important because the safe harbor must survive direct judicial scrutiny rather than relying on agency guidance. State-level changes, including new mini-TCPA laws in Texas and Oregon, have also added compliance layers for multi-state outbound programs.
What Is The Reassigned Number Safe Harbor?
Under 47 C.F.R. § 64.1200(m), callers can receive protection from liability for calls to reassigned numbers if four conditions are met: the caller previously obtained consent from the original subscriber, the caller queried the FCC’s Reassigned Numbers Database before calling, the database returned a “No” response indicating the number had not been reassigned since the consent date, and the call was placed in reliance on that response, which later proved erroneous. A “No Data” response does not qualify for the safe harbor. A “Yes” response means the number has been reassigned and the call should not be placed. The safe harbor applies only when valid consent existed and the database response was erroneous.
Does The TCPA Safe Harbor Apply To Text Messages?
The DNC safe harbor under 47 U.S.C. § 227(c) does not replace the consent requirements under 47 U.S.C. § 227(b), which address robocalls and automated texts to cell phones. Marketing texts to mobile numbers require prior express written consent regardless of whether the number appears on the National DNC Registry. Scrubbing an SMS list against the registry can support risk management but does not protect against a TCPA claim if documented written consent was never obtained. The circuit courts are currently divided on whether text messages qualify as “telephone calls” under Section 227(c)(5), with the Seventh Circuit holding they do not and the Ninth Circuit holding they do. Consult qualified counsel for guidance on SMS compliance in specific jurisdictions.
How Long Should TCPA Compliance Records Be Kept?
The FTC’s business guidance recommends 24-month retention for DNC records, but the TCPA carries a four-year statute of limitations under 28 U.S.C. § 1658. Keeping records for five years is a practical standard for many operations. Some state laws impose longer requirements; Virginia requires 10-year retention for DNC opt-outs. Records that should be retained include dated scrub confirmations, RND query logs, training records with attendee documentation, consent records, call logs, and the written Do-Not-Call policy itself with version history. Because safe harbor functions as an affirmative defense, the burden of producing these records falls on the caller. Records that cannot be produced in discovery are treated as if they never existed.
Conclusion: Build The Safe Harbor Defense Before It Is Tested
The TCPA safe harbor provisions exist to protect callers that maintain written procedures, train their people, honor opt-out requests, scrub against the National DNC Registry, and query the Reassigned Numbers Database. The defense only works when it can be proven with records. Documentation functions as the substance of the defense rather than administrative overhead.
Operators with the lowest litigation risk tend to build compliance into their infrastructure instead of treating it as a manual checklist. Real-time DNC scrubbing, immutable consent logging, automated quiet-hours enforcement, and audit-ready reporting work best as features of the dialing platform instead of processes that depend on individual team members remembering each step.
Plura’s FCC-licensed carrier infrastructure supports this kind of operational compliance at scale, with SOC 2 certification, HIPAA alignment, and 50+ state rule sets enforced on every outbound contact.1 The platform focuses on operational controls and intelligence that support compliance outcomes.
Compare plans and rates side by side. Estimate your potential savings with Plura’s ROI calculator.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.