Outreach
LinkedIn Outreach Email Outreach WhatsApp Automation Dialer Unified Inbox CRM / Pipeline
Data
Signals Lead Finder Email Finder Phone Finder Company Follower
Deliverability
Mailboundry Email Infrastructure (Google, Microsoft & Azure) Email Warmup Inbox Placement Test
AI & Automation
AI Personalization AI Reply Agent ICP Score
Built For
Founders Agencies Sales Teams B2B SaaS
Use Cases
LinkedIn Outreach Cold Email Outreach Multichannel Outreach Signal-Based Outreach Outbound Sales Lead Generation Account-Based Outreach Appointment Setting Recruiting Outreach Link Building & PR Outreach
Resources
Free Tools Help Center API & Webhooks Roadmap Blog Affiliate Pricing Log in Book a demo Start free trial
BlogSalesSales

Cold Calling Compliance: DNC, TCPA, GDPR and What You Can Dial

What B2B calling rules actually say in the US, UK and EU, and the recording-consent trap most dialers walk into.

RARavi KewatSeptember 10, 2026
← All articles

Buyers ask about this before they buy phone data, and most vendors answer with a shrug and a disclaimer. Here is the practical version, with the disclaimer stated once: this is general information, not legal advice. The rules differ by state, country and how you dial, and your own counsel should sign off before you scale.

The four questions that decide what you can dial

  1. Whose number is it? A corporate switchboard, a company desk line and a personal mobile used for work are treated differently almost everywhere, and the third is the one that carries consumer-grade protection.
  2. Where is the person? Obligations follow the recipient, not your office.
  3. How are you dialing? A human clicking a number and an automated dialer with pre-recorded audio are different legal categories in the US.
  4. Are you recording? This is the rule most teams break without noticing, because recording is usually on by default.

United States

TCPA is the headline statute and it is aimed primarily at consumer calls. Live, manually dialed B2B calls to a business line sit outside most of its heaviest provisions. Two things pull you back in: automated dialing technology and pre-recorded or artificial-voice messages, both of which raise the consent bar sharply, and personal mobiles, which are widely used as work numbers and can attract consumer treatment.

Do-not-call rules. The national registry is aimed at residential and personal numbers, and pure B2B calling to corporate lines is largely carved out. In practice a meaningful share of the mobiles on any B2B list are personal numbers, so screening against the registry and honouring it is the defensible position rather than the strictly required minimum.

Your internal list matters more than the national one. Anyone who asks not to be called must be recorded and suppressed permanently, across every campaign, sequence and channel. That is both a compliance requirement in practice and the thing an angry recipient will check.

State law adds on top. Several states have their own telemarketing statutes with registration requirements, calling-hour restrictions and private rights of action that are stricter than federal rules. If you dial nationally, you inherit the strictest state you call into.

United Kingdom and EU

In the UK, live calls to businesses are permitted, but you must screen against the Corporate Telephone Preference Service for corporate lines and the Telephone Preference Service for personal and sole-trader numbers, and you must not call anyone who has told you to stop. Automated calls with recorded messages require prior consent.

Across the EU the pattern is: calling a business contact about a relevant business matter can often rest on legitimate interest rather than consent, and that comes with obligations rather than freedom. You have to be able to justify the balance, tell people where you got their data if they ask, and stop when they ask. Several countries layer their own telemarketing registers or consent requirements on top, and a few are effectively opt-in for calls to individuals, including sole traders.

The practical rule for EU calling: your list must have a defensible provenance, your first sentence should make the business relevance obvious, and your suppression on request has to be immediate and permanent.

Dialer

Local numbers by area code, recordings and transcripts as explicit per-campaign settings, and outcomes that map to pipeline stages on the call.

See the Dialer

Recording and transcription: the rule everyone breaks

Most dialers, including ours, can record by default and transcribe at 1 credit a minute. That is genuinely useful for coaching and for CRM hygiene, and it is also the fastest way to a complaint you cannot defend.

Where Consent needed What that means operationally
One-party-consent US states Yours is enough You can record without announcing it, though announcing is still better practice
All-party-consent US states Everyone on the call Announce at the start and get a verbal yes, or do not record
UK and EU Inform, plus a lawful basis State it in the opening seconds and be able to explain why you keep it and for how long
Cross-border calls The stricter side wins If in doubt, announce

Because the rule follows the recipient, the only maintainable policy for a team dialing across states or countries is to announce on every call. It costs you one sentence, it is disarming rather than off-putting when phrased plainly, and it removes an entire class of risk. If you would rather not announce, turn recording off for those campaigns and rely on transcription of your own side only, or on notes.

Data provenance: the question behind all of it

Every framework above eventually asks the same thing: where did this number come from, and can you show it? Practically that means keeping the source and date on every phone record, retaining evidence of what filters produced the list, being able to answer a “how did you get my number” question honestly in one sentence, and deleting on request rather than suppressing quietly.

This is also why unverified bulk lists are a compliance problem as much as a data-quality one. You cannot document the provenance of a list you bought from an aggregator that will not document theirs.

A calling programme that will survive scrutiny

  • Registry screening in every market you dial, plus a permanent internal suppression list that no automation can edit.
  • Calling hours enforced per recipient time zone, not per rep.
  • Recording announced by default, or off by campaign.
  • Source and date stored on every phone record.
  • Manual-dial mode where automated dialing raises the consent bar, particularly on US mobiles.
  • A single disposition for “asked not to be contacted” that suppresses across all four channels, not just the phone.

That last point is the one that trips up multichannel teams. A do-not-contact request on a call has to stop the emails, the LinkedIn messages and the WhatsApp thread too, and if your channels live in different tools it usually does not.

Next: how to find and verify mobile numbers, or what gets a number labelled Spam Likely.

Frequently asked questions

Does TCPA apply to B2B cold calls?

Its strictest provisions target consumer calls, and business-to-business calls to a company line sit outside much of it. The complication is mobiles: a personal mobile used for work can be treated as a consumer number, and automated dialing technology and pre-recorded messages carry heavier obligations than a person dialing manually.

Do I have to check do-not-call registries for business numbers?

Registry rules generally cover residential and personal numbers rather than corporate lines, but a large share of B2B mobiles are personal numbers. The safe operating position is to screen against the national registry in each market you dial and to maintain your own internal do-not-call list, which is required in practice and is simply good hygiene.

Can I cold call in the EU and UK under GDPR?

Calling a business contact can rest on legitimate interest rather than consent in many EU jurisdictions, but you must be able to justify it, tell them where their data came from on request, and stop on request. Several countries add their own telemarketing registers on top, and the UK has its own opt-out registers for corporate and personal lines.

Do I need consent to record a call?

It depends where both parties are. Some US states require all-party consent, others one-party. Most of the EU and UK require you to inform the other party and have a lawful basis. Because recording is on by default in most dialers, this is the single most commonly breached rule in outbound calling.

Is this legal advice?

No. This is general information for planning purposes, written for sales teams rather than lawyers. Rules change, differ by state and country, and depend on your specific setup. Get your own counsel to sign off on your calling programme before you scale it.

Ready to run outbound on autopilot?

Start free trial