Is it illegal for cold callers?
Cold calling is legal but regulated. Learn TCPA fines, Do Not Call rules, B2B exemptions, and how to vet an outreach provider's compliance practices.

Is it illegal for cold callers?
Key Facts
- Cold calling is legal across the US, Canada, UK, and EU — but heavily regulated with per-call penalties that scale with dial volume according to legal analysis
- TCPA violations carry $500 per call, trebled to $1,500 for willful violations, with no cap on total damages per penalty framework
- A 200-call campaign against an uncleaned list can create $100,000–$300,000 in theoretical liability per telemarketing law analysis
- The 2024 TSR update expanded coverage to certain B2B telemarketing and extended DNC record retention from 2 to 5 years per regulatory analysis
- TCPA wireless rules have no B2B carve-out — calling a prospect's personal cell triggers consumer rules regardless of business context per legal analysis
- TCPA class action filings rose 34.3% year-to-date through June 2026, with March 2026 alone producing 283 filings per WebRecon data
- Spam-tagged numbers lose 70–90% of their connect rate once carriers flag them per carrier-level analysis
No, Cold Calling Isn't Illegal — But It's Heavily Regulated
The short answer: no. Cold calling remains legal across the US, Canada, the UK, and the EU. What draws liability isn't the call itself — it's calling the wrong type of number, using the wrong dialing technology, ignoring an opt-out, or running into a state where you were required to register and didn't.
In the US, two federal frameworks do most of the work. The FTC's Telemarketing Sales Rule requires specific disclosures, restricts calling hours, prohibits calls to anyone on the National Do Not Call Registry, and bans misrepresentations. The TCPA layers on financial risk: $500 per violating call, trebled to $1,500 for willful violations, with uncapped statutory damages.
Those per-call penalties add up fast. A compliance analysis cites a $925 million jury verdict against a company that made 1.8 million non-compliant calls. Even a modest 200-call campaign against an uncleaned list can theoretically carry six-figure liability.
The core rules are straightforward:
- Call only between 8 a.m. and 9 p.m. local time — and at least 15 states have stricter windows of their own
- Scrub your lists against the Do Not Call Registry at least every 31 days
- Honor opt-outs promptly — within 10 business days under the TCPA
- Get prior express written consent before autodialing or prerecorded messages to wireless numbers
That last point is where many B2B teams get burned. The B2B exemption is real but narrower than commonly assumed. The TCPA's wireless-number rules have no B2B carve-out at all — if your prospect hands out her personal mobile as her working line, consumer rules govern that call. And since May 2024, the TSR has expanded to cover certain B2B telemarketing, with record retention extended from two years to five.
The practical takeaway for anyone hiring an outreach partner: compliance is a system, not a checkbox. Ask any provider — including Worqd — how they verify consent, how often they scrub lists, and how they document opt-outs. It's why our approach is personalized, permission-aware outreach to relevant accounts, with explicit consent captured up front, rather than a template blast to a purchased list.
The rules are learnable in an afternoon. Building the systems that enforce them on every dial is what separates lawful outreach from expensive lawsuits.
CTA: Book a growth call to see how permission-aware outreach fits your pipeline. Social proof: One partner, one plan, one report — the whole path from first click to booked call.
The Real Cost of Getting It Wrong: Penalties and Enforcement
The penalties for getting cold calling wrong aren't theoretical — they're per-call, uncapped, and they add up faster than most businesses realize. A single campaign against an uncleansed list can generate six figures of exposure before anyone notices the problem.
Start with the TCPA. Under the penalty framework for TCPA violations, each non-compliant call carries $500 in statutory damages, trebled to $1,500 for willful or knowing violations — with no cap on total damages. There's no ceiling, so exposure scales directly with dial volume.
The TSR adds another layer. Civil penalties run up to $53,088 per violation for conduct after January 13, 2025, indexed annually for inflation. Calling a number on the National Do Not Call Registry can trigger a separate fine of $43,792 per call.
Now do the liability math. A modest 200-call campaign against an uncleaned list represents $100,000–$300,000 in theoretical liability. Scale that to 10,000 calls and exposure clears $15 million. This is why compliance isn't a legal-team afterthought — it's a core business risk.
Real enforcement cases show courts are willing to impose these numbers:
- A multi-level marketing company that made over 1.8 million calls in violation of autodialer rules received a $925 million jury verdict, later affirmed on appeal (DNC.com's penalty analysis).
- A satellite TV provider class action trebled $400-per-call damages to $1,200, producing a $61 million total.
- In Europe, Italy fined telecom TIM €27.8 million under GDPR for unsolicited calls, while France fined Futura Internationale €500,000 for cold calling people who had objected.
- The UK's ICO fined Skean £100,000 in January 2024 for 614,342 unsolicited calls to TPS-registered numbers.
The risk is also growing, not shrinking. TCPA filings were up 34.3% year to date through June 2026, with Q1 2026 setting an all-time record for class actions — March alone produced 283 filings. Meanwhile, at least five states, including Texas, Oregon, Virginia, Florida, and Washington, have rewritten telemarketing statutes with private rights of action, meaning individuals can sue you directly without waiting for a regulator.
Plaintiffs' firms drive much of this litigation — roughly 42% of consumers filing TCPA suits are repeat litigators who know exactly what to look for. An uncleansed list, a missing opt-out process, or calls outside permitted hours are invitations.
This is the context in which choosing an outreach partner becomes a compliance decision. When you vet a provider, ask how they scrub lists against DNC registries (required at least every 31 days), how they document consent, and how they handle opt-outs. Worqd's approach — personalized, permission-aware outreach with explicit consent captured before any contact — reflects what the regulations actually demand. The cheapest campaign is never the one that ends in a class action.
The B2B Exemption Is Narrower Than You Think
Many sales teams operate on a comfortable assumption: if you're calling a business, the rules don't really apply. That assumption is now one of the most expensive mistakes a company can make.
It's true that B2B calls are largely exempt from consumer Do Not Call rules — a distinction sales research from ZoomInfo identifies as a key difference from B2C calling. But "largely exempt" is not "exempt," and the gaps have grown wider in the last two years.
The 2024 TSR expansion changed the baseline. An April 2024 update to the FTC's Telemarketing Sales Rule extended coverage to certain B2B telemarketing activities and added new record-keeping requirements for both B2C and B2B telemarketers, according to ActiveProspect's breakdown of the rule. The same update stretched DNC record retention from two years to five.
The FTC's own guidance draws the line clearly: B2B solicitation calls are exempt from the TSR unless they involve retail sales of nondurable office or cleaning supplies, or solicit purchases from employees, per the FTC's compliance guide. Those carve-outs catch more campaigns than most callers expect.
Then there's the cell phone trap — arguably the biggest B2B risk of all. The TCPA's wireless rules contain no B2B carve-out whatsoever. As Martal Group's legal analysis puts it, if your prospect is a CFO who hands out her personal mobile at conferences, a marketing call to that number is governed by consumer TCPA rules — not by any B2B exemption you thought you had. With TCPA penalties running $500 per call and up to $1,500 for willful violations, per DNC.com's penalty overview, a single uncleaned list can turn into six-figure exposure fast.
California adds another layer. The CCPA's B2B exemption expired on January 1, 2023, meaning California business contacts now hold the same opt-out rights as consumers, as Instantly's legal guide notes. Any list built before that date needs a fresh look.
Finally, a point that matters enormously when hiring an outreach partner: third-party agencies don't inherit their clients' exemptions. If you run outbound for a bank, the bank is exempt — you are not. The FTC's guidance confirms that any company contracting with exempt entities to provide telemarketing services must still comply with the TSR in full.
So when you vet a provider, ask questions that expose whether they understand these limits:
- How do you handle prospects whose business line is a personal cell phone?
- How often do you scrub against DNC registries — and can you show it?
- How do you document consent and honor opt-outs, and for how long?
- Which TSR provisions apply to your agency directly, regardless of our status?
This is why Worqd builds its B2B outreach around personalized, permission-aware contact with relevant accounts — the opposite of a template blast — and captures explicit consent in its own booking funnel. In a landscape where the B2B exemption keeps shrinking, permission isn't just polite; it's protection.
What Compliant Outreach Actually Looks Like
Most teams treat compliance like a firewall purchase: buy it once, check the box, move on. But as compliance experts point out, lawful outreach is a continuous system, not a one-time checkbox — and the rules themselves are learnable in an afternoon, while building the systems that enforce them on every dial is a different problem entirely.
That system has six moving parts. Here is what compliant outreach actually looks like in practice:
- Verified lead data — clean, verified lists are your first line of defense, because list quality determines call quality.
- DNC scrubbing every 31 days — screening against Do Not Call registries at least monthly, not once at campaign launch.
- Consent documentation — records showing who agreed to be contacted, when, and how.
- Compliant scripts and prompt opt-out honoring — internal opt-outs must be honored within 10 business days.
- Record retention — the 2024 TSR update extended DNC record retention from 2 years to 5 years, per regulatory analysis of the rule changes.
The stakes are concrete. TCPA violations run $500 per call, trebled to $1,500 for willful violations, with uncapped statutory damages. A single 200-call campaign against an uncleaned list can create $100,000–$300,000 in theoretical liability, per telemarketing law analysis.
The rules are also tightening around AI. In February 2024, the FCC ruled that AI-generated voices count as artificial voices under the TCPA, which means they now require prior express written consent before any call goes out. If a provider runs AI voice agents without documented consent, that is not a gray area — it is a per-call violation.
This is why vetting matters more than promises. When Worqd runs B2B outreach, the approach is personalized, permission-aware outreach to relevant accounts — the opposite of a template blast — with explicit consent captured directly in the booking funnel before anyone is ever contacted. Ask any provider you are evaluating the same questions: How often do you scrub DNC lists? Where is consent documented? How fast do you honor opt-outs? How long do you keep records?
Compliant outreach is not slower outreach. It is outreach that keeps connecting — because spam-tagged numbers lose 70–90% of their connect rate once carriers flag them, while clean, consented calling keeps the line open.
How to Vet an Outreach Provider's Compliance Practices
Most companies don't ignore compliance because they don't care — they ignore it because the rules are scattered across federal statutes, state laws, and carrier-level filters that change quarterly. The FTC's Telemarketing Sales Rule sets the federal floor: calling hours restricted to 8 a.m.–9 p.m. local time, DNC scrubbing at least every 31 days, and record retention now extended to five years after the 2024 update FTC Telemarketing Sales Rule. Layer on the TCPA's $500–$1,500 per-call exposure for wireless numbers — where no B2B carve-out exists — and a single uncleaned list of 200 contacts can represent six figures of theoretical liability Martal Group cold calling laws. Add state regimes like Texas, Oregon, and Florida with private rights of action, and the compliance burden shifts from a checklist to a continuous system Instantly B2B cold calling legal guide.
When you evaluate an outreach partner, ask these five questions. The answers reveal whether compliance is built into their operating rhythm or bolted on as an afterthought.
- How frequently do you scrub against the National DNC Registry and state lists — and can you show the audit trail?
- What consent evidence do you capture at intake, and how is it tied to each contact record?
- How are opt-outs processed across every channel, and within what timeframe?
- What calling-hour logic do you enforce for each recipient's local time zone, including stricter state windows?
- How long are call logs, consent records, and suppression lists retained, and are they exportable on demand?
Worqd structures every outreach program around personalized, permission-aware outreach — explicit consent is captured at the booking funnel with a clear agreement to be contacted about the request, and no sensitive form fields are sent to public analytics. That consent-first intake, combined with DNC hygiene and calling-hour controls baked into the AI SDR workflow, is the baseline any buyer should expect from a growth partner running outbound at scale.
Frequently Asked Questions
Is cold calling actually illegal?
What are the penalties for breaking cold calling laws?
Does the B2B exemption mean I can call any business number?
What hours are cold callers legally allowed to call?
Can I use AI voice agents for outbound calls?
What should I ask an outreach provider to check their compliance?
Legal to Dial, Expensive to Get Wrong
So — is cold calling illegal? No. But the comfortable version of "legal" most sales teams assume stopped being accurate a while ago. The rules are learnable in an afternoon: call between 8 a.m. and 9 p.m. local time, scrub your lists against DNC registries every 31 days, honor opt-outs fast, and get written consent before touching a wireless number. What separates lawful outreach from a lawsuit is the system behind every dial — because with TCPA penalties running $500 to $1,500 per call, a single uncleaned list can turn a modest campaign into six figures of exposure. The B2B exemption won't save you from the cell phone trap, and your agency doesn't inherit your exemptions. Your next step: take the vetting questions from this article to any provider you're evaluating — including us. Worqd builds outreach around explicit consent, personalized contact with relevant accounts, and documented compliance, because permission isn't just polite; it's what keeps your pipeline producing instead of paying fines. Book a growth call and see how permission-aware outreach fits your pipeline — one partner, one plan, one report, from first click to booked call.
Want help putting this into action?
Book a Growth Call