TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros

Can I auto call someone?

Can you legally auto call someone? Learn TCPA consent rules, AI voice restrictions, FCC fines up to $23,727, and a compliant dialing workflow that prote...

Flat illustration of a smartphone with automated dialing rings connected to a compliance shield, representing legal auto-calling rules under TCPA.

Key Facts

Auto-dialing might seem like a fast track to more conversations, but it carries serious legal exposure. The allure of efficiency can quickly turn into costly liability if consent isn’t properly verified before dialing. Many businesses don’t realize that the caller—not the lead generator—bears full responsibility for TCPA violations, even when using third-party leads.

Under the TCPA, statutory damages range from $500 to $1,500 per violating call or text, with consumers able to sue via private right of action. Regulatory penalties compound the risk: the FCC can impose fines up to $23,727 per violation, while the FTC may levy penalties as high as $50,120 under the Telemarketing Sales Rule. These amounts apply per call, meaning a single campaign with hundreds of unauthorized dials can trigger six- or seven-figure exposure.

Liability falls squarely on the entity placing the call, not the source of the lead. As compliance experts note, "The legal liability falls on the company that made the call, not the company that generated the lead." This shifts the burden to buyers to validate consent records before initiating contact—especially when using AI-driven follow-up systems.

Adding urgency, the FCC’s February 2024 ruling explicitly classifies AI-generated voices as "artificial or prerecorded voices" under TCPA. There is no AI loophole: any outbound call using synthetic voice technology must meet the same prior express written consent (PEWC) requirements as traditional robocalls. This means disclosures, opt-out mechanisms, and consent verification apply equally, regardless of whether the voice is human or machine-generated.

To mitigate risk, businesses must implement real-time consent verification before dialing. This includes confirming PEWC exists, contains required elements like timestamp, IP address, and disclosure language, and covers the specific seller. Consent records should be retained for at least five years and validated immediately prior to each contact attempt. DNC scrubbing—now extended to text messages—and immediate, permanent honoring of opt-outs across voice, SMS, and email are equally essential.

For companies using AI Speed-to-Lead follow-up, like GrowthPros’ integrated voice, SMS, and email sequence, compliance isn’t optional—it’s foundational. Every lead delivered includes a consent trail with disclosure text, timestamp, IP, and the named contacting party, ensuring buyers can verify authorization before engagement. Reactivation campaigns similarly target only pre-existing, opted-in relationships, aligning with FCC one-to-one consent principles.

Without these safeguards, the promise of speed collides with the reality of risk. The most efficient outreach isn’t just fast—it’s lawful from the first dial.

What the Law Actually Requires Before You Auto Call

Before hitting "dial" on an autodialer, businesses must clear several legal hurdles under the TCPA and related regulations. The foundational requirement is obtaining prior express written consent (PEWC) before making any autodialed or prerecorded marketing call to a cell phone, with violations carrying statutory damages of $500 to $1,500 per call. This consent must be specific, documented, and verifiable—including exact disclosure language, timestamp, IP address, and the named seller—since the legal liability falls on the caller, not the lead generator. GrowthPros embeds these elements into every lead delivery, ensuring consent records are timestamped, sourced, and attached to each contact for immediate compliance verification.

The FCC’s one-to-one consent direction further tightens requirements by prohibiting daisy-chaining consent across multiple sellers, meaning a single consent cannot cover calls from different businesses even if they are "partners" in a lead network. Each seller must obtain separate, explicit authorization from the consumer, and consent must clearly specify no more than one identified seller is authorized to contact them via autodialer or artificial voice. This rule aims to eliminate ambiguous lead-sharing practices that previously allowed broad consent to mask unwanted calls. Compliance requires real-time verification before dialing to ensure consent is valid, specific to the seller, and not revoked—failure to do so risks significant penalties, including FCC fines up to $23,727 per violation.

Beyond federal rules, businesses must also navigate a patchwork of state mini-TCPA laws, with more than 30 states enacting their own telemarketing statutes, some of which impose stricter consent or calling time requirements than federal law. Additionally, the National Do Not Call Registry’s protections now extend to text messages, requiring DNC scrubbing before any SMS outreach, and predictive dialers are limited to a 3% abandoned-call rate per campaign over a 30-day period under FTC/TSR rules. Critically, FTC Do Not Call exemptions for B2B calls do not override TCPA restrictions, state laws, or protections for personal wireless numbers—meaning even business-to-business calls to an individual’s cell phone demand full TCPA compliance, including PEWC and proper opt-out handling.

Winning a TCPA lawsuit rarely comes down to whether consent existed — it comes down to whether you can prove it, on demand, in a format a court accepts. When a plaintiff's attorney demands your consent records, "we think they filled out a form" is not a defense.

According to compliance documentation best practices, a defensible consent record is far more than an email address in your CRM. Each record must capture:

  • The exact disclosure language the consumer saw at the point of capture
  • The full source URL where consent was given
  • The consumer's IP address and a timestamp accurate to the second
  • The consumer's affirmative action — the click, checkbox, or signature
  • The named seller the consent authorizes to contact them

That last element matters more than ever. The FCC's one-to-one consent framework requires that consent clearly authorize no more than one identified seller — a single checkbox covering unnamed "partner companies" no longer holds up.

Every credible source converges on the same retention standard: keep lead and consent records for at least five years from last contact. TCPA statutory damages run $500 to $1,500 per violating call, and FCC fines can reach $23,727 per violation — a single campaign's worth of undocumented calls can snowball into six or seven figures fast.

The stakes are higher for lead buyers than most realize. As legal analysts note, liability falls on the company that made the call, not the company that generated the lead. Buying leads without verifying the consent trail means inheriting someone else's compliance failures.

The expert warning is blunt: "If you cannot produce these records quickly and completely, your defense weakens dramatically." Documentation alone isn't enough — you need real-time pre-dialer verification that checks consent validity immediately before every outbound attempt and blocks the call when records are missing, incomplete, or revoked.

This is why GrowthPros attaches a full consent record — disclosure text, timestamp, IP address, and the named contacting party — to every lead before delivery, rather than leaving buyers to reconstruct evidence after a dialer has already fired. As one compliance guide cautions, the TCPA landscape shifts constantly through new rulings and state laws, so yesterday's vendor policy is not a defense today.

The bottom line: consent you cannot produce is consent the court treats as nonexistent. Build the record before the call, verify it at the dialer, and keep it for five years.

How to Auto Call Legally: A Practical Workflow

Knowing the rules is one thing; running a compliant outbound program is another. The good news is that legal auto calling follows a repeatable workflow — and the businesses that follow it get speed-to-lead without betting $500 to $1,500 per call on a lawsuit.

Start with your list. Before a single number is dialed, scrub it against the National DNC Registry, state DNC lists, internal suppression lists, litigator databases, and reassigned number databases. According to compliance documentation guidance, every contact should also pass real-time pre-dialer verification — meaning the system blocks the call automatically if the consent record is missing, incomplete, or revoked.

Then set guardrails before you let the dialer run:

  • Time and frequency caps — restrict calling windows and contact attempts per campaign, and keep predictive dialer abandonment under the FTC's 3% threshold per campaign per 30-day period.
  • Transparent scripts — disclose who is calling and why, and remember the FCC's February 2024 ruling treats AI-generated voices as "artificial or prerecorded voices" under TCPA, so conversational AI gets no exemption.
  • Natural-language opt-out recognition — when someone says "stop calling," the system must honor it immediately and permanently across SMS, voice, and email.
  • Complete event logging — capture timestamp to the second, IP address, disclosure language, and source URL, and retain records for at least five years.
  • Human routing — hand high-value, sales-ready leads to a live person rather than pushing them through another automated sequence.

This mirrors the seven-step safe workflow compliance experts recommend: build consent-aware lists, set guardrails, script transparently, recognize opt-outs conversationally, log everything, route leads to humans, and review metrics weekly. The documentation burden is real — as one compliance analysis puts it, if you cannot produce consent records quickly and completely, your defense weakens dramatically. And remember: liability falls on the company that made the call, not the one that generated the lead.

This is why GrowthPros builds compliance into the pipeline itself. Every lead is DNC-scrubbed before dialing and carries a full consent record — disclosure text, timestamp, IP address, and the named contacting party. AI then follows up by voice, SMS, and email inside a five-minute window, 24/7, because speed matters — but only when the paperwork behind it holds up.

Speed-to-lead and compliance are not competing goals. The right workflow delivers both: fast contact with the prospect, and a documented trail proving you earned the right to make the call.

Frequently Asked Questions

Do I need consent before making an autodialed call to someone's cell phone?
Yes, prior express written consent (PEWC) is generally required before making autodialed or prerecorded marketing calls to cell phones under the TCPA, with violations carrying statutory damages of $500 to $1,500 per call.
Can I use AI-generated voices for outbound calls without triggering TCPA rules?
No, the FCC's February 2024 ruling explicitly classifies AI-generated voices as 'artificial or prerecorded voices' under TCPA, meaning they require the same prior express written consent as traditional robocalls.
What happens if I call someone who's on the National Do Not Call Registry?
Calling a number on the National DNC Registry violates TCPA and Telemarketing Sales Rule protections, which now extend to text messages, and can result in FCC fines up to $23,727 per violation.
How long must I keep consent records for telemarketing calls?
Consent and lead records must be retained for at least five years from last contact to defend against TCPA lawsuits, as statutory damages can reach $1,500 per violating call.
Does buying leads from a third party protect me from TCPA liability?
No, legal liability falls on the company that made the call, not the lead generator, so buyers must verify consent records before dialing to avoid inheriting compliance failures.
Are B2B calls to cell phones exempt from TCPA requirements?
No, FTC Do Not Call exemptions for B2B calls do not override TCPA restrictions, so calls to personal wireless numbers still require prior express written consent regardless of business context.

Speed and Safety: How to Outbound Without the Risk

The allure of fast outreach is undeniable—contacting leads within five minutes dramatically increases conversion odds—but speed without compliance is a costly gamble. As we’ve seen, the TCPA leaves no room for ambiguity: prior express written consent must be specific, documented, and verified before every autodialed call, with liability falling squarely on the caller, not the lead generator. From AI-generated voices treated as artificial under TCPA to the FCC’s one-to-one consent rule and extended DNC protections for texts, the regulatory landscape demands precision. GrowthPros builds this precision into every lead—delivering consent-recorded, DNC-scrubbed opportunities with AI follow-up inside the promised five-minute window—so you can engage fast without gambling on liability. If you’re ready to see how compliant, consent-backed leads can transform your outreach, book a 15-minute qualification call to explore fit—no pressure, just clarity on whether our approach aligns with your goals.

This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.

Start

More booked calls. Not more form fills.

Tell us your niche and your goal. We will show you realistic volume, exclusivity options, and what follow-up looks like on a live call — no pressure, no 40-page deck.