Cold Calling Laws in 2026: A Compliance Guide for Sales Teams

Cold calling still works in 2026 — but one bad dial can cost you $500 to $1,500 per call. Here's a plain-English guide to the TCPA, TSR, and Do Not Call rules that keep your sales team legal.

Jul 7, 2026 9 min read 2,151 words
Cold Calling Laws in 2026: A Compliance Guide for Sales Teams

Cold Calling Laws in 2026: A Compliance Guide for Sales Teams

Cold calling is not dead — but calling carelessly can be very expensive. Between the TCPA, the Telemarketing Sales Rule, and a patchwork of state statutes, a single non-compliant dial can trigger fines that dwarf the deal you were chasing. This guide breaks down the cold calling laws that matter in 2026, in plain English, so your reps can prospect confidently instead of guessing.

Disclaimer: This article is general information for sales and marketing teams, not legal advice. Regulations change and vary by jurisdiction. Confirm your specific obligations with qualified counsel before launching any outbound calling program.

TL;DR#

  • Three federal frameworks govern B2B and B2C calls: the TCPA (FCC), the Telemarketing Sales Rule (FTC), and the National Do Not Call Registry.
  • Fines are per call, not per campaign — the TCPA allows $500–$1,500 per violation, and TSR penalties can reach roughly $50,000+ per violation.
  • Consent and Do Not Call scrubbing are the two biggest risk areas. Autodialers, prerecorded messages, and cell phones raise the stakes sharply.
  • B2B calls get more leeway than B2C, but "business-to-business" is not a blanket exemption — cell phones, DNC requests, and state laws still apply.
  • Clean, accurate contact data is a compliance tool, not just an efficiency one. Dialing wrong or outdated numbers multiplies your exposure.

Confused sales rep pleading to double-check the Do Not Call list before dialing
Confused sales rep pleading to double-check the Do Not Call list before dialing

Diagram: TL;DR
Diagram: TL;DR

What are cold calling laws, and who enforces them?#

Cold calling laws are the federal and state rules that govern unsolicited sales and marketing phone calls. In the United States, three pillars carry most of the weight:

  1. The Telephone Consumer Protection Act (TCPA) — enforced primarily by the Federal Communications Commission (FCC). It governs autodialers, prerecorded/artificial voice messages, text messages, and calls to cell phones. Crucially, the TCPA includes a private right of action, meaning individuals can sue you directly — which is why TCPA class actions are a cottage industry.
  2. The Telemarketing Sales Rule (TSR) — enforced by the Federal Trade Commission (FTC). It covers deceptive and abusive telemarketing practices, disclosure requirements, calling-time windows, and the Do Not Call framework.
  3. The National Do Not Call Registry — the list of consumers who have opted out of telemarketing calls. Sellers must scrub against it and honor company-specific opt-outs.

On top of these, individual states layer their own statutes. Florida, Oklahoma, and Washington, among others, have passed "mini-TCPA" laws with stricter consent and calling-window rules than the federal baseline. If your reps dial across state lines, you inherit the strictest applicable rule.

For the definitions behind the acronyms, Tomba's B2B glossary is a useful quick reference, and the FTC's own Telemarketing Sales Rule overview is the authoritative primary source.

What's the difference between the TCPA, the TSR, and the Do Not Call Registry?#

These three are often lumped together, but they solve different problems and are enforced by different agencies. Here's how they compare.

Attribute TCPA Telemarketing Sales Rule (TSR) Do Not Call Registry
Enforcing body FCC (plus private lawsuits) FTC FTC (list); FCC/FTC enforce
Main focus Autodialers, prerecorded calls, texts, cell phones Deceptive/abusive telemarketing, disclosures Consumer opt-out from sales calls
Consent required? Yes — prior express (written) consent for many auto/prerecorded calls Yes, for certain practices N/A — it's an opt-out list
Private right of action? Yes (a major litigation driver) Limited No (via TSR/state rules)
Typical penalty $500–$1,500 per call/text Up to ~$50,000+ per violation Rolled into TSR penalties
Calling-time window 8 a.m.–9 p.m. local time

The practical takeaway: the TCPA is your biggest lawsuit risk (because consumers can sue), while the TSR is your biggest regulatory-fine risk (because the FTC can hit you with steep per-violation penalties). You have to satisfy both.

Diagram: What's the difference between the TCPA, the TSR, and the Do Not Call Registry
Diagram: What's the difference between the TCPA, the TSR, and the Do Not Call Registry

Yes — B2B cold calling is legal, and it remains one of the most effective outbound channels. But "B2B" is not a magic exemption, and reps who treat it that way get organizations into trouble.

Here's what actually applies to business-to-business calling:

  • Calls to business landlines are largely outside the National Do Not Call Registry's scope, and the TSR gives B2B telemarketing broad (though not total) relief.
  • Calls to cell phones — even a prospect's business cell — still fall under TCPA restrictions on autodialers and prerecorded messages. Since a huge share of business contacts now use mobile numbers, this is where B2B teams get exposed.
  • Company-specific Do Not Call requests must be honored regardless of B2B status. If a business contact says "stop calling," that request stands.
  • State mini-TCPA laws may not fully exempt B2B calls, especially when a mobile number is involved.

So the honest framing is: B2B cold calling gets meaningful leeway on the federal Do Not Call list, but it does not exempt you from the TCPA's autodialer and cell-phone rules, nor from state laws. Manual dialing to accurate direct lines is the lowest-risk approach — which is exactly why data quality matters so much (more on that below).

What are the penalties for breaking cold calling laws?#

The penalties are structured per call, which is what makes non-compliance so dangerous at scale. A rep making 100 bad dials isn't facing one fine — they're facing 100.

  • TCPA: $500 per violation for negligent breaches, rising to $1,500 per violation for willful or knowing ones. There's no statutory cap, so class actions can reach into the millions.
  • TSR / FTC: civil penalties that the FTC periodically adjusts for inflation, currently in the range of roughly $50,000+ per violation.
  • State laws: additional per-call damages, sometimes stacked on top of federal exposure. Florida's mini-TCPA, for example, created its own private right of action.

Real-world TCPA settlements have run from hundreds of thousands to over $100 million. You don't need to be a spam-call operation to get caught — a misconfigured dialer or an un-scrubbed list is enough.

One does not simply ignore the TCPA and scale outbound calling
One does not simply ignore the TCPA and scale outbound calling

Diagram: What are the penalties for breaking cold calling laws
Diagram: What are the penalties for breaking cold calling laws

How do you keep your cold calling compliant?#

Compliance is mostly about a handful of disciplined habits. Build these into your process and you eliminate the majority of your risk.

  1. Scrub against the Do Not Call Registry — check numbers against the National Do Not Call Registry and maintain your own internal do-not-call list. Re-scrub regularly; registrations don't expire, but your list grows.
  2. Respect calling windows — no telemarketing calls before 8 a.m. or after 9 p.m. in the recipient's local time zone. This is where accurate location data earns its keep.
  3. Get and document consent — for autodialed or prerecorded calls to cell phones, obtain prior express written consent and keep records. Assume you'll have to prove consent in court, because you might.
  4. Identify yourself — state who you are, the company you represent, and the purpose of the call. The TSR requires prompt, truthful disclosure.
  5. Honor opt-outs immediately — when someone asks to be removed, log it and stop. Company-specific requests apply even to B2B contacts.
  6. Be careful with autodialers and prerecorded messages — these carry the highest TCPA exposure. Manual dialing to verified direct lines is the conservative default for most B2B teams.

Consent and disclosure rules also connect to how you handle contact records — treat your calling data with the same care you'd apply to email deliverability and sender reputation on the email side. Sloppy data hygiene is a compliance liability in both channels.

Why does data accuracy matter for cold calling compliance?#

Because every wrong number multiplies your risk. If your list is full of stale, recycled, or misattributed phone numbers, you're not just wasting rep time — you're increasing the odds of calling a reassigned cell phone, a consumer who never opted in, or a number that's now on the Do Not Call list under a different owner. The FCC's Reassigned Numbers Database exists precisely because recycled cell numbers are a well-known TCPA landmine.

Accurate, well-sourced contact data reduces that surface area in three ways:

  • Correct number type — knowing whether a line is a business landline or a cell phone tells you which rules apply before you dial.
  • Current ownership — verified, recently refreshed data lowers the chance of hitting a reassigned number.
  • Clean formatting and validation — bad or unreachable numbers get filtered out instead of dialed.

This is where Tomba fits into a compliant workflow. Tomba's phone finder surfaces B2B phone numbers tied to verified business contacts, and the phone validator checks that a number is real and correctly formatted before your reps ever pick up the phone. You still own the compliance decisions — scrubbing, consent, timing — but you're making those decisions on cleaner inputs.

Here's how tooling maps to each compliance task:

Compliance task What it prevents Supporting tool
Validate number is real/active Dialing dead or invalid numbers Phone validator
Confirm business vs. mobile Applying the wrong TCPA rule Enriched contact data
Source accurate direct lines Reassigned-number exposure B2B phone finder
Keep records current Acting on stale opt-in data Data enrichment

Good data won't make you compliant on its own — process and consent do that — but it removes a huge category of avoidable mistakes.

Diagram: Why does data accuracy matter for cold calling compliance
Diagram: Why does data accuracy matter for cold calling compliance

What about text messages and voicemail drops?#

Two channels deserve a specific warning because teams often assume they're "softer" than calls:

  • SMS/texts are treated as calls under the TCPA. Sending marketing texts without proper consent carries the same $500–$1,500 per-message exposure as a phone call. Do not assume texting a prospect is a low-risk alternative to dialing.
  • Ringless voicemail / voicemail drops have been the subject of ongoing FCC scrutiny and litigation. Regulators have signaled that dropping a prerecorded message straight into voicemail can qualify as a call under the TCPA. Treat it as high-risk unless you have consent.

When in doubt, the safe hierarchy for outbound is: a manually dialed call to a verified business direct line is lower risk than an autodialed call, which is lower risk than a prerecorded message or bulk text to a mobile number.

How do cold calling laws differ by state?#

Federal law is the floor, not the ceiling. A growing number of states have enacted their own telemarketing statutes that are stricter than the TCPA:

  • Florida (FTSA) — created a private right of action and tighter consent rules; it reshaped how many national teams handle Florida numbers.
  • Oklahoma, Washington, and others — have passed or expanded mini-TCPA laws with their own consent and disclosure requirements.
  • Calling windows and caller-ID rules vary; some states narrow the permitted hours or add explicit registration requirements for telemarketers.

Because your prospect's location determines which state law applies, accurate location and number data (again) becomes a compliance input. If you run multi-state outbound, default to the strictest rule set you're likely to encounter, and have counsel review your program state by state.

The industry consensus you'll find on review platforms like G2 is consistent: teams that centralize compliance rules and clean their data upstream spend far less time firefighting complaints than those that bolt compliance on after the fact.

Quick compliance checklist before your next campaign#

Run through this before you launch:

  • Registry scrub done? National DNC plus your internal list.
  • Consent documented? Especially for any autodialer, prerecorded, or SMS activity to cell phones.
  • Time zones mapped? No dials outside 8 a.m.–9 p.m. local.
  • Disclosures scripted? Identity, company, and purpose stated up front.
  • Opt-out logging live? Requests honored and recorded instantly.
  • Data validated? Numbers verified, number type known, list recently refreshed.
  • State rules checked? Strictest applicable law identified for each region.

If every box is checked, you've eliminated the mistakes that generate the overwhelming majority of complaints and lawsuits.

Start with clean, compliant contact data#

Cold calling laws in 2026 reward the same discipline that makes outbound effective in the first place: knowing exactly who you're calling, on what kind of line, with a documented reason to reach out. You can't outsource the legal judgment — but you can remove the data errors that turn honest reps into liability.

That's the practical role of clean sourcing and verification. Use Tomba's phone finder to pull accurate B2B direct lines, run them through the phone validator before dialing, and see Tomba pricing to find the plan that fits your team — the free tier lets you test the workflow before you commit. Compliant calling starts with data you can trust, and that's exactly what Tomba is built to give you.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.