Outbound calling is heavily regulated and the rules differ by country, sector and call type. This article makes no claims about what any law requires — it cannot. It is the list of questions to answer and the groundwork to assemble so that the legal conversation is short and specific.
What this checklist is
Outbound calling is one of the more heavily regulated things a business can do, and the rules differ substantially between countries, between sectors, and sometimes between the kinds of call you are making. Adding an automated agent adds further questions about disclosure and about how the conversation is handled.
This article makes no statements about what any law requires. It cannot — the answer depends on where you are calling from, where the recipients are, what you are calling about, how you obtained the number, and what sector you operate in. Determining that is the job of whoever advises your business, and this checklist exists to make that conversation short and specific.
What it does provide is the list of questions to answer, the factual groundwork to assemble first, and the controls that should exist in the system regardless of which way the legal analysis lands. Most organisations find the difficult part is not the advice but describing their own setup accurately enough to receive it.
Where did the number come from?
The provenance of each number is the first question, and for many businesses it is the hardest to answer honestly.
- For each list, how was the number obtained — a purchase, an enquiry, a form, a signup, a third party, a public source? Document this per list, not in general.
- What was the person told at the time about how their number would be used? Retrieve the actual wording that was shown, not a description of it.
- Does that wording cover calling them for this purpose? Marketing, service and transactional calls are frequently treated differently.
- Does it cover calling them with an automated system, which may be a distinct question from calling them at all?
- Is there a record of when and how permission was given, retrievable for an individual contact?
- For purchased or third-party lists, what evidence of permission came with them, and have you seen it rather than been assured of it?
- Has any permission expired, where the arrangement had a time limit?
- For existing customers, does the existing relationship change what is permitted, and in which direction?
Assemble this per list before seeking advice. A lawyer cannot tell you whether your calling is permissible without knowing how the numbers were obtained, and reconstructing that afterwards is considerably harder than recording it now.
Who must not be called
Suppression obligations vary, but the controls needed to honour them are the same everywhere and should be built regardless.
- Do-not-call registers: which apply to your markets, how often you must check them, and whether your system does so automatically.
- Your own opt-out list, honoured permanently, across every campaign and every channel — not per campaign.
- How an opt-out given during a call is recorded, and how quickly it propagates. Immediately is the only defensible answer.
- How an opt-out given on another channel reaches the calling system.
- Whether an opt-out from one brand or entity covers others in the group, which is a decision someone must make explicitly.
- Complaints and disputes, which should suppress regardless of formal obligation.
- Numbers identified as belonging to someone other than the intended contact.
- How suppression is checked — at list build or at dial time. Dial time is the only version that works, as covered in retry strategy.
When may calls be made?
Permitted calling hours are among the most commonly regulated aspects, and among the easiest to get wrong with automation.
- Which hours are permitted in each market you call into, and does that differ by call type?
- Does the rule follow the recipient's location rather than yours? For automated systems calling across regions, this needs handling explicitly.
- How are public holidays and weekends treated in each market?
- Is the restriction enforced by the system, or relied upon in the campaign schedule? Enforcement is the only version that survives a trigger firing at an unexpected hour — a real risk with event-driven calling.
- What happens to a call queued within hours that would connect outside them?
- Are there frequency limits — maximum contacts per person per period — and is there a cap enforced across all campaigns rather than within each?
- Are there rules about repeated attempts after a refusal?
The system-enforcement point matters more with automation than with human calling, because a rota naturally constrains human calling to working hours and an automated trigger does not.
What must the call disclose?
Automated calling raises disclosure questions that human calling does not, and the answers are jurisdiction-specific.
- Must the call identify the calling organisation, and at what point?
- Must it state a purpose, and how specifically?
- Must it disclose that the caller is an automated system? This is the question most specific to AI calling and it should be asked directly rather than assumed either way.
- Must an opt-out mechanism be offered during the call, and in what form?
- Are there requirements about the number presented to the recipient?
- Must a human be reachable, and within what timeframe?
- Are there requirements about recording notice, which overlap with but are distinct from recording and privacy questions?
- Do any of these differ for service and transactional calls compared with marketing ones?
Whatever the legal position, disclosing that the call is automated at the opening is worth doing. Recipients who work it out themselves respond markedly worse than recipients who were told, which makes this a practical decision as well as a compliance one.
Controls worth building regardless
These should exist whatever the legal analysis concludes. They reduce risk, they make any future review straightforward, and several of them improve results.
- Immediate, permanent, cross-channel opt-out handling, testable end to end.
- A global frequency cap across every campaign and trigger.
- Calling-time rules enforced in the system, per market, based on the recipient's location.
- Dial-time suppression checks against a live list.
- An audit trail: which list, which permission record, which campaign, which attempt, what outcome, for every call.
- A hard attempt cap per contact.
- Immediate escalation to a person on any complaint or objection.
- A recording and retention arrangement that someone owns.
- A kill switch that stops all outbound calling in minutes, tested by someone who did not build it.
- Monitoring of call volume per contact, so a data change firing thousands of calls is caught before they are made.
The audit trail is the item that makes everything else demonstrable. Being able to show, for any individual call, where the number came from and what permission existed is what turns a complaint into a closed matter. Our automation services page covers building these controls, and AI telesales platforms differ in how many they enforce natively rather than leaving to configuration.
Preparing for the legal conversation
The advice you receive is only as good as the description you provide. Assembling these first makes the review faster and cheaper.
-
1
A list inventory
Every list, its source, how the numbers were obtained, what the contacts were told, and what evidence exists. Per list, not in aggregate.
-
2
A call-type inventory
What each campaign or trigger is actually about — marketing, service, transactional, collections. The classification frequently determines which rules apply.
-
3
A geography map
Where you call from, where recipients are, and which markets are in scope. Cross-border calling raises questions single-market calling does not.
-
4
A description of the system
What the automated agent does, what it discloses, what it records, what happens on objection, and which controls are enforced where.
-
5
The data flow
Where recordings, transcripts and derived data go, including third parties and their sub-processors — the same inventory as the privacy checklist.
-
6
Your proposed cadence
Attempts, spacing, caps and suppression rules, written down as the policy you intend to operate.
Bringing these six documents to a legal review converts an open-ended question into a set of specific ones, which is both faster and more likely to produce usable guidance.
Common gaps found before launch
These recur across outbound reviews and are worth checking specifically.
- No record of how numbers on older lists were obtained.
- Opt-outs held per campaign rather than centrally.
- Opt-out from one channel not reaching the calling system.
- Calling-time rules in the campaign schedule rather than enforced by the system.
- Frequency caps within campaigns but not across them.
- Suppression checked at list build.
- No audit trail linking a call back to a permission record.
- Purchased lists accepted without seeing evidence of permission.
- No tested kill switch.
- Disclosure wording written by the project team and never reviewed.
What this checklist does not cover
Stating the limits plainly, because a checklist that implies completeness is worse than no checklist.
- What any specific law requires in any specific jurisdiction.
- Sector-specific rules — financial services, healthcare, utilities and others frequently have additional obligations.
- Contractual restrictions in your own agreements, which may be stricter than any regulation.
- Rules about the content of what is said, as distinct from the fact of calling.
- Cross-border data transfer questions, which overlap with the privacy checklist and need their own review.
- Whether a particular automated disclosure satisfies a particular requirement, which is exactly the kind of question that needs qualified advice.
Use this to prepare for that advice, not to substitute for it.
Decision framework and next step
Four questions to answer before scheduling a launch.
-
1
Can you say, per list, how every number was obtained?
If not, that is the first task and it may change which lists are usable.
-
2
Is opt-out immediate, permanent and cross-channel, and has it been tested?
Tested end to end, not documented.
-
3
Are calling-time and frequency rules enforced by the system?
Schedules and intentions are not controls.
-
4
Has someone qualified reviewed your disclosure wording and permission basis for each market?
This is the item that cannot be resolved internally.
Assemble the six documents, build the controls that are worth having regardless, and then seek review for the market-specific questions. Launching before the permission provenance is established is the risk most worth avoiding. Our AI solutions overview covers how these reviews are usually sequenced alongside an outbound build.
Frequently asked questions
-
1
Does this article tell me whether my outbound calling is compliant?
No. Requirements differ by jurisdiction, by sector, by call type and by how the numbers were obtained, and determining them requires qualified advice for your markets. This is a list of questions to answer and groundwork to assemble before that conversation.
-
2
What should be established first?
Permission provenance per list: how each number was obtained, what the contact was told at the time, whether that covers this purpose and automated calling, and what evidence exists. Advice cannot be given without this.
-
3
Which controls should exist regardless of the legal analysis?
Immediate permanent cross-channel opt-out, a global frequency cap across all campaigns, system-enforced calling-time rules based on the recipient's location, dial-time suppression, a full audit trail, an attempt cap, immediate escalation on objection, and a tested kill switch.
-
4
What is the most common gap found before launch?
No record of how numbers on older lists were obtained, followed by opt-outs held per campaign rather than centrally, and calling-time rules relied upon in scheduling rather than enforced by the system.
-
5
Should a call disclose that it is automated?
Whether it must is a jurisdiction-specific question for your advisers. Whether it should, as a practical matter, is clearer: recipients who work it out themselves respond markedly worse than those who were told at the opening.
The groundwork is the part you can do now, and it is what makes the legal review specific, quick and useful.