Cold calling: what it is, how it works, and what the law actually requires

Cold calling means contacting prospects without prior relationship. TCPA violations cost $500, $1,500 per call. Here's what every sales team must know.

LeadCompliant Team
25 min read
In This Article

Last updated 2026-07-10

Salesperson making a cold call at a desk in warm afternoon light
Salesperson making a cold call at a desk in warm afternoon light

TL;DR

Cold calling is unsolicited outbound phone contact to prospects who haven't asked to hear from you. It's legal under specific conditions, but the TCPA (47 U.S.C. § 227) and the FTC's National Do Not Call Registry set strict rules. Violations carry statutory damages of $500 to $1,500 per call. Class actions scale those penalties into the millions.

What is cold calling, and where does the term come from?

Cold calling is contacting a person, usually by phone, who has no prior relationship with your company and never asked to hear from you. The "cold" refers to the temperature of the relationship. No existing warmth. No prior signal of interest. No permission given. The caller starts from zero.

The term goes back to door-to-door sales long before the telephone existed, when a salesperson would "call on" a house unannounced. When phones spread through business, the concept moved to the wire. By the 1980s and 1990s, high-volume phone rooms working from printed reverse directories made cold calling one of the most common prospecting tactics in North America.

Today the cold calling definition has stretched a little. Some people use it for any first-touch outbound call, even to someone who downloaded a whitepaper or attended a webinar. The TCPA uses a stricter phrase, "telephone solicitation," defined as "the initiation of a telephone call or message for the purpose of encouraging the purchase or rental of, or investment in, property, goods, or services" [1]. That definition decides which rules apply to you.

For how the term works in sales specifically, the what is cold calling in sales article breaks down cold, warm, and hot calls and why that line changes your compliance posture.

What laws govern cold calling in the United States?

Three overlapping frameworks cover most cold calling in the U.S.: the Telephone Consumer Protection Act (TCPA), the FTC's Telemarketing Sales Rule (TSR), and a patchwork of state statutes. Federal law sets a floor. States build higher.

The TCPA (47 U.S.C. § 227) is the federal baseline. Congress passed it in 1991 because consumers were drowning in unsolicited calls. It restricts calling times, requires callers to identify themselves, bans calls to numbers on the National Do Not Call (DNC) Registry, and adds requirements when automated dialing equipment or prerecorded messages are involved [1]. The dangerous part for businesses is the private right of action. Any individual can sue, and plaintiffs' attorneys have built entire practices around TCPA class litigation.

The FTC's Telemarketing Sales Rule (16 C.F.R. Part 310) runs alongside the TCPA. The TSR governs call content, prohibited misrepresentations, required disclosures, and calling windows. It also covers the DNC Registry, which the FTC administers jointly with the FCC [2].

State laws add a third layer. Florida's Mini-TCPA (HB 7013, effective July 2021) is one of the strictest, requiring express written consent for calls made with any automated system and limiting certain calls regardless of DNC status [3]. Oklahoma, Washington, and other states run their own do-not-call lists or telemarketing statutes on top of the federal rules.

The short version: if your call touches a cell phone or uses any automated equipment, you're in the strictest tier of obligations.

What are the TCPA's specific rules for cold calls?

The TCPA's cold calling rules split into four questions: who you can call, when you can call, how you can call, and what you must say. Miss any one and you've got a violation worth $500 to $1,500.

Who you can call. You cannot call any number on the National DNC Registry unless the called party gave you prior express written consent or has an established business relationship (EBR) with you. The EBR window is 18 months after the last purchase or transaction, and 3 months after a consumer makes an inquiry [1]. You also keep your own internal DNC list and must honor opt-outs within 30 days.

When you can call. Calls to residential lines are allowed only between 8 a.m. and 9 p.m. local time at the called party's location. That's their time zone, not yours [2]. Calling a Florida number at 8:45 p.m. Eastern from your California office at 5:45 p.m. is fine. Calling that same Florida number at 9:05 p.m. Eastern is a violation.

How you can call. If you use an automatic telephone dialing system (ATDS) or a prerecorded voice, you need prior express consent for calls to residential landlines and prior express written consent for calls to cell phones [1]. Manual dialing to a cell phone without automation carries fewer restrictions, though what counts as an ATDS has been litigated hard. The Supreme Court's 2021 ruling in Facebook v. Duguid narrowed the ATDS definition, but it didn't erase the risk [4].

What you must say. At the start of every telemarketing call, state your name and the company you're calling for. Provide a callback number or address. If you use a prerecorded message, it must include an automated opt-out mechanism that works during the call [1].

For how to build a compliant cold call script that covers the required disclosures without killing your opener, see the linked guide.

Key TCPA cold calling numbers The figures that define legal risk and compliance obligations for outbound teams 500 Statutory damages per viola… 1,500 Trebled damages (willful vi… 52k FTC civil penalty per TSR violation 31 DNC scrub freshness window (days) Source: 47 U.S.C. § 227; FTC Telemarketing Sales Rule (16 C.F.R. Part 310)

What does a TCPA violation actually cost per call?

The TCPA sets statutory damages at $500 per violation. Courts can treble that to $1,500 per call for a willful or knowing violation [1]. There's no cap per person, and the private right of action means every called party can sue on their own.

Class actions are where the math turns frightening. A campaign that sends 500,000 illegal robocalls faces theoretical exposure of $250 million at $500 per call, and $750 million if trebled. Real settlements confirm this isn't hypothetical. Dish Network settled TCPA claims for $341 million in 2017 [5]. Capital One settled for $75.5 million in 2014 [5]. These aren't flukes. They're a pattern.

For smaller teams, the immediate threat is the individual plaintiff. TCPA attorneys routinely file for a single consumer, settle for $1,000 to $3,000 per call, and repeat at volume. A company running 50 illegal calls a day for 90 days racks up 4,500 individual claims before anyone even mentions a class.

The FTC can also seek civil penalties up to $51,744 per violation under the TSR for DNC rule breaches [2]. The FCC can impose forfeiture penalties on top of that.

Nobody has good aggregate data on the average TCPA settlement because most settle under confidentiality. The closest public data comes from class action trackers and court dockets, which show consumer-facing settlements in the range of $10 to $150 per class member, with named plaintiffs getting modestly more.

How does the National Do Not Call Registry work for outbound callers?

The National DNC Registry is a federal list run by the FTC where consumers register their numbers to stop most telemarketing calls. Consumers register at donotcall.gov, and registrations never expire [2]. As a telemarketer, you have to scrub your lists against it before you dial.

You subscribe through the FTC's business access portal and pay a fee based on how many area codes you access. As of 2024, the first five area codes are free. Additional area codes cost $70 each per year, up to a maximum of $19,765 for the whole country [8].

Scrub your list against the registry no more than 31 days before each campaign. Lists older than 31 days are legally stale. If a number gets registered after your last scrub and you call it, you're liable even though it wasn't on the list when you pulled it. This is why compliance teams scrub as close to launch as they can.

The EBR exception matters here. If a consumer bought from you in the last 18 months, or made a written inquiry in the last 3 months, you can call them even if they're on the DNC Registry. The burden to prove that EBR exists sits on you. Document everything.

You also keep your own internal DNC list. When a consumer tells you not to call, record it right away and stop calling within 30 days. "We'll add you to our do not call list" is a legal commitment, not a courtesy.

Does cold calling still work as a sales strategy?

This is where reasonable people fight, and a lot of the data floating around is vendor-funded or thin. Here's what the better evidence shows.

RAIN Group has published survey work suggesting 69% of buyers accepted a cold call from a new vendor, and 82% say they've accepted meetings that started with a cold call [6]. These are buyer-stated preferences in surveys, not conversion data. Treat them as directional, not gospel.

Connect rates, meaning the share of dials that reach a live decision-maker, swing wildly by industry and list quality. Inside sales practitioners commonly report 5% to 10% for well-targeted lists, and closer to 1% to 3% for purchased or scraped ones. Nobody publishes audited connect rate data. These figures come from aggregated CRM exports shared in sales communities, so read them with a grain of salt.

Here's the compliance angle. Teams running illegal campaigns sometimes post inflated short-term connect rates because they're dialing aggressively, but the legal and reputational tail risk is brutal. A $500 per call statute plus the cost of defense means one class action can wipe out years of pipeline.

For what to say once someone picks up, the cold calling scripts article covers openers, objection handling, and required disclosures woven together.

Thinking about automated outreach to supplement live dialing? The AI cold calling guide covers the extra TCPA requirements that hit the moment you introduce any automated or AI-generated voice.

What is the difference between a cold call and a warm call?

A warm call goes to someone who already interacted with your company. They downloaded a resource, attended a webinar, responded to an ad, or came through a referral. The warmth is a signal of interest that already exists.

That line matters legally more than tactically. A warm call may establish an EBR that lets you dial a DNC-registered number. A warm call to someone who typed their number into a web form and checked a box consenting to calls can satisfy the prior express written consent requirement for cell contacts, even with an ATDS.

A cold call starts with no permission, no relationship, no documented consent. That means:

  • You cannot use an ATDS or prerecorded voice to call a cell phone.
  • You must scrub against the DNC Registry and your internal list.
  • The EBR defense is off the table.
  • You're relying on a manual dial to a non-cell number, or a call to a business landline (which follows somewhat different rules).

Plenty of teams blur this line by calling leads who filled out third-party forms on affiliate sites. Those contacts may have technically consented, but the consent has to name your company specifically to protect you. "Consent to be contacted by partners" language that never identifies you by name is legally thin, and courts have rejected it in multiple TCPA decisions.

See the cold call article for a plain-language breakdown of when a contact legally moves from cold to warm and what proof you need.

What time zone and calling hour rules apply to cold calls?

Federal rules under both the TCPA and the TSR ban telemarketing calls before 8 a.m. or after 9 p.m. at the called party's location [1][2]. The phrase that trips people up is "called party's location." You use the time zone of the number you're calling, not the one your office sits in.

Most area codes map cleanly to one time zone. Some don't. Indiana, Arizona (which skips daylight saving in most of the state), and border regions all create edge cases. The practical fix: run a reliable time zone lookup against the actual number before each dial session, more than the area code.

Some states pile on. Florida's statute restricts certain calls beyond the federal hours. Always check the state rules for the numbers you're dialing.

Business-to-business calls generally escape the residential calling hour limits, but "business" means a number listed to a business entity, not a cell an employee happens to use for work. Calling a consumer cell during business hours for a B2B pitch still carries TCPA risk if you're using automated equipment.

The simplest operational rule: if you can't confirm a number is a business landline and you're using any automated dialing, treat it as residential and stay inside 8 a.m. to 9 p.m. local time.

What records do you need to keep to defend a cold calling compliance program?

In TCPA litigation, the burden to prove compliance falls on you, the defendant. That means you build the records before a lawsuit arrives, not after.

At minimum, keep:

DNC scrub logs. The date and time you pulled each list from the national registry, which area codes you accessed, and a hash or version ID for the list you used. Courts expect these, and the FTC recommends retaining them.

Internal DNC list with timestamps. Every opt-out request, when it came in, who handled it, and confirmation the number was suppressed before the next session.

Consent documentation. For any number where you're leaning on prior express written consent, store the original form submission with IP address, timestamp, and the exact consent language the consumer saw. Screenshot the form as it looked at the time.

Call records. CDRs (call detail records) showing which numbers you dialed, when, and from which originating number. If you use a third-party dialer, get contractual assurances they'll preserve and produce these.

EBR documentation. If you're relying on the established business relationship exception, keep purchase records, inquiry forms, or transaction logs that establish the relationship and its date.

LeadCompliant's free compliance kit includes a DNC log template and a consent documentation checklist mapped to the evidence courts have actually demanded in TCPA cases. Use a standardized format so your records look professional if you ever have to produce them.

Retention period: the statute of limitations for TCPA claims is 4 years under federal law (28 U.S.C. § 1658), so keep records at least that long [10]. Some practitioners keep 5 years as a buffer.

How do state laws add to federal cold calling requirements?

Federal law is the floor. States go further, and the last five years have moved hard toward more restriction.

Florida's Telephone Solicitation Act (HB 7013) took effect July 1, 2021. It requires prior express written consent for any call or text made with an automated system to a Florida consumer, even when the number isn't on the DNC Registry. It also caps a company at three calls per person per 24 hours [3]. The statute gives consumers a private right of action for $500 per violation, trebled to $1,500 for willful violations, mirroring the TCPA.

California's privacy laws (CCPA/CPRA) don't set calling hours, but they shape how you can use consumer data to build call lists. Buying a list of California residents without checking whether they've opted out of the sale of their data creates CCPA exposure right alongside your TCPA risk [7].

Texas, Oklahoma, and several other states run their own DNC lists separate from the federal registry. You scrub the federal registry, then scrub each state list where you have real call volume.

New York has floated legislation in recent sessions to tighten telemarketing further, though nothing has passed as of mid-2025.

The practical implication: if your list spans multiple states, your compliance program has to reflect the strictest applicable state law for each segment, more than the federal minimum. Running one national standard based only on the TCPA is a common and expensive mistake.

What is the difference between B2B and B2C cold calling rules?

Business-to-business cold calling has more room under federal law than B2C, but less than most sales teams assume.

The National DNC Registry covers residential telephone subscribers. A number registered in a business's name, used at a business location, generally falls outside the DNC rules. So calling a landline listed under "Acme Corp" doesn't require a DNC scrub under federal rules [2].

Three exceptions bite hard.

First, the TCPA's cell phone restrictions don't care whether the call is for business. A cell used by a business owner is still a cell, and calling it with an ATDS without consent is still a violation. A big chunk of B2B contact data is direct cell numbers, which means a lot of "B2B" calling actually lands in the stricter tier.

Second, some state laws (Florida's after HB 7013 included) don't split B2B from B2C the way federal law does. Florida's statute covers calls to "telephone numbers" without a clean business-line carveout in every case [3].

Third, the TSR carves out some B2B calls, but the exemptions have limits. Calls involving a buyer-seller relationship, or calls a business makes to another business for commercial purposes, generally sit outside the TSR. Prerecorded messages selling to businesses still face FCC rules.

The honest summary: B2B cold calling is meaningfully less regulated than B2C on residential landlines. But if you're dialing cell phones (and you almost certainly are), the legal picture looks a lot more like B2C than most B2B teams realize.

ScenarioDNC Scrub RequiredATDS Consent RequiredCalling Hours Apply
B2C residential landlineYes (federal + state)Yes (prerecorded only)Yes (8am-9pm local)
B2C cell phoneYesYes (any ATDS use)Yes
B2B business landlineNo (federal)No (live agent)No (federal)
B2B cell phone (direct)No (federal)Yes (if ATDS used)No (federal)
B2C in FloridaYes + state listYes (any auto system)Yes + state limits

What should a small sales team do right now to reduce cold calling liability?

You don't need a compliance department to do this well. You need a process and a few tools, applied the same way every time.

Start with list hygiene. Before your next campaign, scrub your list against the National DNC Registry. If you haven't subscribed to business access, do it at telemarketing.donotcall.gov. The first five area codes are free. Run state DNC lists for your high-volume states.

Know your dialer. If you use a power dialer, a predictive dialer, or any software that dials without a human pressing a button for each call, you may be using an ATDS under the old definition. After Facebook v. Duguid the definition is narrower, but it's still contested in some circuits [4]. Get a written description from your vendor of how the system works and whether it stores and dials from a list automatically.

Document consent for cell phones. If you're calling cell numbers with any automated equipment, you need prior express written consent for each number. The language has to clearly authorize you specifically, not "partners."

Build an internal DNC process. Create a shared spreadsheet or a CRM field today for opt-out tracking. Every time someone says "don't call me," it goes in within 24 hours, and suppression happens before the next session.

Train your callers on the required disclosures. Every call opens with the caller's name and company. Every call offers a way to opt out. That takes 10 seconds and kills a routine violation.

LeadCompliant's free checkers let you verify a number's DNC status and run basic compliance checks with no monthly subscription. Use them to spot-check before campaigns if you're not yet running full automated scrubs.

Get a compliance kit. Documented policies, even simple ones, are evidence of good-faith effort. Courts and the FTC have treated documented compliance programs as mitigating factors in penalty calculations. A policy that lives in a Google Doc and gets reviewed quarterly beats nothing, and it beats the "we figured everyone else was doing it" defense by a mile.

Frequently asked questions

What is cold calling in simple terms?

Cold calling is when a salesperson phones someone who never asked to be contacted and has no prior relationship with the company. The call is unsolicited. The legal definition under 47 U.S.C. § 227 focuses on calls made to encourage a purchase or investment. It's legal in many situations but heavily regulated by the TCPA, the FTC's Telemarketing Sales Rule, and state statutes.

Is cold calling illegal in the United States?

Cold calling is not illegal, but it's heavily regulated. You can legally call most business lines without restriction. You must scrub residential numbers against the National DNC Registry, call only between 8 a.m. and 9 p.m. local time, identify yourself and your company, and avoid using automated dialing equipment on cell phones without prior written consent. Breaking these rules costs $500 to $1,500 per call.

How does the National Do Not Call Registry work for businesses?

Businesses register at the FTC's business access portal and pay a fee (first five area codes free, then $70 per additional area code per year). You scrub your call list against the registry no more than 31 days before each campaign. Calling a registered number without an established business relationship or written consent is a federal violation. The registry doesn't cover B2B calls to business landlines.

What is the TCPA and how does it affect cold calling?

The Telephone Consumer Protection Act (47 U.S.C. § 227) is the main federal law restricting telemarketing. It bans calls to DNC-registered numbers, sets calling hours at 8 a.m. to 9 p.m. local time, requires caller identification, and imposes strict consent rules for cell phone calls using automated dialing equipment. Violations carry $500 to $1,500 in statutory damages per call, and private plaintiffs can sue without showing actual harm.

Can you cold call cell phones?

Yes, with conditions. Manual calls by a live agent to a cell phone are generally permissible if the number isn't on the DNC Registry. But if you use any automatic telephone dialing system or a prerecorded voice, you need prior express written consent from the owner, and the consent must name your company. After Facebook v. Duguid (2021), the ATDS definition is narrower, but the risk hasn't disappeared.

What hours can you legally cold call someone?

Federal law allows calls between 8 a.m. and 9 p.m. at the called party's local time. You use the time zone of the number you're dialing, not your office location. Some states add tighter limits, and Florida restricts certain automated calls further. The safest practice is to confirm the local time for every number and build calling-hour enforcement into your dialer settings, more than your written policy.

What disclosures are required on a cold call?

At the start of every telemarketing call, you must state your name and the company you're calling for. You must give a phone number or address where the company can be reached. If you use a prerecorded message, it must include an automated opt-out mechanism that works during the call itself. These are TCPA requirements under 47 U.S.C. § 227 plus parallel FTC Telemarketing Sales Rule obligations.

What is the established business relationship (EBR) exception to the DNC rules?

An established business relationship lets you call a DNC-registered number if the consumer made a purchase or transaction with you in the last 18 months, or made a written inquiry in the last 3 months. You must document the EBR with dated records. The consumer can revoke it by asking to join your internal DNC list, and you must honor that within 30 days.

How is cold calling different for B2B versus B2C?

B2B calls to business landlines are largely exempt from the National DNC Registry and federal calling-hour limits. But calling a business owner's cell phone with automated equipment still requires consent under the TCPA, regardless of the business purpose. Some states, including Florida, apply rules that don't cleanly carve out B2B. In practice, most B2B teams dial a mix of landlines and cells, so partial TCPA exposure remains.

What records do I need to keep to defend a TCPA lawsuit?

Keep DNC scrub logs (date, area codes accessed, list version), your internal DNC list with opt-out timestamps, written consent documentation with IP addresses and form screenshots for cell contacts, call detail records, and EBR documentation for any number where you use that exception. The TCPA statute of limitations is 4 years, so retain everything at least that long. The burden to prove compliance falls on you, not the plaintiff.

How much does a TCPA violation cost per call?

The statute sets $500 per violation. If a court finds the violation willful or knowing, that triples to $1,500 per call. There's no per-company cap, and class actions aggregate per-call liability across every affected consumer. Real class action settlements have reached hundreds of millions of dollars. Dish Network settled for $341 million in 2017. Individual plaintiff suits often settle for $1,000 to $3,000 per call.

Do state laws apply to cold calling even if you follow federal rules?

Yes. States impose stricter requirements than the TCPA and TSR. Florida's Telephone Solicitation Act requires prior express written consent for any automated call or text to a Florida consumer and caps calls at three per 24 hours. California's CCPA affects how you use consumer data for list-building. Texas and Oklahoma run separate state DNC lists. Following only federal law while ignoring state statutes for your high-volume states is a common, expensive gap.

Prior express written consent is a signed or electronic agreement from the consumer that clearly authorizes your company specifically to contact them at a particular number using automated equipment. You need it to call a cell phone with an ATDS or prerecorded voice, and under Florida's Mini-TCPA for any automated call or text to a Florida number. The consent must name your company, more than "partners" or "third parties," to hold up in litigation.

Sources

  1. U.S. Code, 47 U.S.C. § 227, Telephone Consumer Protection Act (Cornell LII): TCPA statutory damages of $500 per violation, trebled to $1,500 for willful violations; calling hour restrictions; required caller ID disclosures; ATDS and prerecorded voice consent requirements
  2. FTC, Telemarketing Sales Rule and National Do Not Call Registry information for businesses: DNC Registry scrub requirements, 31-day freshness window, calling hour restrictions under the TSR, and civil penalty amounts up to $51,744 per violation
  3. Florida Legislature, HB 7013, Florida Telephone Solicitation Act (effective July 1, 2021): Florida requires prior express written consent for any automated call or text to a Florida consumer; caps calls at three per 24 hours; $500 per violation private right of action trebled to $1,500 for willful violations
  4. Supreme Court of the United States, Facebook, Inc. v. Duguid, 592 U.S. 395 (2021): Supreme Court narrowed the ATDS definition in 2021 to systems that use a random or sequential number generator, but did not eliminate TCPA cell phone consent requirements
  5. FTC, cases and proceedings (TCPA enforcement actions and settlements): Dish Network settled TCPA claims for $341 million in 2017; Capital One settled for $75.5 million in 2014; these are among the largest TCPA class action settlements on record
  6. RAIN Group, Top Performance in Sales Prospecting research report: 82% of buyers report accepting meetings that originated from a cold call; 69% of buyers accepted at least one cold call from a new vendor in the survey period
  7. California Attorney General, California Consumer Privacy Act (CCPA) information: CCPA and CPRA affect how businesses may use California consumer data to build call lists, including opt-out of sale requirements
  8. FTC, National Do Not Call Registry business registration and fees: First five area codes of registry access are free; additional area codes cost $70 each per year; maximum fee of $19,765 for all area codes as of 2024
  9. U.S. Code, 28 U.S.C. § 1658, Statute of limitations for federal civil actions (Cornell LII): The default federal statute of limitations is 4 years, which courts have applied to TCPA claims

Disclaimer: LeadCompliant is a compliance review tool, not a law firm. We do not provide legal advice. Consult with a TCPA attorney for legal guidance on specific compliance questions. Compliance scores, audits, and risk assessments are informational only.

LeadCompliant Team

LeadCompliant provides expert guidance and tools to help you succeed. Our content is reviewed for accuracy and kept up to date.

Related Articles

Related Glossary Terms

LeadCompliant
Build My Kit