ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Do Not Call Rules

How many times is it acceptable to call someone?

Back to InsightsHow many times is it acceptable to call someone?

How many times is it acceptable to call someone?

Key Facts

  • Neither TCPA nor Do Not Call rules set a numeric call limit — consent, not persistence, defines acceptability according to TCPA specialists.
  • FCC penalties reach $16,000 per violation and $26,000 when intentional, per TCPA guidance.
  • Private plaintiffs can claim up to $500 per communication, or $1,500 for willful violations, under TCPA rules.
  • Cumulative TCPA judgments in recent years have exceeded $925 million, per legal analysis.
  • A transactional established business relationship lasts 18 months after purchase; inquiry-based EBRs last only 3 months, per FDIC examination guidance.
  • Telemarketing lists must be scrubbed against the National DNC Registry at least every 31 days, per regulatory requirements.
  • Company-specific do-not-call requests must be honored for at least 5 years — even if the customer keeps buying from you, per FDIC guidance.

Why There's No Magic Number for Call Frequency

If you're searching for a hard number — "three calls and stop," or "five attempts max" — you'll be disappointed. According to TCPA guidance from specialized attorneys, neither the Telephone Consumer Protection Act nor Do Not Call regulations set a numeric limit on call attempts. The rules simply don't work that way.

What regulators actually care about is consent. Without proper consent, even one call can constitute a violation. With documented consent, the permissible scope of your outreach is defined by that consent — and by how well you manage opt-outs. The FDIC's examination manual confirms the same consent-based framework, emphasizing that a seller-specific do-not-call request terminates an established business relationship for telemarketing purposes, even if the customer keeps doing business with you.

That doesn't mean frequency is a free-for-all. The regulations impose concrete obligations that effectively discipline how often and how you call:

  • Scrub your list against the National DNC Registry at least every 31 days for telemarketing calls.
  • Honor company-specific do-not-call requests for at least 5 years — many companies honor them indefinitely.
  • Provide an automated, interactive opt-out mechanism during each autodialed or prerecorded telemarketing call.
  • Track consent revocations, which customers can make at any time, by any reasonable means — even a casual text.

The stakes explain why businesses take this seriously. FCC penalties reach up to $16,000 per violation ($26,000 for intentional ones), private plaintiffs can claim up to $500 per communication, and cumulative TCPA judgments in recent years have exceeded $925 million. A call-count rule of thumb offers no protection against any of this; consent documentation and opt-out discipline do.

The established business relationship (EBR) framework adds another layer. A transactional EBR lasts 18 months after a purchase; an inquiry-based EBR lasts only 3 months. So while there's no cap on attempts, the window in which a relationship carries weight is finite — and a do-not-call request closes it immediately.

For service businesses running reactivation outreach, this is why process matters more than arbitrary limits. At CallMyCustomers, campaigns work from real customer lists, every message is approved by the owner before it goes out, and opt-outs are honored immediately. Frequency becomes acceptable when each contact has a reason to reconnect — a seasonal need, an old quote, a renewal — and the customer's consent status is checked before every wave.

The honest answer to "how many times is it acceptable?" is: as many times as your consent, your list hygiene, and your customer's patience allow. The regulations measure permission, not persistence.

Here's the truth most callers miss: there is no magic number of calls that keeps you compliant. According to TCPA specialists, acceptability is determined by consent status, Do Not Call compliance, and opt-out management — not a numeric threshold. Without proper consent, even one call can violate the law.

Prior express consent is the first gatekeeper. Telemarketing calls made with autodialers or prerecorded voices to cell phones require prior express written consent (PEWC), while non-telemarketing calls using that technology need prior express consent (PEC). The scope of what a customer agreed to defines what you can send, how, and for how long.

The second gatekeeper is the Established Business Relationship (EBR) framework, which provides limited exemptions. Per the FDIC's examination manual, a transactional EBR lasts 18 months after a purchase, while an inquiry EBR lasts just 3 months after an application or inquiry.

Critically, an EBR is fragile. A seller-specific do-not-call request terminates the relationship exemption for telemarketing purposes — even if the customer keeps buying from you. The 2012 FCC rules also eliminated EBR as a substitute for written consent on autodialed or prerecorded telemarketing calls.

The third gatekeeper is DNC list hygiene, which comes with hard deadlines:

  • Scrub your list against the National DNC Registry at least every 31 days for telemarketing calls.
  • Honor company-specific do-not-call requests for a minimum of 5 years — many businesses honor them indefinitely.
  • Capture opt-outs from any reasonable channel, including non-standard texts like "please stop calling me," and suppress the contact immediately.
  • Provide an automated, interactive opt-out mechanism during each autodialed or prerecorded telemarketing call.

The stakes explain why these rules matter. Private plaintiffs can recover up to $500 per communication, and up to $1,500 per willful violation, while the FCC can impose penalties reaching $16,000 per violation ($26,000 for intentional ones). Recent TCPA judgments have exceeded $925 million in cumulative awards.

Consent can also be revoked at any time by any reasonable means, so a customer who once welcomed your calls can change their mind mid-campaign. Businesses that track revocations promptly — and segment outreach by relationship recency — stay inside the lines. This is why CallMyCustomers builds its list review around real customer records, recency tiers, and immediate opt-out honoring before any outreach begins.

The practical takeaway: frequency limits come from the relationship itself. Segment by how recently someone transacted, refresh consent for older segments, and let every opt-out end the conversation for good.

Revocation Risk: Why One Non-Standard 'Stop' Can Trigger Liability

Revocation Risk: Why One Non-Standard 'Stop' Can Trigger Liability

A single text saying "I don't want to hear from you" can carry the same legal weight as a formal "STOP" reply under TCPA rules, and plaintiffs are increasingly testing whether businesses honor such revocations in real time. Consent can be withdrawn at any moment by any reasonable means — including informal language — and failure to act immediately opens the door to liability, especially when autodialed calls are involved. The FCC now requires an automated, interactive opt-out mechanism during every autodialed telemarketing call, leaving no room for delayed compliance.

For businesses like CallMyCustomers that rely on permissioned reactivation of known customers, this means opt-out capture cannot be batch-processed or delayed until the end of a campaign. Every channel — voice, text, email — must feed into a unified suppression system that acts before the next outreach attempt. Plaintiffs exploit gaps in this process, suing when a revocation is logged but not honored for hours or days, turning one overlooked message into a costly class action risk.

  • FCC penalties reach up to $16,000 per violation ($26,000 for intentional), with private actions allowing up to $500 per communication ($1,500 for willful)
  • Company-specific DNC requests must be honored for at least 5 years, though many businesses maintain them indefinitely
  • National DNC Registry scrubbing is required every 31 days for telemarketing calls

Honoring revocations instantly isn’t just about avoiding fines — it’s about preserving trust. When a customer signals they want no further contact, respecting that boundary immediately reinforces the permission-based foundation that makes reactivation effective. For CallMyCustomers, this means routing every reply back to the client’s booking process in real time, ensuring opt-outs are suppressed across all channels before the next call goes out. In a regulatory landscape where consent — not call count — defines acceptability, real-time opt-out management is the only defensible practice.

Operationalizing Compliance in a Reactivation Campaign

Compliance isn't a policy document sitting in a drawer — it's a sequence of operational steps that either happen every time or don't. When the rules hinge on consent rather than call counts, the only way to stay safe is to build the regulatory requirements directly into the workflow.

That starts at list intake. Before any campaign runs, every contact should pass a consent audit: documented permission appropriate to the call type, a clean relationship history, and a working number. Because TCPA violations can cost up to $16,000 each — and $26,000 when intentional — verifying consent before the first dial is far cheaper than litigating after it.

Next comes segmentation, which maps neatly onto the Established Business Relationship framework. Under federal examination guidance, a transactional EBR lasts 18 months after a purchase, while an inquiry-based EBR lasts just 3 months. Sorting a list by recency — customers active within 30 days, within 6 months, or beyond 12 months — isn't just good targeting. It's a direct alignment with the legal windows that determine who can be called and under what basis.

Then the mechanics of DNC compliance, which are refreshingly concrete:

  • Scrub the list against the National DNC Registry at least every 31 days, since regulators require that cadence for telemarketing calls.
  • Maintain a company-specific do-not-call list honored for at least 5 years — indefinitely is safer.
  • Capture opt-outs from every channel — call, text, email, even a verbal "please stop" — and suppress the contact before the next wave goes out.

That last point matters more than most businesses realize. Consent can be revoked at any time, by any reasonable means — including a non-standard text like "I don't want to hear from you" rather than a formal "STOP." Plaintiffs increasingly test whether companies honor those unusual revocations promptly, which is why a human-in-the-loop review process beats a purely automated one. Automation handles the scale; a person catches the edge cases the software misses.

This is how CallMyCustomers structures its reactivation campaigns: a free list review that doubles as a consent audit, recency-based segmentation that mirrors the EBR windows, owner-approved scripts so every message reflects the business's own judgment, and immediate opt-out honoring across all channels. For dental and med spa clients, outreach runs under BAA/HIPAA agreements, where penalties can reach $50,000 per violation.

The result is a campaign that satisfies the law without treating customers like legal risks. Permission-based outreach feels different from the recipient's side — a call about an expiring membership or an old quote reads as helpful, not harassing. Compliance and goodwill aren't competing goals; done operationally, they reinforce each other.

Healthcare and Regulated Industries: Layered Compliance Requirements

For healthcare and regulated industries like dental practices, med spas, and clinics, call frequency compliance extends beyond TCPA rules to include critical HIPAA and Business Associate Agreement (BAA) obligations. These sectors handle protected health information (PHI), requiring additional safeguards that layer onto standard telemarketing regulations. CallMyCustomers’ clinical outreach protocols are designed to meet these heightened standards, ensuring patient communications remain both compliant and relationship-focused.

HIPAA violations carry significant financial risk, with penalties ranging from $100 per record to up to $50,000 per violation, depending on the level of negligence and corrective action taken. This makes proactive compliance essential — particularly when it comes to BAAs, which govern how patient data is handled during outreach campaigns. Research shows that negotiating favorable BAA terms — such as liability caps, breach notification timelines, and data deletion clauses — succeeds 60–70% of the time when addressed pre-signature, but drops to less than 20% after the agreement is finalized. This underscores the importance of addressing privacy obligations early in the vendor relationship.

CallMyCustomers already operates under established clinical standards that align with these requirements, including immediate opt-out honoring, secure data handling, and consent-based outreach limited to the scope of the existing patient relationship. For dental, med spa, and clinic clients, this means reactivation campaigns respect both communication preferences and privacy regulations — turning compliance into a foundation for trust rather than a barrier to engagement.

  • Maintain documented consent for all patient contacts before initiating outreach
  • Honor opt-outs immediately across all channels, including verbal and non-standard requests
  • Scrub National DNC Registry every 31 days and retain company-specific DNC lists for 5+ years
  • Limit call frequency to the scope of the established relationship and consent given
  • Ensure all call recordings and data flows comply with HIPAA and negotiated BAA terms
By integrating these layered requirements into every campaign, CallMyCustomers helps healthcare providers reactivate patients safely, ethically, and effectively — without compromising compliance or care.

Frequently Asked Questions

Is there a specific number of calls that's legally allowed before I have to stop?
No — neither the TCPA nor Do Not Call regulations set a numeric limit on call attempts. According to TCPA guidance from specialized attorneys, acceptability is determined by consent status, DNC compliance, and opt-out management, not a call-count threshold. Without proper consent, even one call can be a violation.
How much can I actually be fined for calling a customer too many times?
FCC penalties reach up to $16,000 per violation ($26,000 for intentional ones), and private plaintiffs can claim up to $500 per communication — $1,500 for willful violations. Cumulative TCPA judgments in recent years have exceeded $925 million, which is why consent documentation and opt-out discipline matter more than any call-count rule of thumb.
How long does an established business relationship let me keep calling a past customer?
A transactional relationship lasts 18 months after a purchase, while an inquiry-based relationship lasts only 3 months. Per the FDIC's examination manual, a seller-specific do-not-call request terminates that exemption immediately — even if the customer keeps buying from you. Segmenting your list by recency keeps outreach inside those legal windows.
If a customer texts something informal like 'please stop calling me,' do I really have to stop?
Yes — consent can be revoked at any time, by any reasonable means, and a casual text carries the same legal weight as a formal 'STOP.' TCPA specialists note that plaintiffs increasingly test whether businesses honor non-standard revocations promptly, so delays in suppressing a contact can turn one overlooked message into class-action risk.
How often do I need to check the National Do Not Call Registry?
For telemarketing calls, you must scrub your list against the National DNC Registry at least every 31 days. You also need to honor company-specific do-not-call requests for a minimum of 5 years — though many businesses maintain them indefinitely, which is the safer practice.
Do extra rules apply if I'm calling patients at a dental practice or med spa?
Yes — healthcare outreach layers HIPAA and Business Associate Agreement obligations on top of TCPA rules, since patient data is protected health information. HIPAA penalties range from $100 per record up to $50,000 per violation, and research shows BAA terms like liability caps and data-deletion clauses are negotiated successfully 60–70% of the time before signing, but under 20% after — so address privacy terms early with any vendor.

Why Permission Beats Persistence in Customer Reactivation

There is no magic number for how many times you can call a customer—only the boundaries set by consent, Do Not Call compliance, and timely opt-out management. As we’ve seen, regulations focus on permission, not persistence: one call without consent can trigger liability, while documented consent allows outreach that feels helpful, not intrusive, when tied to a real reason to reconnect like a seasonal need or expiring membership. For service businesses, this means shifting from arbitrary call limits to a process rooted in list hygiene, recency-based segmentation, and immediate honoring of opt-outs across every channel. When compliance is built into your workflow—scrubbing the National DNC Registry every 31 days, honoring company-specific requests for five years or more, and capturing revocations in real time—you protect your business from costly violations while strengthening customer trust. The result? Reactivation campaigns that drive booked appointments without damaging goodwill. Take the first step: get a free list review from CallMyCustomers to see what your existing customer base can produce—no obligation, no software to buy, just clarity on your repeat revenue potential.

Stay in the Loop