
How to auto dial a phone number?
Key Facts
- TCPA judgments have exceeded $925 million in recent years, with penalties reaching $1,500 per call or text per legal FAQ guidance.
- FCC penalties run up to $16,000 per violation — $26,000 for intentional TCPA violations according to legal analysis.
- Businesses must scrub calling lists against the National Do Not Call Registry at least every 31 days under federal rules.
- Predictive dialer abandonment rates must stay at or below 3% to qualify for the FTC's safe harbor per FTC guidance.
- Over 20 states impose calling hour restrictions stricter than the federal 8 a.m.–9 p.m. window according to compliance research.
- Internal do-not-call requests must be honored for at least five years, even for active customers under federal TCPA rules.
- The 11th Circuit vacated the FCC's One-to-One Consent Rule in 2025, easing consent standards for callers per legal analysis.
Understanding the Legal Risks of Auto Dialing in 2025
If you're planning to auto dial customers in 2025, the technology is the easy part — the law is where businesses get hurt. TCPA judgments have exceeded $925 million in recent years, and defense attorneys report a major uptick in lawsuits targeting small and mid-sized businesses that had no idea they were violating the law.
The core framework is the Telephone Consumer Protection Act (TCPA), enforced by the FCC, alongside the FTC's Telemarketing Sales Rule. The stakes are steep: FCC penalties run up to $16,000 per violation ($26,000 for intentional violations), while private statutory damages reach $500 per call or text — $1,500 if the violation was willful or knowing.
Consent is the foundation of everything. Marketing calls made with an automatic telephone dialing system (ATDS) or prerecorded voice to cell phones require prior express written consent, and the caller — not a lead seller — bears the burden of proving it. Even a good-faith but mistaken belief about consent is no defense, and bot-generated leads count as no consent at all, per TCPA consent guidance.
The rules shifted in 2025, though the direction favored callers. The 11th Circuit vacated the FCC's One-to-One Consent Rule, which would have raised the consent standard for telemarketing, and the FCC formally declined to seek further review, according to legal analysis of the FCC's 2025 dial-back. Separately, the FCC delayed portions of its Consent Revocation Rule by one year — originally set for April 11, 2025 — giving financial institutions and healthcare organizations time to update their systems.
Despite the flux, the compliance fundamentals haven't changed. Any business dialing customers should:
- Scrub calling lists against the National Do Not Call Registry at least every 31 days, unless an exemption applies
- Call only between 8 a.m. and 9 p.m. local time — and check state rules, since over 20 states impose stricter hours
- Keep predictive dialer abandonment rates at or below 3%, per FTC Telemarketing Sales Rule guidance
- Honor opt-outs by any reasonable means — including non-standard replies like "I do not want to hear from you" — and retain consent records for 4+ years
State law adds another layer. So-called mini-TCPA statutes in states like Florida, Oklahoma, and Maryland are more expansive than the federal TCPA and can carry criminal penalties, and Florida has become a hotspot for text message litigation under its own solicitation act.
One practical safeguard for service businesses: the Established Business Relationship exemption covers transactional relationships within 18 months and inquiries within 3 months, which reduces exposure when calling real, known customers. That's the model CallMyCustomers operates on — working only from lists of actual customers, with the business owner approving every message before anything goes out, and opt-outs honored immediately. Given that plaintiffs increasingly sue over untimely revocations, immediate opt-out honoring is the safest posture, regardless of the formal legal window. For more on the TCPA's impact on small businesses, defense counsel perspective is worth reviewing before your next campaign.
How CallMyCustomers Ensures Compliant Outbound Calling
Most businesses that get hit with TCPA penalties never saw it coming — legal experts report a major uptick in lawsuits targeting small and mid-sized businesses that had no idea they were violating the law. With penalties of $500 to $1,500 per call or text and judgments exceeding $925 million in recent years, the way you dial matters as much as who you dial.
That's why compliance isn't an afterthought at CallMyCustomers — it's the foundation the entire service is built on. The model starts with a structural advantage: outreach runs only from lists of real customers, never purchased leads or scraped data. This matters because under the TCPA, the calling business bears full liability for invalid consent, even when working with third-party data — and bot-generated leads count as no consent at all.
Working from genuine customer lists also aligns with the Established Business Relationship (EBR) framework. Under federal rules, a transactional relationship within 18 months — or an inquiry within 3 months — qualifies as an EBR, which affects how National DNC Registry scrubbing requirements apply. A customer who booked an HVAC tune-up last spring or received a dental quote last month isn't a cold contact; they're someone with a documented history with your business.
Opt-out handling is where many campaigns fail. The law currently allows up to 30 days to honor a revocation, but the FCC has proposed tightening this to 24 hours — and plaintiffs increasingly sue over non-standard revocations like a casual "please stop texting me." The safest posture is immediate honoring, which is exactly how every opt-out is treated, regardless of the formal legal window.
The operational guardrails are equally disciplined:
- Calling hours stay within the federal 8 a.m.–9 p.m. local window, with awareness that over 20 states impose stricter limits
- Internal do-not-call requests are honored for at least five years, even for customers with an active business relationship
- Consent and outreach records are retained well beyond the TCPA's four-year statute of limitations, and past the TSR's 24-month recordkeeping requirement
- For dental, med spa, and clinic clients, outreach operates under the required privacy agreements, including BAA/HIPAA and A2P 10DLC registration
Because every script, offer, and message is approved by the business owner before anything goes out, there's a clear chain of accountability from consent to contact. The booking flow also collects explicit consent at the point of scheduling, creating fresh documentation with every appointment rather than relying on stale permissions.
The result is reactivation outreach that feels like what it actually is: a business reconnecting with people who already know and trust it — done inside the rules, not around them.
Practical Steps to Maintain TCPA Compliance in Your Outreach
Staying compliant with TCPA rules isn’t just about avoiding fines — it’s about building trust with every call you make. For businesses relying on outbound outreach, especially those using automated systems, following established safeguards ensures both legal safety and customer respect.
Start by scrubbing your calling list against the National DNC Registry at least every 31 days, a requirement that applies unless you’re contacting someone with an Established Business Relationship, such as a transaction within the last 18 months or an inquiry within the past three months. Maintaining your own internal DNC list is equally important, as federal rules require honoring company-specific opt-out requests for at least five years, even if the number isn’t on the national registry.
Operational discipline is just as critical. Always transmit accurate Caller ID, limit calls to between 8 a.m. and 9 p.m. in the recipient’s local time zone, and keep abandonment rates at or below 3% when using predictive dialers — a threshold recognized as a safe harbor under the FTC’s Telemarketing Sales Rule. Equally vital is honoring opt-outs immediately through any reasonable means, whether it’s a verbal request, a text like “STOP,” or an email; treating every withdrawal of consent as binding reduces exposure to litigation, especially as plaintiffs increasingly target businesses that ignore non-standard revocations.
- Scrub against the National DNC Registry every 31 days
- Call only between 8 a.m. and 9 p.m. local time
- Maintain abandonment rates under 3% for predictive dialing
- Honor opt-outs immediately via any reasonable means
- Transmit accurate Caller ID on every outbound call
For a service like CallMyCustomers, which works exclusively from verified customer lists and requires owner approval before any message is sent, compliance is woven into the process from list review to follow-up. This approach minimizes risk by focusing on documented relationships and immediate responsiveness to customer preferences — turning regulatory adherence into a foundation for sustainable reactivation.
Frequently Asked Questions
Is auto dialing phone numbers even legal in 2025?
What consent do I need before auto dialing or texting customers?
Do I have to scrub my calling list against the Do Not Call Registry?
How quickly do I have to honor opt-out requests?
What are the main rules for compliant dialing — hours, Caller ID, abandonment rates?
Can I get in trouble auto dialing if I'm just a small business?
Key Takeaways
{ "title": "Your Next Booked Customer Already Knows Your Business", "content": "Auto dialing isn't a technology problem — it's a consent problem. The TCPA framework hasn't changed in its fundamentals: prior express written consent for marketing calls to cell phones, scrubbing against the Nationa