ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Do Not Call Rules

What is a DNC?

Back to InsightsWhat is a DNC?

What is a DNC?

Key Facts

  • The National DNC Registry surpassed 258 million active numbers in FY 2025, adding 4.8 million new registrations in one year, per the FTC's biennial report.
  • DNC registrations never expire — the FTC eliminated expiration dates in 2008, so the list only grows, compliance analysis confirms.
  • The FTC received over 2.6 million DNC complaints in FY 2025, up from more than 2 million the prior year, its Data Book shows.
  • Since 2003, the FTC has filed 173 lawsuits against 570 companies and 449 individuals, collecting nearly $400 million from violators, per FTC enforcement data.
  • TCPA statutory damages run $500–$1,500 per call or text with no cap on class exposure, legal analysis finds.
  • Safe Harbor protection requires scrubbing lists against the National Registry at least every 31 days, per compliance guides.
  • A customer's personal opt-out overrides the 18-month Established Business Relationship window — a clean Registry scrub won't cure it, legal analysis warns.

The Rising Risk of Non-Compliant Outreach in Customer Reactivation

Every time your phone rings with an unfamiliar number, you're witnessing a regulatory battleground — and if your business runs reactivation campaigns, you're standing on it. The numbers behind the Do Not Call Registry tell a story of consumers who are increasingly unwilling to tolerate unsolicited outreach, and increasingly willing to report it.

The scale of consumer opt-outs keeps climbing. According to the FTC's biennial report to Congress, the National DNC Registry grew to over 258 million active telephone number registrations by the end of fiscal year 2025, with 4.8 million new numbers added in that year alone. Registrations never expire — the FTC eliminated expiration dates back in 2008 — so this list only moves in one direction: up.

Complaint volume is rising just as fast. The FTC received over 2.6 million DNC complaints in FY 2025, up from more than 2 million the year before, per the FTC's National Do Not Call Registry Data Book. Those complaints aren't just venting; the FTC uses them to identify trends and support enforcement actions against violators.

The financial exposure is real. Since 2003, the FTC has filed 173 lawsuits against 570 companies and 449 individuals, collecting nearly $400 million from violators. Under the TCPA, statutory damages run $500 to $1,500 per call or text, with no cap on class exposure — a four-year statute of limitations means old campaigns can come back to haunt you.

For businesses running reactivation outreach, the risk concentrates in a few specific gaps:

  • Internal opt-outs override everything. A customer who personally asked you to stop calling is off-limits even within the 18-month Established Business Relationship window — a clean National Registry scrub doesn't cure it.
  • Vendor claims don't transfer liability. The entity making the call owns compliance, even when a vendor promises a "pre-scrubbed" list.
  • Texting rules are in flux. A 2026 federal court ruling in Alabama found SMS messages don't trigger a private right of action under TCPA's DNC provisions in that jurisdiction — yet the FCC still treats texts as calls, so jurisdictional risk varies.
  • Batch scrubbing isn't enough. Effective programs run DNC checks in real time before each dial, since compliance analysis shows reconstructing compliance after a complaint turns a defense into a settlement negotiation.

This is why reactivation done right starts with permission. CallMyCustomers works only from lists of real customers, honors opt-outs immediately, and routes every message through owner approval before anything is sent — turning compliance from a liability shield into a foundation for outreach that actually gets answered.

How DNC Compliance Works: Safe Harbor, Real-Time Scrubbing, and Internal Lists

Knowing the DNC rules exist is one thing; running a compliant operation is another. The gap between the two is where most businesses get into trouble—often without realizing it until a complaint arrives.

The FTC offers a Safe Harbor framework that shields businesses from liability for accidental calls, but only when four pillars are met: documented written DNC procedures, employee training, recording and honoring internal opt-outs, and scrubbing calling lists against official registries at least every 31 days, per this compliance guide. That 31-day ceiling matters—federal rules under 47 CFR § 64.1200(c)(2) and 16 CFR § 310.4(b)(3)(iv) cap the gap between your last scrub and the call date at exactly that.

Here's where many programs break down. Legal analysis identifies the single most common gap as failing to distinguish between the National DNC Registry and your internal DNC list. These are two different obligations:

  • National Registry scrubbing — checking your list against the FTC's registry of over 258 million numbers, per the FTC's biennial report, at least every 31 days.
  • Internal DNC list — capturing every customer who personally asks your company to stop, then suppressing that number permanently.
  • Honoring internal opt-outs immediately — the FCC allows up to 30 days, but immediate suppression is the operational standard.

The distinction has real teeth. A customer's personal opt-out overrides the Established Business Relationship exception regardless of purchase history—a clean National Registry scrub does nothing to cure a call to someone who told your company to stop. That's why CallMyCustomers honors opt-outs immediately and works only from lists of real customers with a genuine relationship to the business.

Batch processing isn't enough, either. Compliance programs protect the business only when the rules run in real time before each call or text—reconstructing compliance after a complaint turns a defense into a settlement negotiation. The entity making the call owns its own compliance, even when a vendor claims a list is "pre-scrubbed."

The stakes justify the discipline. TCPA statutory damages run $500–$1,500 per call or text with no cap on class exposure, and the FTC has collected nearly $400 million from violators since 2003 through 173 lawsuits against 570 companies and 449 individuals. Real-time scrubbing at the point of dial, paired with an airtight internal list, is what keeps reactivation outreach a revenue engine instead of a liability.

Reactivation campaigns live in a unique compliance zone: you're contacting people who already know your business, but that history doesn't exempt you from Do Not Call rules. In fact, the Established Business Relationship exception—which permits calls to DNC-registered numbers within 18 months of a purchase—does nothing to protect a call to someone who told your company personally to stop calling.

Timing is the first constraint. Federal rules restrict telemarketing calls to 8 a.m.–9 p.m. local time, but state variations run stricter, including Maine's 9 a.m.–5 p.m. weekday-only window and Florida's 8 p.m. cutoff. Because number portability makes area codes an unreliable proxy for time zone, time-zone detection belongs in the dial path, not in a spreadsheet. A composite nationwide window of 9 a.m.–8 p.m. recipient local time minimizes risk across state lines.

Consent is the second. For autodialed or prerecorded calls and texts to cell phones, TCPA requires prior express written consent—and courts have granted summary judgment for plaintiffs when defendants produced only bulk spreadsheets without individual timestamps. Pre-checked boxes don't satisfy the standard. This is why reactivation programs should collect explicit consent during the booking flow and retain consent records; the FTC's Telemarketing Sales Rule amendments increased record retention requirements to five years as of April 2024.

Text messages carry their own evolving risk profile. The FCC has treated texts as "calls" under the TCPA since 2003, applying the same scrubbing, consent, and calling-hour rules. Yet a 2026 federal court ruling in the Northern District of Alabama held that SMS messages don't qualify as "telephone calls" under the TCPA's DNC provisions for private right of action, based on the statute's 1991 ordinary meaning of sound transmission. Interpretations vary by jurisdiction, and until Congress amends the statute, text-based outreach warrants jurisdiction-specific legal guidance.

For a done-for-you reactivation service like CallMyCustomers, the practical takeaway is that the entity making the call owns compliance—even when a vendor claims a list is "pre-scrubbed." The stakes are real: penalties reach up to $1,500 per willful violation per call, and the FTC has collected nearly $400 million from violators since 2003. Sound reactivation practice includes:

  • Scrubbing against the National DNC Registry at least every 31 days to qualify for Safe Harbor protection
  • Honoring internal opt-outs immediately, regardless of purchase history or EBR status
  • Calling and texting only within a conservative 9 a.m.–8 p.m. local-time window
  • Securing documented written consent with individual timestamps before any autodialed contact

Done well, compliance and reactivation reinforce each other. The FTC reports unwanted telemarketing calls have dropped more than 50 percent since 2021, and consumers respond to permission-based outreach that respects the rules. When every script and message is approved before anything is sent, and opt-outs are honored the moment they arrive, reactivating a known customer—at roughly 5x cheaper than acquiring a new one—becomes both a revenue engine and a defensible one.

Frequently Asked Questions

What exactly is the National Do Not Call Registry and how big is it?
The National Do Not Call Registry is an FTC-maintained database where consumers register phone numbers to opt out of telemarketing calls and texts. As of the end of fiscal year 2025, it contained over 258 million active registrations, with 4.8 million new numbers added that year alone, and registrations never expire since the FTC eliminated expiration dates in 2008 according to the FTC's biennial report to Congress.
If a customer tells us directly to stop calling, does the Established Business Relationship exception still protect us?
No — a customer's personal opt-out request to your company overrides the Established Business Relationship exception entirely, regardless of purchase history or how recent the transaction was. A clean National Registry scrub does nothing to cure a call to someone who told your company personally to stop, making immediate internal opt-out suppression critical per legal analysis of TCPA and DNC requirements.
How often do we need to scrub our calling lists against the National DNC Registry to stay compliant?
Federal rules require scrubbing at least every 31 days to qualify for FTC Safe Harbor protection, with a maximum 31-day gap allowed between your last scrub and the call date under 47 CFR § 64.1200(c)(2) and 16 CFR § 310.4(b)(3)(iv) per compliance analysis of TCPA DNC requirements. Batch processing once a month isn't enough — effective programs run real-time checks before each dial.
Are text messages treated the same as phone calls under DNC rules?
The FCC has treated texts as "calls" under the TCPA since 2003, applying the same scrubbing, consent, and calling-hour rules, but a 2026 federal court ruling in Alabama held that SMS messages don't qualify as "telephone calls" under the TCPA's DNC provisions for private right of action in that jurisdiction per legal commentary on the Alabama court decision. This creates jurisdictional inconsistency, so text-based outreach warrants jurisdiction-specific legal guidance.
What are the actual penalties for violating DNC rules?
TCPA statutory damages run $500 to $1,500 per call or text with no cap on class exposure, and the FTC has collected nearly $400 million from violators since 2003 through 173 lawsuits against 570 companies and 449 individuals per the FTC's biennial report to Congress. A four-year statute of limitations means old campaigns can still trigger liability.
If we use a vendor that promises a "pre-scrubbed" list, are we off the hook for compliance?
No — the entity making the call owns compliance responsibility even when a vendor claims a list is "pre-scrubbed" or "DNC compliant." Reconstructing compliance after a complaint turns a defense into a settlement negotiation, which is why real-time scrubbing at the point of dial is the operational standard per legal analysis of TCPA DNC requirements.

Compliance Is the Foundation — Permission Is the Advantage

Understanding the DNC landscape comes down to a few non-negotiables: scrub against the National Registry at least every 31 days, honor internal opt-outs immediately (they override even the 18-month Established Business Relationship window), keep documented written consent with individual timestamps, and call within a conservative 9 a.m.–8 p.m. local-time window. The stakes are hard to ignore — TCPA statutory damages run $500 to $1,500 per call or text, and the FTC has collected nearly $400 million from violators since 2003. But here's the encouraging part: the same discipline that keeps you compliant is what makes reactivation outreach work at all. Consumers have shown they respond to permission-based contact — and reactivating a customer runs roughly 5x cheaper than acquiring a new one. Your next step is simple: audit your current process against the four Safe Harbor pillars, confirm your opt-out handling is immediate, and know your rate before you spend a dollar. CallMyCustomers offers a free list review that does exactly that — you'll see what your customer list can produce, with every message approved by you before anything is sent.

Stay in the Loop