Type: Blog
Topic: Do Not Call Solution

Businesses that call a phone number on the National Do Not Call (DNC) List without a valid exemption can face serious financial and legal consequences. The FTC’s Telemarketing Sales Rule (TSR) and the Telephone Consumer Protection Act (TCPA) set strict rules for telemarketing outreach, and penalties can accumulate fast when violations span multiple calls or campaigns.
Key penalties at a glance:
PossibleNOW’s Do Not Call compliance software helps businesses avoid these penalties by automating list scrubbing, enforcing suppression rules, and maintaining audit-ready compliance records across federal, state, and internal registries.
In the following sections, you’ll find information on:
Speak With an Expert Today
“Penalties often follow repeated failures, not a single mistake. Monitor suppression accuracy, investigate exceptions, and fix the underlying process gaps quickly.”
Federal penalties for DNC violations come from two distinct regulatory tracks, each with its own enforcement mechanism.
The TSR governs telemarketing practices and the National Do Not Call Registry. Businesses that contact numbers on the registry without a valid exemption face civil penalties of up to more than $53,000 per non-compliant contact. The FTC enforces these penalties and can pursue action against both the company and any vendors conducting outreach on its behalf.
The TCPA is enforced through multiple channels. Consumers can sue businesses directly under the statute’s private right of action, with statutory damages of $500 per violation, increasing to $1,500 when the court finds the conduct was willful. These damages apply to unauthorized telemarketing calls, robocalls, and text messages, whether the contact was made in-house or through a vendor.
The FCC also has authority to pursue administrative fines against violators, and state attorneys general can bring their own enforcement actions under the TCPA and applicable state statutes.
Several factors affect how penalties are assessed:
For a deeper overview of how these obligations apply to outbound programs, see PossibleNOW’s beginner’s guide to TCPA.
The TCPA’s private right of action means consumers can sue businesses directly for unauthorized contact, and the statute does not require proof of actual damages. That low barrier to filing creates significant litigation exposure, particularly for outbound programs that touch large volumes of numbers.
A single complaint can serve as the basis for a class-action lawsuit, especially when records show similar violations across multiple calls, campaigns, or time periods. TCPA-related class-action settlements routinely reach into the millions, and even cases resolved outside of court carry substantial legal fees.
Professional TCPA litigators add another layer of risk. These plaintiffs deliberately engage with businesses to establish a basis for claims, and the volume of TCPA-related lawsuits continues to grow. PossibleNOW’s TCPA litigator list helps businesses identify known plaintiffs before outreach, reducing this exposure.
A clear understanding of consumer rights under Do Not Contact laws is essential for recognizing where litigation risk originates and how to manage it.
Federal penalties are only part of the picture. Many states enforce their own telemarketing regulations, and violations at the state level can compound federal exposure significantly.
A fragmented compliance approach, where federal and state rules are managed separately or inconsistently, creates the greatest risk for multi-state operations.mers can sue for damages of $500 to $1,500 per violation, depending on whether the violation was willful while the TSR has fines up to $50,000 per violation.

Avoiding DNC penalties requires a proactive, documented compliance program. The following six practices address the most common sources of violations.
The TSR requires sellers and telemarketers to scrub calling lists against the National Do Not Call Registry at least once every 31 days. In addition, businesses should scrub against applicable state DNC lists. States such as Florida and Louisiana maintain their own registries with separate requirements.
The FCC’s Reassigned Numbers Database (RND) tracks telephone numbers that have been permanently disconnected and reassigned to new subscribers. Calling a reassigned number is one of the most common paths to a TCPA violation, because consent obtained from the original subscriber does not transfer to the new one.
Every organization that conducts outbound telemarketing must maintain an internal DNC list of consumers who have directly requested not to be contacted. Opt-out requests must be honored as soon as possible and no later than 10 business days after receipt.
Federal law requires internal DNC records to be maintained for at least 5 years, though some states require 10 years, and many businesses choose to retain these records indefinitely as a best practice. Text opt-outs should be treated as call opt-outs and vice versa. If a consumer replies “STOP” to a text, that number should be suppressed from calls as well.
Before contacting a number on the National or state DNC list, businesses must verify whether a valid exemption applies. The two primary exemptions are:
Both exemptions should be verified systematically before every campaign. Consent can be revoked, EBR windows can expire, and an entity-specific opt-out from the consumer overrides any active EBR. This means that a consumer who was exempt from the DNC list at the start of a campaign may not be weeks or months later.
Courts have consistently found that brands are responsible for the actions of their third-party marketing partners, including lead aggregators and remarketers, under TCPA and TSR vicarious liability standards. If a vendor contacts a number that should have been suppressed, the liability falls on the business, not just the vendor.
Vendors should receive updated suppression lists and consent details on a consistent schedule. Contracts should clearly require adherence to TCPA and TSR rules, and regular vendor audits help verify that lead sources and calling practices remain compliant.
All employees, contractors, and vendors involved in outbound contact must be trained on current DNC compliance requirements. helping businesses stay compliant with both federal and state regulations while minimizing the risk of costly penalties.
Request a Demo Today
PossibleNOW provides enterprise-grade tools that automate compliance and reduce the risk of costly DNC violations.
DNC penalties can accumulate quickly, and liability extends across the entire vendor ecosystem. A documented, automated compliance program is the most effective protection against fines, litigation, and reputational damage.
To evaluate your current compliance posture or strengthen your DNC program, contact PossibleNOW today.