Is Cold Calling Legal? TCPA, GDPR, and Compliance Rules for B2B Teams
Cold calling is legal. That’s the short version. It’s also the version that gets sales teams into trouble. The rules that make it legal are a lot narrower than “cold calling is fine.”
Most teams learned compliance from a US rule written for landlines in 1991. Almost every B2B contact today only owns a cell phone. Global teams now call into countries with completely different rules. That gap between the old assumption and the current reality is where the real risk lives.
This article breaks the rules down by jurisdiction: US federal, US state, UK and EU, India, and financial services. Jump to the one that applies to your team.
Where the Real Risk Actually Lives
Cold calling a business is generally legal in the US, UK, EU, and India. The exceptions almost always involve one thing: a cell phone, an autodialer or AI voice, or a jurisdiction with no B2B exemption at all.
Live, manually dialed calls to a business landline sit in the safest category under US federal law. A few things push a call outside that safe zone. Autodialing. AI voice. A personal cell phone used for work. A call placed into a country with its own rules. Any of those needs a closer look before you scale it.
The B2B Exemption Myth
The “B2B exemption” is the single most misunderstood concept in cold calling compliance. It’s worth being precise about what it actually covers.
Under the FTC’s Telemarketing Sales Rule, most business-to-business calls are exempt from the National Do Not Call Registry’s provisions. That’s it. That exemption doesn’t extend to the TCPA’s separate rules on autodialers, prerecorded voice, or AI-generated voice calls to cell phones.
The TCPA treats a wireless number as protected. It doesn’t matter if the person answering is a consumer or a VP of Sales. Most B2B contacts today are reachable only on a mobile number. That means the exemption protecting business landlines barely applies to the list most SDR teams are actually calling.
| Call Type | Requires Prior Consent? |
|---|---|
| Live call to a business landline | No, generally exempt |
| Live call to a personal cell phone | No, if manually dialed one at a time |
| Autodialed or predictive-dialed call to a cell phone | Yes, prior express written consent required |
| AI-generated or prerecorded voice to a cell phone | Yes, same consent standard as a robocall |
US Federal Rules for Cold Calling
A few rules cover most legitimate B2B outbound programs at the federal level.
- Calling hours: 8 AM to 9 PM in the recipient’s local time zone. Several states narrow this further, and the best time to cold call within that legal window still shifts by market.
- Do Not Call scrubbing: Scrub against the National DNC Registry every 31 days. Numbers move between personal and business use, so scrubbing matters even for technically exempt B2B calls.
- Consent for automated calls: A February 2024 FCC ruling counts AI-generated voices as an “artificial or prerecorded voice” under the TCPA. Autodialed or AI-voice calls to a cell phone need prior express written consent. No exceptions.
- Caller ID: Blocking or spoofing caller ID on a telemarketing call is prohibited outright.
- Opt-outs: Honor any do-not-call request immediately. Keep it on an internal list for at least five years.
If your cold calling dialer uses predictive or AI-voice technology on cell phone numbers, the consent rule above still applies. It doesn’t matter how the contact ended up on your list.
US State Laws That Go Further Than Federal Law
Federal law is the floor, not the ceiling. Several states layer on “mini-TCPA” laws that shrink or eliminate the B2B exemption entirely.
| State | What’s Different |
|---|---|
| Florida | Narrower calling window, caps on call attempts, minimal B2B exemption |
| Oklahoma | Similar attempt caps and stricter consent standards |
| Washington | Reduced B2B exemption, private right of action |
| Maryland | Additional consent requirements beyond federal TCPA |
| Oregon | Calling window narrowed to 8 AM-8 PM with a call-frequency cap |
| Texas | Narrower calling window (9 AM-9 PM, Monday-Saturday) |
If your list spans multiple states, build your program around the strictest state on it. Don’t assume federal rules cover you everywhere.
UK and EU Rules: GDPR for Cold Calling
GDPR doesn’t ban cold calling. It does add a data-protection layer on top of rules written specifically for phone calls. That combination is where US teams calling into Europe usually get caught out.
The Lawful Basis
For B2B calling, “legitimate interest” is the usual legal basis under GDPR Article 6(1)(f), the same basis used for B2B cold email. It requires a documented Legitimate Interest Assessment that weighs your business reason against the recipient’s privacy expectations.
The UK-Specific Layer
The UK’s Privacy and Electronic Communications Regulations add a rule most US teams have never encountered. A Corporate Telephone Preference Service exists specifically for business numbers, separate from the consumer list. Unlike the US system, the UK requires scrubbing against this business-specific registry, not just a consumer one. ICO fines for violations can reach £500,000.
Country-by-Country Variation
GDPR is a framework. EU member states enforce it differently for calling. Legitimate interest generally works for B2B outreach. But documentation and opt-out requirements vary enough that a multi-country program deserves a country-by-country review, not one blanket assumption.
India: TRAI, DND, and DPDP Rules
India runs one of the strictest outbound calling regimes in the world. It catches a lot of global teams off guard, especially teams running SDR operations out of India or calling into the Indian market.
The Regulator and the Registry
The Telecom Regulatory Authority of India (TRAI) enforces outbound calling through the Telecom Commercial Communications Customer Preference Regulations. Consumers opt out through the National Customer Preference Register, universally known as the DND (Do Not Disturb) registry. Roughly 60-65% of active Indian mobile numbers already carry a DND preference, a far larger share than the US or UK equivalent.
Registration and Number Ranges
Telemarketers must register as a Principal Entity on India’s DLT (Distributed Ledger Technology) platform, register as a telemarketer, and place commercial calls only from a designated number series. The 140 series is the common one. A regular 10-digit business number placing high call volumes is exactly the pattern TRAI’s detection systems flag.
Calling Hours
Promotional calls are restricted to 9 AM to 9 PM, a full hour tighter on both ends than the US federal window. This quiet period applies even to numbers that haven’t registered for DND.
Scrubbing Frequency
Check lists against the DND registry before every campaign, and re-check regularly. The registry has known lag, so a list scrubbed weeks ago can already be stale.
Data Protection
India’s Digital Personal Data Protection Act, fully in effect as of 2026, adds a consent layer on top of TRAI’s calling rules. Its legitimate interest exemption is narrower than GDPR’s. A legitimate interest argument that works for the UK doesn’t automatically cover the same call into India.
Penalties
TCCCPR violations carry escalating fines. A 2025 amendment lowered the complaint threshold to just five complaints in ten days, which speeds up enforcement considerably.
FINRA Rules for Financial Services Cold Calling
If you’re calling on behalf of a broker-dealer or investment firm, FINRA Rule 3230 adds a layer on top of everything above.
Rule 3230 largely mirrors the FCC’s telemarketing rules. Same 8 AM to 9 PM calling window. Mandatory DNC scrubbing. Required caller ID transmission. A firm-specific do-not-call list on top of the national one. It also recognizes an “established business relationship” exception, generally covering a customer the firm has done business with in the past 18 months.
Enforcement here is real. One major wirehouse learned this the hard way. Trainees made unsupervised calls to numbers on the do-not-call registry. The firm paid a combined $1.4 million in fines to FINRA and a state securities regulator.
When Cold Calling Becomes Harassment
Most cold call complaints aren’t about the first call. They’re about the fifth one after someone asked to be removed.
A few habits can turn aggressive sales into legally actionable harassment. Calling a number again after a do-not-call request. Disguising or blocking caller ID. Using high call volume specifically to wear someone down. The rule that holds up everywhere: honor every opt-out immediately, and don’t treat “not interested” as an invitation to call back sooner.
What It Costs You If You Get It Wrong
TCPA violations aren’t a theoretical risk. They’re an active area of litigation. Law firms specialize specifically in filing these claims, both for individual plaintiffs and class actions.
Statutory damages run $500 per unintentional violation and up to $1,500 per willful or knowing one. Each call can count as a separate violation. A single autodialed campaign that hits a few hundred non-consented numbers can generate real exposure fast. India’s TCCCPR penalties follow a similar escalating logic, and the lower complaint threshold introduced in 2025 means enforcement moves faster than it used to.
Compliance Checklist
None of this requires a legal department to get right. It requires a handful of habits built into the outbound process.
- Scrub your cold calling database against the National DNC Registry at least every 31 days, and keep your own internal do-not-call list permanently.
- Default to manual, live dialing for cell phones unless you have documented prior express written consent for autodialed or AI-voice calls.
- Keep US calls inside the 8 AM-9 PM local-time window, and check whether any state on your list narrows that further.
- If you’re calling into India, register on the DLT platform, use the correct number series, and scrub against the DND registry before every campaign.
- If you’re calling into the UK or EU, scrub against the relevant business do-not-call registry, not just a consumer one.
- Never block or spoof caller ID.
- Honor every opt-out immediately and log it.
Conclusion
Cold calling is legal in the US, the UK, the EU, and India alike, and it’s likely to stay that way. The channel isn’t dead and isn’t disappearing. It’s just less forgiving of shortcuts than it used to be.
What actually gets teams into trouble is narrower than most people assume. Automated technology. Cell phones. Ignored opt-outs. Rules that shift the moment your list crosses a border. Build the checklist above into your process from day one. Treat the strictest jurisdiction on your list as your baseline. And confirm anything fact-specific with an attorney rather than a blog post, this one included.
Frequently Asked Questions
Is cold calling illegal?
No. Cold calling itself is legal in the US, UK, EU, and India. What’s illegal is narrower: autodialed or AI-voice calls without consent, ignored do-not-call requests, and jurisdiction-specific rules with no B2B exemption.
Is it legal to cold call businesses?
Generally yes, especially live calls to a business landline in the US. The exemption narrows once the call goes to a personal cell phone or uses autodialing technology. It narrows further in a stricter country like India or the UK.
What are the FCC rules for cold calling?
The FCC enforces the TCPA. It sets the 8 AM-9 PM calling window and requires prior express written consent for autodialed or AI-voice calls to cell phones. Since a 2024 ruling, it also treats AI-generated voices the same as any other prerecorded voice.
Does GDPR ban cold calling?
No. GDPR permits B2B cold calling under a legitimate interest legal basis. Calling into the UK specifically adds a requirement to scrub against the Corporate Telephone Preference Service, separate from the consumer registry.
What are the TRAI rules for cold calling in India?
Register on India’s DLT platform and place commercial calls from a designated number series. Scrub lists against the DND registry before every campaign, and stay within a 9 AM-9 PM window. Roughly 60-65% of Indian mobile numbers are already DND-registered.
What is the “no cold callers” sign about?
A different context entirely. It refers to physical door-to-door solicitation in the UK, not B2B phone outreach. Some local authorities treat ignoring the sign as an offense under consumer protection law. Even UK trading standards officers debate its legal weight.
Can I get sued for cold calling?
Yes, and it happens regularly. TCPA violations carry statutory damages of $500 to $1,500 per call, and law firms specializing in these claims actively monitor for non-compliant campaigns.
