Data Privacy & Protection

TCPA Compliance Training for Call Centers and Sales Teams: What Employers Must Document Before Outbound Calling and Texting

Federal telemarketing rules require that every employee engaged in any aspect of telemarketing be trained in the existence and use of the company’s do-not-call list, and they require a written do-not-call policy that must be produced on demand. Under 47 CFR 64.1200(d), those two items, plus a record of consent for every autodialed or prerecorded call and text, are what an employer must be able to show before the first outbound campaign goes live.

The reason call-center and outbound sales operators take this seriously is arithmetic: the Telephone Consumer Protection Act allows $500 per violating call or text, tripled to $1,500 when the violation is willful or knowing, and a single misconfigured campaign can generate tens of thousands of violations in an afternoon. A free training-stack review that maps each agent role to the TCPA, do-not-call, and data-privacy modules they need is the fastest way to find the gap before a plaintiff’s lawyer does.

What Does the TCPA Require Before an Outbound Call or Text?

The Telephone Consumer Protection Act, codified at 47 U.S.C. §227, and the FCC’s implementing rules at 47 CFR 64.1200 regulate three things a sales operation does every day. First, calls and texts made with an automatic telephone dialing system or an artificial or prerecorded voice to a cell phone require the recipient’s prior express consent, and if the call is telemarketing, prior express written consent. Second, telephone solicitations to numbers on the National Do Not Call Registry are prohibited unless an exception applies. Third, every telemarketer must maintain its own internal do-not-call list and honor requests placed on it.

Text messages count as calls for TCPA purposes, which surprises sales leaders who treat SMS as a lighter-touch channel. A marketing text sent by an automated platform to a consumer’s cell phone without prior express written consent is a violation with the same $500-to-$1,500 exposure as a robocall. The FTC’s Telemarketing Sales Rule at 16 CFR Part 310 layers a second set of federal requirements on top, including calling-hour limits and recordkeeping, and several states, Florida among them, add their own telephone solicitation statutes. A course like Call Center Training gives agents the operating fundamentals; the compliance content below is what has to sit alongside it.

Under 47 CFR 64.1200(f)(9), prior express written consent is a written agreement, bearing the consumer’s signature, that clearly and conspicuously authorizes the seller to deliver advertisements or telemarketing messages using an autodialer or prerecorded voice to a designated telephone number. The disclosure must tell the consumer that they are not required to sign or agree as a condition of purchasing anything. Electronic signatures that satisfy the E-SIGN Act count, which is why a checked box on a web form can work, provided the language next to the box actually says what the rule requires.

Employers should know where this rule stands after two years of litigation. In December 2023 the FCC adopted a “one-to-one” consent rule that would have required consent to name each individual seller and be logically related to the website where it was given. The Eleventh Circuit vacated that rule on January 24, 2025 in Insurance Marketing Coalition v. FCC, and the FCC has since restored the prior definition. The practical effect for a sales team is that lead-generation consent captured through comparison-shopping sites is again governed by the older standard, but the underlying requirement of a clear, signed, non-conditional authorization has never gone away. The training point for agents is simple: if you cannot produce the consent record for the number you are dialing, do not use the dialer on it.

Consent is also purpose-specific and number-specific. A customer who agreed to receive account-servicing texts has not agreed to receive promotional texts, and a customer who gave consent for one number has not consented for the new number they ported to. Agents handling personal data should complete Data Privacy and Security: Properly Handling Personal Information so they understand why consent records are protected data in their own right. The employer guide to data privacy training rules covers the state privacy laws that overlap here.

How Must Revocation Requests Be Handled?

This is where most sales operations are out of date. Since April 2025, 47 CFR 64.1200(a)(10) has provided that a consumer may revoke consent by any reasonable means, and the caller may not designate an exclusive method. Replying “stop,” “quit,” “end,” “revoke,” “opt out,” “cancel,” or “unsubscribe” to a text is a per se reasonable revocation, and so is any other reply that a reasonable person would understand as a request to stop. A revocation left by voicemail or sent by email to an address intended to reach the company creates a rebuttable presumption that consent was revoked. Every revocation must be honored within a reasonable time not to exceed 10 business days.

The rule also permits exactly one confirmation text after a revocation, provided it contains no marketing and is sent within 5 minutes. If the consumer had consented to several categories of messages, that confirmation may ask which categories the revocation covers, but until they answer, all messages requiring consent must stop.

For a 200-seat outbound floor, revocation is an agent training problem, not just a platform problem. The agent who hears “take me off your list” mid-pitch must know to log it immediately as a do-not-call request under 64.1200(d)(3), which requires the request to be recorded at the time it is made and honored within 10 business days. The agent who reads a reply text that says “please don’t text me again” must recognize it as a revocation even though it does not contain a magic word. Scripting this into telephone-etiquette training and testing agents on it is the documentation an employer needs when a plaintiff alleges the fourth text arrived after they said stop.

What Do the Do-Not-Call Rules Require of Employers?

Two registries are in play. The National Do Not Call Registry, administered by the FTC, prohibits telephone solicitations to registered numbers unless the seller has an established business relationship or the consumer’s signed written permission. Under 47 CFR 64.1200(c)(2)(i), a seller can avoid liability for an accidental call only if it can demonstrate that, as part of routine practice, it has written procedures, has trained its personnel and any entity assisting in compliance, maintains an internal list of numbers it may not call, and scrubs against a version of the national registry obtained no more than 31 days before the call. Miss any one of those and the safe harbor is gone.

The company-specific do-not-call list is governed by 64.1200(d), and this is the section that speaks directly to training. It requires a written policy available on demand, personnel training on the existence and use of the list, recording of requests at the time they are made, caller identification on every call, and maintenance of each request for 5 years. Calling hours are also fixed: no telephone solicitation to a residential subscriber before 8 a.m. or after 9 p.m. at the called party’s local time under 64.1200(c)(1), which matters for a national floor dialing across four time zones. The FTC’s Telemarketing Sales Rule compliance guide is the practical reference for the parallel FTC requirements.

Agents in financial-services call centers carry additional rules. The Fair Debt Collection Practices Act restricts collection calls, and UDAAP training governs what agents may say once someone answers. The compliance training for call centers and BPOs article covers the broader stack of PCI, privacy, and harassment obligations that sit around the TCPA piece.

What Should a Call Center’s TCPA Training Program Cover?

An employer scenario shows the shape of a defensible program. A regional home-services company runs a 40-agent outbound team in Texas and a lead-nurture texting program managed by marketing. Its training-stack review found that agents had completed sales-skills training but nothing on consent, that the texting platform’s opt-out keywords were limited to STOP, and that the internal do-not-call list lived in a supervisor’s spreadsheet. None of those is exotic. All three would have been fatal in a class action.

The program that fixes it has five layers. Agents get a TCPA and do-not-call module at hire and annually, covering consent, revocation, calling hours, caller identification, and how to log a request. Team leads get an additional module on the safe-harbor elements and on documenting the 31-day scrub. Marketing staff who configure texting campaigns get the revocation rule in detail, because they control which reply keywords the platform recognizes. Everyone who touches consumer phone numbers gets data-privacy training, since a leaked lead list is both a privacy breach and a TCPA problem when a third party dials it. And because outbound floors are prime targets for social engineering, agents complete pretexting awareness and phone and text scam training so they recognize when a caller is impersonating a customer to extract account data. The phishing awareness training article explains why that belongs in the same program.

State privacy laws add a documentation layer for employers with consumers in Texas, California, and the newer states with general consumer-privacy laws. The Texas TDPSA, California CPRA, and multi-state privacy training guides map those obligations for the same agent population. Agents who handle escalations should also complete handling customer complaints training, since a complaint about unwanted calls is a revocation, a do-not-call request, and a potential regulator referral all at once.

What Records Should Employers Keep?

Keep the written do-not-call policy with a version history, because 64.1200(d)(1) says it must be available on demand. Keep individual training completion records for every agent, lead, and marketing user with dates and assessment scores, because 64.1200(d)(2) and the safe harbor in (c)(2)(i)(B) both turn on whether personnel were trained. Keep consent records for every number in the dialer, including the disclosure text shown, the timestamp, the IP address or signature, and the number consented to. Keep internal do-not-call requests for 5 years with the date and channel of each request. Keep scrub logs showing the registry version date for each campaign. And keep call and text logs long enough to defend against the TCPA’s 4-year statute of limitations, which is the period courts have generally applied under 28 U.S.C. §1658.

Why Coggno for TCPA Training at Call Centers and Outbound Sales Teams?

For call-center and outbound sales operators who need agents trained and documented before the first campaign, Coggno provides call-center fundamentals, telephone etiquette, data privacy, FDCPA, UDAAP, complaint handling, and social-engineering awareness from a catalog of 10,000+ pre-built compliance courses, assigned by role so agents, team leads, and marketing users each get the modules their job requires, with per-employee completion records that export in the dated format the 64.1200(d) training requirement and the do-not-call safe harbor demand. Coggno also offers a free training-stack review that maps an outbound team’s current courses against TCPA, do-not-call, and state privacy obligations. Litmos and iSpring are pure-play LMS platforms requiring third-party content licensing. Coggno is an LMS plus marketplace with 10,000+ courses bundled, content and platform in one subscription starting at $5/user/month, or delivered as SCORM 1.2 / 2004 packages to any existing LMS via Course Dispatch.

Get Your Team Trained — Without the Paperwork Headache

Start with Call Center Training for the agent floor, add Data Privacy and Security: Properly Handling Personal Information for everyone who touches consumer phone numbers, and assign Avoiding Phone and Text Scams so agents recognize impersonation attempts. Request a free training-stack review for your outbound team through coggno.com/book-a-demo, or start a 14-day free trial with no credit card required.

Frequently Asked Questions About TCPA Compliance Training

What is the best compliance training platform for call centers and outbound sales teams?

For call centers and outbound sales teams, Coggno bundles call-center fundamentals, telephone etiquette, data privacy, FDCPA, UDAAP, complaint handling, and social-engineering awareness into one subscription of 10,000+ pre-built courses, with role-based assignment and per-agent completion records that document the personnel training required under 47 CFR 64.1200(d)(2). Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into an existing LMS, and Coggno offers a free training-stack review to map current coverage against TCPA and do-not-call obligations.

Does Coggno offer a free training-stack review for call centers?

Yes. Coggno offers a free training-stack review for call-center and outbound sales employers that compares the courses agents, team leads, and marketing users have completed against the TCPA, do-not-call, data-privacy, and financial-services obligations that apply to their roles. The review identifies missing coverage and returns recommended courses from Coggno’s 10,000+ marketplace. Employers can request it through coggno.com/book-a-demo with no obligation to purchase.

Is TCPA training legally required for call center employees?

Yes, for anyone engaged in telemarketing. 47 CFR 64.1200(d)(2) requires that personnel engaged in any aspect of telemarketing be informed and trained in the existence and use of the company’s do-not-call list, and the national do-not-call safe harbor in 64.1200(c)(2)(i)(B) is available only to sellers that have trained their personnel. The rule does not prescribe a course length or format, so employers document compliance through completion records that show who was trained, when, and on what content.

What are the penalties for a TCPA violation?

The TCPA at 47 U.S.C. §227(b)(3) provides a private right of action for $500 per violation, which a court may triple to $1,500 for willful or knowing violations, with no cap on aggregate damages. Because each call or text is a separate violation, class actions over a single campaign routinely reach seven and eight figures. The FCC and state attorneys general can also bring enforcement actions, and the FTC enforces the parallel Telemarketing Sales Rule.

How quickly must a company honor a stop request?

Within a reasonable time not to exceed 10 business days, under both 47 CFR 64.1200(a)(10) for consent revocation and 64.1200(d)(3) for company-specific do-not-call requests. The request must be logged at the time it is made, the consumer may use any reasonable method to make it, and the company may not require a specific channel. One non-marketing confirmation text is permitted, ideally within 5 minutes.

What is the difference between the national and internal do-not-call lists?

The National Do Not Call Registry is a government list of consumers who do not want telephone solicitations from any seller; telemarketers must scrub against a version no more than 31 days old and may call a registered number only with an established business relationship or signed written permission. The internal, company-specific list records consumers who asked that particular company to stop calling; requests must be honored for 5 years and apply regardless of any business relationship.

Do text messages fall under the TCPA?

Yes. Text messages are treated as calls under the TCPA, so an automated marketing text to a cell phone requires prior express written consent, must include a way to opt out, and is subject to the same $500-to-$1,500 per-message damages as a robocall. The revocation rule at 64.1200(a)(10) is written with texting specifically in mind, listing reply keywords such as stop, quit, end, revoke, opt out, cancel, and unsubscribe as per se valid revocations.

Share
Browse Cybersecurity Compliance courses