> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lumisreach.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance & Regulations

> Understand calling regulations and stay compliant. TCPA, DNC, and best practices.

Phone calls and texts are regulated. This guide helps you stay compliant.

***

<Warning>
  This is educational information, not legal advice. Consult a lawyer for specific compliance questions.
</Warning>

***

## Key regulations

### TCPA (Telephone Consumer Protection Act)

The main US law governing phone calls and texts:

* **Consent required** for marketing calls/texts
* **Time restrictions** on when you can call
* **Do-not-call compliance** required
* **Penalties** up to \$1,500 per violation

### State laws

Many states have additional requirements:

* **California** - Stricter consent requirements
* **Florida** - Written consent for texts
* **New York** - Enhanced caller ID requirements

Check laws in states where you call.

***

## Consent requirements

### For marketing calls

You need **prior express consent**:

* Customer gave you their number
* They knew you might call
* They agreed to receive calls

### For marketing texts

You need **prior express written consent**:

* Customer explicitly agreed to texts
* Agreement was documented
* They knew what they'd receive

### For informational calls

Lower threshold:

* Appointment reminders (existing relationship)
* Order updates (transactional)
* Service notifications (non-marketing)

Still respect opt-outs and calling hours.

***

## Calling hours

**Federal:** 8 AM - 9 PM (recipient's time zone)

**Best practice:** 9 AM - 8 PM

| Time  | Compliant? | Recommended?  |
| ----- | ---------- | ------------- |
| 7 AM  | No         | No            |
| 9 AM  | Yes        | Yes           |
| 12 PM | Yes        | Maybe (lunch) |
| 6 PM  | Yes        | Yes           |
| 9 PM  | Yes        | Borderline    |
| 10 PM | No         | No            |

LumisReach automatically respects time zones.

***

## Do-not-call (DNC)

### National DNC Registry

Check numbers against the national list:

* **Before calling** - Scrub your list
* **Every 31 days** - Re-scrub regularly
* **Honor requests** - Add to internal DNC immediately

### Internal DNC list

When someone says "don't call me":

* **Remove immediately** - Within 24 hours
* **Across all campaigns** - Not just the current one
* **Keep records** - Document when they opted out

LumisReach manages your DNC list automatically.

***

## Recording disclosure

Most states require one-party consent (you can record if you're on the call). But some require all-party consent:

**All-party consent states:**

* California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Washington

**Best practice:** Always announce recordings.

```
"This call may be recorded for quality and training purposes."
```

Enable automatic disclosure in Settings → Compliance.

***

## Caller ID

Rules for displaying caller ID:

* **Don't spoof** - Must be a number you control
* **Be reachable** - Number must work if called back
* **Be identifiable** - Ideally shows your business name

See [Branded Caller ID](/getting-started/setup/phone-numbers#branded-caller-id).

***

## Text message compliance

Special rules for SMS:

* **Clear identification** - Include business name
* **Opt-out instructions** - "Reply STOP to unsubscribe"
* **Honor STOP immediately** - No more messages
* **Frequency disclosure** - Tell them how often you'll text
* **Data rates disclaimer** - "Msg & data rates may apply"

***

## LumisReach compliance features

Built-in tools to help you stay compliant:

<Checklist>
  * Automatic DNC list management
  * Time zone-aware calling hours
  * Recording disclosure announcements
  * Consent tracking
  * Opt-out handling (STOP for texts)
  * Caller ID verification
  * Campaign logging and records
</Checklist>

***

## Record keeping

Keep records of:

| Record                | Retention |
| --------------------- | --------- |
| Consent documentation | 4+ years  |
| DNC requests          | 5+ years  |
| Call logs             | 2+ years  |
| Opt-out requests      | 5+ years  |

LumisReach stores these automatically.

***

## Best practices

<AccordionGroup>
  <Accordion title="Get clear consent">
    Don't assume consent. Have explicit opt-in for marketing calls/texts.
  </Accordion>

  <Accordion title="Identify yourself">
    Start calls with who you are and why you're calling.
  </Accordion>

  <Accordion title="Make it easy to opt out">
    Don't hide the unsubscribe. Make it simple.
  </Accordion>

  <Accordion title="Respect the relationship">
    Just because you can call doesn't mean you should. Be reasonable.
  </Accordion>

  <Accordion title="Document everything">
    Keep records of consent, opt-outs, and compliance measures.
  </Accordion>
</AccordionGroup>

***

## If you receive a complaint

1. **Take it seriously** - Investigate promptly
2. **Document** - Record the complaint and your response
3. **Remediate** - Fix the issue
4. **Add to DNC** - Immediately stop calling that number
5. **Review processes** - Prevent recurrence

***

## Compliance Center widget

The Outreach page includes a persistent **Compliance Center** button:

* **Amber warning triangle** until the workspace acknowledges TCPA/DNC obligations.
* **Green shield** once acknowledged. Annual re-acknowledgement prompt at 30 days before expiry.

Open it to see, in one place:

* Workspace acknowledgement status (and who acknowledged, when).
* Active disclosures (recording, SMS STOP append, TCPA quiet hours, DNC scrubbing, two-party-consent state list).
* Per-active-campaign checkmarks: terms accepted, recording disclosure attested, calling-window configured, frequency cap set, 30-day attestation rate.
* Consent record counters (voice / SMS / email opt-in, inbound-originated) and recent consent events.
* 30-day disclosure attestation rates for voice + first-touch SMS.
* "Export full audit" — CSV with channel, source, timestamp, sender, use case, disclosure attestation, two-party-state flag.

## Per-channel consent records

When you (the workspace operator) record an opt-in for a contact, LumisReach persists:

| Field                     | Description                                                                 |
| ------------------------- | --------------------------------------------------------------------------- |
| `{channel}OptIn`          | Boolean per channel (voice, SMS, email).                                    |
| `{channel}OptedInAt`      | Timestamp the opt-in was captured.                                          |
| `{channel}ConsentSource`  | Origin of consent (e.g. `csv_upload`, `manual_admin`, `inbound_initiated`). |
| `{channel}ConsentSender`  | The user / system actor that captured the consent.                          |
| `{channel}ConsentUseCase` | Free-form use-case label (e.g. `sales_followup`).                           |
| `firstInbound{Channel}At` | First time the contact initiated inbound on that channel.                   |

When a contact initiates an inbound call or SMS, an **inbound-initiated** opt-in is recorded automatically with `ConsentSource = "inbound_initiated"`.

Capture opt-ins programmatically via the partner API, on contact CSV import, or manually from the contact-detail page.

## Frequency cap

Each outbound campaign has a `dailyCallsPerContact` setting (default `1`). Calls to a contact past the cap are deferred to local midnight of the next day. Admin TCPA bypass does **not** bypass the frequency cap.

## Recording disclosure attestation

Every outbound call records:

* `disclosureAttested` — true when the agent's live greeting contained the recording disclosure phrase.
* `disclosureText` — the disclosure phrase actually attached (first sentence of the greeting).
* `twoPartyStateAtCallTime` — true when the recipient's area code maps to an all-party-consent state.

Powers the Compliance Center "Last 30 days" attestation rate.

***

## Resources

* [FCC TCPA Guide](https://www.fcc.gov/general/telemarketing-and-robocalls)
* [FTC Do Not Call](https://www.donotcall.gov)
* [National DNC Registry](https://www.donotcall.gov/register)
* [Outreach audit reference](/concepts/outreach-audit)

***

<Card title="Compliance Settings" icon="shield-check" href="https://app.lumisreach.com/settings/compliance">
  Configure compliance features
</Card>
