B2B cold calling compliance: TCPA, do-not-call rules and GDPR explained in plain language

A plain-language guide to cold calling compliance for B2B teams: what the TCPA requires for mobile numbers in the US, how do-not-call rules apply, and what GDPR means for prospecting in the EU.

10 min read · Updated September 20, 2026

The short answer

Short answer. Cold calling business contacts is legal in most markets, but the rules depend on whose number you dial and where they are. In the US, the TCPA restricts calls to mobile numbers that use autodialers or prerecorded messages, while manual B2B calls to mobiles are generally permitted. Federal and state do-not-call registries mainly protect consumers, not business lines, though some states cover business mobiles. In the EU and UK, GDPR allows B2B outreach under legitimate interest, paired with opt-out duties and local e-privacy rules. This guide covers the rules, the common mistakes, and the records you should keep. It is general information, not legal advice.

Key takeaways

  • In the US, the TCPA tightly restricts autodialer and prerecorded calls to mobile numbers; manually dialled B2B calls to mobiles are generally allowed.
  • Do-not-call registries are built for consumers, but some states treat business mobile numbers like consumer numbers, so scrubbing against DNC lists is the safe default.
  • Calling hours matter: telemarketing rules in the US generally restrict calls to between 8am and 9pm local time of the person called.
  • In the EU and UK, GDPR legitimate interest can cover B2B prospecting, but you must identify yourself, state your purpose, and honour objections immediately.
  • Whatever the market, keep a suppression list, record opt-outs, and train reps to end a call cleanly the moment someone asks.

The baseline: cold calling businesses is legal, with conditions

B2B cold calling is lawful in the US, Canada, the UK and most of the EU, but every market attaches conditions about who you call, how you dial, when you call and what you say.

The starting point in most jurisdictions is that calling a person in their professional capacity about a relevant business offer is a legitimate activity. The conditions sit around the edges: the type of number you dial, the technology you dial with, the hour you place the call, and how you respond when someone objects.

The mistakes that create real legal exposure are almost always operational rather than exotic: dialling mobiles with automated equipment without consent, ignoring a do-not-call entry, calling at 7am because the rep is in a different time zone, or keeping someone on a list after they asked not to be called.

This guide is general information to help you set up compliant operations. It is not legal advice, and for a specific campaign or market you should confirm the details with counsel.

United States: the TCPA and mobile numbers

The TCPA requires prior express written consent before calling or texting a mobile number using an automatic telephone dialling system or a prerecorded or artificial voice. Manually dialled B2B calls to mobiles are generally permitted.

The Telephone Consumer Protection Act is the law most buyers worry about, because LeadNumbers-style data includes mobile numbers. Its strictest rules attach to the dialling technology, not to the mere fact of calling a mobile. Calls placed with an autodialer, or with a prerecorded or artificial voice, require prior express written consent when the destination is a mobile. A rep selecting a number and dialling it by hand is a different case.

Two practical consequences follow. First, your dialling stack matters as much as your list: if you load mobile numbers into automated dialling equipment, you need consent you will not have for cold outreach, so keep mobiles in manual or click-to-dial workflows. Second, texts count as calls under the TCPA, so automated texting into a cold list carries the same problem.

Statutory damages under the TCPA run from $500 to $1,500 per call or text, and class actions aggregate quickly, which is why the dialling-technology question deserves real attention rather than a shrug.

  • Manual dialling to B2B mobile numbers: generally permitted.
  • Autodialer or prerecorded voice to a mobile: prior express written consent required.
  • Marketing texts to mobiles: treated like calls, same consent standard.
  • Penalty exposure: $500 to $1,500 per violation, per call or text.

Do-not-call rules: federal registry, state lists and B2B nuance

The National Do Not Call Registry protects personal and residential numbers, and most B2B calls to business numbers are exempt from telemarketing sales rules. Some states cover business mobiles anyway, so scrubbing is the safe default.

The FTC's Telemarketing Sales Rule and its National Do Not Call Registry are aimed at calls to consumers. Calls to business lines about business offers are broadly exempt, which is why B2B outbound exists as an industry at all.

The complication is that a mobile number is a personal identifier as well as a business one. A sole trader's mobile can sit on the registry, and several states run their own mini-TCPA statutes with their own registries, consent standards and calling-hour rules that can reach business-to-business calls. Florida, Oklahoma and Washington are frequent examples cited by compliance teams.

The operationally safe posture is simple: scrub your lists against the federal registry and relevant state registries before dialling, honour every opt-out immediately, and keep a dated record of both. Reputable data providers support suppression lists for exactly this reason.

RuleWho it protectsWhat it means for B2B callers
National Do Not Call RegistryConsumers and personal numbersScrub lists; sole traders' mobiles may be registered
FTC Telemarketing Sales RuleConsumersMost B2B calls exempt, but disclosure duties apply to covered calls
State mini-TCPAsVaries, sometimes including business mobilesCheck the states you dial into; some need consent or registration
Calling-hour limitsPeople being calledGenerally 8am to 9pm in the recipient's local time zone

EU and UK: GDPR and e-privacy rules for B2B prospecting

GDPR permits B2B outreach under legitimate interest when the contact is relevant to the recipient's professional role, provided you identify yourself, explain why you are contacting them, and honour objections at once.

GDPR does not ban cold outreach to businesses. It requires a lawful basis, and for carefully targeted B2B prospecting that basis is usually legitimate interest: contacting a person about something their job makes relevant, in a way they would reasonably expect, with an easy way to object.

Legitimate interest is a standard you document, not a magic word. The working test is three questions: is the outreach genuinely relevant to the recipient's role, is the intrusion minimal, and would the person be surprised to hear from you. Write the answers down; that record is what makes the basis defensible.

Alongside GDPR sit national e-privacy rules that govern calls and emails specifically, and they differ by country. The UK allows corporate subscriber marketing under PECR with an opt-out duty. Germany is stricter and generally expects prior consent for cold calls even between businesses. Before dialling a new EU market, check that country's e-privacy implementation rather than assuming one rule covers the bloc.

Wherever you operate, the universal duties are: say who you are and why you are calling at the start of the call, stop the moment someone objects, record the objection, and never contact that person again.

  • Lawful basis: document a legitimate interest assessment for your target segments.
  • Transparency: name your company and the reason for the call immediately.
  • Objection: honour it at once, suppress the record, and never resupply it.
  • Country rules: e-privacy implementations differ; Germany is notably stricter on cold calls.

The operating habits that keep a calling team compliant

Compliance failures in outbound teams are almost never deliberate. They come from missing process: a rep who was never told the rules, a list that was never scrubbed, an opt-out that lived in a notebook instead of a suppression system.

The fix is a short list of habits that run on their own rather than depending on memory.

  • Scrub every list against federal and state do-not-call registries before it is dialled, and on a schedule thereafter.
  • Keep mobiles out of automated dialling and texting workflows unless you hold documented consent.
  • Schedule calls in the recipient's local time zone, inside legal calling hours.
  • Give reps a one-sentence identification script and a hard rule that any request to stop ends the call politely and permanently.
  • Centralise opt-outs in one suppression list that every tool and every future list respects.
  • Keep dated records of scrubs, consents and objections, because in a dispute the record is the defence.

How LeadNumbers supports compliant outreach

LeadNumbers supplies business contact data for legitimate business-to-business outreach, screened before delivery, with records intended for contacting people in their professional capacity about relevant offers.

Opt-out requests are honoured across the whole platform within one business day, and suppressed contacts are never resupplied to any account. You can also upload your own suppression list so numbers you must not call are excluded from every future delivery automatically.

You remain the caller, so calling rules, registration duties and consent requirements in your market are yours to follow. The sections above are the framework most teams work from, and your counsel should confirm the specifics for the markets you dial.

Frequently asked questions

Is it legal to cold call mobile numbers for B2B sales in the US?

Generally yes when the call is manually dialled by a person. The TCPA's strict consent requirement applies to calls made with autodialers or prerecorded voice, and to marketing texts. Keep mobiles in manual or click-to-dial workflows and scrub against do-not-call registries.

Does the Do Not Call Registry apply to business numbers?

The federal registry protects personal and residential numbers, and most B2B calls to business lines are exempt from the telemarketing sales rules. Some state laws cover business mobiles, and sole traders' numbers may be registered, so scrubbing is the safe default.

What hours can you legally cold call?

US telemarketing rules generally restrict calls to between 8am and 9pm in the local time of the person being called. Some states narrow that window further. Always schedule in the recipient's time zone.

Is cold calling legal under GDPR?

GDPR can permit B2B outreach under legitimate interest when the contact is relevant to the recipient's professional role, you identify yourself and your purpose, and you honour objections immediately. National e-privacy rules sit alongside GDPR and differ by country, with Germany notably stricter on cold calls.

What happens if someone asks not to be called?

End the call politely, record the objection, add the person to a suppression list, and never contact them again. With LeadNumbers, opt-outs are suppressed platform-wide within one business day and never resupplied.

See the data before you decide

Five sample leads in your ideal customer profile, with mobile or direct dial and verified work email. No card required.

Keep reading