Before You Cold Call: TCPA, ABA, 31 Day DNC for U.S. Law Firms

Law firms can cold call prospective clients in the United States, but three rules govern every dial: the TCPA controls consent and technology, the FTC’s Telemarketing Sales Rule governs Do-Not-Call compliance, and ABA Model Rule 7.3 restricts live solicitation. Before a firm dials a single number, it needs confirmed consent for any autodialed or prerecorded call, a scrubbed list checked against the federal registry and state rules, and a vendor oversight process with documented evidence. Platforms like RevRing build compliance infrastructure around exactly these requirements.
TL;DR:
- Law firms must obtain specific, verified written consent for autodialed or prerecorded calls to wireless numbers, with clear disclosure language and documentation of revocations.
- All calling lists must be scrubbed against the federal DNC registry within 31 days before outreach, and firms need an internal suppression list for opted-out consumers.
- State-specific rules, such as Pennsylvania’s treatment of SMS as live solicitation, require tailored compliance measures for texting and local calling hours.
- Using AI-generated voices or predictive dialers triggers the same TCPA consent requirements as traditional prerecorded messages, demanding strict consent management.
- Firms should implement thorough recordkeeping of consent, call logs, and revocation requests for at least 24 months to defend against regulatory or bar complaints.
Table of Contents
- TCPA and FCC rules for autodialed calls, AI voices, and consent
- Telemarketing Sales Rule and Do-Not-Call requirements for firms
- ABA Rule 7.3, Formal Opinion 501, and state-by-state variation
- An operational checklist for cold-calling compliance
- How predictive dialers, AI voices, and texting change the analysis
- Penalties, enforcement triggers, and safe-harbor practices
- Launching or auditing a compliant cold-calling program
- Where compliance programs actually fail
- How RevRing supports a compliant calling program
- Sources
- FAQ
TCPA and FCC rules for autodialed calls, AI voices, and consent
The Telephone Consumer Protection Act is the federal statute that controls most cold-calling risk for law firms. It restricts calls made with an automatic telephone dialing system, commonly called an autodialer, and calls that use a prerecorded or artificial voice, under certain conditions. The FCC’s implementing regulations, codified at 47 CFR § 64.1200, spell out which calls need consent and what type.
Prior express written consent is required before a firm or its vendor places an autodialed or prerecorded call to a wireless number, and the same standard applies to prerecorded or artificial voice calls to residential lines. A signed intake form, a website opt-in with clear disclosure language, or a documented verbal agreement captured on a recorded line can each serve as evidence, but the consent has to name the specific caller and the specific purpose of the call.
Recent FCC rulemaking changed how firms must handle the back end of consent. The agency’s 2024 Report and Order clarified that consumers can revoke consent through any reasonable method, whether that is a text reply, a verbal request during a call, or an email to the firm’s listed contact. Callers must honor that revocation within a reasonable time, and the same order tightened the one-to-one consent standard to close the loophole where a single consent checkbox on a lead-generation site covered dozens of unrelated buyers.
For a law firm running outreach through a lead vendor or aggregator, this is where exposure hides. A lead purchased from a marketplace often carries a consent record that only proves an unrelated data broker collected it, not that it covers your firm’s specific outbound campaign.
Records worth keeping for every contact number:
- The consent capture date, method, and exact disclosure language shown to the consumer
- The call logs showing dialer mode, timestamp, and outcome for every attempt
- Any revocation request received, the channel it arrived on, and the timestamp the number was suppressed
- The vendor or source attribution for purchased or aggregated leads
One-to-one consent now closes a major loophole: the FCC’s 2024 order requires that consent obtained through comparison-shopping or lead-generation websites be tied to a single identified seller, not shared across a marketplace of buyers. Firms buying leads from aggregators should confirm the consent language names the firm directly.
Telemarketing Sales Rule and Do-Not-Call requirements for firms
The FTC’s Telemarketing Sales Rule governs commercial calls that solicit a purchase, which covers most law firm cold-calling campaigns aimed at individual consumers. Full guidance sits in the FTC’s compliance resource on the TSR, which lays out seller and telemarketer responsibilities and the required Do-Not-Call procedures.
The National Do-Not-Call Registry is the operational backbone of TSR compliance. Firms calling consumers must subscribe to the registry for every area code they intend to dial, according to the FTC’s business guidance on the DNC rules. That guidance also sets the scrub cadence: call lists must be checked against the registry within 31 days of use, and firms need to maintain their own entity-specific suppression list for consumers who ask not to be called again, regardless of registry status.
Business-to-business calls carry a general exemption from the DNC provisions, which matters for firms marketing to corporate clients rather than individuals. But the exemption is narrower than it looks. It does not cover retail sales of nondurable office or cleaning supplies, and it does not shield calls that solicit an individual employee rather than the business itself. A firm pitching general counsel services to a company’s leadership is on firmer ground than one dialing individual staff members at that same company.
Key operational steps for TSR compliance:
- Subscribe to the registry and obtain a Subscription Account Number for every area code called
- Run list scrubs within the 31-day window before each calling campaign
- Maintain a firm-specific do-not-call list independent of the federal registry
- Document the safe-harbor procedures used to catch and correct inadvertent violations
None of this satisfies a state bar. TSR compliance addresses FTC exposure, not the separate ethical layer that governs how lawyers solicit clients, and firms that treat the two as interchangeable tend to discover the gap during a bar complaint rather than an FTC inquiry.
ABA Rule 7.3, Formal Opinion 501, and state-by-state variation
Model Rule 7.3 is the ethical backbone for lawyer solicitation, and it prohibits live person-to-person contact, in person, by phone, or through real-time electronic exchange, when a significant motive is the lawyer’s pecuniary gain. Three exceptions carve out room for legitimate outreach:
- Contact with another lawyer is permitted without the same restriction.
- Contact with a person who has a family, close personal, or prior professional relationship with the lawyer is allowed.
- Contact with a person who routinely uses the type of legal services offered, for business purposes, generally falls outside the prohibition.
Outside those three lanes, live cold calling a stranger to pitch legal services runs directly into the rule.
The ABA’s Formal Opinion 501 closed a gap firms had been exploiting: hiring a third-party marketing vendor to make the calls a lawyer could not make directly. The opinion states plainly that lawyers remain responsible for live solicitation conducted on their behalf, whether by an employee, a marketing company, or a lead-generation partner. A vendor’s call script, its training, and its actual call behavior all become the firm’s ethical exposure the moment that vendor is working the firm’s leads.
State variation adds another layer firms cannot skip. Pennsylvania’s version of RPC 7.3 treats text messages as a form of live, person-to-person solicitation, a stricter reading than many other states apply to the same channel, and recent Pennsylvania rule changes specifically prohibit text solicitation of prospective clients. A firm running a multistate campaign that treats SMS as a safe, non-live channel everywhere is building on a false assumption in at least one jurisdiction.
Firms operating across state lines should request an advisory opinion from the relevant state bar before launching any calling or texting campaign that touches a gray area, rather than assuming a national script clears every jurisdiction’s ethics rules at once.
An operational checklist for cold-calling compliance
A defensible program needs controls at three levels: consent, calling behavior, and recordkeeping. None of the three substitutes for the others.
Consent capture and classification. Every number in a calling list should carry a classification tag: wireless or landline, consented or unconsented, and the specific consent method on file. Numbers without written consent should be excluded from any autodialed or prerecorded campaign entirely rather than flagged for manual review later.
DNC scrub cadence. Lists need a fresh scrub against the national registry within the 31-day window before use, plus a check against the firm’s own suppression list, which should update in real time as opt-out requests come in.

Calling-hours enforcement. The federal baseline restricts calls to between 8 a.m. and 9 p.m. in the recipient’s time zone, and some states apply narrower windows. A dialer configured only for the office’s local time zone will violate this rule the moment a call crosses into a different one.
Vendor controls. Contracts with any outreach vendor should include compliance warranties, audit rights, and lead-source traceability back to the original consent record. Training records and call monitoring should be reviewable on demand, and the contract should specify penalties, including termination, for documented noncompliance.
Scripting and agent conduct. Scripts should avoid guarantees of outcome, pressure tactics, or misleading statements about the firm’s experience, consistent with the advertising limits in RPC 7.1 alongside the solicitation limits in RPC 7.3. Agents need training on what they cannot say as much as what they can.
Recordkeeping. Consent records, call logs, and revocation evidence should be retained for at least 24 months, longer if state rules or litigation holds require it. The goal is to produce a complete evidence trail on short notice if a bar complaint or TCPA claim arrives.
- Classify every number by consent status and type before it enters a call list
- Scrub against the federal registry within 31 days and maintain a live internal suppression list
- Enforce calling hours by the recipient’s time zone, not the caller’s
- Require vendor contracts to include audit rights and compliance warranties
- Retain consent, call, and revocation records for at least 24 months
Pro Tip: Build your suppression list update into the same workflow that logs opt-out requests, so a revoked number is blocked from every future campaign the same day it comes in.
How predictive dialers, AI voices, and texting change the analysis
Technology choice determines which consent standard applies, which makes the dialer configuration a compliance decision as much as an operational one. A predictive dialer or any system that can autonomously dial numbers from a stored list qualifies as an autodialer under the FCC’s reading of the TCPA, triggering the written-consent requirement for wireless numbers the moment it is used.
AI-generated voices raise the same flag. The FCC has confirmed that TCPA obligations apply to calls using AI technology that generates a humanlike voice, treating them the same as traditional prerecorded messages for consent purposes. A firm testing an AI voice assistant for outreach needs the same prior express written consent it would need for a recorded human voice.
Engineering controls reduce exposure at the technology layer:
- Consent flags attached to each contact record that block autodialed or AI-voice calls absent written consent on file
- Automated opt-out enforcement that suppresses a number across every channel the moment a revocation arrives
- Human hand-off design that routes uncertain or high-risk contacts to a live agent for manual dialing instead of the autodialer
- Number-type segmentation that separates wireless and landline records into different calling rules automatically
Texting deserves its own risk category. Some states, Pennsylvania among them, treat SMS outreach as live solicitation subject to the same restrictions as a phone call, while other states allow more latitude. Firms should manage SMS as a high-risk channel with jurisdiction-specific rules rather than a single national policy, and RevRing’s guidance on consent capture outlines how to build that segmentation into an outreach workflow.
Penalties, enforcement triggers, and safe-harbor practices
TCPA violations carry statutory damages per call, which means a single unconsented autodialed campaign can generate liability that scales with call volume rather than with any actual harm proven. The FTC pursues separate enforcement under the TSR, with civil penalties tied to violations of the Do-Not-Call and disclosure requirements described in its TSR guidance.
Firms should watch for the enforcement triggers regulators and bar counsel see most often: unauthorized autodialed calls to wireless numbers without written consent, failure to honor a revocation within a reasonable window, calls to numbers on the national or firm suppression list, and consumer or bar complaints alleging pressure tactics in live solicitation.
Safe-harbor practices matter because both the FCC and FTC frameworks reward documented process over perfect execution. A firm that can show written procedures, agent training records, current SAN and DNC scrub documentation, and prompt revocation handling has a materially stronger defense than one relying on informal practice.
Launching or auditing a compliant cold-calling program
Standing up a compliant program, or auditing an existing one, follows a sequence rather than a checklist run in parallel.
- Run a prelaunch legal and ethics review. Confirm which states the campaign will touch, pull the relevant RPCs, and get counsel sign-off on scripts, consent language, and vendor contracts before any number is dialed.
- Prepare the data. Classify every contact by number type, scrub the list against the national registry within the 31-day window, and flag consent status on each record so the dialer configuration matches what evidence actually supports.
- Confirm vendor readiness. Review vendor contracts for compliance warranties and audit rights, verify agent training records, and run a limited test batch to check script adherence and call outcomes before scaling volume.
- Launch with operational guardrails in place. Enforce calling-hour restrictions by recipient time zone, route opt-out requests to immediate suppression across every channel, and log every call and consent event for retention.
- Audit on a recurring schedule. Sample call recordings against scripts, confirm suppression lists are current, and re-verify vendor compliance documentation rather than treating the initial review as permanent.
A limited test batch before full launch catches script and consent gaps while the exposure is still small, and RevRing’s speed-to-lead benchmarks offer a useful reference point for setting response-time and QA metrics during that test phase.
Where compliance programs actually fail
The most common mistake I see is the assumption that outsourcing calling to a vendor also outsources the liability. It does not. Formal Opinion 501 exists precisely because firms tried that move, and bar counsel treats a vendor’s bad script as the firm’s bad script.
A close second is overreliance on vendor representations about consent, especially with leads pulled from aggregated marketplaces where a checkbox on someone else’s website is treated as blanket permission. That consent rarely names your firm specifically, and the one-to-one consent standard now makes that gap explicit rather than a gray area.
My default recommendation is conservative settings over clever workarounds: no autodialer or AI voice to a wireless number without documented written consent, calling windows narrower than the federal baseline where any doubt exists about a recipient’s time zone, and vendor contracts with real audit teeth. Firms that build around RevRing’s compliance workflows tend to bake these defaults in at setup rather than retrofitting them after a complaint.
— Marc
How RevRing supports a compliant calling program
Every control this article describes, consent flagging, DNC integration, calling-hour enforcement, vendor audit trails, maps directly to features RevRing builds into its calling infrastructure. Consent status attaches to each contact record, DNC scrubs run against your suppression lists automatically, and call recordings and logs stay available for the recordkeeping window your compliance policy requires.

RevRing’s plans start at $39.99 per month per seat on the Starter tier, with Scale and Pro tiers adding AI call scoring and expanded dialer modes as your outreach volume grows. The how it works page walks through dialer modes, CRM connectivity, and the compliance workflows built into each one. If your firm is standing up a new outreach program or auditing an existing one, a pilot on RevRing’s infrastructure gives your compliance team a documented, auditable system from the first call rather than a patchwork built after the fact.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- FCC Report and Order and Further Notice on TCPA and robocalls
- Complying with the Telemarketing Sales Rule — FTC
- ABA issues guidance on ‘live person’ lawyer solicitation — American Bar Association
- Telemarketing
- 47 CFR § 64.1200 — Restrictions on Telemarketing and Telephone Solicitation
FAQ
What is the 80/20 rule in cold calling?
This rule in cold calling generally refers to the idea that a large share of results comes from a small share of effort, such as most conversions coming from a minority of calls or callers. It is a sales heuristic rather than a legal or ethical standard, and it has no defined figure in TCPA, TSR, or ABA guidance.
What are the legal rules for cold calling?
The core legal rules come from the TCPA and its FCC implementing regulations at 47 CFR § 64.1200, which govern autodialed and prerecorded calls, plus the FTC’s Telemarketing Sales Rule, which governs Do-Not-Call compliance. For law firms specifically, ABA Model Rule 7.3 adds an ethical layer restricting live solicitation on top of these federal rules.
What is the 80/20 rule for lawyers?
There is no recognized ethics rule by that term for lawyers under the ABA Model Rules or state bar guidance covered in this article. If a specific state bar or practice-management source uses that term, it refers to a business heuristic rather than a solicitation or advertising rule.
Is there a law against cold calling?
Cold calling itself is not illegal, but federal law heavily regulates how it can be done. The TCPA requires prior express written consent for autodialed or prerecorded calls to wireless numbers, and the FTC’s Do-Not-Call rules require sellers to scrub against the national registry, so noncompliant cold calling carries real statutory exposure even though the practice is not banned outright.
Can lawyers cold call prospective clients directly?
Live, person-to-person cold calling to solicit a stranger for pecuniary gain is generally prohibited under ABA Model Rule 7.3, with narrow exceptions for other lawyers, close personal or family relationships, and routine business users of legal services. Firms considering any outreach outside those exceptions should check their state’s specific rule and request an advisory opinion when the case is unclear.