31 Day Scrub Rule: U.S. Court Ready Evidence for TCPA Safe Harbor

The TCPA DNC safe harbor can shield your business, but only if you can prove it before litigation starts. It’s a narrow affirmative defense for do-not-call registry errors, and it works when you can show both an error occurred and that your company had established and implemented reasonable procedures to avoid it. The single highest-priority action: build documented, demonstrable implementation, meaning a written policy backed by automated logs, not just a policy sitting in a drawer.
TL;DR:
- To qualify for the safe harbor, companies must demonstrate that an error occurred despite having established and documented reasonable procedures that can be verified with system logs and records.
- Proper evidence collection involves maintaining detailed scrub reports, consent timestamps, call records, and monitoring vendor compliance, all with immutable and time-stamped logs.
- Safe harbor protections are limited to accidental DNC registry errors and do not apply to autodialer violations or cases of willful misconduct, which require stronger evidence of proper controls.
- Companies should focus on timely scrub cycles within 31 days, real-time opt-out processing, and long-term retention of compliance records to strengthen their safe harbor defense.
- Recent case law emphasizes the importance of operational proof and detailed logs over mere policy statements, making automation and organized evidence critical in defending TCPA claims.
Table of Contents
- What Is the TCPA DNC Safe Harbor, and What Does It Actually Cover?
- The Core Test Courts Apply: Error Plus Established Procedures
- Building the Evidence: Systems, Logs, and Vendor Controls That Hold Up in Court
- The Timelines That Actually Determine Compliance
- What the Safe Harbor Doesn’t Fix
- What Recent Case Law Tells Compliance Teams
- How to Actually Invoke Safe Harbor Once Litigation Starts
- A Working Checklist You Can Adopt This Week
- Why the Paper Trail Matters More Than the Policy
- Turning This Checklist Into a Working System With Revring
- Sources
What Is the TCPA DNC Safe Harbor, and What Does It Actually Cover?
The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, and its implementing regulation at 47 C.F.R. § 64.1200©(2)(i), create a defense for companies that call a number on the National Do-Not-Call Registry by accident. In plain terms: if you make a call you shouldn’t have, but you can prove the error happened despite reasonable safeguards, you may avoid liability. This is not blanket immunity. It’s a targeted defense that applies to a specific category of mistake.
There are three safe harbors worth knowing, and they don’t overlap the way many compliance teams assume.
National DNC safe harbor. Covers calls to numbers on the national registry, provided you scrubbed against a current list and the number still slipped through.
Ported-number safe harbor. A limited window that protects calls to numbers recently moved from a landline to a wireless carrier, before that number’s new status catches up in your data.
Reassigned-number protections. Related but distinct, this addresses numbers recycled to a new subscriber who never consented to your calls.
Here’s the part that trips up even experienced counsel: safe harbor is an affirmative defense. That means the burden sits with you, the caller, not the plaintiff. You have to raise it, plead it, and prove it with evidence. Practitioner guidance from Eversheds Sutherland consistently stresses that meticulous recordkeeping is what separates a successful defense from a costly settlement. If you wait until a complaint lands to start assembling records, you’ve already lost ground.
The Core Test Courts Apply: Error Plus Established Procedures
Judges evaluating a TCPA safe harbor claim run a two-prong analysis. First, did an actual error occur, a call placed to a number that should have been suppressed? Second, and this is where most cases turn, did the caller have established and implemented reasonable procedures to prevent exactly that error? Both prongs need proof. Neither survives on assertion alone.
Courts break that second prong into concrete, checkable elements. Compliance teams that pass this test typically have:
- A written do-not-call policy that names specific responsible roles, not vague departmental references
- A documented scrub cadence against the national registry, run frequently enough to catch new additions
- An internally maintained company-specific DNC list that updates in real time as consumers opt out
- A process for honoring revocation requests across every channel a customer might use to make one
- Calling-hour restrictions built into dialer configuration, not just written into a manual
- Active vendor oversight, meaning contracts and audits, not a one-time onboarding checklist
Where courts differ is in how strictly they apply this standard. Some judges look for “substantial compliance,” meaning a program that’s fundamentally sound even with small gaps. Others hold a stricter line and expect near-perfect execution. What tips the scale is nearly always evidence quality. A Fox Rothschild analysis of a recent summary judgment win noted that judges are often skeptical of safe-harbor claims at the outset, but structured, time-stamped logs tied to written policy and training records can move a case out of jury territory entirely.
That’s the practical lesson: the legal standard rewards paper trails, not intentions. A policy that looks good on letterhead means nothing if you can’t produce the system logs proving someone followed it on the day the disputed call happened.
Building the Evidence: Systems, Logs, and Vendor Controls That Hold Up in Court
Passing the legal test requires specific artifacts, not general assurances. When a plaintiff’s attorney requests production, “we have a policy” is not an answer. Courts want to see the operational trail behind that policy.
The core evidence set typically includes:
- Scrub reports that name the vendor, the dataset vintage, and the exact date the list was pulled
- Consent screenshots with E-SIGN Act metadata showing timestamp, IP address, and the specific disclosure language shown to the consumer
- Call detail records (CDRs) with full dispositions, not just call duration
- Opt-out propagation logs showing how fast a revocation moved from one system to every connected system
- Vendor contracts with audit rights, reassigned-number-database checks, and indemnification language
Vendor contracts deserve particular attention because third-party failures are a common blind spot. If your list broker or lead vendor mishandles a scrub, you’re still on the hook unless your contract gives you audit rights and requires them to run their own reassigned-number checks. Indemnity clauses matter too, but they only help after the fact. Audit rights help you catch problems before a lawsuit does. A LeadCompliant analysis of safe harbor defenses flags this repeatedly: buyers who assume a purchased lead’s consent is valid without independent verification are gambling with someone else’s paperwork.
Training records round out the evidence file. You need attendance logs tied to specific curricula, QA scoring that shows agents were evaluated against DNC rules in real calls, and archived, timestamped records of when each training event happened. A training program that isn’t documented might as well not exist in a courtroom.
Pro Tip: Automate opt-out propagation across every connected system, your dialer, CRM, and any lead intake workflow, and keep the resulting logs immutable. Manual opt-out handling is where most safe-harbor claims quietly fall apart, because a revocation that takes three days to reach your dialer is a revocation your system effectively ignored.
The Timelines That Actually Determine Compliance
Precision on timing separates a defensible program from a vulnerable one. Three windows matter most.
- The 31-day scrub cadence. Your National DNC Registry scrub can be no older than 31 days to qualify for safe harbor. “Vintage” refers to the date the registry snapshot was pulled, and your scrub report needs to state that date explicitly. A scrub run on day 32 doesn’t count, even if you scheduled it for day 30 and a vendor delay pushed it back.
- The 15-day ported-number window. Numbers recently moved from wireline to wireless get a narrow 15-day safe harbor, detectable through ported-number feeds like Neustar’s reassigned-number database. This protects you only if the number isn’t already on the national registry or your internal DNC list.
- Opt-out processing speed. The regulatory floor allows up to 10 business days to honor a request, but that floor is not a target. Real-time or same-business-day processing is the practical standard courts and regulators increasingly expect.
Retention matters just as much as speed. Internal DNC lists need a long-term retention period. Consent records and scrub reports should be kept at least as long, since litigation can surface years after a call was placed. Purge cycles that run faster than that leave you unable to prove compliance when it counts most.
What the Safe Harbor Doesn’t Fix
Safe harbor is not a universal shield, and treating it like one is a mistake that costs companies real money. It’s built specifically for DNC registry errors. It typically does not extend to autodialer violations, prerecorded voice message (PRV) issues, or text message consent failures. If your problem is that you lacked prior express written consent (PEWC) for an autodialed call, the DNC safe harbor doesn’t apply. That’s a different legal question entirely, governed by different consent standards.
Willful or knowing violations sit outside safe harbor protection entirely. If a company knew its list was stale and kept dialing anyway, no amount of paperwork rescues that conduct. Courts read willfulness broadly, and evidence of internal warnings ignored, or complaints repeatedly dismissed, tends to surface during discovery.
The biggest misconception, though, is procedural: companies assume a written policy is the finish line. It’s the starting point. A policy document with no logs behind it proves nothing in court. Judges want record-level proof that the policy was followed on the specific date a specific call was placed. Deep-knowledge analysis of successful defenses consistently shows that companies who preserved system-level scrub logs, archived consent screenshots, and vendor invoices as immutable evidence were the ones who mapped each disputed call against an actual operational control, which is what won them summary judgment.
What Recent Case Law Tells Compliance Teams
Two decisions illustrate how courts are actually applying this defense right now, and both carry lessons that go beyond their specific facts.
In Johansen v. eFinancial, the court credited the defendant’s substantial compliance program and its online consent capture process. The takeaway isn’t that online consent automatically wins. It’s that the defendant could produce a coherent trail connecting its consent capture mechanism to the specific call at issue. That connective evidence, not the consent mechanism alone, is what carried weight.
Van Elzen v. American Home Shield pushed the point further. The court granted summary judgment based heavily on program design and system logs, even where consent was disputed by the plaintiff. According to Fox Rothschild’s analysis of the ruling, the defendant’s documented operational controls were strong enough that the unresolved consent question didn’t defeat the safe-harbor defense at summary judgment. That’s a meaningful signal: you don’t always need to win the consent argument outright if your compliance program’s documentary record is airtight.
The pattern across 2024 through 2026 rulings is consistent. Courts increasingly demand documentary proof over policy assertions. Consent disputes often survive early motions because they’re genuinely fact intensive, but a well-built compliance program with real logs can still win on safe-harbor grounds even when consent itself remains contested. That’s the practical opening most defense counsel should be building toward from day one, not scrambling to construct after a complaint arrives.

How to Actually Invoke Safe Harbor Once Litigation Starts
Raising the defense in an answer is easy. Proving it is where cases are won or lost, and preparation before a complaint ever lands makes the difference.
Your evidence production should include:
- Written policy documents, dated and version-controlled
- Scrub reports showing vendor name, dataset vintage, and pull date
- Consent screenshots with full E-SIGN metadata
- Call detail records matched to the specific disputed calls
- Training logs with attendance, curriculum, and QA scoring
- Vendor contracts showing audit rights and compliance obligations
- Change-control records documenting when policies or systems were updated
- System configuration exports showing calling-hour restrictions and suppression rules were actually active
Organization matters as much as content. Build an index that maps each artifact to the specific policy element it proves, scrub report to registry-check obligation, training log to agent-education requirement, so opposing counsel and the judge can follow the logic without your team narrating it live. Redact personal data carefully but preserve metadata fields like timestamps and IP addresses, since stripping those often destroys the evidentiary value plaintiffs’ counsel will challenge first.
Coordinate with litigation counsel early, ideally before any dispute, so your compliance team understands what “produce it under pressure” actually requires. The strongest defense narrative connects three layers cleanly: policy, the system controls that enforce it, and the discrete artifacts proving those controls were live on the date in question. That chain, policy to system to artifact, is what “implemented with due care” looks like to a judge.
A Working Checklist You Can Adopt This Week
Turning legal theory into daily practice means assigning ownership, not just writing rules.
Operational actions:
- Daily: verify opt-out requests processed and propagated across all connected systems
- Weekly: spot-check CDRs against calling-hour restrictions and suppression list activity
- Monthly: run and archive the national DNC scrub, confirming vintage stays under 31 days
- Quarterly: audit vendor contracts and confirm reassigned-number-database checks are current
Litigation evidence checklist:
- Scrub reports filed with vendor name, pull date, and file hash
- Consent screenshots archived with timestamp and IP metadata
- Training attendance logs tied to specific curriculum versions
Assign a named owner to each task, not a department. Escalation should follow a clear matrix: frontline compliance staff catch daily issues, a compliance manager reviews weekly and monthly checks, and legal counsel gets looped in the moment a discrepancy touches consent or scrub timing.
Why the Paper Trail Matters More Than the Policy
Most compliance teams treat the written DNC policy as the finished product. It’s closer to a table of contents. The actual defense lives in the boring, unglamorous layer underneath it: log files, timestamps, and vendor invoices that most companies delete the moment they’re no longer “needed” for daily operations.
What’s underappreciated here is how much this shifts the incentive structure. A company with a mediocre policy but excellent logging infrastructure will often out-defend a company with a beautifully written policy and no system-level proof behind it. Judges, as the recent case law shows, are pattern-matching for operational discipline, not polished prose. That means the real return on compliance investment isn’t in legal drafting. It’s in the unglamorous work of automated scrub scheduling, immutable audit trails, and opt-out propagation that doesn’t depend on someone remembering to update a spreadsheet.
The other overlooked point: safe harbor readiness and consent-defense readiness are not the same project, even though companies often bundle them. Treating them as one compliance initiative is how gaps form, because the evidence each defense needs is structurally different. Build them as related but distinct workstreams, and your legal exposure narrows on both fronts simultaneously.
— Marc
Turning This Checklist Into a Working System With Revring
Every control this article describes, scrub automation, consent capture, opt-out propagation, and audit trails, is exactly what falls apart when it’s spread across five disconnected tools instead of one system of record. Revring centralizes those controls in a single platform, so the logs your legal team needs during litigation already exist, timestamped and organized, instead of scattered across a dialer, a CRM, and a spreadsheet nobody’s updated since March.

The platform’s predictive dialer enforces calling-hour restrictions and suppression lists at the system level, not just on paper. Automated scrub scheduling keeps your DNC registry checks inside the 31-day window without a manual reminder. Consent records capture the metadata courts actually ask for, and audit logs stay immutable by design. If you’re rebuilding your compliance stack around evidence you can actually produce under pressure, start with a demo of the RevRing platform or review current pricing and plans to see what fits your call volume.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.