Compliance for Non-Lawyers
Plain-English overview of the rules that apply.
This page is a plain-English overview of the rules that apply when you make automated phone calls. It's not legal advice — for that, talk to a lawyer who specializes in telecom or marketing. But this should give you enough to know what to ask about and what the platform handles for you.
The short version. Most of what you need to do is built into the platform. Three things you must do yourself: (1) get consent before calling people who didn't ask to be called, (2) honor opt-outs, (3) don't pretend the AI is human if asked directly.
The big rules, by region
United States — TCPA
The Telephone Consumer Protection Act regulates automated calls and texts.
Rules of thumb:
- Informational calls (appointment reminders, delivery confirmations, account alerts) — generally allowed without written consent if you have an existing business relationship.
- Marketing calls (promotions, cold sales) — require prior express written consent to call a mobile number with an automated system. "Written" includes typed-in form submissions where the form explicitly says they consent to automated calls.
- Calling time restrictions — no calls before 8 AM or after 9 PM in the caller's local time.
- National Do Not Call Registry — for marketing only. Scrub your list against the registry before each campaign.
- Opt-out honor — anyone who says "stop calling me" must be added to your suppression list within 30 days. The platform's auto-opt-out task handles this if you enable it.
What the platform handles: STIR/SHAKEN attestation, time-of-day enforcement (if you set calling hours), suppression-list scrubbing.
What you handle: Getting consent before adding people to outbound campaigns, honoring opt-outs (use the opt_out post-call field), scrubbing against DNC registry.
United States — state two-party consent
In California, Florida, Illinois, Massachusetts, Maryland, Montana, New Hampshire, Pennsylvania, Washington, and a few others, all parties on a call must consent to being recorded.
What you must do: Add a recording disclosure to the start of every Finn that operates in or calls into these states.
Easy disclosure:
"This call may be recorded for quality purposes."
Add it to the welcome message OR enable the platform's built-in disclosure injection under Settings → Compliance → Recording Disclosure.
United States — STIR/SHAKEN
Carrier-level caller-ID attestation. Without it, your calls show "SPAM LIKELY" and answer rates collapse.
What you must do: Register every outbound number under Settings → Phone numbers → [Number] → Caller ID Registration.
What the platform handles: The attestation signing itself, once your number is registered.
United States — Healthcare (HIPAA)
If you're handling Protected Health Information (PHI), you need a Business Associate Agreement with FinnAI.
- Available on Enterprise plan only.
- BAA must be signed before sending any PHI through the platform.
- Appointment reminders that only mention date/time/provider are usually fine under the TPO (Treatment, Payment, Operations) exception — no separate authorization needed.
- But the moment you discuss diagnosis, test results, or treatment specifics, you need full HIPAA-compliant handling.
Practical advice: For reminder use cases, keep the Finn's script generic ("your appointment with Dr. Patel at 3 PM tomorrow") and route any medical questions to a human. This keeps you in the TPO safe harbor without needing a BAA.
European Union — GDPR
Personal data protection law that applies to any EU resident, regardless of where you are.
Rules of thumb:
- Lawful basis — you need a reason to process someone's data. For appointment reminders to existing customers, this is "legitimate interest" or "performance of a contract." For cold outbound marketing, you need explicit consent.
- Right to delete — anyone can ask for their data to be deleted, and you must comply within 30 days.
- Data minimization — only collect what you need.
- Data residency — EU customer data should generally stay in the EU. Set your account region to EU during signup if you have EU customers.
What the platform handles: EU data residency option, right-to-delete via dashboard and API, encryption at rest and in transit.
What you handle: Establishing lawful basis before adding contacts, responding to delete/access requests.
EU — ePrivacy Directive
Specific rules about unsolicited marketing calls in EU member states. Generally stricter than GDPR alone.
Default position: Don't make cold outbound marketing calls to EU consumers without prior opt-in. Soft opt-in (existing customer relationship with right to opt out) is usually OK for similar products.
India — TRAI
Telecom Regulatory Authority of India. Strict rules around commercial calls.
- DLT registration required for commercial calls in India. The platform helps you register your business and use cases under Settings → Compliance → India DLT.
- DND list — India's Do Not Call equivalent. Scrub against it.
- Calling time restrictions — 9 AM to 9 PM.
Canada — CRTC / CASL
Similar to US TCPA, but stricter on consent requirements.
- CASL requires opt-in consent for commercial electronic messages, including some categories of voice calls.
- National DNC registry applies. Scrub.
- Calling time — 9 AM to 9:30 PM weekdays, 10 AM to 6 PM weekends.
Australia — Spam Act / TCPA equivalent
Australia has its own Do Not Call register and consent rules. Generally follows the EU "opt-in for marketing" pattern.
Other countries
Most countries have local rules. The platform tries to enforce sane defaults (calling-hour windows, do-not-call lists) but you are responsible for compliance in every jurisdiction you call into. If you're calling internationally, talk to a lawyer familiar with the destination country.
The three things you must do, regardless of region
1. Get consent before outbound marketing calls
If someone didn't ask to hear from you, you need to be able to point to a record of how you got permission to call them.
Acceptable forms:
- Filled out a form with explicit "you may contact me by phone" checkbox.
- Existing customer with prior relationship.
- Inbound inquiry where they shared their number.
Not acceptable:
- Scraped from a website.
- Bought from a list broker without verifiable consent records.
- Inferred from a LinkedIn profile.
If in doubt: don't call. The fines for TCPA violations alone start at $500 per call and can reach $1,500 per call.
2. Honor opt-outs immediately
Anyone who says "stop calling me" must be added to your global suppression list and never called again.
The platform helps:
- Add a post-call field
opt_out(yes/no). When the Finn detects an opt-out request, this field is marked yes. - Enable Settings → Compliance → Auto-Suppress on Opt-Out. When
opt_out = yes, the number is automatically added to your global suppression list. - Suppression is global — applies to every audience, every deployment, immediately.
3. Don't lie about being AI
In most jurisdictions, it's not yet illegal to use an AI voice agent. But it IS illegal to actively deceive someone who directly asks if they're talking to a human.
Always allow your Finn to disclose: Include a guardrail like "If the caller asks if you're a real person, tell them honestly that you're an AI assistant."
Most callers don't ask. The ones who do appreciate the honesty.
Recording & data retention
Recording calls
- Recording is on by default.
- You can disable per-Finn (under Call Settings) or globally (Settings → Compliance).
- In two-party-consent states/countries, you MUST disclose recording at the start of the call.
How long recordings are kept
- Default: 90 days.
- Configurable up to 7 years for regulated industries.
- After retention period, recordings are permanently deleted (no recovery).
What's in a recording
- Audio of the full call.
- Transcript (text version).
- Metadata (timestamps, caller ID, etc).
- Any post-call analysis fields.
PII redaction
Opt-in feature under Settings → Compliance → PII Redaction. Redacts SSNs, full credit card numbers, and similar from transcripts. The audio recording is unaffected — for audio redaction, you need to manually delete or trim recordings of sensitive calls.
Industry-specific notes
Healthcare
- HIPAA + state laws + (for telehealth) state medical board rules.
- Appointment reminders generally safe under TPO.
- Anything clinical needs full HIPAA compliance — BAA + careful design.
- Some states require additional disclosures for AI in healthcare contexts.
Financial services
- Multiple overlapping regimes: TCPA, FDCPA (debt collection), state UDAP laws, GLBA.
- Debt collection has additional restrictions on time, frequency, content.
- Never threaten legal action you don't intend to take.
- Never imply consequences that aren't real ("we'll affect your credit," etc).
Insurance
- State insurance commissioner rules on top of TCPA/CASL.
- Some states require licensed agents for any selling activity, even quote requests.
- Disclosure requirements vary by line of insurance.
Real estate
- Local MLS rules may restrict who can be called and how.
- Most jurisdictions consider real estate calls as subject to TCPA marketing rules.
Legal services
- Most states restrict legal-service solicitation by phone.
- Bar association rules vary widely.
What if I'm sued?
Hopefully you won't be. But if a TCPA or similar complaint lands:
- Don't panic. Most are settled, not litigated.
- Pull the call records. The platform retains everything — call audio, transcript, time, consent records you uploaded.
- Talk to a lawyer immediately. Don't respond to the complainant directly.
- Contact FinnAI support. We've seen these before and can help you pull the right records.
Best defense: a clean consent paper trail, prompt opt-out honor, and a Finn that doesn't pretend to be a human when asked.
Quick compliance checklist before launching a campaign
- I have a clear lawful basis (consent / contract / legitimate interest) for every contact on the list.
- The list is scrubbed against the national Do Not Call registry (where applicable).
- The Finn has a recording disclosure if calling into a two-party-consent jurisdiction.
- The Finn has a guardrail to disclose AI nature if directly asked.
- The
opt_outpost-call field is enabled. - Auto-Suppression is enabled in Settings → Compliance.
- Calling-hour windows are set to local time of the recipient.
- I've registered caller ID for US numbers (STIR/SHAKEN).
- I've registered for India DLT if calling into India.
- I've signed a BAA if handling US healthcare PHI.
If you can check every box, you're meeting the platform-side requirements. The business-side requirements (lawful basis, lawyer-approved scripts for regulated industries) are still on you.
Next
- FAQ → — common questions about consent, recording, and disclosure.
- Phone Numbers → — STIR/SHAKEN registration walkthrough.
- Audience → — global suppression list management.
Was this page helpful?
Still stuck or have feedback?
Email support@hirefinn.ai or use the chat bubble in the bottom-right corner — it's a Finn that knows the Academy cold.