Configuring TCPA Compliant Outbound Dialer for Law Firms

TL;DR
Configuring a TCPA compliant outbound dialer for law firms requires getting seven things right: time-zone-aware calling windows, federal and state DNC list scrubbing, documented prior express written consent for every contact, abandoned call rates below 3%, opt-out processing within 10 business days, call recording with audit trails, and valid caller ID display. The one-to-one consent rule was vacated in January 2025 and is no longer active law, but state mini-TCPA laws in Florida, Oklahoma, and others impose stricter requirements that most firms overlook. TCPA litigation surged 60% in 2025, and law firms themselves are now defendants.
Why TCPA Compliance Is an Existential Issue for Law Firms
Here is the uncomfortable irony: personal injury and mass tort firms routinely file TCPA class actions against corporations, yet many of those same firms run marketing campaigns that violate the very statute they litigate. This is not hypothetical. On September 25, 2024, 1-800-LAW-FIRM, PLLC was sued in the Eastern District of Michigan for allegedly violating ATDS and National DNC provisions. Plaintiff’s attorneys are now targeting other law firms.
The math is punishing. Each violation carries $500 in statutory damages, or $1,500 if the court finds the violation was willful. A single outbound campaign touching a few thousand numbers without proper configuration can generate millions in exposure. According to WebRecon LLC’s 2025 year-end litigation report, plaintiffs filed 2,628 TCPA cases in federal court in 2025, a 60% jump over 2024. Class actions surged 112% year-over-year, and nearly 80% of all TCPA cases are now class actions. Through February 2026, filings ran 26.8% ahead of the prior year’s pace.
Configuring a TCPA compliant outbound dialer for law firms is not a nice-to-have compliance exercise. It is the difference between a functioning practice and a seven-figure settlement.
If your firm uses outbound calling for lead follow-up, intake, or case development, book a demo to see how purpose-built legal dialing tools handle compliance from the start.
What Is a TCPA Compliant Outbound Dialer?
The Telephone Consumer Protection Act (TCPA), enacted in 1991, restricts how businesses can use automated telephone equipment to contact consumers. The Federal Communications Commission (FCC) oversees enforcement, and private plaintiffs can bring lawsuits directly. An outbound dialer is any software or hardware system that places calls from a pre-loaded list of numbers, whether it dials one at a time or uses predictive algorithms to dial several simultaneously.
“TCPA compliant” is a configuration state, not a product feature. No dialer ships compliant out of the box. Compliance lives in how the dialer is configured: what consent records are required before a call is placed, when calls are allowed, how opt-outs are processed, and how all of this is documented. Practitioners on Reddit and compliance forums consistently warn that lead vendors and dialer companies marketing their products as “TCPA compliant” are often overstating their protections. As TCPA attorney Eric Troutman has noted, take vendor compliance claims for what they are worth: a “help protect” that may not be there for you if you have a problem.
Key TCPA Terms Every Law Firm Should Know
ATDS (Automatic Telephone Dialing System)
Under the TCPA, an ATDS is equipment that has the capacity to store or produce telephone numbers using a random or sequential number generator and dial those numbers. In 2021, the Supreme Court unanimously narrowed this definition in Facebook v. Duguid. Justice Sotomayor wrote that expanding the definition would “take a chainsaw to these nuanced problems when Congress meant to use a scalpel.” The ruling means that most power dialers and predictive dialers used by law firms, which dial from pre-loaded lists rather than generating random numbers, likely do not qualify as ATDS under federal law.
This does not mean the rest of TCPA compliance is optional. DNC rules, consent requirements for prerecorded messages, calling hour restrictions, and abandoned call limits all still apply regardless of ATDS classification. And critically, some state laws define autodialers more broadly than the federal standard.
Prior Express Written Consent (PEWC)
This is the highest tier of consent under the TCPA. It is required before making telemarketing calls or texts using automated technology or prerecorded voices to cell phones. PEWC must be documented with a signed written agreement (electronic signatures count) that includes specific disclosures. The lower tier, “prior express consent,” applies to non-marketing calls (like case-related follow-ups) and can be established through the act of providing a phone number in a relevant context.
The Troutman Nine
Compliance attorney Eric Troutman’s framework has become the de facto standard for evaluating whether a consent form will hold up. Your PPC landing page or intake form needs all nine elements, or the consent may be unenforceable:
- Written verification of consent
- Clear and conspicuous notice
- Specific authorization for telemarketing
- Explicit technology disclosure (including AI-generated voice if applicable)
- Precise seller identification with your firm’s name visible on the form
- Phone number tied to the consent
- No-condition-of-purchase statement
- Revocation rights notification
- Consent captured before the first automated contact
Firms running PPC campaigns should audit their landing pages against this checklist immediately. The intake form is where consent is first captured, and if it fails the Troutman Nine, every subsequent automated call is built on sand. For firms looking to tighten their intake-to-dialer pipeline, Lawtté’s intake solution is purpose-built for legal workflows.
National Do Not Call Registry
The federal DNC registry, maintained by the FTC, holds over 249 million active numbers. Telemarketers must scrub their call lists against this registry before launching campaigns. Violations carry per-call penalties.
Internal DNC List
Every firm must maintain its own suppression list of people who have asked not to be called. This is separate from the federal registry. If someone tells your receptionist, your intake form, or your text platform to stop calling, that number goes on your internal DNC list immediately.
Abandoned Call
A call that connects to a live person but no agent is available to speak with them. The FCC caps abandoned calls at 3% of calls answered by a live person, measured per campaign over a 30-day window. Exceeding this threshold creates per-call liability.
Calling Window / Quiet Hours
Federal law prohibits telemarketing calls before 8 a.m. or after 9 p.m. in the recipient’s local time zone. Some states impose tighter windows. This seems simple until you realize a firm in Los Angeles calling leads across four time zones can easily violate quiet hours if the dialer does not account for the recipient’s location.
The quiet hours issue is generating a litigation wave. Over the past several months, more than 480 class action complaints have been filed alleging that marketing texts were sent outside permitted windows. For firms that send automated follow-up texts through intake automation, this is the fastest-growing area of exposure.
One-to-One Consent Rule (VACATED)
This rule, adopted by the FCC in early 2024, would have required that consent for marketing calls name a single specific seller. On January 24, 2025, the U.S. Court of Appeals for the Eleventh Circuit vacated the rule entirely. The FCC subsequently deleted the vacated language and reinstated prior rules. Half the TCPA articles on the internet still warn about this rule as if it is active. It is not. This is one of the most commonly misrepresented points in current compliance content.
Revoke-All Rule (DELAYED)
The FCC’s “revoke-all” provision, which would require that a consumer’s revocation of consent apply to all future communications from a caller (not just the specific campaign), has been delayed. The effective date is now January 31, 2027. Firms should prepare for this rule but do not need to comply with it yet.
Mini-TCPA
A shorthand term for state-level telemarketing laws that impose requirements beyond the federal TCPA baseline. These are the hidden compliance layer that most dialer guides ignore, and they are where many law firms get caught.
Dialer Types and Their Compliance Risk
Not all outbound dialers carry the same regulatory risk. When configuring a TCPA compliant outbound dialer for law firms, the choice of dialer type is the first and most consequential decision.
| Dialer Type | How It Works | TCPA Risk Level | Law Firm Fit |
|---|---|---|---|
| Preview Dialer | Shows lead info before the agent manually initiates the call | Lowest | Best for high-value intake (PI, medical malpractice) |
| Power Dialer | Dials one number at a time automatically after the current call ends | Low to Medium | Good balance for most firm sizes |
| Progressive Dialer | Auto-dials the next number when an agent becomes available | Medium | Works for follow-up campaigns with documented consent |
| Predictive Dialer | Dials multiple numbers simultaneously using algorithms to predict agent availability | Highest | Avoid unless you maintain rigorous consent records and dedicated compliance staff |
Preview and progressive dialers present one call at a time and carry the lowest TCPA risk. A preview dialer most consistently complies with TCPA requirements because the agent initiates each call after reviewing the contact record. Predictive dialers, by contrast, generate abandoned calls by design (since they dial more numbers than available agents) and must stay under the 3% abandonment threshold.
One critical warning: even though power dialers dial one number at a time, because the dialing itself is automated, some state mini-TCPA laws may classify them as autodialers requiring prior express written consent. Florida’s Telephone Solicitation Act (FTSA) defines “autodialer” more broadly than the federal post-Duguid standard, so the Duguid protection may not help a firm calling Florida numbers.
Dialer Configuration Settings That Affect Compliance
This is the core of configuring a TCPA compliant outbound dialer for law firms. Each setting below maps to a specific regulatory requirement.
Time-Zone-Aware Calling Windows
Configure your dialer to enforce calling windows based on the recipient’s local time zone, not your office’s time zone. The safe federal baseline is 8 a.m. to 9 p.m. local time for both calls and texts. Then apply stricter state rules on top. Florida and Oklahoma, for example, cut off at 8 p.m. rather than 9 p.m.
The dialer should determine time zone from the called number’s area code and registered location. If it cannot do this automatically, you need a manual process, and manual processes fail at scale.
Practical example: your PI firm in Dallas runs a PPC campaign generating leads across the country. A lead fills out a form at 8:45 p.m. Central Time. Your dialer fires an automated follow-up call. If that lead’s number is registered in the Eastern time zone, it is 9:45 p.m. for them, and you just violated federal quiet hours. If the number is in Florida, you violated state law at 8:01 p.m. Each call or text is a separate potential violation.
DNC List Scrubbing
Before every campaign, scrub your call list against both the National DNC Registry and all applicable state DNC registries. Eleven states maintain their own separate registries: Colorado, Connecticut, Florida, Indiana, Louisiana, Massachusetts, Missouri, Oklahoma, Pennsylvania, Tennessee, Texas, and Wyoming.
Firms calling leads in Texas or Florida need to scrub against those state registries in addition to the federal list. Your dialer should integrate with a DNC scrubbing service that covers both federal and state databases, and the scrub should happen automatically before any campaign launches.
Consent Verification Gate
This is the single most important configuration for outbound marketing campaigns. Before a record hits the dialer, the system should verify that a consent record exists, that it names your firm specifically, matches the campaign topic, and includes a timestamped source.
The FCC’s updated rules eliminated lead generators’ ability to sell a single consent across multiple buyers. Every firm now needs its own documented prior express written consent before making a marketing call or sending a text. Practitioners in legal marketing forums repeatedly note that lead vendors selling “TCPA-compliant leads” often provide inadequate consent documentation. If you buy leads from a third-party vendor and their intake form does not name your firm, that consent is likely unenforceable.
Your dialer should block any call to a contact that lacks a verified consent record. This means building a consent verification step between your intake system and your dialer, a workflow that AI-powered intake tools can automate.
Abandoned Call Rate Threshold
If you use a predictive dialer, configure the abandonment rate threshold at or below 3%, measured per campaign over a 30-day window. Most dialer platforms allow you to set a maximum abandonment rate that automatically throttles pacing when the threshold is approached.
For law firms, the simplest way to avoid abandoned call violations is to not use predictive mode. Power dialers and preview dialers eliminate the problem entirely because they never dial more numbers than available agents.
Opt-Out and Revocation Processing
Since April 2025, the FCC requires that opt-out requests be processed within 10 business days. State mini-TCPA statutes generally require that opt-out requests be honored immediately and apply across all numbers associated with that consumer.
Configure your dialer to:
- Automatically recognize standard opt-out keywords (“stop,” “unsubscribe,” “remove”) in text responses
- Immediately suppress the number from all active campaigns upon opt-out
- Log the opt-out with a timestamp and source
- Sync the suppression to your internal DNC list in real time
Missing a revocation is not a process gap. It is a per-call violation. If your dialer contacts someone who said “stop” last week, each subsequent call carries its own civil penalty.
Call Recording and Audit Trails
Your dialer must produce records showing that agents placed calls within the correct time window for each time zone. Keep these records for at least four years. Audit logs should capture the consent record associated with each call, the time zone determination, the opt-out status check, and the DNC scrub result.
If your firm is ever named in a TCPA lawsuit, these records are your defense. Without them, you have no way to prove compliance.
Caller ID Configuration
Every outbound call must display a valid, callable number. The recipient must be able to reach your firm by calling back the displayed number. Spoofing or displaying disconnected numbers violates both the TCPA and the Truth in Caller ID Act.
Campaign-Level Pacing Controls
Set maximum calls per agent per hour and maximum daily attempts per contact. Most compliance-conscious firms limit contact attempts to three per day and six per week to a single number. There is no specific federal cap on attempts, but excessive calling to the same number can be used as evidence of willfulness, which triples damages.
State Mini-TCPA Compliance Matrix
This is the compliance layer that catches firms off guard. Federal TCPA rules are the floor, not the ceiling. The following states impose additional requirements that affect how you configure your dialer.
| State | Key Statute | Notable Requirement | How It Differs from Federal |
|---|---|---|---|
| Florida | FTSA (2021) | Broader autodialer definition; requires prior express written consent for any automated call to a cell phone | Duguid narrowing does not apply; power dialers may need PEWC |
| Oklahoma | OTSA | One-to-one consent standard still enforced at the state level | Federal one-to-one consent rule was vacated, but Oklahoma’s survives |
| Texas | SB 140 | Maintains a state DNC registry; specific telemarketing restrictions | Must scrub against Texas state DNC list separately |
| Connecticut | SB 1058 | Requires PEWC for any telephonic sales call | Penalties up to $20,000 per violation (vs. $500/$1,500 federal) |
| Virginia | SB 1339 | Opt-out requests must be honored for 10 years (effective Jan. 1, 2026) | Federal law has no minimum duration for honoring opt-outs |
| Arizona | HB 2498 | Prohibits unsolicited text messages | Fines up to $1,000 per violation |
| California | Multiple statutes | Strict consumer protection framework | Layered state and federal requirements |
| Washington | State telemarketing act | Requires registration and bonding for telemarketers | Additional administrative compliance beyond calling rules |
The practical implication: your dialer configuration cannot use a single set of rules for all states. If your firm serves clients in California and Florida, you need state-specific calling windows, consent requirements, and DNC scrub protocols for each jurisdiction. The safest approach is to configure your dialer to apply the most restrictive applicable rule based on the called number’s state.
PI-Specific Outbound Scenarios
Personal injury firms face unique considerations when configuring a TCPA compliant outbound dialer because their outbound calling spans several distinct categories with different consent requirements.
PPC Lead Callbacks
When someone fills out an intake form from a paid search ad, that form is where consent lives or dies. The form must satisfy the Troutman Nine framework before the first automated outbound call. If the form says “a law firm may contact you” without naming your specific firm, the consent is likely insufficient. Many firms running Google Ads for PI intake have forms that were built by a marketing agency without TCPA review. Audit them now.
For firms managing high-volume personal injury intake, the speed-to-lead imperative creates tension with compliance requirements. The answer is not to skip compliance for speed. It is to build compliant consent capture into the intake form itself so the dialer can fire immediately without risk.
DEC Letter Follow-Ups
Calls to claimants following up on representation letters of protection (DEC letters) are typically case-related rather than telemarketing. This changes the consent tier required. Prior express consent (the lower tier) may suffice for these calls because you are not selling a service but rather managing an existing or prospective legal matter. However, the DNC and calling hour rules still apply regardless of the call’s purpose.
Medical Record Chases
Calls to medical providers requesting records are generally business-to-business communications directed to business lines. These fall outside the TCPA’s scope when made to business numbers. But if your staff is calling a provider’s personal cell phone, the analysis changes. Configure your dialer to flag numbers identified as personal mobile numbers for medical providers separately from business lines.
Common Configuration Mistakes Law Firms Make
After reviewing compliance discussions across legal marketing communities and practitioner forums, these are the configuration errors that appear most frequently.
Using the same calling window for all states. Florida and Oklahoma cut off at 8 p.m., not 9 p.m. If your dialer treats 9 p.m. as a universal cutoff, every call between 8:01 p.m. and 9:00 p.m. to numbers in those states is a violation.
Scrubbing only the federal DNC list. Eleven states maintain separate registries. If you are calling into those states and only scrubbing federal, you are exposed.
Treating third-party lead consent as sufficient. A lead vendor’s generic intake form that says “our partners may contact you” does not provide your firm with prior express written consent. You need consent that names your firm specifically.
Running predictive mode on cell-phone-heavy lists. Predictive dialers generate abandoned calls by design. Combining predictive mode with a list that is primarily mobile numbers multiplies your risk because mobile numbers carry stricter consent requirements in many states.
Not logging consent source per contact before loading into the dialer. If you cannot produce a timestamped consent record tied to a specific contact, you cannot defend the call. The consent record should be attached to the contact in your CRM before the number ever enters a dialer campaign.
Sending automated follow-up texts outside quiet hours. Many firms set up automation that texts leads within minutes of form submission, regardless of time. A lead who fills out a form at 11 p.m. does not need a text at 11 p.m. Queue it for the next compliant window.
Ignoring the 10-business-day opt-out deadline. Since April 2025, this is actively enforced federal law. If someone texts “stop” and your system takes three weeks to suppress them, every contact in that gap is a separate violation.
Putting It All Together: A Configuration Workflow
When configuring a TCPA compliant outbound dialer for law firms, the setup process should follow this sequence:
-
Choose the right dialer type. For most law firms, a preview or power dialer provides the best balance of efficiency and compliance risk. Reserve predictive dialing for campaigns with bulletproof consent records and dedicated compliance oversight.
-
Integrate DNC scrubbing. Connect to both the federal DNC registry and all applicable state registries. Set scrubbing to run automatically before every campaign launch and at least every 30 days for ongoing campaigns.
-
Build the consent verification gate. No contact enters a dialer campaign without a verified consent record that names your firm, matches the campaign purpose, and includes a timestamp.
-
Set time-zone rules. Configure calling windows by state, applying the most restrictive rule. Default to 8 a.m. to 8 p.m. if you call into Florida or Oklahoma.
-
Configure opt-out automation. Set up real-time suppression for all standard opt-out keywords. Sync suppression lists across all campaigns and channels within hours, not days.
-
Set abandonment thresholds. If using predictive mode, cap at 3%. Better yet, use power or preview mode and eliminate the issue.
-
Enable call recording and audit logging. Every call should generate a record showing the consent source, time-zone check, DNC scrub result, and timestamp.
-
Test before launching. Run a test campaign to verify that time-zone enforcement, DNC blocking, and consent gating all function correctly.
Lawtté’s Scale product is built specifically for law firm outbound dialing with TCPA compliance baked into the workflow. Explore Lawtté’s platform to see how these configuration steps are handled within a legal-specific environment.
Frequently Asked Questions
Does the one-to-one consent rule still apply to law firm dialers?
No. The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit Court of Appeals on January 24, 2025. The FCC subsequently deleted the vacated language and reinstated prior rules. However, some states like Florida and Oklahoma enforce similar one-to-one consent standards under their own statutes, so you may still need seller-specific consent for calls into those states.
What type of dialer is safest for a law firm to use?
A preview dialer carries the lowest TCPA risk because the agent manually initiates each call after reviewing the contact record. Power dialers are the next safest option for firms that need more volume. Predictive dialers carry the highest risk due to abandoned call generation and should be avoided unless the firm has dedicated compliance staff and ironclad consent documentation.
How quickly must my firm process opt-out requests?
Federal law requires processing within 10 business days, a rule that has been active since April 2025. Many state mini-TCPA laws require immediate processing. Configure your dialer to suppress opted-out numbers in real time across all active campaigns.
Do I need to scrub against state DNC lists, or is the federal list enough?
The federal list is not enough. Eleven states maintain separate DNC registries, and you must scrub against the applicable state registry for any state where you are calling leads. Failure to do so is a per-call violation.
Are law firms actually getting sued for TCPA violations?
Yes. 1-800-LAW-FIRM, PLLC was sued in September 2024 for alleged ATDS and National DNC violations. TCPA plaintiff’s attorneys are increasingly targeting other law firms, particularly those running high-volume outbound campaigns without proper compliance controls.
Does the Duguid ruling mean my power dialer is not an ATDS?
Under federal law, likely yes, because power dialers work from pre-loaded lists rather than generating random or sequential numbers. But Florida’s FTSA and other state mini-TCPA laws define “autodialer” more broadly. A power dialer that is not an ATDS federally may still be classified as an autodialer under state law, requiring prior express written consent for calls to cell phones in those states.
What is the Revoke-All rule, and do I need to comply with it now?
The FCC’s Revoke-All rule would require that a consumer’s revocation of consent apply to all future communications from the caller, not just one campaign. The effective date has been delayed to January 31, 2027. You do not need to comply yet, but you should begin configuring your systems to handle universal revocation before that deadline.
How does configuring a TCPA compliant outbound dialer differ for PI firms versus other practice areas?
PI firms typically make three types of outbound calls with different compliance profiles: marketing callbacks to PPC leads (requiring full PEWC), DEC letter follow-ups to claimants (case-related, requiring only prior express consent), and medical record chases to providers (often B2B and outside TCPA scope if directed to business lines). Each call type needs a different consent tier configured in the dialer. Treating all outbound calls identically either over-restricts your workflow or under-protects your firm.
Configuring a TCPA compliant outbound dialer for law firms is not a one-time setup. It requires ongoing attention as state laws evolve, FCC rules take effect, and litigation patterns shift. The firms that treat compliance as a continuous operational practice, rather than a box to check, are the ones that avoid becoming defendants in the very type of lawsuit they file.
Ready to see compliant outbound dialing configured for your firm’s specific practice areas and states? Book a demo with Lawtté to walk through the setup.
Bring Lawtté to your firm.
Walk us through your intake and case workflow — we'll have your AI live in 14 days.
Book a Demo →