veriastra_
Guide · Do Not Call · 3 min read

The do-not-call safe harbor has six conditions, and a vendor can help with two

16 CFR 310.4(b)(3) lists six things a seller must demonstrate to avoid liability for a do-not-call violation. Most of them are yours, not your vendor's.

Vendors sell "safe harbor" as though it were a product you buy. It is not. It is an affirmative defence written into the Telemarketing Sales Rule, and it only holds if you can demonstrate all six conditions as part of your routine business practice. Here is the text.

A seller or telemarketer will not be liable for violating § 310.4(b)(1)(ii) and (iii) if it can demonstrate that, as part of the seller's or telemarketer's routine business practice: (i) It has established and implemented written procedures to comply with § 310.4(b)(1)(ii) and (iii); (ii) It has trained its personnel, and any entity assisting in its compliance, in the procedures established pursuant to § 310.4(b)(3)(i); (iii) The seller, or a telemarketer or another person acting on behalf of the seller or charitable organization, has maintained and recorded a list of telephone numbers the seller or charitable organization may not contact, in compliance with § 310.4(b)(1)(iii)(A); (iv) The seller or a telemarketer uses a process to prevent telemarketing to any telephone number on any list established pursuant to § 310.4(b)(3)(iii) or 310.4(b)(1)(iii)(B), employing a version of the “do-not-call” registry obtained from the Commission no more than thirty-one (31) days prior to the date any call is made, and maintains records documenting this process; (v) The seller or a telemarketer or another person acting on behalf of the seller or charitable organization, monitors and enforces compliance with the procedures established pursuant to § 310.4(b)(3)(i); and (vi) Any subsequent call otherwise violating paragraph (b)(1)(ii) or (iii) of this section is the result of error and not of failure to obtain any information necessary to comply with a request pursuant to paragraph (b)(1)(iii)(A) of this section not to receive further calls by or on behalf of a seller or charitable organization.

16 CFR 310.4(b)(3)

Read it as six separate obligations rather than one. Written procedures. Training. A maintained list. A scrubbing process with records, against registry data no more than 31 days old. Monitoring and enforcement. And the violation being an error rather than a failure to capture a request.

Now notice what a software vendor is actually in a position to do. Nobody can write your procedures for you, train your staff, or monitor your own compliance. Two of the six are about keeping records, and those are the two any vendor — including us — can genuinely carry.

(i) Written proceduresYou. A document, approved internally.
(ii) Training your personnelYou, and anyone assisting your compliance.
(iii) A maintained, recorded do-not-call listCan be kept in software.
(iv) A scrubbing process, with records, on registry data under 31 days oldCan be kept in software; the registry subscription is still yours.
(v) Monitoring and enforcing your own proceduresYou.
(vi) The violation being an error, not a missed requestDepends on how you captured the request.

This is why we sell a record and not a guarantee. A vendor that promises safe harbour is promising something four-sixths of which happens inside your organisation, where they cannot see. What we can do is make conditions (iii) and (iv) demonstrable: dated entries, a registry access log, and scrub results whose hashes you can recompute years later.

One more thing worth reading twice: condition (iv) says the registry version must have been obtained "no more than thirty-one (31) days prior to the date any call is made". The clock runs from the call, not from your last download. A scrub done on day 30 covers a call on day 31 and not a call on day 33.

This page quotes the regulation and describes what it says. It is not legal advice, and whether any particular call complied depends on facts we do not hold. Talk to a lawyer about your own programme.