Skip to content
Sales

TCPA, PECR and CASL: What "Compliant Outbound" Actually Means in Three Markets

US, UK and Canadian outbound rules are not the same rulebook with different names. Here is what genuinely differs, and what a compliant operating procedure has to cover.

Shoora Global Editorial3 min read

Outbound sales teams that operate across the US, UK and Canada often treat the compliance rules as one blurry category — "don’t spam people, don’t call at 3am." That gets you most of the way, but each market has specific, different requirements, and the gaps between them are exactly where outbound programmes get into trouble.

United States — TCPA

The Telephone Consumer Protection Act governs calls and texts, with the National Do Not Call Registry as the enforcement backbone for consumer calling. Business-to-business calling has more latitude than consumer calling, but not unlimited latitude — time-of-day restrictions apply (generally 8am–9pm in the recipient’s local time), and automated dialing or pre-recorded messages trigger stricter consent requirements regardless of B2B context.

United Kingdom — PECR

The Privacy and Electronic Communications Regulations sit alongside UK GDPR and specifically govern unsolicited electronic communications. Business-to-business email has a narrower "soft opt-in" allowance than consumer email, but it still requires a clear, easy opt-out on every message and a legitimate prior relationship or reasonable expectation of contact — not a purchased list emailed cold.

Canada — CASL

Canada’s Anti-Spam Legislation is generally regarded as the strictest of the three. It requires either express or narrowly-defined implied consent before commercial electronic messages are sent, mandates clear sender identification, and requires a functional unsubscribe mechanism honoured within ten business days. The implied-consent categories are specific and narrower than most teams assume.

What this means for an operating procedure, not just a policy document

  • Calling lists are screened against the relevant do-not-call registry before every campaign, not once at list purchase
  • Time-of-day restrictions are enforced by the dialer or the sequencer, not left to an agent’s judgement
  • Every commercial email carries a working, immediate unsubscribe, honoured the same day, not within some vague future batch
  • Consent basis is recorded per contact, per market, so a compliance question can be answered from the record rather than reconstructed from memory

The common thread across all three regimes is the same: consent and identification requirements exist to be operationalised, not laminated and forgotten. A policy PDF that nobody’s dialer actually enforces is not a compliance programme — it is a document that will read very badly if a regulator ever asks to see how it was implemented.

This article describes the shape of each regime in outline. It is not legal advice, and the specific rules that apply to a given campaign depend on facts a lawyer should review — particularly around consent categories and B2B carve-outs, which shift more often than most outbound teams realise.

Get started

Ready to talk through your own version of this?

Book a scoping call and we'll tell you honestly whether outsourcing is the right move yet.