---
title: "Compliance, country by country"
description: "How AssistBPO runs compliant phone, SMS and email work in the US, UK, Canada and Australia: consent, do-not-call scrubbing, calling hours. Get in touch."
url: https://assistbpo.com/compliance/
updated: 2026-09-20
publisher: AssistBPO (SS Support Network LLC)
language: en-US
---

# Compliance, country by country

Compliance

TCPA compliant appointment setting in the US, PECR-screened calling in the UK, CASL express consent in Canada and Do Not Call Register washing in Australia. Every outbound call, text and email an AssistBPO assistant sends goes out with lawful consent and do-not-call scrubbing, inside the calling hours each country allows.

- DNC, TPS, DNCL and DNCR scrubbing
- Live agents, never robocalls
- HIPAA-trained staff and a BAA

[Get a staffing plan](https://assistbpo.com/get-a-staffing-plan/)[Book a 20-minute call](https://assistbpo.com/book-a-call/) This page lists the rules by country, what we do for each, and what we will not do. It is a summary, not legal advice.

Updated September 2026

## United States

7 rules that shape a desk here

| Rule | What it requires | What AssistBPO does |
| --- | --- | --- |
| TCPA | Prior express consent for marketing calls and texts to mobiles, calling hours of 8am to 9pm in the called party's time zone, National Do Not Call scrubbing, no autodialed or prerecorded calls without consent | Consent checked before every list is loaded, DNC scrubbing before every campaign, consent logs kept per contact, call windows set by the called party's zone, live agents only, never robocalls |
| State mini-TCPAs (Florida, Oklahoma, Washington and others) | Stricter consent, calling hours and frequency limits in some states | Lists are tagged by state and the stricter rule applies; weekly review confirms the windows in use |
| Call-recording consent | All-party consent in states such as California, Florida and Washington | A recording notice at the start of every recorded call; recording off where you ask |
| CAN-SPAM | Accurate sender identity, a physical address and a working unsubscribe on every commercial email | Identity and address in every campaign, unsubscribes processed within the statutory window, suppression list kept in your email tool |
| HIPAA | A business associate agreement, trained staff, minimum-necessary access for protected health information | BAA signed, HIPAA-trained staff on every healthcare desk, access limited to the assigned team |
| GLBA Safeguards Rule | Safeguards for customer financial information handled for financial-services clients | Access controls, managed devices and a written safeguards summary for advisors, lenders and insurance agencies |
| PCI DSS | Card data protected wherever it is handled | Assistants never take, type or store card numbers; payments run through your portal or payment link |

## United Kingdom

3 rules that shape a desk here

| Rule | What it requires | What AssistBPO does |
| --- | --- | --- |
| UK GDPR and Data Protection Act 2018 | A lawful basis, a data processing agreement and a transfer mechanism for data leaving the UK | DPA with the International Data Transfer Agreement or UK Addendum, a privacy notice, and processing only on your instructions |
| PECR | No marketing calls to numbers on the Telephone Preference Service or Corporate TPS, and no marketing calls to anyone who has objected | Every marketing list screened against TPS and CTPS before calling, objections recorded the same day, consent for texts and email |
| Ofcom persistent-misuse rules | Limits on abandoned and silent calls, no repeated calling that causes distress | Live agents only, no dialer that drops calls, call attempts capped per contact and logged |

## Canada

3 rules that shape a desk here

| Rule | What it requires | What AssistBPO does |
| --- | --- | --- |
| PIPEDA and Quebec Law 25 | Consent, transparency about cross-border processing, privacy impact assessments for Quebec data | Privacy addendum, support for your impact assessment, and a named person in charge of personal information |
| CASL | Express consent before commercial electronic messages, sender identification and an unsubscribe in every message | Consent recorded with date and source before any campaign, identification and unsubscribe in every text and email, opt-outs honored within the statutory window |
| CRTC Unsolicited Telecommunications Rules and the National DNCL | National Do Not Call List subscription and scrubbing, calling hours, identification at the start of each call | DNCL subscription under your registration, scrubbing before every campaign, scripts that identify the caller and the business first |

## Australia

3 rules that shape a desk here

| Rule | What it requires | What AssistBPO does |
| --- | --- | --- |
| Privacy Act 1988 and APP 8 | Transparency and reasonable steps before personal information is disclosed overseas | Cross-border disclosure recorded in your privacy addendum, contractual protections for data handled at our second office |
| Spam Act 2003 | Consent, sender identification and a functional unsubscribe for every commercial electronic message | Consent captured before texts or email go out, identification and unsubscribe in every message |
| Do Not Call Register Act 2006 and the ACMA Telemarketing and Research Calls Industry Standard | Register washing before calls, standard calling hours and days, caller identification | Lists washed against the Register before every campaign, calls inside the Standard's hours, scripts that identify the business and the purpose |

## Which rules apply in every market?

Three things do not change with the country you are calling into, because they are about who does the work and what they are allowed to hold.

- **Employment**Assistants are employees of SS Support Network LLC. You never co-employ them and never deal with a marketplace or contractor, so the employer of record for the people on your desk is never in question.
- **Recording notices**Per-country notice scripts live in your phone platform and match the caller's country and state. Recording is off wherever you ask.
- **Data processing**A written agreement covering instructions, security, sub-processors, transfers and breach notice, with the transfer mechanism for your country and breach notice within 72 hours.

## What will an AssistBPO assistant not do?

- Third-party debt collection. Assistants may remind your own customers about your own invoices; we are never a collection agency and never collect for anyone else.
- Robocalls, autodialed campaigns or prerecorded voice. Every call is a live person.
- Licensed advice. Assistants schedule, intake, follow up and support; they do not give legal, medical, financial or tax advice, and scripts say so.
- Calling numbers without a lawful basis. No purchased lists without provenance, no cold outreach to numbers on a do-not-call register.
- Taking card numbers. Payments go through your portal, a payment link or your own staff.

## Outbound and data rules we follow

**United States**
: TCPA consent and calling hours, DNC scrubbing, two-party recording notices, CAN-SPAM; HIPAA-trained staff and a BAA for healthcare clients.

**United Kingdom**
: UK GDPR with a data processing agreement and IDTA, PECR with TPS and CTPS screening, Ofcom persistent-misuse rules, call-recording notices.

**Canada**
: PIPEDA and Quebec Law 25, CASL express consent for every commercial message, CRTC rules and National DNCL subscription.

**Australia**
: Privacy Act 1988 with APP 8 cross-border disclosure, Spam Act 2003, Do Not Call Register washing and ACMA telemarketing standard hours.

Outbound calls, texts and emails only with lawful consent and do-not-call scrubbing. Certifications are listed only when held.

Sources: fcc.gov, ftc.gov, hhs.gov, ico.org.uk, ofcom.org.uk, priv.gc.ca, crtc.gc.ca, fightspam.gc.ca, oaic.gov.au, acma.gov.au. This page is a summary, not legal advice. Controls are on the [security page](https://assistbpo.com/security/); processor terms are in the [data processing agreement](https://assistbpo.com/dpa/).

## Frequently asked questions

### Is your appointment setting TCPA compliant?

Appointment setting runs on lists with documented consent or an existing business relationship, scrubbed against the National Do Not Call Registry and your internal do-not-call list before every campaign, called by live agents inside 8am to 9pm in the contact's own time zone, with state rules layered on top. We keep the consent log per contact and never use autodialers or prerecorded voice. Your counsel signs off the script and the list source before the first call.

### What does CASL compliant outreach look like in Canada?

Express consent, recorded with the date and where it came from, before any commercial text or email; sender identification and a working unsubscribe in every message; and calls scrubbed against the National DNCL under your subscription. Implied consent from an existing business relationship is used only within the periods CASL allows, and the team lead reviews the consent basis at the weekly review.

### How do PECR telemarketing rules affect a UK campaign?

Marketing calls go only to numbers that are not on the TPS or CTPS and have not objected to you directly, so every list is screened before calling. Texts and email need consent under PECR, and the caller must identify the business and offer a way to opt out. Ofcom's persistent-misuse rules are met by using live agents and capping attempts per contact.

### What is Do Not Call Register compliance in Australia?

Lists are washed against the Do Not Call Register before each campaign, calls are placed inside the hours and days set by the ACMA Telemarketing and Research Calls Industry Standard, the caller identifies the business and the purpose, and the contact can opt out at any point. Texts and email follow the Spam Act: consent, identification and unsubscribe.

### Who is responsible for consent, you or us?

You are the controller or business and own the relationship with your contacts, so the consent has to be yours. We check that each list carries a documented basis before it is loaded, scrub it against the registers, keep the log, and stop a campaign if the basis is missing. Where you have no consent yet, the desk can capture it lawfully through inbound calls, forms and existing-customer messages.

### Can assistants make outbound calls at all?

Yes, for confirmations, reminders, follow-ups, reactivation and appointment setting, always with lawful consent and do-not-call scrubbing. Inbound-driven work such as answering, intake and callbacks needs no marketing consent at all, and most desks run mostly on it.

### Do you give legal advice on these rules?

No. This page is a plain-language summary of the rules we operate under and the controls we apply. Your counsel or compliance lead decides what applies to your business; we build the scripts, lists and logs to their instructions and keep the evidence.

Next step

## Your desk, staffed. Wherever you are.

Tell us what is overloaded. A named person replies within 1 business day with a staffing plan, and we propose your assistant within 72 hours.

[Get a staffing plan](https://assistbpo.com/get-a-staffing-plan/) [Book a 20-minute call](https://assistbpo.com/book-a-call/) Or call [+1-657-777-0006](tel:+16577770006) during US, UK or Australian business hours, or [hear our demo receptionist](https://assistbpo.com/demo-line/).

- A named assistant proposed within 72 hours
- Employed, screened and managed staff, never freelancers
- Your hours, your tools, your data

---

Source: https://assistbpo.com/compliance/ · Contact: https://assistbpo.com/contact/ · Full site map for agents: https://assistbpo.com/llms.txt
