Skip to main content

Security and compliance

Rules by region

What changes when you call across a border.

What changes at a border

The Finn platform does not vary its behavior by destination country on its own. Calling hours, do-not-call scrubbing, consent records, and recording disclosure are settings you configure per workspace and per Finn. If you point a campaign at a new country and change nothing else, you will be running that country's calls under the previous country's rules.

This page is an overview, not legal advice. For anything you plan to run at volume, talk to a lawyer familiar with the destination country.

Calling hours by region

Calling-hour windows are enforced against the recipient's local time, and only if you set them. See outbound campaigns for where the window is configured.

RegionPermitted windowSource rule
United States8:00 to 21:00TCPA
India9:00 to 21:00TRAI
Canada (weekdays)9:00 to 21:30CRTC
Canada (weekends)10:00 to 18:00CRTC
EU, Australia, elsewhereNot enforced by defaultLocal rules vary

If you leave the window unset, calls go out whenever the campaign runs. A 3 AM call into a TCPA jurisdiction is a per-call violation, and TCPA fines start at $500 per call and reach $1,500 per call.

RegionMarketing callsInformational callsSuppression list to scrub
United StatesPrior express written consent required for automated calls to mobilesGenerally allowed with an existing business relationshipNational Do Not Call Registry
EUPrior opt-in. Soft opt-in acceptable for similar products to existing customersLawful basis required (legitimate interest or contract)Member-state lists
CanadaOpt-in consent under CASL, stricter than TCPAStill subject to CASL categoriesNational DNC
IndiaDLT registration required for commercial callsDLT registration still requiredDND registry
AustraliaOpt-in for marketing, following the EU patternLocal rules applyDo Not Call Register

"Written consent" in the US includes a typed form submission, provided the form text explicitly says the person consents to automated calls. A scraped number, a purchased list without verifiable consent records, and an inferred LinkedIn contact are all outside that definition.

Recording disclosure

Ten US states plus a few others require all parties to consent to recording: California, Florida, Illinois, Massachusetts, Maryland, Montana, New Hampshire, Pennsylvania, Washington, and others. Add a disclosure to the start of every Finn that operates in or calls into those states, either in the welcome message or through disclosure injection under Settings → Compliance → Recording Disclosure in the dashboard. There is no API for that toggle. See recording consent.

Recording is on by default. Disable it per Finn under Call Settings, or globally under Settings → Compliance.

Caller ID and attestation

STIR/SHAKEN is US-specific. Register every outbound US number under Settings → Phone numbers → [Number] → Caller ID Registration in the dashboard. Unregistered numbers do not get attestation signing, which means they display as "SPAM LIKELY" and answer rates fall. See caller ID and spam labeling.

India requires DLT registration of your business and use cases, done under Settings → Compliance → India DLT. Commercial calls placed before that registration completes are non-compliant regardless of consent.

Data handling across borders

GDPR applies to any EU resident, wherever you operate from. EU customer data should generally stay in the EU, and the account region is set during signup. Moving an existing workspace's region is not covered here. See data residency.

Delete and access requests must be answered within 30 days. Right-to-delete is available through the dashboard and the API. Default recording retention is 90 days, configurable up to 7 years for regulated industries. After the retention period, deletion is permanent with no recovery. See retention.

PII redaction is opt-in under Settings → Compliance → PII Redaction. It redacts SSNs, full credit card numbers, and similar strings from transcripts only. The audio is untouched, so a redacted transcript still sits next to a recording that says the number out loud. To remove it from audio you delete or trim the recording manually.

What stays the same everywhere

Three obligations do not change at a border.

  1. Hold a consent record before any outbound marketing call. If you cannot point to how you got permission, do not call.
  2. Honor opt-outs. Set the opt_out post-call field and enable Settings → Compliance → Auto-Suppress on Opt-Out. Suppression is global across every audience and deployment. The US deadline is 30 days, but there is no reason to wait. See analysis fields.
  3. Let the Finn admit it is AI when asked directly. Using an AI voice agent is generally legal. Denying it to someone who asks is not. Add a guardrail instructing honest disclosure. See guardrails.

For sector rules layered on top of these, see industry compliance. For the general overview, see compliance.