What changes at a border
The Finn platform does not vary its behavior by destination country on its own. Calling hours, do-not-call scrubbing, consent records, and recording disclosure are settings you configure per workspace and per Finn. If you point a campaign at a new country and change nothing else, you will be running that country's calls under the previous country's rules.
This page is an overview, not legal advice. For anything you plan to run at volume, talk to a lawyer familiar with the destination country.
Calling hours by region
Calling-hour windows are enforced against the recipient's local time, and only if you set them. See outbound campaigns for where the window is configured.
| Region | Permitted window | Source rule |
|---|---|---|
| United States | 8:00 to 21:00 | TCPA |
| India | 9:00 to 21:00 | TRAI |
| Canada (weekdays) | 9:00 to 21:30 | CRTC |
| Canada (weekends) | 10:00 to 18:00 | CRTC |
| EU, Australia, elsewhere | Not enforced by default | Local rules vary |
If you leave the window unset, calls go out whenever the campaign runs. A 3 AM call into a TCPA jurisdiction is a per-call violation, and TCPA fines start at $500 per call and reach $1,500 per call.
Consent posture by region
| Region | Marketing calls | Informational calls | Suppression list to scrub |
|---|---|---|---|
| United States | Prior express written consent required for automated calls to mobiles | Generally allowed with an existing business relationship | National Do Not Call Registry |
| EU | Prior opt-in. Soft opt-in acceptable for similar products to existing customers | Lawful basis required (legitimate interest or contract) | Member-state lists |
| Canada | Opt-in consent under CASL, stricter than TCPA | Still subject to CASL categories | National DNC |
| India | DLT registration required for commercial calls | DLT registration still required | DND registry |
| Australia | Opt-in for marketing, following the EU pattern | Local rules apply | Do Not Call Register |
"Written consent" in the US includes a typed form submission, provided the form text explicitly says the person consents to automated calls. A scraped number, a purchased list without verifiable consent records, and an inferred LinkedIn contact are all outside that definition.
Recording disclosure
Ten US states plus a few others require all parties to consent to recording: California, Florida, Illinois, Massachusetts, Maryland, Montana, New Hampshire, Pennsylvania, Washington, and others. Add a disclosure to the start of every Finn that operates in or calls into those states, either in the welcome message or through disclosure injection under Settings → Compliance → Recording Disclosure in the dashboard. There is no API for that toggle. See recording consent.
Recording is on by default. Disable it per Finn under Call Settings, or globally under Settings → Compliance.
Caller ID and attestation
STIR/SHAKEN is US-specific. Register every outbound US number under Settings → Phone numbers → [Number] → Caller ID Registration in the dashboard. Unregistered numbers do not get attestation signing, which means they display as "SPAM LIKELY" and answer rates fall. See caller ID and spam labeling.
India requires DLT registration of your business and use cases, done under Settings → Compliance → India DLT. Commercial calls placed before that registration completes are non-compliant regardless of consent.
Data handling across borders
GDPR applies to any EU resident, wherever you operate from. EU customer data should generally stay in the EU, and the account region is set during signup. Moving an existing workspace's region is not covered here. See data residency.
Delete and access requests must be answered within 30 days. Right-to-delete is available through the dashboard and the API. Default recording retention is 90 days, configurable up to 7 years for regulated industries. After the retention period, deletion is permanent with no recovery. See retention.
PII redaction is opt-in under Settings → Compliance → PII Redaction. It redacts SSNs, full credit card numbers, and similar strings from transcripts only. The audio is untouched, so a redacted transcript still sits next to a recording that says the number out loud. To remove it from audio you delete or trim the recording manually.
What stays the same everywhere
Three obligations do not change at a border.
- Hold a consent record before any outbound marketing call. If you cannot point to how you got permission, do not call.
- Honor opt-outs. Set the
opt_outpost-call field and enable Settings → Compliance → Auto-Suppress on Opt-Out. Suppression is global across every audience and deployment. The US deadline is 30 days, but there is no reason to wait. See analysis fields. - Let the Finn admit it is AI when asked directly. Using an AI voice agent is generally legal. Denying it to someone who asks is not. Add a guardrail instructing honest disclosure. See guardrails.
For sector rules layered on top of these, see industry compliance. For the general overview, see compliance.