---
id: compliance
title: Compliance
slug: /compliance
description: Manage your Do Not Call list, card-payment and healthcare protections, and the change history for your account.
---

Outbound calling is regulated. Chatley helps you stay compliant with a required
**Do Not Call (DNC) attestation** and an **account-wide DNC list** that blocks
numbers you must not call. This applies to [outbound calls and campaigns](./outbound.md).

![Compliance flow — accept the DNC attestation to unlock outbound calls; every number is checked against your account-wide Do Not Call list, which is fed by manual entries, CSV uploads, and auto-detected verbal opt-outs; matches are blocked](/img/compliance-dnc.svg)

## Around the page

Open **Compliance** under **Setup** (the page title is *Compliance & Do Not Call*).
It has three tabs:

| Tab | What it covers |
| --- | --- |
| **Do Not Call list** | Numbers your agents must never call. |
| **Card payments and healthcare** | Protections for agents that take card details (PCI) or handle patient information (HIPAA). |
| **Change history** | An append-only record of every Do Not Call action in your account. |


## Step 1 — Accept the DNC attestation

Before an agent can place outbound calls, you must accept the **DNC Compliance
Attestation** on that agent. You acknowledge that:

- you are responsible for compliance with the **Telephone Consumer Protection Act
  (TCPA)** and all applicable Do Not Call regulations, and
- you will honour opt-out requests and won't call numbers on the DNC list.

Tick the acknowledgement box and choose **Accept & Continue**. Until you do,
outbound calls are blocked with **"DNC Compliance Required."**

## Step 2 — Manage your Do Not Call list

The **Do Not Call list** tab shows the numbers blocked now, with *how it was
added*, a reason and the date blocked.

:::warning[Account-wide enforcement]
The DNC list is enforced at the **account level** — a number opted out in **any**
workspace is blocked across your **entire account**.
:::

Ways numbers get onto the list:

- **Block** — add a single number yourself, with an optional reason. *Manually added.*
- **Import** — bulk-import a CSV. Columns: `phone_number` (required) and
  `reason` (optional). *Imported from CSV.*
- **Automatically** — callers who ask not to be called again are added for you.
  *Detected from call.*
- **Through the API** — numbers your own systems add.

You can **search** a phone number, **Export** the list as CSV, and **remove** a
number when appropriate. Removed numbers move to a separate list so you can see
them later.

## What happens on each call

When an agent is about to dial, the number is checked against the DNC list:

- **Not on the list** → the call proceeds.
- **On the list** → the call is **blocked** ("Call Blocked — DNC List"). Remove
  the number from the list first if calling it is appropriate.

## Troubleshooting

| Problem | What to check |
| --- | --- |
| **DNC Compliance Required** | Accept the DNC attestation on the agent before dialing. |
| **Call Blocked — DNC List** | The number is opted out somewhere in your account. Review it in the DNC dashboard. |
| A number won't unblock | Remember enforcement is account-wide — check other workspaces too. |

## Next steps

- [Outbound](./outbound.md) — place calls and run campaigns once compliant.
- [Getting started](./getting-started.md) — the basics of workspaces and agents.

## Card payments and healthcare

This tab holds protections you switch on **per agent**:

- **Card payments (PCI)** — turn this on, under **Voice & conversation**, for an
  agent that takes card details over the phone. Voice models are restricted,
  non-compliant voices are switched automatically, and transcripts and recordings
  are unavailable for those calls.
- **Healthcare (HIPAA)** — protects patient information in calls, transcripts and
  recordings across all your workspaces. HIPAA is an add-on to your plan; the
  tab links to **Plan and billing** where you can add it.

## Change history

Every addition and removal on the Do Not Call list is recorded here, with who
or what made the change. The record is append-only: it cannot be edited.
Until something happens the tab says *No audit events yet*.
