DNC Compliance Checklist for Nearshore Call Centers

DNC LATAM · Compliance guides

A DNC compliance checklist for a nearshore call center or BPO needs to cover three things for every campaign: which country’s Do Not Call registry the numbers being dialed fall under, whether the list has been scrubbed against the current release of that registry, and whether a dated record of the scrub exists to show a client or regulator. Get any one of those wrong and the exposure is per call, not per campaign.

Nearshore operations have a specific version of this problem: the agents are in one country, but the numbers they’re dialing — and the calling client — can be in a different one entirely. A BPO seat in Mexico or Argentina might be running a campaign for a US client into US numbers, a Mexico campaign for a US client, or both at once from the same floor. Each of those is a distinct compliance obligation, and “we scrub our lists” is not a specific enough answer to any of them.

Why nearshore adds a layer most checklists skip

A domestic call center only has to track one country’s rules. A nearshore BPO calling on behalf of a US client into US numbers is still governed by the TCPA and the National DNC Registry — physical location of the agent doesn’t change which registry applies, the destination number does. If that same floor also dials into Mexico or Argentina for other campaigns, or for the same client’s LATAM expansion, those calls are governed separately by each country’s own registry and regulator. See TCPA vs. Mexico and Argentina DNC rules for how the three regimes diverge — the short version is that none of them recognizes another country’s scrub as proof of compliance.

That means a nearshore operation running mixed campaigns needs to know, list by list, which registry each set of numbers belongs to — not just where the agents sit.

The checklist

Registry and scrubbing

  • Every list is tagged with its destination country before it reaches a dialer.
  • US-number lists are scrubbed against the National DNC Registry no older than 31 days (the TSR standard).
  • Mexico-number lists are scrubbed against the current official release — Mexico republishes every 15 days, so a scrub from the prior cycle is stale.
  • Argentina-number lists are checked against a current download, not a periodic one — see how Argentina’s Registro No Llame works.
  • No campaign launches on a scrub older than 30 days, regardless of destination.

Consent and records

  • Prior express consent is logged per number, per country — a consent record from one market is not assumed to cover another.
  • Opt-outs are honored immediately and permanently, independent of registry status.
  • Consent and opt-out logs are stored somewhere the client, not just the BPO, can access on request.

Calling windows and disclosure

  • Calling hours respect the destination consumer’s local time zone, not the agent’s.
  • Required disclosures (caller identity, purpose, opt-out method) are scripted per country, since requirements aren’t identical across markets.

Audit trail

  • Every campaign has a dated scrub certificate showing which registry release it was checked against.
  • Certificates and consent logs are retained long enough to cover the client’s own audit window, not just the BPO’s.
  • The client sees the same documentation the BPO would need to show a regulator directly.

For the mechanics behind the scrubbing step itself, see how DNC scrubbing works.

Where the client-BPO contract has to be explicit

The most common gap isn’t technical — it’s contractual. Compliance obligations attach to the party making the call, but a BPO agreement doesn’t automatically say who owns the scrubbing, the consent records or the audit trail if a regulator comes asking. Before a campaign starts, the contract should state in writing:

  • Which party pulls the registry data and runs the scrub — the BPO, the client, or a shared vendor.
  • Who retains scrub certificates and for how long, and who can request them.
  • What happens when a campaign spans more than one destination country and the scrubbing obligations differ by list.

BPOs that skip this step tend to discover the gap during a client’s own compliance audit, when it turns out nobody can produce a certificate for a specific campaign date. Our call center compliance guide covers the four pillars — scrubbing, consent, calling windows and audit trail — that this checklist is built around, in more depth.

The mistake specific to nearshore operations

Because nearshore centers usually built their compliance stack around whichever market they served first — often the US — it’s common to find a mature TCPA scrubbing process sitting next to an ad hoc or missing process for Mexico or Argentina numbers when a client expands into those markets. The checklist above is the same regardless of which country a given list targets; what changes is which registry, which refresh cadence and which local access requirements apply. DNC LATAM covers the country-specific registry side of that gap — official registry access, current scrubs and dated certificates through the same API or CSV workflow a BPO already uses for its US lists, so adding a market doesn’t mean building a second compliance process from scratch. If the dialer or CRM itself needs the check wired in rather than run as a separate step, see DNC scrubbing API integration for dialers and CRMs.