Step 0: Before you dial, understand what each market regulates
The most common mistake is treating compliance as a single global rule. It is not. Every country you call has its own mix of rules on telemarketing, data protection, call recording, and, increasingly, the use of artificial intelligence. Setting up a campaign correctly starts by mapping the markets you will call, not by writing the script.
This is an operational starting point, not a legal ruling. Nothing here replaces review by legal counsel in each country. The goal is to reach that conversation with the right questions and a conservative default configuration already in place.
Run this mini-process for each market before launch: (1) identify the data protection rules that apply in that country; (2) locate the official do-not-call or advertising-exclusion registry and how to check it; (3) confirm the permitted hours for commercial contact; (4) verify the call-recording rules (one-party or all-party consent); (5) check whether there are specific requirements about disclosing AI use. Document the answer to all five in a per-country table; that table becomes your single source of truth for configuration.
Step 1: Transparency, disclose that people are speaking with an AI
Transparency is the foundation of AI call compliance and, increasingly, an explicit requirement in several jurisdictions. The practical rule is simple: the person must know, early and clearly, that they are talking to an automated system and not a human. Do not hide it or leave it ambiguous.
Configure the disclosure in the first seconds of the call, before collecting any data or purchase intent. A neutral, reusable example: "Hello, I'm a virtual assistant from [company]. I'm calling about [reason], and this conversation may be recorded. Is now a good time to continue?" That single line covers three things at once: automated identity, reason, and recording notice.
Transparency checklist: (1) the AI disclosure plays at the opening, not the end; (2) the system identifies itself with company name and reason; (3) the assistant answers honestly if asked "are you a person?"; (4) there is a clear exit to reach a human or end the call; (5) the disclosure is spoken in the caller's language. In Vendrava this is defined once in the opening template and applied to inbound, outbound, and cold calls alike, so no campaign goes out without the disclosure.
Step 2: Consent and opt-in, the legal basis to make contact
Before you call, you must be able to answer one question: on what basis am I contacting this person? In many markets, telemarketing and automated voice contact require prior consent, especially for cold calls or automated messages. In others, a legitimate interest with an easy opt-out is enough. The answer changes by country and by campaign type.
Treat consent as a traceable data point, not a loose checkbox. For each contact, store: the data source, the exact consent text they accepted, the date and time, the channel (web, form, point of sale), and the purposes it covers. If that person asks tomorrow why you are calling, you should be able to reconstruct the answer in seconds.
Actionable steps: (1) segment your lists by contact basis (explicit opt-in, existing customer, purchased list, etc.) and never mix them; (2) block sending to any contact without a documented valid basis; (3) always offer an immediate opt-out within the call itself ("say remove me and we won't call again"); (4) process that removal on the spot, not in an overnight batch; (5) keep proof of both the consent and the opt-out. An opt-out that isn't honored quickly is one of the most expensive compliance failures.
Step 3: Permitted calling hours and each country's do-not-call registry
Two controls prevent most complaints: calling only within reasonable time windows, and not calling anyone who asked not to be called. Both are configured, not improvised. And both vary by country, so the setup must be per-market, not global.
On hours: define conservative contact windows per country and apply them based on the number's real time zone, not your office's. Avoid early mornings, meal times, late evenings, and local holidays. When in doubt, narrow the window; an off-hours call generates complaints even when everything else is flawless.
On exclusion: each country typically has its own do-not-call or advertising-exclusion registry, and you must also maintain your own internal removal list. Steps: (1) locate the applicable official registry in each market and its lookup procedure; (2) scrub your lists against that registry before every campaign, not just once; (3) keep a permanent internal suppression list of everyone who asked to be removed; (4) apply both filters (official and internal) at dial time; (5) record the date of the last scrub so you can prove it. Do not assume one country's registry covers another.
Step 4: Human oversight and handoff, the AI never decides alone
A responsible setup always keeps a human in the loop. The AI qualifies, schedules, and handles the repetitive work, but there are moments when it must hand control to a person, and that handoff has to be smooth and designed in advance.
Define explicit escalation triggers. At minimum: (1) the caller asks to speak with a person; (2) it detects a complaint, vulnerability, or distress; (3) a question arises outside the assistant's scope; (4) there is a legal request (opt-out, data access, complaint); (5) the caller seems confused about talking to a machine. Any of these should open a handoff, not a loop of the AI insisting.
The handoff must preserve context: the person receiving the call sees who the contact is, what has been said, and where things stand, without asking them to repeat everything. Good practices: keep human coverage during the windows you call in, define escalation routes by case type and time of day, and periodically review transcripts of escalated calls to tune the triggers. Vendrava is built with this human oversight included, so the assistant knows when to pass the call along instead of forcing an automated resolution.
Step 5: Recording and traceability, with consent and an audit trail
Recording brings quality, training value, and proof of compliance, but it is one of the areas with the most divergent rules across countries. Some require one-party consent, others all-party consent. Never enable recording globally without verifying the market.
Configure recording like this: (1) include the recording notice in the opening, alongside the AI disclosure; (2) where explicit consent is required, do not continue or record until you get a clear "yes"; (3) if the person declines recording, have defined what the system does (continue without recording, or close politely); (4) apply the rule of the caller's country, not yours; (5) log the recording decision in the call record itself.
Traceability goes beyond the audio. For each call, keep a queryable trail: timestamp, number, outcome, notices given (AI and recording), consents, human escalations, and any opt-out. This traceability is what turns a compliance claim into something you can demonstrate in an audit or a complaint. Also define how long you keep recordings and transcripts, and purge on that schedule instead of accumulating indefinitely.
Step 6: Data handling and the final pre-launch checklist
Everything above generates personal data, and that data must be handled under the data protection rules applicable in each market. The operational principles are cross-cutting: collect only what the purpose needs, use it only for what was consented to, keep it only as long as necessary, protect it, and make it easy to exercise rights (access, correction, removal).
Have the rights flow ready: if someone asks during the call to access or delete their data, the assistant should acknowledge the request, log it, and route it to the appropriate human process, without promising what it cannot deliver. Also watch data transfers between countries and to vendors: every vendor that touches the data (telephony, AI, CRM) must be covered by an appropriate agreement.
Final checklist before launching each campaign: (1) per-country table complete (data, do-not-call, hours, recording, AI); (2) AI and recording disclosures in the opening, in the right language; (3) lists scrubbed against official and internal registries with a recent date; (4) immediate opt-out live and tested; (5) human handoff with defined triggers and active coverage; (6) traceability and retention periods configured; (7) final review with your legal counsel per market. If any point fails, don't launch: in compliance, the cost of waiting is always lower than the cost of repairing.

