General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.
Quick summary
- If a call or message creates an immediate threat or danger, emergency services are the first resource.
- Spam calls, texts, and robocalls are usually regulated through consent, telemarketing, privacy, and consumer-protection rules, but the details depend on where you live and whether the sender is a business, political group, scammer, or debt collector.
- Caller-ID spoofing can make it difficult to identify the sender, but records of the communications can still help with blocking, reporting, or legal action.
What it means
If a call or message creates an immediate threat or danger, emergency services are the first resource. Spam calls, texts, and robocalls are usually regulated through consent, telemarketing, privacy, and consumer-protection rules, but the details depend on where you live and whether the sender is a business, political group, scammer, or debt collector. Caller-ID spoofing can make it difficult to identify the sender, but records of the communications can still help with blocking, reporting, or legal action.
How the law works
How the law usually works
The law generally distinguishes between:
- Marketing communications: Promotions for goods, services, charities, or events.
- Automated calls or messages: Calls using prerecorded voices, artificial or synthesized voices, or automatic dialing systems.
- Transactional messages: Account alerts, delivery notices, appointment reminders, and similar communications.
- Fraud or scams: Attempts to obtain money, passwords, account access, or personal information.
- Harassment or threats: Repeated unwanted contact, intimidation, stalking, or threats of harm.
Consent is a central issue. A business may have permission to contact you because you gave your number, requested information, bought something, or agreed to terms. That permission may be limited by the wording of the agreement, the type of message, and whether you later withdrew consent. Rules often require marketing messages to identify the sender and provide a practical way to opt out.
Do-not-call systems can reduce lawful telemarketing but generally do not stop every call. They may not cover political calls, charities, surveys, debt collection, fraud, emergency notifications, or businesses with whom you have an existing relationship. Scammers may ignore the rules entirely.
Caller ID is not conclusive evidence of who called. Spoofing can display a local number, a government number, or the number of an unrelated person. A fake caller ID does not necessarily make the recipient responsible for the conduct, and it can complicate efforts to identify the actual sender.
Privacy laws may apply when a company collected, shared, or used your phone number improperly. Separate consumer-protection rules may apply when a caller impersonates a bank, government agency, delivery company, or technical-support provider. Repeated communications may also become relevant to harassment or stalking laws, especially when they are directed at one person and include threats.
Common processes
- Preserve evidence. People commonly save screenshots, voicemails, text messages, email headers, caller-ID displays, dates, times, numbers, and the wording of any opt-in or opt-out message. They may keep a short log showing frequency and whether the contact continued after an opt-out request.
- Avoid engaging with suspected scams. People commonly avoid clicking links, opening attachments, sharing passwords or verification codes, sending money, or calling an unfamiliar number from a message. They may independently find the organization’s official contact details rather than using the message.
- Use an opt-out where appropriate. For a legitimate business, people often use the stated unsubscribe method or reply with the permitted opt-out word. They may keep proof of the request. Replying to an obvious scam can confirm that a number is active, so blocking or reporting may be safer.
- Block and filter communications. Phone carriers, operating systems, and messaging services commonly offer spam filters, call screening, and blocking. These tools can reduce contact but generally do not establish who sent a message or prevent all future spoofed calls.
- Report the conduct. Depending on location and subject matter, reports may go to a telecommunications regulator, consumer-protection agency, privacy regulator, do-not-call administrator, police, or the organization being impersonated. A report can support enforcement even when it does not produce an immediate individual remedy.
- Contact the real organization separately. If a message claims to come from a bank, government office, employer, or delivery service, people commonly use a known website or statement to contact that organization. They may ask whether the communication was genuine and report impersonation.
- Consider a legal claim or formal complaint. Some systems allow complaints to regulators, compensation requests, or court claims. The possible remedy depends on proof of the sender, the type of message, consent, the number of contacts, and the local law.
Deadlines and time limits
Deadlines vary substantially. Common examples include:
- A regulator may ask that complaints be made soon after the call or message, particularly if records are needed.
- A business may have an internal complaint period stated in its terms or privacy notice.
- Court claims may be subject to limitation periods commonly ranging from about one to six years, depending on the legal basis and jurisdiction.
- Privacy-access or correction requests often have response periods measured in weeks, while some complaint systems use shorter periods after a final response from the organization.
- Criminal or regulatory investigations may not follow the same limitation period as a private lawsuit.
These are broad ranges, not a deadline for a particular claim. Confirmation with the relevant regulator, court, or a licensed attorney where you live is important.
Documents that usually matter
Useful materials commonly include:
- Screenshots showing the number, sender name, date, time, and message content
- Audio recordings or voicemails, subject to local recording laws
- A call and text log, including repeated or missed contacts
- Proof of consent, such as an online form, contract, account settings, or prior business relationship
- Copies of opt-out or unsubscribe requests and later communications
- Phone bills, carrier records, and messaging-service reports
- The sender’s terms, privacy notice, and marketing preferences
- Evidence of financial loss, identity theft, or account compromise
- A report or reference number from a regulator, carrier, bank, or police service
How it differs by jurisdiction
United States. The Telephone Consumer Protection Act and Federal Communications Commission rules commonly address autodialed calls, prerecorded or artificial-voice calls, and marketing texts. The Federal Trade Commission’s Telemarketing Sales Rule and the National Do Not Call Registry also matter. Political calls, charities, debt collection, informational calls, and emergency-related communications may be treated differently. Some TCPA violations can support a private lawsuit, while other matters are mainly handled through agency enforcement. State laws may impose additional consent, recording, privacy, or anti-spoofing requirements.
England and Wales. The Privacy and Electronic Communications Regulations 2003, commonly called PECR, regulate many unsolicited direct-marketing calls, texts, and emails. The Telephone Preference Service is relevant to certain marketing calls. The Information Commissioner’s Office handles many complaints and enforcement matters. UK data-protection law may also apply to the use of your phone number. Threatening or persistently abusive contact can raise separate criminal or civil issues.
Canada. Canada’s anti-spam law, CASL, generally regulates commercial electronic messages and often requires consent, sender identification, and an unsubscribe mechanism. The Canadian Radio-television and Telecommunications Commission administers the National Do Not Call List and related telemarketing rules. Privacy laws may also apply to collection and use of phone numbers. Rules and enforcement can differ for charities, political parties, surveys, existing business relationships, and non-commercial messages.
Australia. The Spam Act 2003 addresses many commercial electronic messages, while the Do Not Call Register Act 2006 concerns certain telemarketing calls and marketing faxes. The Australian Communications and Media Authority handles much regulatory enforcement, and privacy law may apply to personal information. Scam reporting commonly involves Scamwatch and the Australian Competition and Consumer Commission. State and territory laws may separately address harassment, threats, stalking, or recording conversations.
When people consult a lawyer
Legal advice can be useful when:
- Contact continues after clear opt-out requests or appears targeted and threatening
- You suspect identity theft, financial loss, or misuse of private information
- You want to bring a court claim or respond to a demand from a caller
- The sender is difficult to identify because of spoofing or multiple numbers
- The communications involve employment, debt collection, health information, political activity, or a business dispute
- You need advice about recording calls, preserving electronic evidence, or a limitation deadline
If there is an immediate threat, stalking concern, or risk of physical harm, contact emergency services or local police before focusing on a complaint or lawsuit.
Primary sources
- RegulationUnited States: Telephone Consumer Protection Act, 47 U.S.C. § 227; FCC rules at 47 C.F.R. § 64.1200; Federal Trade Commission, Telemarketing Sales Rule, 16 C.F.R. Part 310; Federal Communications Commission and Federal Trade Commission official consumer pages.United States (federal)
- RegulationEngland and Wales: Privacy and Electronic Communications (EC Directive) Regulations 2003; UK General Data Protection Regulation and Data Protection Act 2018; Information Commissioner’s Office and Telephone Preference Service official pages.England & Wales
- Official sourceCanada: Canada’s Anti-Spam Legislation, S.C. 2010, c. 23; Canadian Radio-television and Telecommunications Commission official National Do Not Call List and telemarketing pages; Office of the Privacy Commissioner of Canada official guidance.Canada
- StatuteAustralia: Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth); Australian Communications and Media Authority, Australian Competition and Consumer Commission, and Scamwatch official pages.Australia
Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →
- Last updated
- Sep 26, 2026
- Jurisdiction
- General — United States, England & Wales, Canada, Australia
- Written by
- House Legal editorial (AI-generated, earlier format)