# The Suppression Scrub Standard: Clearing a List to Send

*You can grade any campaign list as cleared-to-send or held against a fixed set of suppression sources and produce the timestamped audit record that defends the call.*

- Canonical URL: https://www.refolk.ai/guides/suppression-scrub-standard
- Pillar: Process, data, and compliance
- Format: Standard
- Published: 2026-09-13
- Last reviewed: 2026-09-13
- Reading time: 15 min

Before an outbound campaign goes out, someone has to certify that nobody on the list is a person you are legally or contractually forbidden to contact. This guide is the definition of done for that certification, written for revenue operations, recruiting operations, and anyone answerable for how a list was cleared. Read it and you can grade any campaign list as cleared-to-send or held against a fixed set of suppression sources, and produce the timestamped audit record that defends the decision if it is ever challenged.

This is deliberately the opposite move from a deletion. Guides on processing erasure requests and purging data whose basis expired tell you how to remove a record. Suppression tells you how to keep a minimal do-not-contact record so a suppressed person is never re-acquired and re-mailed. Getting those two backwards is the single most common way a compliant-looking team re-mails someone who asked to be left alone.

## What "cleared to send" actually means

A list is cleared to send only when every do-not-contact source is current and every match against those sources has been removed and reasoned. Anything short of that is held. There is no partial credit, and no "we'll fix it after the first batch."

The reason to set the bar this high is not caution for its own sake. It is that the controlling federal standard is itself all-or-nothing. The Telemarketing Sales Rule safe harbor requires five elements: written compliance procedures, personnel training, monitoring and enforcement, scrubbing against the registry within 31 days before each call campaign, and reliance on the current registry version. All five must be documented and provable. Miss any one and the safe harbor is gone. A grading standard that lets a list pass with four of five would certify something the FTC would not.

So the pass/hold call rests on two questions, and both must be yes:

- **Currency.** Is every suppression source current as of send? The National Do Not Call Registry pull must be no more than 31 days old. State lists and internal opt-outs must reflect the live source of truth, not last month's batch.
- **Coverage.** Has every record on the campaign list been matched against every source, on every identifier, with a reason code on every removal?

> **Rule:** The bar is documentation, not intent
>
> The safe harbor is a documentation test, not a good-faith test. The FTC has rejected safe harbor claims where sellers bought the registry list but could not show written procedures, training records, or monitoring evidence. The audit record is the control, not a byproduct of it.

## The suppression sources every list is graded against

A list is graded against five source classes, unified into one master keyed on email and phone. A suppression list must be unified across campaigns, brands, and platforms; without centralization, opt-outs slip through the gaps and expose the business to liability.

The five classes:

1. **Internal opt-outs.** Every unsubscribe and STOP you have ever received, from any channel.
2. **Honored objections.** GDPR and UK GDPR Article 21(3) direct-marketing objections, retained as suppression rather than deleted.
3. **Statutory registries.** The National Do Not Call Registry.
4. **State lists.** Separate state registries such as Florida's, which telemarketers must suppress against in addition to the national list.
5. **Ownership and relationship conflicts.** Internal exclusion lists for existing customers, partners, and accounts owned by another team.

Internal opt-outs arrive from more places than most teams inventory. Capture every one: email footers, SMS replies, IVR menus, branch requests, web forms, mobile apps, and contact center scripts. An opt-out that lands in a channel you do not sweep is an opt-out you will violate.

#### The suppression master, outermost first

1. **Internal opt-outs** - unsubscribes and STOPs from every channel you operate
2. **Honored objections** - GDPR Article 21 direct-marketing objections retained as suppression
3. **Statutory registries** - the National Do Not Call Registry, pulled within 31 days
4. **State lists** - separate registries such as Florida's, for in-scope numbers
5. **Ownership conflicts** - customers, partners, and accounts owned by another team

*Every campaign list is graded against all five layers, unified on email and phone.*

The point of collapsing these into one master is that the dialer, the SMS platform, and the CRM all need to check the same source of truth. If those systems drift apart, one team keeps calling a number another team already excluded. The master is the thing that stops drift.

## What each regime costs when you get it wrong

The per-unit math is the whole argument for grading before send rather than apologizing after. At $53,088 per message with no statutory cap tied to revenue, a mid-size non-compliant send outruns most legal reserves. This is not a rounding error you absorb.

**$53,088 - CAN-SPAM maximum penalty, per email**

Increased from $51,744 effective January 17, 2025, with no cap tied to revenue.

| Regime | Max penalty | Unit |
|---|---|---|
| CAN-SPAM | $53,088 | per email |
| TCPA (standard) | $500 | per call/text |
| TCPA (willful) | $1,500 | per call/text |
| DNC registry | $43,792 | per violation (snapshot) |
| GDPR Art. 21 | €20M or 4% turnover | per infringement |

Two things about this table matter for grading. First, willful TCPA violations are trebled to $1,500, so a knowing send is three times the exposure of a careless one, which is exactly why an undocumented process is worse than none. Second, the DNC registry figure is a snapshot; treat it as indicative and confirm the current FCC number before you cite it in a policy. The largest CAN-SPAM penalty on record, Verkada's $2.95M settlement in August 2024, shows the per-message math is not theoretical.

Note two boundaries the dossier is explicit about. CAN-SPAM does not provide a private right of action for individual consumers, so enforcement there is regulatory. TCPA does, and it carries no cap on statutory damages, which is why text and call campaigns deserve the tighter controls.

## The timing clocks you are grading against

Currency is not one deadline; it is a set of clocks, and the strictest applicable one governs. A record that is clean on the loosest clock can still fail the standard.

| Requirement | Clock | Source |
|---|---|---|
| DNC registry re-scrub | within 31 days before call | FTC Q&A |
| CAN-SPAM honor opt-out | 10 business days | FTC guide |
| FCC list-level opt-out | 10 business days | LeadCompliant |
| FTSA internal DNC | 30 days | leadgen-economy |
| GDPR direct-marketing suppression | near-immediate | Legiscope |

There is a genuine disagreement in the sources about which control is primary. Some treat immediate suppression at the moment of capture as the main defense, with the pre-send scrub as backup. The FTSA and FCC line pushes near-immediate suppression. The TSR frames the 31-day scrub as the campaign gate. In practice you want both, and you should resolve the conflict toward the stricter reading: a revocation should suppress the number from your automated queue immediately, not wait for a month-end batch update. The pre-send gate then catches anything the live suppression missed.

> A record clean on the loosest clock can still fail the standard; the strictest applicable rule sets the bar.

## How to run the scrub, step by step

The procedure below is the operational spine of the standard. Run it in order. Each step has a done condition that a second person could verify independently.

#### The suppression scrub, in order

1. **Assemble suppression sources** - Pull internal opt-outs, honored GDPR objections, the National DNC download, state DNC lists such as Florida, and internal exclusion lists into one deduplicated master keyed on email and phone.
2. **Timestamp the registry pull** - Record the date and time of the National DNC download; it must be no more than 31 days old at send. Log the actual download date, not the subscription.
3. **Normalize and match the campaign list** - Match on all identifiers, not just the address used for this send, so every record resolves against the master by both email and phone.
4. **Apply suppression and tag reasons** - Remove matches and attach a reason code per record - opt-out, objection, registry, EBR conflict, or ownership - leaving a held or cleared flag on every row.
5. **Run the pre-send gate** - The sending platform checks the final audience against current suppression at release, until there are zero suppressed records in the audience.
6. **Produce the audit record** - Freeze a timestamped snapshot of who scrubbed, against which sources and versions, and counts held versus cleared, as an exportable dated certificate.
7. **Grade and decide** - Mark cleared-to-send only if all sources are current and all matches removed; otherwise hold, and record the pass or hold decision.

The gate at step five is what separates this from a store-the-opt-outs-somewhere approach. The practical standard is higher than storing opt-outs: the system has to check every outbound event against current suppression rules before a message, call, or audience sync goes out. A "cleared" report generated before the nightly sync ran is a false pass.

Finding the people who actually own this work inside a target organization is its own sourcing problem, and it is the kind of question you can ask in plain English rather than reverse-engineering from job titles.

I ran this search: `Revenue operations managers at US B2B SaaS companies with 200 to 1,000 employees who list marketing compliance or GDPR.` - [see the full result list](https://www.refolk.ai/s/73wr9wrsg9).

*Returns the operators who own suppression and consent inside mid-market SaaS, the people who would adopt this standard as policy.*

Refolk turns that description into a named list without you writing a boolean string, which is the point: you describe the seat, not the keywords.

## The per-record fields that make a decision defensible

A suppression entry defends the decision only if it carries identifier plus provenance. The minimum is the contact identifier, plus when and how the opt-out was captured, the channel or source, where the suppression was applied, and which campaigns respected it.

#### What a defensible suppression entry records

1. **Capture** - when and how the opt-out occurred, with a timestamp and source
2. **Apply** - where the suppression was written, so the CRM, ESP, and dialer agree
3. **Respect** - which campaigns suppressed or respected this contact
4. **Audit** - an exam-ready record that survives a challenge

*Provenance is what lets a second person reconstruct and defend the exclusion later.*

Be honest about the limit here. There is no single federal statute enumerating exact field names for a suppression record. The field set above is best-practice guidance drawn from practitioner tooling, not a codified schema. That gap is not established publicly, so state it in your own policy rather than implying a legal mandate. What is firm: an entry missing timestamp, channel, and source cannot defend the decision, so reject it.

**Minimum suppression record schema**

```
identifier_email:        person@example.com
identifier_phone:        +1XXXXXXXXXX
captured_at:             2025-01-01T14:32:00Z
capture_channel:         sms_reply | email_footer | web_form | ivr | contact_center | branch
reason_code:             opt-out
applied_in:              crm, esp, dialer
last_verified_at:        2025-01-01T14:32:00Z
retain_until:            longest-applicable (TSR 5y / VA 10y / GDPR indefinite)
```

*Adopt as your table definition. Add fields, never remove these five. reason_code is one of: opt-out, objection, registry, ebr_conflict, ownership.*

## How much to keep, and for how long

Retain each suppression entry to the longest window that applies to any contact on the list. The strictest applicable rule sets the floor, the same way it does for timing.

| Rule | Minimum retention | Source |
|---|---|---|
| TSR call/records | 5 years | NatLawReview |
| Virginia STOP/UNSUBSCRIBE | 10 years | AvairAI |
| GDPR suppression entry | as long as needed to honor the preference | ICO |

Virginia's 10-year floor, effective January 1, 2026, is twice the federal TSR five-year floor, and it is the practical governing number for any US text program with Virginia contacts. On the GDPR side, the retention rule is a minimisation rule: hold just enough information about the person to ensure their preference not to receive direct marketing is respected in future, mark it clearly so it is not processed for purposes they objected to, and keep the request date, the specific processing objected to, the outcome of the assessment, and a record of the final communication sent.

> **Note:** Retention is a floor, not a schedule to purge on
>
> These numbers are minimums. A suppression entry exists precisely so the person is never re-contacted, so purging it early defeats its only purpose. When your general retention policy fires, the suppression record is the one thing that should survive it.

## How this goes wrong

Most suppression breaches are operational drift, not intent. The recurring pattern is mundane: a volunteer uploads an old spreadsheet whose consent nobody can verify, and the opt-out list from a previous vendor never gets migrated. This section is the part of the standard worth the most, because a clean-looking list fails in specific, repeatable ways.

- **Address-only matching.** Scrubbing on the email actually used misses the same person under a second address or phone. The dialer, SMS platform, and CRM need the same source of truth; if they drift, one team calls a number another already excluded. Check: match on every identifier, email and phone.
- **Deleting instead of suppressing.** A GDPR erasure that wipes the record lets the person be re-acquired from a fresh lead source and re-mailed. Check: suppression must preserve the email and phone in a do-not-contact list to prevent re-onboarding.
- **Stale registry pull.** A download older than 31 days silently breaks the safe harbor even if everything else is right. Check: the logged download date, not "we have a subscription."
- **Federal-only scrub.** Relying on the National DNC misses state lists; a Florida record can be clean federally yet suppressed under FTSA. Check: suppress against state lists for in-scope numbers.
- **Month-end batch lag.** Waiting for a nightly or monthly sync means live queues keep hitting opted-out people, and a "cleared" report generated before the sync ran is a false pass. Check: the pre-send gate reads current suppression at release.
- **Vendor hand-off gap.** A migrated opt-out list that never transfers is a classic breach. Check: reconcile counts across the old and new platforms before the first send on the new one.
- **Assuming B2B email is exempt.** Teams treat cold B2B as outside CAN-SPAM; it is not. Check: every commercial B2B email carries opt-out and suppression duties.
- **No provenance on the entry.** A suppression record without timestamp, channel, and source cannot defend the decision. Check: reject any entry missing those fields.

> **Watch out:** The false pass to watch for
>
> The most dangerous outcome is not a held list. It is a list marked cleared by a report that ran before the live suppression synced. If your certificate can be produced without the pre-send gate having run against current data, your certificate is decorative.

The two variables that decide most of these failures are how fresh your sources are and how completely you match. It helps to see them as a grid.

#### Grading a list on freshness and match completeness

Horizontal axis runs from sources stale to sources current. Vertical axis runs from partial match to full multi-identifier match.

| Quadrant | What it means |
| --- | --- |
| Stale + partial | Held. Re-pull sources and re-match on all identifiers before regrading. |
| Current + partial | Held. Sources are fine, but address-only matching is leaking people; re-match on email and phone. |
| Stale + full | Held. Matching is sound, but the registry or state list is past its clock; re-pull and regrade. |
| Current + full | Cleared to send. Freeze the audit record and record the pass. |

*Only the top-right cell is cleared to send; everything else is held.*

## The clearance checklist

Run this before you call any list cleared. If any item is unchecked, the list is held, not cleared.

#### Cleared-to-send verification

- [ ] The National DNC download is logged and dated within 31 days of send.
- [ ] All applicable state DNC lists (for example Florida) have been suppressed against for in-scope numbers.
- [ ] Internal opt-outs from every channel - email, SMS, IVR, web, app, branch, contact center - are in the master.
- [ ] GDPR Article 21 objections are suppressed, not deleted, and clearly marked.
- [ ] The campaign list was matched on both email and phone, not the send address alone.
- [ ] Every removed record carries a reason code: opt-out, objection, registry, EBR conflict, or ownership.
- [ ] The pre-send gate ran against current suppression and returned zero suppressed records in the final audience.
- [ ] Counts reconcile across CRM, ESP, and dialer, including any migrated vendor list.
- [ ] A timestamped audit certificate records who scrubbed, against which sources and versions, and held-versus-cleared counts.
- [ ] The pass or hold decision is recorded against that certificate.

## Keeping the standard current

A suppression standard decays because the rules underneath it move, so schedule a review rather than treating this as set-and-forget. Three mechanisms will change the numbers in this guide, and each has a way to re-check it.

- **Inflation-adjusted federal penalties** are reissued by the FTC, which is how CAN-SPAM moved from $51,744 to $53,088. Re-check the FTC's annual penalty notice and update Table A.
- **State mini-TCPA laws** keep tightening; Virginia's 10-year retention takes effect January 1, 2026, and others follow their own timelines. Re-check state coverage whenever you add contacts in a new state.
- **Court interpretation is loosening from the FCC.** After McLaughlin v. McKesson on June 20, 2025, district courts are no longer bound by FCC TCPA interpretations, so the safe reading may diverge by circuit. When you rely on an FCC interpretation, confirm it still holds where you operate.

Deliverability is now entangled with compliance too. The Google and Yahoo bulk-sender rules made one-click unsubscribe a deliverability requirement, so an unsubscribe you fail to honor now costs you inbox placement on top of legal exposure. Treat suppression as a growth control, not just a legal one, and the standard defends itself. The last move is the one people skip: once you have this working, source the operators who own it. A search like data protection officers in the UK who have worked on suppression lists or Article 21 objection handling, run through [Refolk](/), returns the exact people who can be held accountable for grading a list the same way twice.

## Frequently asked questions

### Does CAN-SPAM apply to cold B2B email?

Yes. CAN-SPAM applies to any electronic mail message whose primary purpose is commercial advertisement or promotion, and it makes no distinction between business-to-business and business-to-consumer email. Treating cold B2B outreach as exempt is one of the most common and expensive mistakes, because each violating message carries a penalty of up to $53,088. Every commercial B2B email carries opt-out and suppression duties, full stop.

### How often do I have to re-scrub against the National Do Not Call Registry?

Under the FTC Telemarketing Sales Rule safe harbor, you must access the registry no more than 31 days before calling any consumer and keep records documenting it. This 31-day interval has applied since January 1, 2005, replacing the earlier quarterly rule. The clock is on the download date, not on holding a subscription, so log the actual pull date and reject any list whose registry data is older than 31 days at send.

### Should I delete a record when someone objects to marketing, or suppress it?

Suppress it. Deleting the record removes the identifier and lets the person be re-acquired from a fresh lead source and re-mailed. GDPR Article 21(3) treats the direct-marketing objection as absolute, and the ICO confirms a controller may hold a suppression list for compliance purposes. Retain just enough information to honor the preference, mark it clearly so it is never processed for the objected purpose, and never re-onboard it.

### How long must I keep suppression and opt-out records?

The strictest applicable rule sets the floor. The amended TSR requires keeping records for five years. Virginia, effective January 1, 2026, requires honoring a texted STOP or UNSUBSCRIBE for at least ten years. GDPR suppression entries are held for as long as needed to keep honoring the preference. Because a federally clean record can still be a state violation, retain to the longest window that applies to any contact on your list.

### What fields make a suppression record defensible in an audit?

At minimum, the identifier plus its provenance: when and how the opt-out was captured, the channel or source, where the suppression was applied, and which campaigns respected it. Practitioner tooling documents timestamps and opt-out sources as the baseline for exam-ready reporting. There is no single federal statute enumerating exact field names, so this is best-practice guidance rather than a codified schema. Reject any entry missing timestamp, channel, and source.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/suppression-scrub-standard*
