TCPA Compliance for Lead Buyers
Updated 2026-08-28
The agent who makes the call carries the risk. Not the vendor, not the publisher who ran the ad, not the upline who recommended the source. If a consumer complains or sues over a call you placed, you are the defendant.
This is not legal advice. It is a working summary written for agents, and the rules change through regulation and court decisions. Talk to a lawyer who handles telemarketing compliance before setting your policies, and talk to your carriers about their requirements.
What the TCPA covers for lead buyers
The Telephone Consumer Protection Act governs calls and texts to consumers, with the strictest requirements applying to marketing calls and texts made with automated technology or prerecorded messages to mobile numbers.
The pieces that matter to an agent buying leads:
- Prior express written consent is generally required for marketing calls and texts placed with an autodialer or an artificial or prerecorded voice
- The National Do Not Call Registry restricts marketing calls to registered numbers absent consent or an established business relationship
- Internal do-not-call lists are required, and requests to stop must be honored promptly and permanently
- Calling hours are restricted, generally to 8am through 9pm in the consumer's time zone
- Identification requirements: state your name, your business, and a callback number
- State laws frequently add stricter requirements, including their own registries, tighter hours, and additional consent rules
Damages are statutory and are assessed per call or text, which is why a modest list problem can become a very large number quickly. That structure also supports a professional plaintiff industry that seeds phone numbers into lead forms specifically to generate calls.
Two consequences for how you buy. First, the consent record attached to a lead is the product's most important attribute. Second, cheap leads with no documented consent are not cheap.
What valid consent looks like
Consent is a document, not a checkbox someone described to you on a sales call. For a purchased lead, a defensible consent record generally includes:
- The exact disclosure text the consumer saw, verbatim, as rendered on the page
- A screenshot or archived copy of the form page as it appeared on that date
- The URL where the form was submitted
- Timestamp of submission, with time zone
- IP address of the submitting device
- The consumer's entered data, including the phone number as typed
- The named party or parties authorized to call
- Confirmation that consent was not a condition of purchase and that the checkbox was not pre-checked
Weak consent looks like: a disclosure buried in a link, a checkbox already ticked, a page that says "our marketing partners" with a list of hundreds of companies behind another link, or a vendor who can tell you consent exists but cannot produce the page.
Ask for the full record on a random sample from your first order. Every legitimate internet lead vendor can produce it within a day or two. This one request separates serious operations from resellers who never had the documentation in the first place.
Store what you receive. If a claim arrives eighteen months later, your defense is the file you kept, not the vendor's goodwill.
One-to-one consent and why naming matters
Regulatory attention in recent years has focused hard on the practice of a single consumer form producing consent for dozens or hundreds of unnamed "marketing partners." The direction of travel, across both regulation and litigation, has been toward requiring that consent identify the specific seller who will be calling, and that the call relate to what the consumer actually asked about.
The rulemaking around one-to-one consent has been contested, revised, and litigated, so the precise state of any given requirement changes. What has not changed is the risk profile: consent that names you specifically, on a form about the product you sell, is far more defensible than consent buried in a partner list.
Practical implications when buying:
- Prefer leads where the disclosure names your agency, or where the vendor operates a branded site the consumer clearly engaged with
- Ask how many parties the consent authorized. If the answer is a list you cannot read on one screen, price the risk accordingly
- Check topical match. Consent obtained on a page about a government benefit does not sit comfortably behind a life insurance sales call
- Avoid consent chains you cannot trace. If the vendor bought the lead from someone who bought it from someone else, ask each step to be documented
- Watch for consent that has aged. A form submitted three years ago is a weak foundation for a call today
Ask your own lawyer how these developments apply to your operation. Do not rely on a vendor's characterization of the rules, since they are describing the compliance posture of the product they want to sell you.
DNC scrubbing and internal lists
Consent from a lead form does not eliminate your do-not-call obligations, and it does not cover a number the consumer later asked you to stop calling.
Operationally:
- Register for access to the National DNC Registry as required for your operation, and scrub before dialing
- Scrub every purchased file, including aged files, before it enters the dialer, not once a quarter
- Maintain an internal do-not-call list covering everyone who has asked you to stop, across all channels
- Honor stop requests immediately and permanently, and make sure your dialer, texting platform, and CRM all share the suppression
- Check state registries where they exist, since several states maintain their own
- Consider a litigator and complainant suppression service. Many agents use one, and it removes known professional plaintiffs from your files
- Document your scrubbing. Keep dated logs showing which file was scrubbed against what, and when
A common failure is the second phone platform. An agent scrubs the dialer carefully and then sends texts from a separate tool that never received the suppression list. Every platform you can reach a consumer from must consume the same do-not-call data.
Another common failure is the handoff. If a lead moves from you to a downline agent or an assistant, the suppression status has to move with it. Build that into how records transfer.
What to demand from every vendor
Put these in the order form or a written agreement before your first purchase:
- Full consent records on request, including the disclosure text, form URL, timestamp, and IP, retained for a defined period
- A named retention period, ideally covering at least the statute of limitations relevant to your exposure, which your lawyer can specify
- Disclosure of the traffic source and of every party in the chain between the consumer and you
- A representation that leads are DNC-scrubbed at the point of generation, and a statement of what that scrub covered
- Indemnification for claims arising from the vendor's collection practices. Read the carve-outs, since most indemnities are narrower than they look
- Prompt notification if a lead source is later found to be non-compliant, and credit for affected records
- Cooperation clause requiring the vendor to produce records promptly if you receive a claim
- No co-registration paths unless disclosed, since co-reg is where the widest consent lists usually originate
Then keep your own copies. A vendor's retention promise is worth nothing if the company is gone in two years, which happens routinely in this industry. Download and archive consent records for every lead you actually call, at the time you call it. Storage is cheap. Reconstruction after a claim is not possible.
Building a defensible operation
The goal is not perfection. It is being able to show, quickly and in writing, that you had a real process and followed it.
A minimum practical program:
- A written calling policy covering hours, identification, consent standards, and stop-request handling
- Consumer time zone enforcement in your dialer, not just your own local hours
- Recorded consent archived per lead, downloaded from the vendor, stored by you
- Dated scrub logs for every file
- A single internal do-not-call list consumed by every calling and texting platform you use
- Training records if you have staff or downline agents dialing on your behalf
- A complaint intake process so a consumer complaint reaches you rather than being handled ad hoc by whoever answered
- Annual review with counsel, since the rules move
Be conservative on the specific things that generate complaints: calls placed outside the consumer's hours, repeated calls after a stop request, texts to numbers with no texting consent, and calls to very old records. Those account for a large share of the complaints agents actually face.
Again, none of this is legal advice. Have a lawyer who works in this area review your policies and your vendor agreements before you rely on them.
Questions agents ask
- Am I liable if the vendor obtained consent improperly?
- You placed the call, so you are generally the party a consumer pursues. Vendor indemnification may help afterward but it does not prevent the claim, and it is only as good as the vendor's solvency. This is not legal advice; consult a telemarketing compliance attorney.
- Does buying a lead mean I have consent to text it?
- Not automatically. Texting consent depends on what the disclosure said and what the consumer agreed to. Read the actual consent language before you enable texting on a lead source.
- How long should I keep consent records?
- Longer than you think, and at minimum through the limitations period relevant to your exposure, which your attorney can identify. Download and archive them yourself rather than relying on the vendor to still exist later.
- Do I still need to scrub against DNC if the lead consented?
- Scrub anyway. Consent can be revoked, records can be wrong, and your internal do-not-call obligations are separate. Scrub every file before it enters the dialer, including aged files.
- What are calling hours based on?
- Generally the consumer's local time zone, not yours, and several states impose narrower windows. Configure your dialer to enforce it automatically rather than relying on agents to check.
- Is a checkbox on a form enough?
- It depends entirely on what the disclosure said, whether it was pre-checked, and who it named. A clear, unchecked box with plain language naming the calling party is far stronger than a partner list behind a link. Ask a lawyer about your specific sources.
Where this applies
Keep reading
More guides