TCPA Compliance for Lead Buyers: What You're Legally Responsible For

By Marcus Brown

TCPA compliance for lead buyers means verifying that every lead you contact gave prior express written consent to be contacted by your specific business—not just the lead generator. Liability follows the caller, not the seller, so due diligence before you dial is non-negotiable.

Looking for pricing and provider comparison? Read the complete TCPA compliance guide for lead buyers →

What TCPA Compliance Means for Lead Buyers

TCPA (Telephone Consumer Protection Act) compliance for lead buyers means confirming that each consumer you call or text gave prior express written consent to receive communications from your company, using an autodialer or prerecorded voice, before any outreach occurs. The FCC and plaintiffs' attorneys hold the caller liable—not the lead vendor—so buying a lead does not transfer legal protection to you.

Penalties: $500 per negligent violation, $1,500 per willful violation. A single bad batch of 1,000 leads can expose you to $1.5 million in statutory damages. Class actions multiply that number fast.


Definition — Prior Express Written Consent (PEWC): A signed agreement, digital or physical, in which a consumer authorizes a specific business (or a clearly named list of businesses) to contact them via autodialer or prerecorded message. Generic consent to "partners" does not satisfy TCPA under the FCC's 2023 one-to-one consent rule.


What Changed with the FCC's One-to-One Consent Rule

In January 2024, the FCC's one-to-one consent rule took full effect. Before this rule, a lead form could bundle consent to dozens of "marketing partners." That practice is now illegal for calls and texts governed by TCPA.

What the rule requires:

This change fundamentally broke many shared-lead models. If you are buying leads from a vendor who collected consent through a generic comparison form, you may already be holding non-compliant leads. See the Exclusive vs Shared Leads: Complete Comparison to understand why exclusive, single-buyer leads carry dramatically lower TCPA exposure.


The Five Things Lead Buyers Must Verify Before Dialing

1. Consent Timestamp and IP Address

You need documented proof that consent was given, when it was given, and from which IP address. Vendors who cannot produce this data should not be trusted.

2. Consent Language on the Source Page

Request a screenshot or archived copy of the exact opt-in language the consumer saw. It must name your company or describe your category precisely enough to meet "logically and topically related" standard.

3. Time Between Consent and Contact

The FTC and TCPA case law both suggest the older the consent, the weaker your defense. DEUS's operating experience: contact within 5 minutes of consent submission produces the best legal posture and the highest contact rates—those two facts are not a coincidence.

4. Do Not Call (DNC) Registry Scrub

Scrub every lead against the National DNC Registry before calling. Also maintain an internal DNC list and honor opt-outs within 30 days (residential) or immediately (your internal list).

5. TCPA Litigation History of the Lead

Some consumers are "TCPA plaintiffs"—serial litigants who opt in specifically to sue callers. Vendors with litigation-screening tools flag these numbers before delivery. Ask your vendor directly whether they screen for known litigants.


TCPA Liability: Who Pays When Something Goes Wrong

Scenario Who Bears Liability
You call using an autodialer without documented PEWC You (the caller) — full exposure
Vendor collected consent, but it was generic/bundled You and possibly vendor — joint exposure
Vendor forged or fabricated consent records Vendor — but you still face defense costs
Lead was on National DNC; you didn't scrub You — strict liability
Consumer revoked consent; you called again You — willful violation, $1,500/call
You called a cell number with prerecorded message, no consent You — regardless of how you got the number

Source: FCC enforcement actions and published TCPA case law (2019–2024, including Ninth Circuit and Eleventh Circuit decisions).


TCPA Penalty Reference Table

Violation Type Statutory Damage per Violation Class Action Exposure (1,000 calls)
Negligent TCPA violation $500 $500,000
Willful TCPA violation $1,500 $1,500,000
State mini-TCPA (e.g., Florida, Oklahoma) Up to $10,000 Varies by state
TRACED Act robotocall violations Up to $10,000 + criminal referral N/A

Florida's Mini-TCPA (FTSA) and Oklahoma's TCPA equivalent impose higher per-call penalties and lower consent thresholds than federal law. If your leads include consumers in these states, layer state law requirements on top of federal.


How to Structure a Compliant Lead Buying Contract

A vendor contract alone does not protect you from TCPA liability, but it determines whether you have indemnification rights when something goes wrong. At minimum, demand:

  1. Consent representation and warranty — Vendor warrants that each lead was collected with TCPA-compliant PEWC naming your company (or your category under the one-to-one rule).
  2. Indemnification clause — Vendor agrees to defend and hold you harmless for consent failures on their end.
  3. Audit rights — You have the right to request consent records for any lead within a defined window (30–90 days recommended).
  4. Data retention obligation — Vendor retains consent records for a minimum period (5 years is standard for TCPA defense).
  5. Replacement/credit for non-compliant leads — Define what happens when a lead fails a DNC scrub or consent audit. DEUS auto-credits disputed leads within 24 hours—that policy exists precisely because compliance failures should not cost buyers twice.

What "Safe Harbor" Actually Means (and What It Doesn't)

Definition — TCPA Safe Harbor: A limited defense available when a caller made a good-faith error despite having established and implemented written TCPA compliance procedures. Safe harbor does not eliminate liability—it reduces willful-violation multipliers.

Safe harbor requires:

Safe harbor is a courtroom defense, not a compliance strategy. It reduces damage exposure; it does not prevent lawsuits from being filed or costs from being incurred.


How Shared Lead Models Increase Your TCPA Exposure

When five companies buy the same lead, each company needs documented, named consent from that consumer. Under the one-to-one consent rule, a form that names all five companies is theoretically compliant—but in practice, most shared-lead aggregators were not structured that way.

The practical problem: you rarely see the consent document before you buy. You are trusting the vendor. If the vendor's consent process fails, you are the one making the call, and you are the one who gets sued.

Exclusive leads eliminate the multi-buyer consent problem because there is one buyer named in the consent chain. That is one of the concrete, measurable reasons DEUS operates on an exclusive model—every lead is sold once, to one buyer, in real time. If you are evaluating vendors in this space, the DEUS vs HomeAdvisor: The Exclusive-Lead Alternative comparison covers how shared-model platforms compare on both cost and compliance risk.


Record-Keeping: What You Must Retain and for How Long

TCPA claims have a 4-year statute of limitations under 28 U.S.C. § 1658. Retain the following for at least 5 years:

Store these in a system that produces auditable, timestamped exports. Spreadsheets are legally acceptable but fragile. A CRM with immutable logs is better.


Practical Checklist Before Your First Dial

For a broader view of due diligence when purchasing leads, see How to Buy Leads Without Getting Burned.


TCPA and B2B Leads: Is Business-to-Business Calling Covered?

TCPA applies to calls and texts to cell phones regardless of whether the recipient is a consumer or a business owner. Calling a business's landline using a prerecorded message has different rules (less restricted), but most B2B outreach today hits mobile numbers.

Practical rule: if you are calling a cell number—even for a business prospect—treat it as TCPA-covered. The number's registration as "business" does not create an exemption. B2B lead buyers in sectors like Lead Generation for Consulting Firms and Lead Generation for Fintech Companies frequently make this mistake and carry more exposure than they realize.


FAQ

Frequently asked questions

Who is liable under TCPA—the lead seller or the lead buyer?

The caller bears primary TCPA liability. If you dial or text a consumer without documented prior express written consent naming your company, you are exposed—regardless of what your lead vendor represented. Vendor indemnification clauses can shift financial responsibility, but they don't prevent lawsuits or legal costs.

Does the FCC's one-to-one consent rule apply to B2B leads?

Yes, if the outreach involves calls or texts to a cell phone. The one-to-one consent rule governs TCPA-covered communications, and TCPA applies to mobile numbers whether the recipient is a consumer or a business professional. Business landlines have narrower TCPA coverage but most B2B contacts are reached on mobile.

How long do I need to keep TCPA consent records?

TCPA claims have a 4-year statute of limitations, so retain consent records, call logs, DNC scrub confirmations, and opt-out documentation for at least 5 years. Records must be retrievable in auditable, timestamped form—not just stored somewhere inaccessible.

What is the difference between a DNC scrub and TCPA consent verification?

A DNC scrub checks whether a number appears on the National Do Not Call Registry or your internal opt-out list—it governs telemarketing solicitation calls. TCPA consent verification confirms the consumer gave prior express written consent to be contacted via autodialer or prerecorded message. Both are required; neither substitutes for the other.

Can I use leads purchased before the January 2024 one-to-one consent rule took effect?

Legally, the one-to-one consent rule applies to consent collected on or after the rule's effective date. Older leads with bundled consent may still be called under older standards, but plaintiffs' attorneys and FCC enforcement will scrutinize when and how consent was collected. When in doubt, re-consent the lead through a compliant opt-in before dialing.

Does buying exclusive leads eliminate TCPA risk?

Exclusive leads significantly reduce TCPA risk because there is only one buyer in the consent chain, making it easier to document and defend named consent. They do not eliminate risk entirely—you still need to verify consent documentation, scrub DNC lists, and follow calling-hour restrictions. But the multi-buyer consent problem that makes shared leads dangerous does not apply.

← All posts