TCPA Compliance for Lead Buyers: What You're Legally Responsible For
By Marcus Brown
TCPA compliance for lead buyers means verifying that every lead you contact gave prior express written consent to be contacted by your specific business—not just the lead generator. Liability follows the caller, not the seller, so due diligence before you dial is non-negotiable.
Looking for pricing and provider comparison? Read the complete TCPA compliance guide for lead buyers →
What TCPA Compliance Means for Lead Buyers
TCPA (Telephone Consumer Protection Act) compliance for lead buyers means confirming that each consumer you call or text gave prior express written consent to receive communications from your company, using an autodialer or prerecorded voice, before any outreach occurs. The FCC and plaintiffs' attorneys hold the caller liable—not the lead vendor—so buying a lead does not transfer legal protection to you.
Penalties: $500 per negligent violation, $1,500 per willful violation. A single bad batch of 1,000 leads can expose you to $1.5 million in statutory damages. Class actions multiply that number fast.
Definition — Prior Express Written Consent (PEWC): A signed agreement, digital or physical, in which a consumer authorizes a specific business (or a clearly named list of businesses) to contact them via autodialer or prerecorded message. Generic consent to "partners" does not satisfy TCPA under the FCC's 2023 one-to-one consent rule.
What Changed with the FCC's One-to-One Consent Rule
In January 2024, the FCC's one-to-one consent rule took full effect. Before this rule, a lead form could bundle consent to dozens of "marketing partners." That practice is now illegal for calls and texts governed by TCPA.
What the rule requires:
- Consent must name your company specifically, or the consumer must select your company individually.
- The consent must be logically and topically related to the website where it was collected.
- Consent obtained through a comparison-shopping site that lists 50 lenders cannot be used by all 50 lenders to auto-dial.
This change fundamentally broke many shared-lead models. If you are buying leads from a vendor who collected consent through a generic comparison form, you may already be holding non-compliant leads. See the Exclusive vs Shared Leads: Complete Comparison to understand why exclusive, single-buyer leads carry dramatically lower TCPA exposure.
The Five Things Lead Buyers Must Verify Before Dialing
1. Consent Timestamp and IP Address
You need documented proof that consent was given, when it was given, and from which IP address. Vendors who cannot produce this data should not be trusted.
2. Consent Language on the Source Page
Request a screenshot or archived copy of the exact opt-in language the consumer saw. It must name your company or describe your category precisely enough to meet "logically and topically related" standard.
3. Time Between Consent and Contact
The FTC and TCPA case law both suggest the older the consent, the weaker your defense. DEUS's operating experience: contact within 5 minutes of consent submission produces the best legal posture and the highest contact rates—those two facts are not a coincidence.
4. Do Not Call (DNC) Registry Scrub
Scrub every lead against the National DNC Registry before calling. Also maintain an internal DNC list and honor opt-outs within 30 days (residential) or immediately (your internal list).
5. TCPA Litigation History of the Lead
Some consumers are "TCPA plaintiffs"—serial litigants who opt in specifically to sue callers. Vendors with litigation-screening tools flag these numbers before delivery. Ask your vendor directly whether they screen for known litigants.
TCPA Liability: Who Pays When Something Goes Wrong
| Scenario | Who Bears Liability |
|---|---|
| You call using an autodialer without documented PEWC | You (the caller) — full exposure |
| Vendor collected consent, but it was generic/bundled | You and possibly vendor — joint exposure |
| Vendor forged or fabricated consent records | Vendor — but you still face defense costs |
| Lead was on National DNC; you didn't scrub | You — strict liability |
| Consumer revoked consent; you called again | You — willful violation, $1,500/call |
| You called a cell number with prerecorded message, no consent | You — regardless of how you got the number |
Source: FCC enforcement actions and published TCPA case law (2019–2024, including Ninth Circuit and Eleventh Circuit decisions).
TCPA Penalty Reference Table
| Violation Type | Statutory Damage per Violation | Class Action Exposure (1,000 calls) |
|---|---|---|
| Negligent TCPA violation | $500 | $500,000 |
| Willful TCPA violation | $1,500 | $1,500,000 |
| State mini-TCPA (e.g., Florida, Oklahoma) | Up to $10,000 | Varies by state |
| TRACED Act robotocall violations | Up to $10,000 + criminal referral | N/A |
Florida's Mini-TCPA (FTSA) and Oklahoma's TCPA equivalent impose higher per-call penalties and lower consent thresholds than federal law. If your leads include consumers in these states, layer state law requirements on top of federal.
How to Structure a Compliant Lead Buying Contract
A vendor contract alone does not protect you from TCPA liability, but it determines whether you have indemnification rights when something goes wrong. At minimum, demand:
- Consent representation and warranty — Vendor warrants that each lead was collected with TCPA-compliant PEWC naming your company (or your category under the one-to-one rule).
- Indemnification clause — Vendor agrees to defend and hold you harmless for consent failures on their end.
- Audit rights — You have the right to request consent records for any lead within a defined window (30–90 days recommended).
- Data retention obligation — Vendor retains consent records for a minimum period (5 years is standard for TCPA defense).
- Replacement/credit for non-compliant leads — Define what happens when a lead fails a DNC scrub or consent audit. DEUS auto-credits disputed leads within 24 hours—that policy exists precisely because compliance failures should not cost buyers twice.
What "Safe Harbor" Actually Means (and What It Doesn't)
Definition — TCPA Safe Harbor: A limited defense available when a caller made a good-faith error despite having established and implemented written TCPA compliance procedures. Safe harbor does not eliminate liability—it reduces willful-violation multipliers.
Safe harbor requires:
- Written compliance policies in place before any calling begins
- Training documentation for everyone who dials
- Evidence of DNC scrub within 31 days of any outreach
- Documented consent verification steps per lead
Safe harbor is a courtroom defense, not a compliance strategy. It reduces damage exposure; it does not prevent lawsuits from being filed or costs from being incurred.
How Shared Lead Models Increase Your TCPA Exposure
When five companies buy the same lead, each company needs documented, named consent from that consumer. Under the one-to-one consent rule, a form that names all five companies is theoretically compliant—but in practice, most shared-lead aggregators were not structured that way.
The practical problem: you rarely see the consent document before you buy. You are trusting the vendor. If the vendor's consent process fails, you are the one making the call, and you are the one who gets sued.
Exclusive leads eliminate the multi-buyer consent problem because there is one buyer named in the consent chain. That is one of the concrete, measurable reasons DEUS operates on an exclusive model—every lead is sold once, to one buyer, in real time. If you are evaluating vendors in this space, the DEUS vs HomeAdvisor: The Exclusive-Lead Alternative comparison covers how shared-model platforms compare on both cost and compliance risk.
Record-Keeping: What You Must Retain and for How Long
TCPA claims have a 4-year statute of limitations under 28 U.S.C. § 1658. Retain the following for at least 5 years:
- Consent records (timestamp, IP, consent language, form URL)
- DNC scrub confirmation logs (date, vendor used, results)
- Call logs (number dialed, time, agent ID, outcome)
- Internal DNC list additions and dates
- Opt-out requests and fulfillment dates
- Vendor contracts and consent warranties
Store these in a system that produces auditable, timestamped exports. Spreadsheets are legally acceptable but fragile. A CRM with immutable logs is better.
Practical Checklist Before Your First Dial
- Vendor has provided consent documentation for this specific lead
- Consent language names your company or your category under one-to-one rule
- Lead has been scrubbed against National DNC Registry (within 31 days)
- Lead has been checked against your internal DNC list
- Lead has been screened for known TCPA litigants (if vendor offers this)
- Your calling platform is configured to respect time-of-day restrictions (8 AM–9 PM consumer's local time)
- Caller ID displays a working number that can receive callbacks
- Agent has been trained on TCPA requirements and can recognize a revocation
For a broader view of due diligence when purchasing leads, see How to Buy Leads Without Getting Burned.
TCPA and B2B Leads: Is Business-to-Business Calling Covered?
TCPA applies to calls and texts to cell phones regardless of whether the recipient is a consumer or a business owner. Calling a business's landline using a prerecorded message has different rules (less restricted), but most B2B outreach today hits mobile numbers.
Practical rule: if you are calling a cell number—even for a business prospect—treat it as TCPA-covered. The number's registration as "business" does not create an exemption. B2B lead buyers in sectors like Lead Generation for Consulting Firms and Lead Generation for Fintech Companies frequently make this mistake and carry more exposure than they realize.
FAQ
Frequently asked questions
Who is liable under TCPA—the lead seller or the lead buyer?
The caller bears primary TCPA liability. If you dial or text a consumer without documented prior express written consent naming your company, you are exposed—regardless of what your lead vendor represented. Vendor indemnification clauses can shift financial responsibility, but they don't prevent lawsuits or legal costs.
Does the FCC's one-to-one consent rule apply to B2B leads?
Yes, if the outreach involves calls or texts to a cell phone. The one-to-one consent rule governs TCPA-covered communications, and TCPA applies to mobile numbers whether the recipient is a consumer or a business professional. Business landlines have narrower TCPA coverage but most B2B contacts are reached on mobile.
How long do I need to keep TCPA consent records?
TCPA claims have a 4-year statute of limitations, so retain consent records, call logs, DNC scrub confirmations, and opt-out documentation for at least 5 years. Records must be retrievable in auditable, timestamped form—not just stored somewhere inaccessible.
What is the difference between a DNC scrub and TCPA consent verification?
A DNC scrub checks whether a number appears on the National Do Not Call Registry or your internal opt-out list—it governs telemarketing solicitation calls. TCPA consent verification confirms the consumer gave prior express written consent to be contacted via autodialer or prerecorded message. Both are required; neither substitutes for the other.
Can I use leads purchased before the January 2024 one-to-one consent rule took effect?
Legally, the one-to-one consent rule applies to consent collected on or after the rule's effective date. Older leads with bundled consent may still be called under older standards, but plaintiffs' attorneys and FCC enforcement will scrutinize when and how consent was collected. When in doubt, re-consent the lead through a compliant opt-in before dialing.
Does buying exclusive leads eliminate TCPA risk?
Exclusive leads significantly reduce TCPA risk because there is only one buyer in the consent chain, making it easier to document and defend named consent. They do not eliminate risk entirely—you still need to verify consent documentation, scrub DNC lists, and follow calling-hour restrictions. But the multi-buyer consent problem that makes shared leads dangerous does not apply.