TCPA Compliance Guide for Lead Buyers
By Marcus Brown
TCPA compliance for lead buyers means verifying that every lead you contact was obtained with prior express written consent naming your business specifically. Fines run $500–$1,500 per violation. This guide covers what lead buyers must do legally, what to demand from vendors, and how DEUS's exclusive delivery model reduces your exposure.
- $1,500 maximum statutory fine per willful TCPA violation — per call or text
- January 27, 2025: FCC one-to-one consent rule effective date — shared marketplace consent now prohibited
- $500K–$76M range of published TCPA class-action settlements against lead buyers and callers (WebRecon, FCC enforcement records)
What Is TCPA and Why Does It Apply to Lead Buyers?
TCPA (Telephone Consumer Protection Act): A federal law enacted in 1991 and significantly tightened in 2024 that restricts unsolicited calls, texts, and faxes to consumers — and holds the calling party liable, not just the lead generator.
If you buy a lead and call it, you are the calling party in the eyes of the FCC. Ignorance of how the lead was generated is not a defense. The 2024 FCC one-to-one consent ruling, effective January 27, 2025, eliminated the "co-registration loophole" where a single consent checkbox could authorize dozens of sellers. Each seller must now be individually named at point of consent.
What the 2024 FCC One-to-One Consent Rule Changed
Before January 2025, a lead form could bundle consent for an entire network of buyers. After the ruling:
- Consent must name your business specifically.
- The consumer's request must be logically and topically related to the website where consent was given.
- Blanket marketplace consent is prohibited.
This single change made shared lead models legally hazardous overnight. Buying from a vendor who sells the same lead to 5 buyers is no longer just a quality problem — it's a TCPA exposure problem.
TCPA Violation Costs: What Lead Buyers Actually Pay
| Scenario | Per-Violation Fine | Class-Action Exposure |
|---|---|---|
| Negligent violation (no consent) | $500 | $500 × call volume |
| Willful violation (knew and called anyway) | $1,500 | $1,500 × call volume |
| Typical class-action settlement (small buyer) | — | $500K–$5M |
| Typical class-action settlement (mid-market) | — | $5M–$76M |
| FCC enforcement action | Up to $10,000/day | Ongoing |
Sources: FCC enforcement records, TCPA litigation tracker (WebRecon), published settlement data.
One lead list purchased from a non-compliant vendor, called 2,000 times, equals $1M–$3M in theoretical willful-violation exposure.
What Lead Buyers Must Verify Before Calling Any Lead
Prior Express Written Consent (PEWC): The specific, documented agreement a consumer provides — in writing, including electronic signature — authorizing a named company to contact them via autodialer or prerecorded message.
As a lead buyer, you must be able to prove PEWC exists for every contact. Here is the minimum documentation checklist:
| Compliance Checkpoint | What to Demand from Your Vendor |
|---|---|
| Consent timestamp | Exact date/time in UTC with IP address |
| Consent language | Full verbatim disclosure text naming your company |
| Source URL | The exact landing page where consent was captured |
| Jornaya or TrustedForm token | Third-party consent certificate tied to that session |
| Opt-out record | Confirmation the number is not on your DNC list |
| TCPA-compliant opt-in confirmation | Evidence consumer initiated the request |
If a vendor cannot provide all six, do not call the lead.
How Exclusive Leads Reduce TCPA Exposure
Exclusive lead: A consumer inquiry sold to exactly one buyer, with consent documentation naming that buyer — never resold, never shared.
Shared leads create two compounding TCPA risks:
- Consent bundling: The original form likely used a catch-all disclosure that no longer satisfies the 2024 one-to-one rule.
- Call stacking: Multiple buyers calling the same number within hours constitutes harassment under FCC guidance, increasing willful-violation risk for every caller.
At DEUS, every lead is captured on our own landing pages with disclosure language that names the receiving buyer at the moment of delivery — not a network, not a marketplace. One lead, one buyer, one consent record. See how our lead generation model works and why exclusivity is the baseline, not an upsell.
Internal DNC Compliance: What Lead Buyers Must Maintain
TCPA compliance is not just a vendor problem — it's an ongoing operational requirement for your sales team.
Do-Not-Call (DNC) list: A registry (federal, state, or internal) of numbers that have opted out of solicitation calls. Calling a number on your internal DNC list after an opt-out request is a per-call TCPA violation.
| DNC Requirement | Frequency | Who Is Responsible |
|---|---|---|
| Scrub against National DNC Registry | Before every campaign | Lead buyer |
| Maintain internal DNC list | Ongoing, real-time updates | Lead buyer |
| Honor opt-outs within 30 days (federal) | Per request | Lead buyer |
| Honor opt-outs within 10 days (some states) | Per request | Lead buyer |
| State-specific DNC lists (FL, TX, IN, etc.) | Per campaign geography | Lead buyer |
Florida, Texas, and Indiana maintain independent state DNC registries with separate registration and scrubbing requirements. If you operate in those states, federal compliance alone is insufficient.
Consent Certificate Platforms: Jornaya vs. TrustedForm
Consent certificate: A time-stamped, session-level record generated by a third-party platform that documents exactly what a consumer saw, typed, and agreed to at the moment they submitted a lead form.
| Platform | What It Captures | Litigation Defensibility |
|---|---|---|
| Jornaya LeadiD | Full session replay, keystroke data, consent timestamp | High — accepted in TCPA litigation |
| ActiveProspect TrustedForm | Page snapshot, certificate URL, retention period | High — accepted in TCPA litigation |
| Vendor self-certification only | Vendor's word | Low — insufficient for defense |
DEUS captures TrustedForm certificates on all lead forms. Buyers receive the certificate URL with every lead delivery, giving you an independent, court-admissible record you did not generate yourself.
State-Level TCPA Additions Lead Buyers Must Know
Several states have enacted laws stricter than federal TCPA:
| State | Key Addition | Effective |
|---|---|---|
| California (CCPA/CPRA) | Broader consent and deletion rights, private right of action | 2020/2023 |
| Florida (FTSA) | Prohibits autodialed calls/texts without prior express written consent; $500/call | July 2021 |
| Oklahoma | Extends TCPA-style protections to intrastate calls | 2022 |
| Washington | Restricts robocalls; AG enforcement + private suits | Ongoing |
If you purchase leads for use in Florida, verify that your vendor's consent language explicitly satisfies the Florida Telephone Solicitation Act, which is written more broadly than federal TCPA.
How to Evaluate a Lead Vendor's TCPA Compliance Posture
Before funding any lead vendor account, ask these five questions:
- Are leads shared or exclusive? Shared = post-2025 consent risk.
- Do you capture a TrustedForm or Jornaya certificate for every lead? No = no proof.
- Is your consent language named for my business or for a network? Network = non-compliant under 2024 FCC rules.
- Can I see a sample consent disclosure verbatim? Refusal = red flag.
- What is your dispute and credit policy? No policy = no accountability.
DEUS operates on a prepaid credit model with disputes auto-credited within 24 hours. If a lead arrives with incomplete consent documentation, you get your credit back — no negotiation required. Review our pricing and credit model before you commit a dollar.
Quick Reference: Lead Buyer TCPA Compliance Checklist
| Action Item | Status |
|---|---|
| Confirm leads are exclusive (one buyer) | Required |
| Obtain consent certificate (TrustedForm/Jornaya) per lead | Required |
| Verify consent names your business specifically | Required post-Jan 2025 |
| Scrub against National DNC before calling | Required |
| Maintain internal DNC with real-time updates | Required |
| Check state-specific DNC registries for campaign geos | Required |
| Audit vendor consent language quarterly | Best practice |
| Train sales team on opt-out handling procedures | Best practice |
For a deeper look at how DEUS sources and verifies leads before delivery, see our lead quality standards.
Frequently asked questions
Am I liable for TCPA violations if the lead vendor collected the consent, not me?
Yes. The FCC holds the calling party — the business that places the call — liable for TCPA violations regardless of who generated the lead. You must independently verify that valid prior express written consent exists naming your business before making any contact.
What did the 2024 FCC one-to-one consent ruling change for lead buyers?
Effective January 27, 2025, a single consent cannot authorize multiple sellers. Each lead buyer must be named individually in the consent disclosure at point of opt-in. Shared-lead marketplace models that used bundled consent are now non-compliant under this rule.
What is the maximum TCPA fine per violation?
$1,500 per willful or knowing violation. For an autodialed call campaign touching 1,000 non-consenting numbers, that is $1.5 million in statutory damages before any class-action multiplier.
Do I need to scrub leads against the National DNC Registry even if they opted in?
Yes. An opt-in on a lead form does not override a consumer's National DNC registration for general solicitation calls. You must scrub the number before calling and maintain an internal DNC list that updates in real time as consumers opt out.
What is a TrustedForm certificate and why does it matter?
A TrustedForm certificate is a session-level record generated by ActiveProspect at the moment a consumer submits a lead form. It captures the exact consent language displayed, a page snapshot, and a timestamp — creating a court-admissible record that the consumer saw and agreed to specific disclosure language.
Are exclusive leads automatically TCPA compliant?
Exclusivity alone is not sufficient. An exclusive lead is still non-compliant if the consent language does not name your business specifically, if no third-party certificate was captured, or if the lead's number appears on your internal DNC list. Exclusivity eliminates shared-consent risk; it does not replace the full compliance checklist.