Compliance9 min read

TCPA compliance for lead buyers: a practical checklist

Liability for an outbound call sits with the caller, not the data supplier. This is the checklist to work through before your first dial — written for buyers, not lawyers.

Key takeaways

  • Liability follows the caller — build your own defence file, don't rely on vendor assurances.
  • Prefer consent that names your company or a tightly described category.
  • Insist suppression is applied at delivery, not at file build time.
  • Retain consent artefacts retrievable by phone number, and decide dialer type per segment.

Start from where the liability sits

The single most important structural fact for a lead buyer is that regulators and plaintiffs pursue the party that placed the call or sent the message. A supplier's assurances are useful evidence and a useful contractual protection, but they do not transfer exposure. Everything else in this checklist follows from that: you are not verifying a vendor's paperwork as a courtesy, you are assembling your own defence file.

None of this is legal advice, and the specifics change with regulation and case law. Treat it as the operational baseline you bring to your own counsel rather than a substitute for them.

Express written consent, and who it names

For regulated marketing calls and texts you need consent that was in writing, that was express rather than inferred, and that identified the party permitted to contact the consumer. The direction of travel in enforcement and litigation has consistently been toward specificity: broad language authorising 'our marketing partners' has become progressively less defensible than language naming the advertiser or a tightly described category.

Practically, this means reading the disclosure attached to the file and asking whether a reasonable consumer would have understood that your company might call. If the answer requires effort to construct, treat the segment as unsuitable for regulated outbound and use it in a channel where the consent clearly applies.

Suppression, applied per delivery

Four suppression layers belong in every outbound program: the national do-not-call registry where applicable to the record type, your own internal do-not-contact list, commercially available litigator and serial-plaintiff suppression, and complainant history. The critical detail is timing. Suppression applied when a file was built months ago is worthless; it has to be applied close to delivery, and re-applied if you hold a file before dialing.

Ask suppliers directly whether screening happens at build time or at delivery time. It is a one-sentence question that reliably distinguishes an operating data business from a reseller passing files along untouched.

Retention, dialer choice and internal discipline

Retain the consent artefact for every record you contact, for as long as your counsel advises, in a form you can retrieve by phone number within minutes. A defence that depends on reconstructing where a lead came from is not a defence. Keep the supplier's delivery manifest, the consent fields, and your own contact logs joined by a stable identifier.

Then make a deliberate decision about dialing technology per segment rather than globally. Some records support automated dialing comfortably; others should be dialed manually or worked by email only. Also enforce the boring internal controls: honour opt-out requests immediately across every channel and every list, respect calling-time windows in the consumer's own time zone, identify your company at the start of each call, and never re-import a suppressed record because it appeared in a newer file.

Written by the HottestData desk. For counts, samples and pricing on any segment discussed here, see lead types or the data catalogue.

Ready to buy sweepstakes leads?

Data is sold by email only. Tell us the volume, geo and vertical you need and we'll confirm availability and send a quote.

hottestdata@proton.me