Guide · Compliance · 13 min read

← All guides

TCPA Compliance for Lead Buyers: What Brokers Must Know

Why brokers who buy business loan leads get sued under TCPA, what consent documentation to demand, and how to reduce your exposure before you dial.


If you buy business loan leads and dial them, TCPA compliance is your problem — not just your vendor's. Liability for a non-compliant call generally lands on whoever placed it, which means a broker can inherit legal exposure baked into a lead long before it hit their CRM.

This article is not legal advice. It's a broker-to-broker briefing on where the risk sits and what to demand from providers. TCPA is a fee-shifting statute with per-call statutory damages, evolving FCC rules, and state-law overlays. Before you build a dialing operation on purchased data, spend the money on a consult with a TCPA attorney. It is dramatically cheaper than the alternative.

Why do lead buyers — not just lead generators — get sued?

Because the buyer makes the calls. The Telephone Consumer Protection Act restricts calls and texts made with automated technology and prerecorded messages, and restricts telemarketing to numbers on the Do Not Call registry. The party with the cleanest exposure to those rules is the party doing the dialing: you.

The chain works like this. A merchant fills out a form somewhere — or doesn't, if the data was scraped. A vendor sells you that record as a lead. Your shop dials it, maybe drops a VM, maybe texts. If the consent behind that record is missing, forged, expired, or doesn't cover your business, every touch is a potential violation, and the plaintiff's lawyer doesn't need to find the vendor. They found you. Your caller ID found them.

Buyers routinely assume the vendor's compliance is their shield. It isn't. "My data broker said it was opted-in" is a fact you'd raise in your defense, not a force field that stops the suit from being filed. And since damages are statutory and per call, a shop hard dialing hundreds of records a day is accumulating exposure at dial speed.

This is also why compliance questions belong inside vendor vetting, not after it. Our guide to vetting a lead provider treats consent documentation as a core due-diligence check, and this article is the deep dive on why.

What is the professional-plaintiff problem?

There is a cottage industry of people who make money by getting called. They seed their phone numbers into lead funnels, keep meticulous logs of every call, text, and VM drop they receive, and then send demand letters or file claims against the callers. Because damages are per call, a number that ends up in circulating lead data can generate claims against every shop that dials it.

This is not a theoretical risk. Brokers on DailyFunder report being targeted, and the threads have a consistent shape: the demand letter arrives, names dates and times of calls, and cites statutory damages that multiply quickly. One detail from those threads should concern every transfer buyer: a broker buying live transfers reported discovering a professional plaintiff among the transfers he had paid for — the "prospect" was delivered to him as a warm, qualified call, and turned out to be someone building a case.

Sit with that one. He didn't scrape a list or blast a dialer. He bought what was sold as a consented, qualified live transfer, and the litigation risk was delivered to him mid-call. It's a sharp illustration that your compliance posture can only be as good as your vendor's funnel — and that "the vendor qualified them" is not the same as "the vendor can document consent." If you're weighing transfers, our breakdown of whether MCA live transfers are worth it covers the economics; this is the legal side of the same purchase.

The professional-plaintiff phenomenon changes the math on sloppy data. On a beat-up list resold across the industry, you aren't just risking wasted dials — you're dialing numbers that may already have claims pending against other shops that called before you.

Does it matter whether I use a dialer or hard dial?

Brokers discuss this constantly, and the distinction is real: TCPA's heaviest provisions target calls made with automated dialing technology and prerecorded or artificial voice messages. That's why shops running power dialers, predictive dialers, and VM drops sit in a different risk category than a rep hard dialing one number at a time from a desk phone.

The way brokers frame it on the forums:

  • Hard dialing — manually keying each call — is treated as the lower-exposure posture, and some shops run manual-dial-only on purchased data for exactly this reason.
  • Automated dialing raises the stakes. Whether a given system legally counts as an autodialer is a moving question that has been litigated for years — which is precisely the kind of question your attorney, not your software vendor, should answer.
  • VM drops (ringless voicemail) are popular in MCA shops and draw particular scrutiny, since prerecorded-message rules are among TCPA's sharpest edges.
  • Texting merchants from your CRM sits under the same consent framework. A text is not a loophole.

Two cautions. First, lower exposure is not zero exposure: DNC rules and state mini-TCPA statutes can reach manually dialed calls too. Second, your actual practices are what get examined — if your "manual" process is a rep clicking through an auto-loaded queue, classification gets murky. Describe your real setup to a TCPA attorney and let them tell you where it lands.

What is the FCC one-to-one consent rule?

For years, lead-gen consent ran on a blanket model: one form, one checkbox, and fine print saying the prospect agrees to be contacted by "our marketing partners" — a linked list that could run to hundreds of companies. That model is what the FCC's one-to-one consent rule was aimed at: the rule requires prior express written consent for regulated calls and texts to apply to a single identified seller at a time, not an undifferentiated partner list.

For lead buyers, the practical implication is blunt: a lead generated under a blanket "partners" opt-in may not constitute valid consent for your calls. When you evaluate a provider, the question to ask is: does the consent behind this lead identify the seller who will actually be calling — and how does your consent flow handle one-to-one?

The rule's precise legal status and application have been contested — court challenges and FCC actions have moved the lines, which is normal for this statute. Do not resolve that from a blog post, including this one. What you can do from a blog post: refuse to buy from vendors whose consent flow is still the 2019-style blanket model, because whatever the current litigation posture, blanket consent to unnamed partners is the weakest paper in the industry.

What consent documentation should I demand from a provider?

A vendor with a real compliance program can produce, per lead:

  • Timestamp of the opt-in.
  • Source URL — the actual page where the form was submitted.
  • The exact consent language the prospect saw, including how the seller was identified.
  • IP address of the submission.
  • A third-party consent certificate — TrustedForm and Jornaya (LeadiD) are the standard services. They capture and store an independent record of the form session, so consent doesn't rest on the vendor's word alone.

Certificates deserve emphasis because they're the one item a vendor can't easily fabricate after the fact. A TrustedForm or Jornaya cert is generated at form-fill time by a script on the landing page; a vendor whose "documentation" is a spreadsheet column that says consent=yes is asking you to take their word for it. Their word is not what you'll be holding when a demand letter arrives.

Ask for the documentation before you buy, and spot-check it after: pull the cert on a handful of leads from every batch and confirm the page, the language, and the timestamps look like what you were promised. Vendors who resell other vendors' data usually fail this check immediately — the consent trail breaks at the first hop, which is one more reason vendor origin matters so much in provider vetting.

One structural note: consent quality correlates with distribution model. A record resold 5–8 times — which competitors' own marketing admits is common — has, at best, a blanket consent stretched across every buyer. An exclusive lead generated for one buyer is where one-to-one consent is even structurally possible. The compliance argument and the close-rate argument for exclusive over shared leads turn out to be the same argument.

What about DNC scrubbing?

The Do Not Call registry is the other half of exposure, and it's the half that reaches even hand-dialed telemarketing calls. Practical posture:

  • Scrub before you dial, every batch. Vendor claims of pre-scrubbed data are only as good as the vendor's process and its recency. Numbers are added to the registry continuously; a scrub from when the data was generated goes stale.
  • Document your scrubs. A dated scrub log is evidence of a compliance process — the kind of artifact that matters when you're showing good faith.
  • Maintain your own internal DNC list. When a merchant says stop calling, that request binds your shop regardless of registry status, and honoring it requires a system, not a rep's memory.
  • Mind state law. Several states run their own DNC regimes and mini-TCPA statutes with their own damages. Multi-state dialing means multi-state exposure — another item for the attorney conversation.

An existing business relationship or a documented opt-in can change the DNC analysis for a given number — but "can change" is doing legal work there, and the fact pattern matters. Default to scrubbing and let your attorney define your exceptions.

What should you ask your provider before buying?

Put these questions in writing and keep the answers.

Question Answer that protects you Answer that exposes you
"How was this lead generated?" Named funnel; can show the landing page and form "Proprietary sources"
"Can you produce per-lead consent records?" Timestamp, source URL, consent language, IP — on request "All our data is opted in"
"Do you use TrustedForm or Jornaya?" Yes — certs available per lead No third-party verification
"How does your consent flow handle the FCC one-to-one rule?" Specific, current answer about seller identification Blank stare or blanket "marketing partners" opt-in
"Is this data DNC scrubbed, and when?" Recent scrub, and they expect you to scrub again "It's all clean" with no date
"Do you generate leads yourself or resell?" Self-generated, consent chain intact Resold data, broken chain
"Will you indemnify buyers for consent defects?" Written clause (and you still verify everything above) No, or evasive
"How do I return a number that demands no contact?" A defined suppression process No process

Notice the pattern: every protective answer is specific and documented; every exposing answer is a vibe. That's the same pattern as quality vetting generally — vendors who can't document consent usually can't document anything else either.

The practical compliance stack for a lead-buying shop

Pulling it together, the posture that brokers and compliance-minded operators converge on:

  1. Buy consent-documented leads only — third-party certs preferred, spot-checked per batch.
  2. Scrub against federal and state DNC before dialing, on your side, every time.
  3. Know how your dialing tech is classified, in writing, from an attorney — especially before running VM drops or texts.
  4. Run an internal suppression list and honor stop requests instantly.
  5. Keep records — consent docs, scrub logs, call logs — organized enough to produce quickly.
  6. Have a TCPA attorney identified before you need one, and route any demand letter straight to them.

None of this makes you bulletproof; professional plaintiffs go after well-run shops too. What it does is shrink the target, and turn a claim you can't defend into one you can.

Where Funders Collective fits

Funders Collective sells exclusive, phone-verified business loan leads generated on our own funnels — so the consent trail is one hop long, documented per lead, and available before you buy, not after a demand letter shows up. If you want purchased leads without inheriting someone else's consent problem, start with a small batch here.

Frequently asked questions

Can I be sued under TCPA for calling leads I bought?
Yes. TCPA liability generally attaches to whoever makes the call, not just whoever generated the lead. If the consent behind a purchased lead is missing, defective, or doesn't cover your business, your outreach can create exposure even though a vendor caused the problem. That's why consent documentation is a purchase requirement, not a nice-to-have.
What is a professional TCPA plaintiff?
A person who deliberately seeds their phone number into lead funnels, logs every call and text they receive, and then files TCPA claims or demand letters against the callers. Brokers on DailyFunder report being targeted this way, including one live-transfer buyer who discovered a professional plaintiff among the transfers he had paid for. Statutory damages accrue per call, which makes volume dialers attractive targets.
What is the FCC one-to-one consent rule?
It's the FCC's requirement that prior express written consent for regulated calls and texts must apply to one identified seller at a time, rather than a blanket opt-in covering a long list of unnamed 'marketing partners.' For lead buyers, the practical question is whether the consent behind a lead names your business or at least a clearly identified seller. Ask every provider how their consent flow addresses it, and have a TCPA attorney review the answer.
What consent documentation should I demand from a lead provider?
Per lead: a timestamp, the source URL where the opt-in happened, the exact consent language the prospect saw, and ideally a third-party certificate such as TrustedForm or Jornaya that captures the form session. A vendor with a real compliance program can produce these on request. A vendor who can't is handing you the liability along with the CSV.
Does hand-dialing leads reduce TCPA risk compared to using a dialer?
Brokers widely treat hard dialing as lower-exposure than automated dialing, because key TCPA provisions target autodialed and prerecorded calls, and technologies like ringless voicemail drops draw additional scrutiny. Lower exposure is not zero exposure — DNC rules and state statutes can still reach manually dialed calls. Get an attorney's guidance on how your specific dialing setup is classified.
Do I need to scrub purchased leads against the DNC registry?
Treat scrubbing as standard practice, yes. A lead vendor's claim that data is 'DNC scrubbed' is only as good as the vendor's process and its recency, and numbers get added to the registry continuously. Running your own scrub before dialing is cheap insurance, and an opt-in from the prospect is a fact you want documented rather than assumed when a number appears on the registry.
What should I do if I get a TCPA demand letter over a purchased lead?
Contact a TCPA defense attorney before responding, and preserve everything: the lead record, the consent documentation from your vendor, call logs, and your purchase agreement. Do not negotiate on your own or ignore the letter. Your leverage depends heavily on whether you can produce consent evidence for that specific number, which is exactly why you should collect it at purchase time rather than after a claim arrives.
Is a vendor's indemnification clause enough to protect me?
No. An indemnification clause is only worth what the vendor can pay and is willing to defend, and a thinly capitalized lead shop may simply disappear when claims arrive. Indemnification language is worth negotiating, but your primary protections are upstream: consent documentation, DNC scrubbing, and vetting how the vendor generates its leads in the first place.