
TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros
Who can be sued for violations of the TCPA?
Learn who is liable for TCPA violations — lead buyers, sellers, and vendors. Discover how to prove consent, avoid $1,500-per-call penalties, and stay co...

Key Facts
- Lead buyers bear all legal and financial risks of non-compliant outreach according to compliance analysts
- Statutory damages for TCPA violations range from $500 to $1,500 per call or text per legal experts
- The FTC logged more than 2.6 million Do-Not-Call complaints in fiscal year 2025 per lead buyer compliance data
- Vicarious liability means companies can be sued for third-party vendors' actions per Foster's legal alerts
- Contractual indemnification does not insulate either party from statutory TCPA liability per Foster's legal alerts
- The burden of proving valid consent falls on the caller or texter per Orrick's analysis
- Marketing partners receiving leads can be sued and may enforce arbitration clauses per Fourth Circuit precedent
The Liability Chain: Why Buying Leads Doesn't Buy You Legal Cover
Buying leads feels like buying a shortcut — someone else sourced the contact, so someone else should carry the legal risk, right? Wrong. Under the Telephone Consumer Protection Act, the moment you dial or text that lead, the liability chain snaps back to you.
Compliance analysts are blunt about it: lead buyers bear all of the legal and financial risk of non-compliant outreach, and they cannot rely on the seller to have gathered consumer consent. If valid consent wasn't obtained — or can't be verified — the buyer faces complaints or litigation, even when a third-party publisher sourced the lead in the first place.
The burden of proof makes things worse. Under FCC rules, the party who texts or calls must prove consent was valid — meaning defects at the lead-generation stage become your problem the instant you make contact. "I bought it from a vendor" is not a defense.
Many buyers assume their lead-purchase agreement shifts risk back to the seller. It doesn't. The FCC has made clear that companies cannot avoid TCPA liability by outsourcing communications to third parties, and contractual indemnification provisions do not insulate either the company or the vendor from statutory liability. Vicarious liability means both parties can be sued.
The enforcement math explains the exposure. TCPA violations carry statutory damages of $500 to $1,500 per call or text, which makes a single class action involving thousands of class members a genuinely existential threat for a business that bought a non-compliant list. The FTC logged more than 2.6 million Do-Not-Call complaints in fiscal year 2025 alone — plaintiffs' attorneys are not short on raw material.
What a defensible lead-buying operation actually requires:
- Independent verification of consent — never the seller's word alone
- Documented proof: landing page URL, timestamp, and the consumer's experience
- Vendor audits instead of reliance on contract language
- Immediate, cross-channel opt-out honoring within the required window
This is why GrowthPros attaches a consent record — disclosure text, timestamp, IP address, and the named contacting party — to every lead it delivers. The lead seller who can't produce that trail is selling you a lawsuit with a phone number attached. Compliance isn't a clause in your vendor contract; it's proof you can produce in court.
Every Party on the Hook: Buyers, Sellers, Lead Generators, and Vendors
Buying a lead doesn't buy you a liability shield. The party that dials or texts carries the statutory risk — $500 to $1,500 per call or text — and that burden follows the lead buyer even when a third party sourced the contact. ActiveProspect puts it plainly: lead buyers "bear all of the legal and financial risks of non-compliant outreach" and "cannot rely on the lead seller to gather consumer consent."
Vicarious liability extends that exposure upstream and downstream. The FCC has made clear that companies "cannot avoid TCPA liability by outsourcing communications to third parties," and contractual indemnification "does not insulate either the company or the vendor from statutory liability." That means lead generators, sellers, and the vendors who actually place the calls can all be named in the same suit. The consent definition itself authorizes a seller "to deliver or cause to be delivered" marketing messages — language courts read as reaching parties who cause calls, not just those who place them.
- Lead buyers — the caller/texter bears the burden of proving valid consent
- Lead generators and sellers — liable when consent is missing, fabricated, or non-compliant
- Third-party vendors and dialer platforms — directly suable under vicarious liability principles
- Marketing partners receiving leads — the Fourth Circuit in Sessoms held they can be sued and may enforce a lead-gen site's arbitration clause as third-party beneficiaries
The Sessoms ruling matters because it gave marketing partners a procedural defense: if the lead-generation website's terms include arbitration, the partner receiving the lead may compel individual arbitration instead of facing a class action. Greenspoon Marder notes this is "one of the first courts of appeals to directly address" the issue, and that arbitration remains "one of the most effective tools available to defend against these claims."
Regulatory whiplash adds complexity. The FCC's 2023 one-to-one consent rule — which would have required consent for each specific marketing partner — was vacated by the Eleventh Circuit in January 2025, and the FCC's September 2025 final rule removed the requirement entirely. Troutman Pepper observes that plaintiffs will now find it "challenging to prevail on lawsuits alleging one-to-one consent is required." But state mini-TCPA laws in Florida, California, and Washington impose stricter, independent standards, so multi-state operators must comply with the most restrictive applicable rule.
At GrowthPros, we treat consent as a product feature, not a checkbox. Every lead we deliver carries a consent record — disclosure text, timestamp, IP address, and the named contacting party — because the party making the call owns the risk. That's the process.
Why Contracts Can't Save You: Indemnification and the Consent-Shifting Trap
Many businesses assume that signing a contract with a lead generator shields them from TCPA liability — but that assumption is dangerously flawed. Contractual indemnification clauses, while common in lead acquisition agreements, do not insulate either party from statutory liability under the TCPA. As legal experts have clarified, companies cannot avoid responsibility by outsourcing communications to third parties, and both the lead buyer and the vendor remain exposed to lawsuits regardless of what the contract says.
This creates a significant risk for businesses that rely on a lead seller’s assurances about consent validity. Lead buyers bear all legal and financial risks of non-compliant outreach, even when a third party sourced the lead. The burden of proving valid consent falls squarely on the caller or texter — meaning the business placing the call or sending the text must demonstrate compliance, not the lead generator. Relying on a seller’s word is what compliance professionals call the “consent-shifting trap,” and it leaves buyers vulnerable when consent cannot be verified or was improperly obtained.
Adding to this complexity is the ongoing regulatory whiplash surrounding consent standards. The FCC’s 2023 one-to-one consent rule, which would have required lead generators to obtain prior express written consent for each marketing partner individually, was vacated by the Eleventh Circuit in January 2025. The FCC declined to appeal, and its September 2025 final rule formally removed the one-to-one consent requirement. Yet even as federal rules shift, state-level mini-TCPA laws in Florida, California, and Washington continue to impose stricter, independent standards — including narrower calling windows and separate consent obligations. Multi-state operators must comply with the most restrictive applicable standard, creating a patchwork of obligations that cannot be resolved through contractual language alone.
For businesses using lead generation services, this means compliance cannot be outsourced or contracted away. Instead, they must independently verify and document consent, audit vendor practices, and build operational controls into their lead-buying process. GrowthPros supports this approach by delivering leads with full consent records — including disclosure text, timestamp, IP address, and the named contacting party — so buyers can verify compliance at the point of use. Ultimately, no contract can replace the need for proactive, end-to-end compliance when statutory damages of $500 to $1,500 per call or text make TCPA violations a significant financial exposure.
How to Protect Your Business: Verify, Document, and Audit
Proactive compliance starts with treating consent as a verifiable asset, not an assumption. Lead buyers cannot shift liability by relying on a seller’s word; the burden of proving valid express consent falls squarely on the party initiating contact. This means documenting the full consent trail—landing page URL, exact timestamp, disclosure language presented, and a record of the consumer’s affirmative action—is non-negotiable for defending against TCPA claims. GrowthPros builds this verification into every lead delivery, attaching consent records to each lead so buyers retain defensible proof from the moment of acquisition.
Equally critical is auditing vendors rather than accepting contractual assurances at face value. Vicarious liability means businesses can be sued for a third party’s non-compliant actions, and indemnification clauses do not erase statutory exposure under the TCPA. Regular audits should confirm that vendors honor opt-outs within 10 business days across all communication channels, scrub lists against the National Do-Not-Call Registry, and maintain auditable consent records—practices that align with Foster’s guidance on operational controls over reliance on contract language alone.
- Independently verify and document consent for every lead, capturing landing page URL, timestamp, disclosure text, and consumer experience
- Audit vendor practices regularly rather than trusting contractual indemnification to shield against liability
- Honor opt-out requests within 10 business days across SMS, voice, and email, applying the suppression universally
- Review lead-acquisition agreements for enforceable arbitration clauses that may divert class actions to individual arbitration
Honoring opt-outs promptly and comprehensively remains a baseline requirement; the TCPA permits only a one-time confirmation message after opt-out, sent within five minutes and free of promotional content. Finally, scrutinizing lead-acquisition agreements for arbitration provisions can offer strategic protection, as recent Fourth Circuit precedent allows marketing partners to enforce such clauses as third-party beneficiaries, potentially shifting disputes from costly class actions to individual arbitration—a nuance highlighted in Greenspoon Marder’s analysis of effective defense tools. These steps transform compliance from a checkbox into a resilient, evidence-based process.
What Compliant Lead Buying Looks Like in Practice
Liability doesn't vanish at the point of purchase. As ActiveProspect's compliance analysis puts it, lead buyers "bear all of the legal and financial risks of non-compliant outreach" — which means the question isn't just who sold you the lead, but what came attached to it.
The burden of proof is the first thing to understand. Under FCC rules, proving valid consent falls on the caller or texter — the party who received the lead — not the party who generated it, according to Orrick's analysis of the consent rules. A seller's verbal assurance that "everyone opted in" is worthless in court. You need the records yourself.
So what should a compliant lead operation actually hand you with every lead? Here's the baseline to demand:
- A complete consent record attached to every lead — disclosure text, timestamp, IP address, and the named party authorized to contact the consumer.
- DNC-scrubbed lists, verified before any outbound call or text is placed.
- Immediate, permanent opt-out handling across every channel — SMS, voice, and email.
- Capped lead distribution, so a consumer isn't getting bombarded by dozens of buyers from a single form fill.
The opt-out point deserves emphasis. Revocation can be communicated through any reasonable means — STOP, CANCEL, UNSUBSCRIBE — and while the FCC allows up to 10 business days to honor it, a compliant partner treats it as immediate and permanent, per Foster's TCPA best practices. A lead vendor who can't show you their opt-out workflow is a vendor who can hand you a $500–$1,500-per-contact problem.
Distribution caps matter too. The now-vacated 2023 one-to-one consent rule was aimed at exactly the "one consent, hundreds of callers" dynamic — the FCC's original rulemaking described consumers receiving robocalls from "tens, or hundreds" of marketing partners off a single consent. Even after the September 2025 rule change, a lead sold to five buyers generates five times the complaint surface — and the FTC logged more than 2.6 million Do-Not-Call complaints in fiscal year 2025.
This is the standard GrowthPros builds against: every lead delivered with its consent trail attached, DNC-scrubbed before contact, opt-outs honored immediately and permanently, and capped-shared distribution capped at two buyers — never five. If you want to see what a documented, consent-recorded lead actually looks like, the 15-minute qualification call walks you through a real sample, with real numbers, before you commit to anything.
Frequently Asked Questions
If I buy leads from a third party, can I still be sued for TCPA violations?
Yes — lead buyers bear all of the legal and financial risk of non-compliant outreach, and buying a lead doesn't protect you from liability if valid consent wasn't obtained or can't be verified. The moment you dial or text that lead, defects at the lead-generation stage become your problem. "I bought it from a vendor" is not a defense in court.
Can a contract with my lead vendor shield me from TCPA liability?
No. The FCC has made clear that companies cannot avoid TCPA liability by outsourcing communications to third parties, and contractual indemnification clauses do not insulate either party from statutory liability. Vicarious liability means both you and the vendor can be sued regardless of what the contract says. Audit vendor practices and document consent yourself instead of trusting contract language.
Who actually has to prove that consent was valid — me or the lead seller?
You do. Under FCC rules, the burden of proving valid consent falls on the caller or texter — the party who received the lead — not the party who generated it. A seller's verbal assurance that "everyone opted in" is worthless in court; you need the records yourself, including the landing page URL, timestamp, and disclosure language shown to the consumer.
How much can a TCPA violation actually cost my business?
TCPA violations carry statutory damages of $500 to $1,500 per call or text, which makes a single class action involving thousands of class members a genuinely existential threat for a business that bought a non-compliant list. The FTC also logged more than 2.6 million Do-Not-Call complaints in fiscal year 2025 alone, so plaintiffs' attorneys are not short on raw material.
Besides the lead buyer, who else can be named in a TCPA lawsuit?
Practically everyone in the chain: lead buyers, lead generators and sellers, third-party vendors and dialer platforms, and marketing partners receiving leads. The consent definition itself authorizes a seller "to deliver or cause to be delivered" marketing messages — language courts read as reaching parties who cause calls, not just those who place them. In the Fourth Circuit's Sessoms ruling, a marketing partner receiving a lead was sued but allowed to enforce the lead-gen site's arbitration clause as a third-party beneficiary.
Is the FCC's one-to-one consent rule still in effect?
No. The FCC's 2023 one-to-one consent rule — which would have required consent for each specific marketing partner — was vacated by the Eleventh Circuit in January 2025, and the FCC's September 2025 final rule removed the requirement entirely. However, state mini-TCPA laws in Florida, California, and Washington impose stricter, independent standards, so multi-state operators must still comply with the most restrictive applicable rule.
The Bottom Line: Liability Follows the Dialer
TCPA liability doesn't respect your vendor contracts. As we've seen, lead buyers, generators, sellers, and third-party vendors can all be named in the same suit — and with statutory damages of $500 to $1,500 per call or text, a single class action is an existential threat, not a line item. The burden of proving valid consent falls on whoever dials or texts, indemnification clauses offer no statutory shield, and shifting FCC rules alongside stricter state mini-TCPA laws mean the only durable defense is operational: independently verified consent, documented proof, vendor audits, and immediate opt-out handling. That's exactly why GrowthPros attaches a consent record — disclosure text, timestamp, IP address, and the named contacting party — to every lead it delivers, with DNC scrubbing and capped distribution baked in. If you're buying leads without a verifiable consent trail, you're carrying risk someone else created. Book the 15-minute qualification call to see what a documented, consent-recorded lead actually looks like — real samples, real numbers, no commitment.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.