CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
List Source Vetting

How to get customer database?

Back to InsightsHow to get customer database?

How to get customer database?

Key Facts

  • A single non-compliant campaign to 50,000 contacts can create $25 million in TCPA statutory exposure per compliance analysis.
  • TCPA class actions filed through mid-2025 were up nearly 95% year-over-year according to compliance guidance.
  • Since January 27, 2025, FCC rules require prior express written consent to name each seller individually per TCPA analysis.
  • Do Not Call Registry violations carry penalties of up to $43,792 per call or text per TCPA compliance research.
  • UnitedHealthcare settled TCPA allegations for $2.5 million, and the FCC proposed a $6 million forfeiture over AI-voice calls per enforcement reporting.
  • Call lists must be scrubbed against the National Do Not Call Registry at least every 31 days per TCPA compliance guidance.
  • Salesforce bluntly advises businesses building first-party databases: "Don't ask for something for nothing" per its data analysis.

Why Most Bought Lists No Longer Support Outbound Calls

That bargain contact list with 50,000 "verified leads" might be the most expensive purchase your business ever makes. A single campaign against it can create millions of dollars in legal exposure — before your team makes a single useful call.

The core problem is the FCC's one-to-one consent rule, effective January 27, 2025. Under this rule, prior express written consent must name each seller individually. A blanket form where a consumer agreed to hear from "insurance providers" or "financial services companies" no longer protects anyone who calls that lead. As compliance guidance puts it plainly: consent obtained through a lead generator or third party cannot be used by multiple downstream businesses, and it does not transfer across brands or affiliates.

Buying leads is still legal — but the rule shifted who carries the consent risk onto the caller, and the TCPA lets plaintiffs sue you directly. Indemnification clauses from aggregators offer limited protection. The numbers explain why this matters so much:

  • TCPA statutory damages run $500 to $1,500 per violating call, and a single 50,000-person campaign can create $25 million in exposure before willfulness multipliers.
  • Do Not Call Registry violations carry penalties of up to $43,792 per call or text.
  • TCPA class actions filed through mid-2025 are up nearly 95% year-over-year, and plaintiffs' attorneys are actively working bought-list cases.

Litigation outcomes make the stakes concrete. UnitedHealthcare settled TCPA allegations for $2.5 million, and the FCC proposed a $6 million forfeiture over AI-voice calls in late 2024 — a category that now includes AI-generated voices treated as artificial voices under the TCPA.

This is why non-vetted lists get declined before any campaign spends a dollar. Nearly every TCPA case turns on whether the defendant can prove valid consent existed at the time of each call — and most can't. A purchased list rarely arrives with the timestamp, IP address, and exact consent language naming your company that courts expect.

That's why My AI Call Center checks list source and consent records before any campaign launches, and flags — and in most cases declines — bought lists without clear permission records. It's better to hear "this list won't support the campaign" before launch than to discover the same thing through a class-action complaint afterward.

Build, Don't Buy: The First-Party Database Strategy That Actually Works

The fastest way to get a customer database in 2026 is also the most dangerous: buying one. The compliant — and ultimately more valuable — path is building your own from people who actually chose to hear from you.

The regulatory line is now explicit. Under the FCC's one-to-one consent rule, effective January 27, 2025, prior express written consent must name each seller individually, so blanket consent forms no longer protect lead buyers. As Infobip's TCPA compliance guidance puts it, consent obtained through a lead generation form or third party "cannot be used by multiple downstream businesses. Each brand must obtain its own consent directly."

The stakes for getting this wrong are concrete. TCPA statutory damages run $500 per violation, up to $1,500 for willful violations — meaning a single non-compliant campaign to 50,000 contacts can carry $25 million in statutory exposure before trebling. TCPA class actions filed through mid-2025 were up nearly 95% year-over-year.

First-party data is information customers volunteer — and people volunteer it when they get something in return. Salesforce's guidance is blunt: "Don't ask for something for nothing." The proven value-exchange tactics include:

  • Loyalty programs — points, perks, and personalized discounts in exchange for contact details and preferences
  • Referral programs — existing customers introduce new ones, with consent captured at the source
  • Memberships and subscriptions — recurring value that keeps the relationship (and the data) current
  • Interactive content — quizzes, assessments, and tools that trade a useful result for an email or phone number
  • Email and phone capture with clear disclosure — an affirmative opt-in (never a pre-ticked box), plain language about what you'll send, and a documented record of when and how consent was captured

These tactics work because, as Salesforce's first-party data analysis notes, "how they behave with your content is always going to matter more than how they behave with anyone else's." You collect less total data — but far more relevant data.

For clinics, franchises, and membership businesses, the best database usually already exists: your own patient, customer, and member records. These contacts have a real relationship with your organization, which makes them both compliant to contact and far more likely to respond. According to customer acquisition research, transparency in data usage fosters trust and strengthens brand credibility — something a purchased list can never provide.

One important distinction: enriching known customer records is not the same as acquiring new contact lists. Appending details to your existing customers' profiles carries a different risk profile than buying outbound lists of strangers. The latter is where consent risk has shifted decisively to the buyer, since the TCPA lets plaintiffs sue the caller directly.

This is exactly why My AI Call Center reviews list source and consent records before any campaign launches — and declines bought lists without clear permission records, telling you plainly before you spend anything. A database you build is a database you can defend.

Before a single dial goes out, every contact list should survive four blunt questions. This audit framework, recommended by compliance specialists at LeadCompliant, has become the practical standard for vetting any lead source — and it takes minutes to run.

Question one: When did the consumer consent? You need a specific date, not a vague "recently." Consent older than 30 days should be checked against the Reassigned Numbers Database, since numbers change hands and consent does not travel with them, according to Infobip's TCPA compliance guidance.

Question two: What exact language did they see? Not a paraphrase — the actual form text. Valid consent requires an affirmative opt-in action (pre-ticked boxes do not count), clear disclosure, and a statement that consent is not a condition of purchase.

Question three: Did it name your company? This is where most purchased lists collapse. Under the FCC's one-to-one consent rule effective January 27, 2025, prior express written consent must name each seller individually. As Infobip puts it, consent obtained on a comparison shopping site or lead generation form cannot be used by multiple downstream businesses — each brand must obtain its own consent directly.

Question four: Is there a timestamp and IP address proving it? This is the litigation question. "Nearly every case turns on whether the defendant can prove valid consent existed at the time of each call or text. Most can't," notes LeadCompliant's analysis of TCPA enforcement. With statutory damages of $500 per violation and up to $1,500 for willful violations, a missing timestamp is an expensive gap.

The rule is simple: if any question cannot be answered with documentation, do not call the list. This is exactly why My AI Call Center reviews list source and consent records before any campaign launches — and tells you plainly if the list will not support the campaign, before you spend anything.

If your organization still relies on third-party leads, three compliant models are emerging that can pass this audit:

  • Real-time lead pings with consent certificates. The buyer's name is dynamically inserted into the consent form before submission, and a timestamped consent record travels with the lead. LeadCompliant calls this "the cleanest setup." Contracts should require each lead to arrive with the consumer's IP address, timestamp, exact form URL, and consent language naming your company.
  • Pre-call consent verification. An SMS or email confirmation goes out before an agent ever dials, re-establishing a documented permission trail on your own terms.
  • Shifting to inbound and owned-list marketing. Build the database from your own customer relationships — loyalty programs, referrals, memberships, and value-exchange content — where the consent trail is self-controlled from day one.

The third option is where the market is heading. Salesforce's first-party data research frames it directly: legislation and an increasingly data-conscious audience have ended third-party data as a viable primary source, making volunteered first-party data the crucial asset for modern marketers.

Whichever model you choose, the audit stays the same. Four questions, documented answers, no exceptions. A list that cannot pass it is not an asset — it is exposure you have not been billed for yet.

List Hygiene Is Ongoing: Scrubbing, Opt-Outs, and DNC Discipline

A clean list on day one can be a liability by day thirty. People change numbers, revoke consent, and file DNC complaints — which is why list hygiene is an ongoing operational obligation, not a checkbox you tick before launch.

The federal rules are specific. Call lists must be scrubbed against the National Do Not Call Registry at least every 31 days, and internal opt-outs honored within 30 days — though waiting the full window is poor practice, since honoring opt-outs in real time is the operational standard. According to compliance guidance on 2026 TCPA rules, registry access runs $79 per area code per year, a modest cost compared to the exposure of skipping it.

Beyond the federal registry, a disciplined scrub covers several layers:

  • National Do Not Call Registry, scrubbed at least every 31 days
  • State DNC lists, since state rules stack on top of federal requirements
  • Internal suppression lists, so a customer who opted out of one campaign never gets called in the next
  • The Reassigned Numbers Database, checked whenever consent is older than 30 days — a number may now belong to someone who never consented

The stakes are real. DNC Registry violations can run up to $43,792 per call or text, and TCPA statutory damages sit at $500 per violation — up to $1,500 for willful breaches, per a TCPA compliance guide. TCPA class actions filed through mid-2025 were up nearly 95% year-over-year, so enforcement risk is growing, not fading.

There is also a carry-over rule that many operators miss: a DNC request isn't scoped to one campaign. If someone opts out during a renewal call, that request must be respected across every future campaign and carried into your permanent DNC records. Fragmented campaign management is where this discipline breaks down.

This is exactly why ongoing hygiene is built into a managed campaign, not handed to the client. At My AI Call Center, scrubbing, suppression, and DNC carry-over happen as part of running the campaign — opt-outs are logged and honored immediately, and DNC requests are respected across all campaigns and carried into client DNC records. Every deliverable includes opt-out and DNC logs, so you can see the work, not just trust it.

One caveat worth stating plainly: requirements vary by location, industry, and consent status, and this article is operational guidance, not legal advice. Clients should obtain appropriate legal guidance before launch. But the operational principle holds everywhere — a compliant list is a maintained list, and maintenance is a recurring deliverable, not a one-time step.

If you'd rather not own that maintenance cycle yourself, the first campaign review is free — you can bring your list, get a plain answer on whether it will support the campaign, and know the full cost before anything launches.

From Vetted List to Live Campaign: Your Step-by-Step Launch Path

A vetted list is only useful if it launches cleanly into a campaign that runs on your terms. One clear goal — confirm, qualify, remind, survey, retain, connect — sets the scope, the script, and the price before a single dial is placed. The FCC's one-to-one consent rule (effective January 27, 2025) means prior express written consent must name each seller individually, so blanket or shared consent forms no longer protect downstream callers (industry analysis). That makes the list-and-consent review the gate every campaign must pass.

The review checks three things: list source, consent records, and calling windows. If the consent language did not name your company, if there is no timestamp and IP address tied to the opt-in, or if the list was purchased without those records, the campaign does not launch — we tell you plainly if the list will not support the campaign, before you spend anything. This aligns with the emerging standard that consent documentation is the decisive factor in TCPA litigation: "Nearly every case turns on whether the defendant can prove valid consent existed at the time of each call or text. Most can't" (compliance guidance).

Once the list clears review, outcomes route straight into the CRM and scheduling tools you already run. Hot leads transfer live or land as follow-up tasks. The script, disclosure language, opt-out handling, and escalation path are approved by you — nothing launches until you sign off. Calls run only in approved windows (federal baseline: 8 a.m.–9 p.m. local time at the called party's location, with state-specific quiet hours layered on top) (regulatory summary). AI-generated voices are treated as artificial voices under the TCPA, so AI disclosure happens on every call and keyword opt-outs (STOP, REVOKE) are honored immediately.

  • Goal definition → quoted campaign with one clear outcome
  • List source, consent records, and window review → go/no-go before spend
  • CRM connection → outcomes, bookings, follow-ups route back automatically
  • Script and escalation approval → nothing launches until you approve
  • Launch in approved windows → real-time monitoring, disposition reporting, opt-out/DNC logs delivered

Disposition codes (confirmed, qualified, renewed, opted out, no answer), per-call notes, and routed follow-ups come back as a named outcome report with completion and coverage metrics. Calling starts at 9¢ per connected minute, tiered by volume, with the rate locked for the campaign. The first campaign review is free; the full number is known before you approve launch.

Frequently Asked Questions

Is it legal to buy a customer database for outbound calling?
Buying leads is still legal, but the FCC's one-to-one consent rule (effective January 27, 2025) shifted the consent risk onto the caller — and the TCPA lets plaintiffs sue you directly. Under the rule, prior express written consent must name each seller individually, so blanket consent forms no longer protect lead buyers.
What's the safest way to get a customer database in 2026?
Build it from first-party, consent-based collection — loyalty programs, referrals, memberships, and value-exchange content where people opt in directly to hear from you. Salesforce's guidance is blunt: legislation and a data-conscious audience have ended third-party data as a viable primary source, making volunteered first-party data the crucial asset for modern marketers.
How much can calling a bad list actually cost me?
TCPA statutory damages run $500 per violating call and up to $1,500 for willful violations, so a single campaign to 50,000 contacts can create $25 million in exposure before trebling. Do Not Call Registry violations can add up to $43,792 per call or text, and TCPA class actions filed through mid-2025 were up nearly 95% year-over-year.
How do I check whether a list is safe to call?
Run the four-question consent audit: When did the consumer consent? What exact language did they see? Did it name your company? Is there a timestamp and IP address proving it? If any question can't be answered with documentation, don't call the list — nearly every TCPA case turns on proving valid consent existed at the time of each call, and most defendants can't.
Can I still use purchased leads at all?
Yes, but only through compliant models: real-time lead pings where your company's name is inserted into the consent form before submission, or pre-call consent verification via SMS or email before any agent dials. Each lead should arrive with a consent certificate including the consumer's IP address, timestamp, exact form URL, and consent language naming your company specifically, since consent cannot transfer across brands or affiliates.
Does list compliance end once the list is vetted?
No — a clean list on day one can be a liability by day thirty, because people change numbers, revoke consent, and file DNC complaints. Call lists must be scrubbed against the National Do Not Call Registry at least every 31 days, and consent older than 30 days should be checked against the Reassigned Numbers Database, per compliance guidance on 2026 TCPA rules. This is why My AI Call Center builds ongoing scrubbing, suppression, and opt-out logging into every managed campaign.

A Database You Can Defend Is the Only Database Worth Having

Getting a customer database in 2026 comes down to one choice: build it from people who actually chose to hear from you, or buy a list and inherit legal exposure you haven't been billed for yet. With TCPA damages of $500 to $1,500 per violating call and class actions up nearly 95% year-over-year, the math favors building. The path forward is clear: collect first-party data through loyalty programs, referrals, memberships, and honest value exchanges; run every list through the four-question consent audit; and treat hygiene — DNC scrubs, opt-out carry-over, reassigned-number checks — as ongoing maintenance, not a one-time task. If you already have a list and want a straight answer on whether it can support a campaign, My AI Call Center reviews list source and consent records before anything launches — and tells you plainly if it won't, before you spend anything. The first campaign review is free, and calling starts at 9¢ per connected minute with the full cost known upfront. Bring your list, get your answer, and launch on solid ground.

Get campaign planning tips