
Is buying leads legal?
Key Facts
- The FCC's December 2023 rules do not prohibit buying leads — but they closed the lead generator loophole, per Cooley LLP's analysis.
- One-to-one consent took effect January 27, 2025, according to Heyflow's regulatory overview.
- TCPA statutory damages reach $1,500 per violating call or text, warn Cooley LLP attorneys.
- California charges data brokers a $6,600 annual registration fee and fines unregistered brokers $200 per day, per McLane Middleton.
- Lead generation services 'will almost always meet the definition' of a data broker under state privacy laws, notes McLane Middleton.
- Experts recommend keeping consumer consent records for a minimum of five years, per ActiveProspect.
- A well-documented response shuts down roughly 25% of TCPA threat letters at the initial stage, according to attorney Michele Shuster.
The Short Answer: Legal, But the Rules Changed
Yes, you can still buy leads in the United States — but whether those leads are safe to call is an entirely different question, and the answer changed dramatically in late 2023.
The FCC was explicit on the first point: its new rules "do not restrain comparison shopping or prohibit parties from purchasing leads from lead generators," according to Cooley LLP's analysis of the December 2023 order. What the FCC did do was close what practitioners call the "lead generator loophole" — the practice where a single consumer consent could cover a sprawling list of marketing partners, leaving people fielding calls from companies they had never heard of.
Three changes matter most for anyone buying leads:
- One-to-one consent — prior express written consent must now authorize no more than one identified seller at a time, with no affiliate exception, as the FCC's order makes clear.
- The end of "daisy-chain" partner sharing — consent to pass a consumer's information along a chain of unnamed "partners" is no longer permitted.
- DNC Registry protections extended to text messages, effective 30 days after Federal Register publication, per the same Cooley analysis.
The one-to-one consent rule carried a January 27, 2025 effective date, with a 12-month transition period for the broader changes. Worth noting: the landscape is still evolving, and some industry observers report a shift back toward a "clear and conspicuous" disclosure standard — a reminder that this area keeps moving and legal guidance specific to your situation matters.
Here is the tension at the heart of the new rules: the legality of a purchased lead no longer hinges on what the seller claims. It hinges on what you can prove. As ActiveProspect puts it bluntly: "If the seller can't show you where traffic comes from, what the consumer saw, and how consent is documented, you're not buying leads, you're buying risk." A lead without proof is a potential liability for both parties.
The stakes are real. The TCPA's private right of action carries statutory damages up to $1,500 per violating call or text, and the new rules, in Cooley's words, "surely will provide new ammunition for an aggressive plaintiffs' bar."
This is why list source vetting has become the practical dividing line between usable leads and legal exposure. My AI Call Center checks list source and consent records before any campaign launches, and bought lists without clear permission records are flagged — in most cases, declined. The seller's word is no longer enough; the documentation is the product.
Why Consent Documentation Is the Real Product
Most buyers focus on lead price and volume. The real product is the paper trail behind each record. A lead without proof is a liability for both parties, not an asset. True TCPA compliance means being able to answer with evidence: who is authorized to contact the consumer, how, what they agreed to, when and where consent happened, and how to audit that consent event. If the seller can't show you where traffic comes from, what the consumer saw, and how consent is documented, you're not buying leads, you're buying risk.
The FCC's December 2023 order closed the lead generator loophole and established one-to-one consent as the standard — prior express written consent must authorize no more than one identified seller at a time, with no affiliate exception and no daisy-chain partner sharing. The statutory damages make documentation non-negotiable: up to $1,500 per violating call or text through the TCPA's private right of action, and the new rules "surely will provide new ammunition for an aggressive plaintiffs' bar." State data broker laws add another layer — California alone imposes a $6,600 annual registration fee and $200 per day for failure to register.
When vetting a lead source, ActiveProspect flags four red flags that should stop a deal cold:
- Proprietary or secret traffic sources the seller won't disclose
- Inability to show the actual forms and disclosures the consumer saw
- Proof limited to screenshots or "trust us" assurances
- Unstable lead IDs that can't be traced back to a consent event
My AI Call Center runs every list through this same lens before a campaign launches. Bought lists without clear permission records are flagged and in most cases declined — we tell you plainly if the list will not support the campaign before you spend anything. The consent review checks list source, consent records, and calling windows so that every outbound call runs on approved, permissioned, or reviewed contacts only. That discipline is what keeps a campaign useful instead of expensive.
The Hidden Compliance Layer: Data Broker Laws
Most lead buyers assume the TCPA is the whole compliance picture. There's a second layer underneath it that almost nobody checks: state data broker laws, and lead generation services almost always fall inside them.
Here's the logic. Privacy laws define a "sale" of personal data broadly, and lead generation involves selling personal data about individuals who are not your customers. According to a privacy law analysis from McLane Middleton, lead generation services "will almost always meet this definition" of a data broker — which triggers registration, transparency, and consumer-rights obligations completely separate from the TCPA.
The hard part is structural. The same analysis notes these requirements are "more difficult to satisfy where the Company lacks a direct relationship with individuals" — which is exactly the position every lead buyer is in. You're trying to honor consumer rights over people you've never spoken to, based on records someone else kept.
California shows what that actually costs. Registered data brokers there pay a $6,600 annual registration fee, and failure to register carries a $200-per-day penalty plus the regulator's administrative expenses. Registered brokers must also check state deletion requests — the DROP mechanism — every 45 days, and independent audits begin on a three-year cycle starting in 2028.
California isn't alone. Vermont, Texas, and Oregon have all enacted data broker laws, and more states are expected to follow. For anyone buying leads at scale, the practical question isn't whether these laws apply — it's whether your lead seller has registered, and can prove it.
That question fits into a broader vetting checklist worth asking any seller before money changes hands:
- Where does the traffic actually come from? Secret or "proprietary" sources are a red flag.
- What did the consumer see — the form, the disclosures, the seller named on the consent?
- How is consent documented, and can it be audited per lead, not just shown as a screenshot?
- Is the seller registered as a data broker in states that require it?
As one compliance-focused analysis puts it, if the seller can't answer those questions, "you're not buying leads, you're buying risk."
This is why list source vetting sits at the front of our process at My AI Call Center. Before any campaign launches, we review where a list came from and what consent records exist. Bought lists without clear permission records get flagged — and in most cases, declined. We tell you plainly if the list will not support the campaign, before you spend anything.
Data broker registration is easy to overlook because it lives outside the calling rules everyone argues about. But it applies to the lead seller today, and the penalties — like California's $200 per day — accrue whether or not anyone notices. Vetting the source up front is cheaper than untangling the liability later.
ctaText: Plan a campaign with a vetted list — from 9¢ per connected minute. socialProofText: List source and consent records reviewed before every launch — bought lists without clear permission records are declined, not run.
How to Vet a Lead Source Before You Buy
A lead seller's pitch deck tells you almost nothing. What matters is whether the seller can prove, lead by lead, that a real person agreed to hear from you — because as one TCPA compliance analysis puts it, if the seller can't show you where traffic comes from, what the consumer saw, and how consent is documented, "you're not buying leads, you're buying risk."
Start with three questions, and treat vague answers as disqualifying. First, where does the traffic come from? Proprietary or "secret" sources are a red flag. Second, what did the consumer actually see — the exact form, disclosure language, and seller name presented at the moment of consent? Third, how is consent documented, and can you audit the consent event itself, not just a screenshot or a "trust us"?
The stakes for skipping this step are concrete. The TCPA carries statutory damages of up to $1,500 per violating call or text through private lawsuits, and attorneys at Cooley LLP warn the newer rules hand "new ammunition for an aggressive plaintiffs' bar." On the state side, lead sellers frequently qualify as data brokers — California alone charges a $6,600 annual registration fee and fines unregistered brokers $200 per day, according to a McLane Middleton legal analysis.
Here is a practical vetting checklist to run before any purchase:
- Ask where the traffic originates and walk away from sellers who treat sources as proprietary secrets
- Request the actual consumer-facing forms and disclosure language, not screenshots or summaries
- Confirm each lead carries auditable consent proof — who consented, to what, when, and where
- Ask whether leads are exclusive or shared, and how many buyers receive the same contact
- Verify the seller's data broker registration status in states like California, Vermont, Texas, and Oregon
That fourth point deserves emphasis. Shared leads carry measurably higher complaint risk than exclusive ones — multiple buyers calling the same person raises the bar for clear seller authorization and process discipline, as ActiveProspect's compliance guidance notes. An exclusive lead costs more upfront; a shared lead can cost far more in complaints.
Once you buy, keep the evidence. Experts recommend retaining consumer consent records for a minimum of five years, per practitioner guidance from ActiveProspect. TCPA attorney Michele Shuster's experience shows why: a well-prepared, documented response shuts down roughly a quarter of threat letters at the initial stage — but only if the proof exists.
Finally, build your process around the fact that the rules are still moving. Some sources describe one-to-one consent — authorization for no more than one identified seller — as the operative standard effective January 27, 2025, per Heyflow's regulatory overview, while others report the industry has shifted back toward a "clear and conspicuous" disclosure standard. That conflict is exactly why legal review belongs in your launch plan, not your crisis plan.
This is the same discipline My AI Call Center applies before any campaign: list source and consent records are reviewed up front, and bought lists without clear permission records are flagged — and in most cases declined — before you spend anything.
How My AI Call Center Vets Lists Before Any Campaign Launches
Buying a list is legal. Calling it without proof of consent is where the lawsuits live — and the difference between the two is decided before the first dial, not after.
That is why every campaign at My AI Call Center goes through a list and consent review before launch. We check three things: where the list came from, what the contact actually agreed to, and whether the calling windows fit the rules. This mirrors the due diligence TCPA practitioners demand: if a seller can't show where traffic comes from, what the consumer saw, and how consent is documented, "you're not buying leads, you're buying risk."
Bought lists without clear permission records are flagged — and in most cases, declined. We tell you plainly if the list will not support the campaign, before you spend anything. That discipline exists because the stakes are concrete: TCPA statutory damages run up to $1,500 per violating call or text, and Cooley LLP's attorneys note the new rules "surely will provide new ammunition for an aggressive plaintiffs' bar" (Cooley's analysis of the FCC order).
The red flags we screen for match what compliance experts warn about:
- Secret or "proprietary" traffic sources the seller won't explain
- Consent proof limited to screenshots or "trust us"
- Unstable lead IDs that can't be audited back to the consent event
- Shared leads sold to multiple buyers, which raise complaint risk
Once a list passes review, protections run through every call. AI is disclosed on every call, and recipients can ask if the call is AI-assisted, request a human, or opt out. Keyword opt-outs — STOP and REVOKE — are honored immediately, and DNC requests are respected across all campaigns and carried into your client records. Nothing launches until you approve the script, disclosure, and escalation path.
The regulatory landscape is still shifting, too. The FCC's one-to-one consent rule took effect January 27, 2025 per one industry analysis, while other practitioners report the standard has since moved back toward "clear and conspicuous" disclosure. Because the rules keep moving, clients remain responsible for obtaining appropriate legal guidance before launch.
The cheapest way to find out if your list will hold up is the free campaign review. We scope one clear goal, review your list source, consent records, and calling windows, and quote the full campaign — starting at 9¢ per connected minute — before a single call goes out.
Frequently Asked Questions
Is it actually legal to buy leads in the U.S. right now?
What changed with the FCC's December 2023 TCPA rules for lead buyers?
What is 'one-to-one consent' and when did it take effect?
How much can a TCPA violation cost me per call or text?
Do state data broker laws apply to lead generation companies?
What should I ask a lead seller before buying to avoid legal risk?
The Paper Trail Is the Product
Buying leads is still legal in the United States — but the FCC's December 2023 rules made one thing unmistakably clear: the seller's word is no longer enough. The documentation is the product. Between one-to-one consent standards, the end of daisy-chain partner sharing, state data broker registration requirements, and statutory damages that can reach $1,500 per violating call or text, the difference between a usable lead and a lawsuit now lives in the paper trail — traffic sources, consumer-facing forms, and auditable consent records. That is the same standard we apply at My AI Call Center: every campaign runs only on approved, permissioned, or reviewed lists, and bought lists without clear permission records are flagged and, in most cases, declined before you spend anything. If you are considering purchased leads, start by asking your seller the three questions from this article — where the traffic comes from, what the consumer saw, and how consent is documented. Vague answers are your answer. And because the rules keep shifting, run your next campaign past a list and consent review first. Plan a campaign with a vetted list — from 9¢ per connected minute — and know exactly what you are calling before the first dial.