
Where can I get business leads?
Key Facts
- The FTC can fine you $53,088 per violating email — and you can't contract away your legal responsibility to a vendor.
- Legal experts advise retaining proof of the consent transaction — not just the lead event — for at least five years.
- California charges data brokers a $6,600 annual registration fee, with a $200-per-day penalty for failing to register.
- Four states — California, Vermont, Texas, and Oregon — already enforce data broker laws that almost always cover lead sellers.
- Roughly 25% of TCPA threat letters can be shut down at the initial stage — but only with documentation to back you up.
- Calling people who expected to be called produced higher conversion rates and lower costs, early industry testing found.
- Purchased lists often contain pristine and recycled spam traps that can get your sending infrastructure blocklisted, deliverability experts warn.
The Real Question Isn't Where to Get Leads — It's Whether You Can Use Them
Finding business leads is the easy part. A quick search returns dozens of vendors promising thousands of contacts for a few hundred dollars — the hard part is using those leads without exposing your business to serious legal risk.
The stakes are higher than most buyers realize. Under the FTC's CAN-SPAM guidance, penalties can reach $53,088 per violating email, and criminal penalties — including imprisonment — apply to anyone using harvested address lists, according to the FTC's official compliance guide. Worse, the FTC is explicit that you cannot contract away liability: "Even if you hire another company to handle your email marketing, you can't contract away your legal responsibility." Both the promoting company and the vendor that sent the messages can be held responsible.
So the real question shifts from "where do I get leads?" to "what permission stands behind them?" A list is only as valuable as the consent records attached to it. Legal expert Michele Shuster of McMurray & Shuster advises that buyers must not only verify consent but retain proof of the consent transaction — and keep it for at least 5 years, per compliance guidance from ActiveProspect.
The regulatory net around list sellers is tightening, too. Lead generation services "will almost always" meet the legal definition of a data sale, and a legal analysis by McLane Middleton notes that California, Vermont, Texas, and Oregon have already enacted Data Broker Laws. California alone charges a $6,600 annual registration fee, with a $200-per-day penalty for sellers who fail to register.
Before you spend money on any lead source, vet it against these questions:
- Can the seller produce documentation of the original consent — not just the lead event?
- Is the seller registered as a data broker where required, and does it honor deletion requests?
- Do the contacts actually expect to hear from a business like yours?
That last question matters commercially, not just legally. Early industry testing found higher conversion rates and lower costs when calling people who expected to be called, according to the same ActiveProspect guidance. Permission-verified lists simply perform better.
This is why My AI Call Center checks list source and consent records before any campaign launches — and declines bought lists that lack clear permission provenance. Telling you plainly that a list won't support a campaign, before you spend anything, is cheaper than learning it from a regulator later.
Why Purchased and Rented Lists Are the Riskiest Channel
Of all the channels for acquiring business leads, purchased and rented lists carry the most legal exposure — and the risk is growing, not shrinking. What used to be a gray area is now a regulated one, and the buyer, not the seller, usually ends up holding the liability.
The regulatory shift starts with data broker laws. According to a legal analysis by McLane Middleton, lead generation services that sell contact lists typically qualify as "data brokers" because they sell personal information about people with whom they have no direct relationship. California, Vermont, Texas, and Oregon have all enacted Data Broker Laws, with more states expected to follow.
The obligations are not trivial. California charges a $6,600 annual registration fee and penalizes unregistered brokers $200 per day. Starting January 2026, the California Delete Act adds deletion-request checks every 45 days and independent audits every three years beginning in 2028. Privacy laws define "sale" so broadly that lead generation services "will almost always meet this definition" — meaning the vendor's compliance problems become your vetting problems.
Beyond regulation, purchased lists have a data quality problem that no vendor guarantee fixes. Deliverability experts at Bouncer advise never purchasing or renting third-party lists, which often contain spam traps — pristine traps built to catch scrapers, and recycled traps made from expired addresses. Hitting either can get your sending infrastructure blocklisted.
The deeper issue is consent — or the absence of provable consent. Legal expert Michele Shuster stresses that buyers must not only verify consent but retain proof of the consent transaction for at least 5 years. Most purchased lists come with no such documentation, which means no legal defense if a complaint arrives.
Here is what "the vendor said it was fine" fails to protect you from:
- CAN-SPAM penalties of up to $53,088 per violating email — and the FTC is explicit that "you can't contract away your legal responsibility" by hiring another company
- Criminal penalties, including imprisonment, for using harvested email addresses
- TCPA exposure on calls, where prior express consent is required and undocumented consent is functionally no consent
- Liability for contacting people who previously opted out, since selling opted-out addresses is prohibited
The performance argument points the same direction as the legal one. Early testing showed higher conversion rates and lower costs when calling people who expected to be called — transparent lead forms simply convert better. A list with clear permission records is not just safer; it works harder.
This is why list source vetting sits at the front of any responsible outbound program. At My AI Call Center, list source and consent records are reviewed before any campaign launches, and bought lists without clear permission provenance are flagged — in most cases, declined. If the list cannot support the campaign, you hear that plainly before you spend anything. That discipline is not a limitation; it is what keeps a calling campaign an asset instead of a liability.
Consent Documentation: The Standard Every Lead Source Must Meet
A lead without documented consent is not an asset — it is a liability waiting for a demand letter. Legal experts who defend TCPA cases say the difference between a defensible call and an expensive settlement usually comes down to paperwork.
The first vetting question for any lead source is deceptively simple: can you see the consent transaction itself? Not the lead event — the actual moment the person agreed to be contacted, what they saw, and what they agreed to. According to compliance guidance from ActiveProspect featuring attorney Michele Shuster of McMurray & Shuster, LLP, companies routinely record that a lead arrived but fail to store the documentation needed for a legal defense. Her recommendation: retain proof of consent for at least five years.
Disclosure quality matters just as much as retention. The current standard requires "clear and conspicuous" disclosures — a lead form may list multiple sellers, but the consumer must plainly understand they could receive calls or texts from all of them. If a vendor cannot show you the exact form language behind their leads, that is a red flag, not a minor gap.
It is also critical to understand that email and calling operate under entirely different consent regimes:
- Email is an opt-out regime. Under CAN-SPAM, you do not need prior consent to send marketing email — but you must honor opt-outs within 10 business days, and penalties reach $53,088 per violating email, per FTC guidance.
- Calling requires prior express consent. The TCPA demands permission before the call, which is why consent records for phone leads carry far more weight.
- Liability cannot be outsourced. The FTC is explicit: even if you hire another company, "you can't contract away your legal responsibility."
- Sellers face their own regulation. Lead list vendors increasingly qualify as data brokers under state laws, per a legal analysis by McLane Middleton.
Shuster also offers practical guidance for when things go wrong. If a TCPA threat letter arrives, ignoring it is the worst possible response. The correct move is to verify the call took place, gather the facts, and prepare to explain why the call was lawful. She estimates roughly 25% of these letters can be shut down at the initial stage — but only when the documentation exists to back you up.
Her broader distinction is worth internalizing. "Good actors" ensure consumers fully understand what will happen with their information; "bad actors" misrepresent it. The encouraging news is that transparency is not just a legal shield — early testing showed higher conversion rates and lower costs when calling people who expected to be called.
This is why disciplined list vetting sits at the center of how we operate. Before any campaign launches, My AI Call Center reviews list source, consent records, and calling windows — and bought lists without clear permission provenance are flagged, and in most cases declined. If a list cannot support the campaign, we say so before you spend anything, because no conversion rate justifies a consent gap.
How to Vet Any Lead Source Before You Spend a Dollar
A lead source can look legitimate on paper and still expose you to five-figure penalties the moment you dial. Before any money changes hands, run the source through this vetting checklist — it takes less time than one TCPA demand letter.
1. Demand documented consent records — and keep them. Recording that a lead event happened is not enough. Legal experts advise that buyers must retain proof of the consent transaction for at least five years to support a legal defense. If a seller cannot produce the actual consent record — what the consumer saw, agreed to, and when — treat the list as unusable.
2. Check whether the seller is registered as a data broker. Lead generation services that sell contact data "will almost always" meet the legal definition of a data sale, and California, Vermont, Texas, and Oregon already enforce data broker registration laws. In California alone, registration costs $6,600 annually, and failure to register carries a $200-per-day penalty. An unregistered seller is a red flag, not a bargain.
3. Confirm deletion and opt-out handling. California's Delete Act, effective January 2026, requires data brokers to process deletion requests every 45 days and undergo independent audits every three years starting in 2028. Ask any source how they honor opt-outs and deletions — and get it in writing.
4. Verify leads at the point of capture. The most effective quality control happens at the source, during the capture process itself, not after bad data enters your CRM. Real-time validation can flag fraudulent or bogus contacts before you pay for them.
5. Remember that liability cannot be outsourced. The FTC is blunt: "you can't contract away your legal responsibility" — and penalties reach $53,088 per violating email, with criminal exposure for harvested lists.
A quick pre-purchase checklist:
- Can the seller produce consent records for each contact, retained for five years?
- Is the seller registered as a data broker in states that require it?
- Do they honor deletion and opt-out requests on a documented schedule?
- Was each lead validated at capture, or only after the fact?
- Will they put their compliance practices in writing?
Here is the part most buyers miss: compliance is a performance advantage, not just a cost. Early testing showed that transparent lead forms and calling consumers who expected to be called produced higher conversion rates and lower costs — along with better call center morale. Permission-verified lists simply work harder.
This is why My AI Call Center reviews list source and consent records before any campaign launches, and flags or declines bought lists without clear permission provenance. We tell you plainly if a list will not support the campaign — before you spend anything. That discipline is not caution for its own sake; it is how a calling campaign starts with contacts who actually pick up and convert.
Putting a Vetted List to Work: From Approval to Outbound Campaign
A vetted list is only valuable if it survives the journey from approval to a live outbound campaign. The gap between "we have leads" and "we can lawfully call these leads" is exactly where most outbound programs succeed or fail.
The first checkpoint is a list source and consent review before anything launches. This means tracing where every contact came from, what disclosure they saw, and what proof of permission exists. Legal experts advise retaining documentation of the consent transaction — not just the lead event — for at least five years as TCPA defense evidence. A spreadsheet of names with no provenance is not a callable asset; it is a liability.
This is where bought lists without clear permission records get flagged — and in most cases declined. The risk is not theoretical. The FTC makes clear that liability cannot be contracted away to a vendor, and harvested lists can carry criminal penalties. List sellers themselves now face data broker registration laws in California, Vermont, Texas, and Oregon, with California charging a $6,600 annual registration fee and $200 per day for non-compliance. If the seller operates in a gray zone, the buyer inherits it.
Once a list passes review, execution follows a structured sequence:
- Approved calling windows — calls run only inside permitted hours, honoring state-specific quiet times and day restrictions.
- AI disclosure on every call — recipients can ask whether the call is AI-assisted, request a human, or opt out at any point.
- Immediate opt-out handling — STOP and REVOKE keywords are honored instantly, and do-not-call requests carry across all campaigns and into client records.
- Script and escalation approval — nothing dials until the client signs off on the script, disclosure language, and escalation path.
- Dispositioned reporting — every call ends with a named outcome: confirmed, qualified, renewed, opted out, or no answer.
That last step matters more than most teams expect. A dispositioned outcome report — with per-call notes, outcome counts, opt-out logs, and follow-ups routed back into your CRM — turns a calling campaign from a black box into an auditable record. You know exactly what happened on every dial, which is precisely what you need if consent is ever questioned.
The discipline pays off commercially, not just legally. Early testing cited by lead generation compliance researchers found that calling consumers who expected to be called produced higher conversion rates and lower costs — permission is a performance strategy, not paperwork.
For businesses unsure whether their list will support a campaign, the lowest-risk first step is a review before any money moves. My AI Call Center's process starts there: list source, consent records, and calling windows are checked up front, and the answer is plain — if the list will not support the campaign, you hear that before you spend anything. The first campaign review is free, and if the list does pass, the full campaign is quoted before launch with a locked per-minute rate that does not move mid-campaign.
Frequently Asked Questions
Can I legally buy a lead list from a vendor and start calling it?
How do I know if a lead source is legitimate before I spend money?
What happens if I ignore a TCPA threat letter about a call I made?
Do compliant lead lists actually perform better, or is consent just legal paperwork?
Are lead list sellers regulated, or is it just the buyers who face risk?
What's the safest first step if I have a list but don't know if I can call it?
The Right Leads Are the Ones You Can Prove
So where can you get business leads? Anywhere — but only a few sources will hand you leads you can actually use. The difference comes down to documentation: a consent record you can produce, a seller registered where the law requires it, and contacts who genuinely expected to hear from a business like yours. Skip that vetting and you are not buying pipeline — you are buying exposure to penalties of up to $53,088 per violating email, with liability you cannot outsource. The good news is that the disciplined path is also the profitable one: permission-verified lists convert better and cost less to work. Your next step is simple — before you spend a dollar on any lead source, run it through the five-point vetting checklist above. And if you would rather have a second set of eyes on it, My AI Call Center reviews list source and consent records before any campaign launches, and the first campaign review is free. If your list will not support a campaign, you will hear that plainly — before it costs you anything.