TCPA Consent for Insurance Leads: What to Demand Before You Buy
TCPA compliance for insurance agents buying leads means you can only auto-dial or text a consumer who gave prior express written consent to YOUR contact, you keep the consent record yourself, and you scrub against the DNC list. The consent travels with the lead, not the vendor.
Buying leads is the fastest way to fill a calendar in this business. It is also the fastest way to buy a lawsuit if the consent behind those leads is thin. The Telephone Consumer Protection Act gives the consumer a private right of action “to recover for actual monetary loss from such a violation, or to receive $500 in damages for each such violation, whichever is greater,” and a court that finds the violation willful or knowing “may, in its discretion, increase the amount of the award to an amount equal to not more than 3 times the amount available” — $1,500 a call or text (47 U.S.C. §227(b)(3)). Plaintiff firms run on volume, not on whether you closed the sale.
This is a practical operator’s walkthrough, not legal advice. We run lead programs for senior-market agents, so we read these vendor agreements for a living. Talk to a telecom attorney before you change your dialing setup.
What the TCPA actually requires
Strip away the jargon and the TCPA asks three questions every time you contact a consumer with technology:
- Did you have consent for the method you used? Autodialed calls, prerecorded or AI voice, and SMS texts to a cell phone require prior express written consent. A manually dialed call to a number you typed yourself is a lower-risk category.
- Did the consent name you? Consent runs to a caller, not to “the industry.” A form that says the consumer agrees to hear from “us and our marketing partners” is weaker than one that names your agency or describes the seller specifically.
- Did you scrub the Do Not Call list? Even with consent, you document the scrub against the National Do Not Call Registry before you dial.
Prior express written consent has a specific meaning, and the FCC wrote it down. Per 47 CFR §64.1200(f)(9), it is “an agreement, in writing, bearing the signature of the person called that clearly authorizes the seller to deliver or cause to be delivered to the person called advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice, and the telephone number to which the signatory authorizes such advertisements or telemarketing messages to be delivered.” The agreement must carry a clear and conspicuous disclosure that signing authorizes those calls and that the consumer “is not required to sign the agreement… as a condition of purchasing any property, goods, or services.” Electronic and digital signatures count.
Two more mechanics from the same rule that catch agents out. The DNC scrub is not a one-time job: §64.1200(c)(2)(i)(D) expects a version of the national registry “obtained from the administrator of the registry no more than 31 days prior to the date any call is made,” with records documenting the process. And revocation is deliberately easy for the consumer — under §64.1200(a)(10), replying “stop,” “quit,” “end,” “revoke,” “opt out,” “cancel,” or “unsubscribe” to a text, or using any designated opt-out mechanism, “constitutes a reasonable means per se to revoke consent,” after which “the caller may not send additional robocalls and robotexts.”
The vacated FCC one-to-one rule (January 2025)
This is the part agents get wrong in 2026, so be precise.
The FCC adopted a rule that would have required separate consent for each individual seller — the “one-to-one” rule — and banned the broad “marketing partners” consent that shared-lead vendors relied on. It was scheduled to take effect January 27, 2025.
Days before, the Eleventh Circuit vacated the rule. In Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (11th Cir. Jan. 24, 2025), the court held that the one-to-one-consent and logically-and-topically-related restrictions conflicted with the ordinary statutory meaning of “prior express consent,” and concluded: “we grant IMC’s petition for review, vacate Part III.D of the 2023 Order, and remand for further proceedings.” So the stricter one-to-one standard is not law. The older written-consent standard still governs.
Here is the trap: the rule being vacated does not mean broad consent is safe. It means the floor didn’t rise. A consumer who agreed to hear from a list of 200 “partners” can still argue they never agreed to your call by name. The one-to-one rule going away removed a regulatory mandate; it did not remove your civil exposure.
| Consent scenario | Risk level for the buying agent | What to do |
|---|---|---|
| Consumer named your agency on the form | Lowest | Keep the record, scrub DNC, call |
| Single-seller form, your name swapped in at delivery | Low–moderate | Verify the swap mechanism is documented |
| Shared lead, named “marketing partners” list | Moderate–high | Get the full seller list and exact text |
| Aged or re-sold list, consent provenance unclear | Highest | Manual dial only, or pass |
For more on how shared sourcing changes your risk and economics, see our breakdown of exclusive versus shared final expense leads.
What to demand from your lead vendor
Most agents accept a CSV and a login. That is not enough to defend a claim. Before you wire money, get these in writing:
- The exact consent language the consumer saw — not a paraphrase, the literal text.
- A copy of the opt-in record per lead: timestamp, originating IP or device, source URL, and the checkbox/signature state.
- The seller list the consent covered, if it was a shared form.
- Their DNC scrubbing practice and who is responsible for the final scrub before you dial — you, them, or both.
- An indemnification clause that survives the contract. Read what it actually covers; many exclude TCPA or cap liability below a single judgment.
If a vendor cannot produce the consent record on demand, you are buying the lead and the liability. Walk. We screen sourcing this way inside our managed insurance lead generation service because the cheapest lead is worthless if it carries an uninsurable risk.
Record-keeping: own your own paper
The single most common mistake we see: the agent’s only proof of consent lives on the vendor’s server. When a demand letter arrives 18 months later and the vendor has churned, gone dark, or deleted the record, the agent has nothing.
Keep your own copy. For every lead you contact with technology, store:
- The consent disclosure text and the affirmative action (check/signature)
- Timestamp and source
- Your DNC scrub result, dated, before the first dial
- Your call and text logs
The federal TCPA statute of limitations is four years, so retain records at least that long. Cheap insurance against an expensive problem.
A simple compliance routine for buying agents
You do not need a legal department. You need a repeatable checklist:
- Confirm written consent language names you or a documented seller before purchase.
- Pull and store the per-lead consent record on your own system.
- Scrub against the National Do Not Call Registry; log the scrub.
- Honor every opt-out immediately and maintain an internal DNC list.
- Match your dialing tech to your consent — manual dial when provenance is weak.
- Retain everything for four years.
This same discipline shows up across paid acquisition. If you advertise to generate your own first-party leads, note that Meta’s and platform rules add their own layer — we cover that context in our guide to Facebook ads for insurance agents and in our broader insurance marketing compliance overview.
Why compliance is a growth lever, not a tax
Skeptical agents read all of this as friction. Flip it. Clean, named, documented consent does three things for your book:
- Connect rates rise because named consent means the consumer remembers requesting contact.
- Cancellations drop because the lead actually wanted the conversation.
- Your downside shrinks because one TCPA judgment can erase a year of margin.
Compliance is a moat. The agencies that treat consent as paperwork are the ones who get named in the class action. The ones who own their records and buy from clean sources keep dialing — and what they dial into is a documented insurance lead follow-up cadence, where every call and text on a purchased lead is timed against the consent record that permits it.
Want a second set of eyes on where your current leads come from and how exposed your dialing setup is? Grab a free marketing audit and we’ll map your sourcing and consent trail with you. If you’d rather see how we structure compliant senior-market campaigns end to end, start with our final expense marketing programs.
This article is marketing guidance for licensed agents and is not legal advice. You are the licensed party; consult a TCPA attorney for your specific setup.
- Insurance Marketing Compliance for Agents: What Actually Trips People Up
Insurance marketing compliance for agents in plain English: TCPA consent, state advertising rules, and the CMS Medicare requirements your ads must meet.
- CMS Medicare Marketing Rules for Agents: A Plain-English Walkthrough
The 4 CMS Medicare marketing rules agents break most, in plain English: the TPMO disclaimer, call recording, Scope of Appointment, and Permission to Contact.
- Scope of Appointment & TPMO Compliance: The Agent's Operational Guide
A focused guide to Scope of Appointment and TPMO compliance for Medicare agents: SOA timing, CMS-10260, the disclaimer, call recording, and third-party rules.