When a TCPA complaint lands, the name on it is the firm that placed the call, not the marketer who sold the lead.
In most contact-privacy regimes the duty sits with whoever actually reaches out to the consumer, not with whoever assembled the record. That one detail turns lead-buying from a pricing decision into a documentation decision.
The live question is not what the law says, which your firm already grasps better than any vendor could. It is what that vendor can physically place in your hands as proof of consent for every lead delivered.
What follows walks through the consent chain and the paperwork worth insisting on. Immileads is a lead generation service, not a law firm, and does not provide legal advice.
Whose name is on the letter
The Telephone Consumer Protection Act is a US federal statute governing telephone calls and text messages. One of its features is a private right of action. Individuals can sue on their own behalf, which is why an entire plaintiff's bar has organized around it.
You understand the doctrine better than I ever will, so rather than rehearse the black-letter rules, let me isolate the single thing lead buyers overlook again and again.
Liability travels with the caller. When a demand letter or a lawsuit arrives alleging an improper call or text, it carries your firm's name, because your firm is what made contact. The marketer who sold you that lead (especially a cheap one carrying no consent trail) has a way of becoming very difficult to get on the phone at precisely that moment.
You inherit the exposure without inheriting the evidence you would need to answer it. That is the structural flaw in buying leads on price alone. It is why the work of proving consent falls to you rather than to whoever generated the form.
So the useful question is not "what does the statute require," which you can answer without me. Turn it toward the vendor instead: if you asked them to document consent for any lead they have ever sent you, could they, and what exactly would land on your desk?
The answer comes in four parts.
The four records to demand
1. The consent record. For each lead, a vendor should be able to surface a timestamp, the IP address behind the submission, and a screen capture of the form itself, showing the precise consent wording that was on screen when the person hit submit.
The TCPA framework calls for consent before automated calls or texts go to a mobile number. The trap firms fall into is that the job of proving that consent ever existed lands on you, not on the applicant. A lead is only as defensible as the record standing behind it. For every lead that leaves our system, that record already exists, and we hand it over whenever you ask.
2. Do-Not-Call screening. A number of jurisdictions operate their own Do-Not-Call registries. You will find them in the US, the UK, France, and Singapore, among others. Dialing a listed number can generate exposure all by itself.
US phone numbers ought to be checked against the Federal DNC list before a lead ever ships, not discovered by your intake team after the call has already gone out. We run that check automatically, which counts for most exactly where a plaintiff's bar has made a specialty of DNC and TCPA claims.
3. Compliant capture. Consent only means something if it was gathered properly to begin with, on the landing page, before any lead existed. For leads coming from or sitting in Europe, that means GDPR-grade consent and privacy practices built into the page itself. Holding every page to that bar is simpler and safer than deciding case by case, so ours meet it wherever a given lead happens to land.
4. Clean handoff. A vendor has no business phoning, emailing, or texting your leads while it generates them. Any contact from their side clouds the consent picture you will later have to defend and muddles the record you would lean on. From the point of delivery forward, both the relationship and its paper trail should belong to you alone, with no intermediary having already reached the prospect.
A capable vendor can show you all four for a real, anonymized lead. Ask to see it. Then put the identical request to your current vendor. The distance between the two answers tells you most of what you need to know.
A note for firms operating from abroad
Immigration practice is unusually cross-border, so one wrinkle deserves stating plainly.
The TCPA concerns calls and texts to US numbers, which means a firm contacting US prospects can fall within its reach no matter where its office sits.
Email works differently. Take CAN-SPAM, the US email law: on its own terms it generally will not touch a sender based outside the United States who never writes to a US person. Yet the major mailbox providers apply its core expectations anyway, so a real postal address and a functioning unsubscribe are worth including whether or not the statute formally binds you.
Comparable regimes exist elsewhere. Canada runs CASL. Australia has its Spam Act. The UK enforces PECR. Each lands in roughly the same place, and each carries real consequences for operators who ignore them.
The sensible move is to build to the strictest standard you plausibly touch instead of trying to thread every jurisdiction one at a time. Confirm your specific exposure with counsel who knows your practice. None of this substitutes for that advice.
Why this is a lead-quality question, not just a legal one
It is tempting to file consent under "compliance" and treat it as a thing apart from lead quality. They are one subject seen from two sides.
A lead with a full consent record is one you can work with confidence and defend if challenged. A lead without one is a liability you paid money to acquire.
The cheapest leads are cheap in part because nobody spent anything documenting consent. That is one of the hidden costs taken apart in the cheap lead that costs you more. And the very discipline that filters out fake submissions before delivery, described in why fake legal leads exist, is what yields a clean consent trail. Both flow from owning the traffic and the capture rather than reselling whatever a cut-rate ad network passes along.
Judge a vendor on what it can prove, not on what it promises. For the full account of how immigration leads are generated, verified, and delivered with the record intact, see our guide to immigration lawyer leads.
FAQ
Who is liable under the TCPA when a purchased lead complains: the firm or the vendor?
In most contact-privacy regimes the duty falls on whoever actually calls or texts the consumer (your firm) rather than on the marketer who compiled the lead.
So when a TCPA demand or suit shows up, it carries your firm's name, and the vendor who sold you a lead with no consent trail tends to be hard to reach by then.
That is why the practical question is less about what the statute says and more about what your vendor can actually hand you as proof of consent for each lead. Treat this as practical operational notes rather than a legal opinion, and check the particulars with counsel who knows your practice.
What consent records should a lead vendor be able to provide?
Four things, on request, for every lead.
One is the consent record itself: a timestamp, the IP address, and a screen capture of the form showing the precise consent wording the person saw at submission.
Another is registry screening (running US numbers past the Federal DNC list before anything ships).
A third is how the data was gathered in the first place: landing pages held to GDPR-grade privacy standards for anyone in or from Europe.
The last is a clean handoff, where the vendor never contacted the lead during generation in a way that muddies the consent you will rely on.
Does the TCPA apply if my firm is outside the United States?
The TCPA is a US federal statute covering calls and texts to US numbers, so a firm reaching out to US prospects can fall within its scope no matter where the firm is based. Separately, CAN-SPAM generally will not touch a sender outside the US who never contacts US persons, yet most mailbox providers apply its core expectations (a postal address and a working unsubscribe) regardless, and Canada's CASL, Australia's Spam Act, and the UK's PECR set out comparable duties. Build to those standards either way, and confirm your exposure with counsel.
Ready to grow your immigration practice?
Qualified, exclusive immigration leads: fixed price per lead, no retainers, no long-term contracts. Start with a 30-100 lead test batch.
GET STARTED NOW