Written by: Matt Beucler, CEO, Plura AI
Key Takeaways
- TCPA-compliant lead qualification requires prior express written consent captured, verified, and logged for each specific seller before any outbound contact attempt.
- Qualification data such as budget, authority, need, or timeline does not grant consent. Capture consent separately and before qualification questions.
- After the Eleventh Circuit vacated the FCC’s one-to-one consent rule in early 2025, operators still need clear, auditable consent records with timestamp, source URL, disclosure language, IP address, and channel scope.
- Non-compliance creates significant financial risk, with statutory damages that can reach millions of dollars for high-volume campaigns.
- Plura AI enforces consent capture, real-time DNC scrubbing, automated quiet hours, and immutable consent logging inside the platform on every outbound contact. See how this works in a live demo.
Core Requirements for TCPA-Compliant Lead Qualification
- One-to-one prior express written consent – consent names a single specific seller, captured before any outbound contact attempt.
- Clear and conspicuous disclosure – disclosure language appears next to the submit button, not buried in terms of service.
- Channel matching – consent authorizes the specific channels used: calls, texts, autodialed, prerecorded.
- Verifiable proof of consent – timestamped, audit-ready records with IP address, source URL, and exact disclosure language.
- Revocation handling – opt-out requests honored within 10 business days and suppressed across all campaigns.
See how Plura captures consent and logs every outbound contact.
The One-to-One Consent Rule in Context
The FCC adopted its one-to-one consent rule in its December 2023 Report and Order (FCC 23-107), published in the Federal Register on December 28, 2023, with a scheduled effective date of January 27, 2025.2 The rule amended 47 CFR § 64.1200 and targeted what the FCC described as the “lead generator loophole.” This practice allowed a single checkbox on a comparison website to authorize dozens of unrelated companies to contact a consumer using an autodialer or prerecorded voice.
Under the rule, prior express written consent had to be for calls and texts made by or on behalf of a single specific seller.2 A consumer could consent to multiple sellers only if the form named each one individually and the consumer took a separate, clear affirmative act for each. Catchall disclosures naming generic categories like “our partners” or “participating lenders” no longer satisfied the consent standard for any of those parties.
The seller who makes the call carries the liability for consent compliance and cannot transfer that obligation to whoever collected the lead form. Courts have consistently held that a vendor’s assurance that consent is clean does not create a legal defense. In Ginwright v. Exeter Finance Corp., 280 F. Supp. 3d 674 (D. Md. 2017), a federal court held that consent obtained through a third-party lead generator did not transfer to the calling party that lacked a direct relationship with the consumer.
The Insurance Marketing Coalition challenged the rule in the Eleventh Circuit. The court vacated the rule in early 2025, finding the FCC exceeded its statutory authority. The underlying consent framework in 47 U.S.C. § 227 remains the operative standard that operators should review with qualified counsel.
Qualification Is Not Consent
The most operationally consequential distinction in TCPA compliance is one the SERP often blurs. Answering qualification questions does not grant consent to be contacted. A consumer who fills out a budget field, selects a coverage type, or describes a timeline has provided qualification data. That data is not consent data. Capture consent separately, per seller, before any outbound contact attempt.
TCPA-Compliant Lead Qualification vs. TCPA-Compliant Lead Generation
Lead generation collects contact information and consent. Lead qualification determines whether that lead is worth contacting. Qualification sits downstream from consent capture and does not replace it. The consent record must exist and be verified before qualification questions are asked over an outbound channel.
Qualification data such as budget, authority, need, and timeline belongs in a separate record from the consent record. That qualification record cannot stand in for consent.
A Step-by-Step TCPA-Compliant Lead Qualification Flow
The sequence below illustrates how operators structure a compliant pipeline. Review it with qualified counsel before implementation.
- Form submit – Consumer submits a form with their phone number and consent disclosure displayed adjacent to the CTA.
- Required-field validation – Validate that the phone number, consent checkbox, and timestamp are captured before the record is created.
- Consent verification – Confirm that the consent record names the specific seller and the specific channels authorized.
- DNC scrub – Scrub the number against the internal DNC list, the National DNC Registry, and state DNC lists before any contact attempt.
- Qualification – Run qualification questions using non-telemarketing data such as budget, authority, need, and timeline, separate from the consent record.
- Routing – Route qualified leads to the appropriate agent or AI voice agent based on qualification score and channel preference.
- Contact – Initiate contact only after consent verification and DNC scrub are complete, within quiet hours, with STIR/SHAKEN authentication on every outbound call.
Sample TCPA Consent Disclosure Language
The following is illustrative sample language. Review it with qualified counsel before use. It is not legal advice and does not constitute a compliance guarantee.
“By submitting this form, you agree that [Company Name] may contact you at the number provided using automated dialing technology and prerecorded messages about [specific product or service]. Consent is not a condition of purchase. Message and data rates may apply. Message frequency may vary. Reply STOP to opt out.”
Placement requirements for the disclosure:
- Directly adjacent to the submit button
- Outside terms of service text
- Checkbox not pre-checked
- Clear and conspicuous on mobile devices
The TCPA Consent Record Schema
Every consent record should capture the following fields. Courts in TCPA cases routinely order production of these records, and missing documentation is often treated as absence of consent.
| Field Name | Description | Example Value |
|---|---|---|
| phone_number | The number the consumer authorized for contact | +1-555-123-4567 |
| consent_timestamp | Date and time consent was captured (UTC) | 2026-09-11T14:32:07Z |
| source_url | The URL of the page where consent was collected | https://example.com/quote |
| consent_language | The exact disclosure text shown to the consumer | “By submitting this form, you agree that…” |
| seller_authorized | The specific seller named in the consent | Acme Insurance LLC |
| ip_address | The IP address of the submitting device | 192.168.1.1 |
| channel_scope | The channels authorized (calls, texts, autodialed, prerecorded) | SMS, autodialed calls |
| form_version | The version of the consent form displayed | v2.3 |
Consent records should be retained for at least four years, matching the federal statute of limitations for TCPA claims under 28 U.S.C. § 1658. Many compliance practitioners recommend five years to cover longer state lookback periods.
DNC Scrubbing and Revocation Handling
DNC compliance and consent compliance operate as parallel obligations. A consumer can provide valid consent and still be on the National DNC Registry, which limits how they can be contacted. Both obligations apply independently.
Key operational requirements under 47 CFR § 64.1200 and the FTC Telemarketing Sales Rule include:
- Scrub against the National DNC Registry at least every 31 days under FTC rules2
- Maintain an internal DNC list and honor opt-out requests within 10 business days
- Honor STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT as opt-out triggers
- Enforce quiet hours, with no calls before 8 a.m. or after 9 p.m. in the called party’s local time
- Apply state-specific DNC lists where they exist, as stricter state floors remain operative over federal baselines
- Apply revocation to the consent itself, so an opt-out received by text suppresses autodialed calls to that number
Plura enforces several controls on every outbound contact. Real-time DNC scrubbing checks numbers against federal and state lists before dialing. TCPA-litigator screening flags known plaintiffs. Automated quiet hours use time-zone detection to block calls outside permitted windows. Immutable consent logging creates an audit trail that cannot be altered. Plura supports customer compliance and does not replace customer obligations.
Watch a demo of Plura’s DNC scrubbing and consent logging.
What Non-Compliance Actually Costs
Under 47 U.S.C. § 227(b)(3), a person may sue for either actual monetary loss or $500 in statutory damages per violation, whichever is greater.2 A court may increase that award to up to $1,500 per violation if it finds the violation was willful or knowing. Each call or text counts as a separate violation.
The math compounds quickly. For example, a campaign of 10,000 texts without valid consent creates potential exposure of $5 million at the $500 floor, or $15 million if a court finds willfulness. Scaling that up, a list of 50,000 contacts receiving three texts each without proper consent represents 150,000 violations, equating to $75 million at the statutory floor.
The FCC can also impose forfeitures under 47 U.S.C. § 503(b) for robocall violations. The private right of action under § 227(b)(3) allows consumers to sue directly in federal or state court without first filing a complaint with the FCC. Plaintiff attorneys often take these cases on contingency because the per-violation statutory damages math makes them profitable. Class actions stack every recipient’s individual claim into one case.
The five major types of TCPA violations regulators and courts have identified are:
- Autodialed calls or texts to cell phones without prior express written consent
- Prerecorded voice calls to residential lines without consent
- Unsolicited fax advertisements
- Calls to numbers on the National DNC Registry without an applicable exemption
- Calls outside quiet hours (before 8 a.m. or after 9 p.m. in the called party’s local time)
For enforcement context, see FCC Enforcement.
Plura AI: Consent Capture, DNC Scrubbing, and Immutable Logging Inside the Platform
Plura AI is its own FCC-licensed audio bridging carrier. Voice traffic routes directly through Plura rather than a third-party CPaaS (Communications Platform as a Service). Plura issues branded caller ID at the carrier level and runs STIR/SHAKEN authentication on every outbound call. It also enforces real-time DNC scrubbing, TCPA-litigator screening, automated quiet hours, and immutable consent logging inside the platform on every outbound contact.

Plura’s AI voice agent, AI SMS, AI RCS, and AI Webchat all share a Stateful Conversation Database. This means consent status and conversation context carry across channels. A consumer who texted at 9 a.m. is the same consumer when the call comes at noon, with no re-explanation required and no consent-status gap between channels.
The table below shows how each core TCPA requirement translates into a specific platform control, so leaders can see where enforcement occurs in the outbound workflow.
| Requirement | What It Means | Plura Enforcement |
|---|---|---|
| One-to-one consent | Consent names a single specific seller | Consent capture enforced inside the platform on every outbound contact |
| DNC scrubbing | Scrub against federal and state registries before dial | Real-time DNC scrubbing before dial |
| Quiet hours | No calls before 8 a.m. or after 9 p.m. local time | Automated quiet-hours enforcement through time-zone detection |
| Consent logging | Timestamped, audit-ready records | Immutable consent logging with one-click audit exports |
Key platform capabilities include:
- Consent capture enforced inside the platform on every outbound contact
- Real-time DNC scrubbing against federal and state registries before dial
- Immutable consent logging with timestamped, audit-ready records
- Automated quiet-hours enforcement through time-zone detection
- STIR/SHAKEN authentication on every outbound call
- Branded caller ID issued at the carrier level
Plura’s compliance framework includes SOC 2, HIPAA, ISO certification, GDPR, STIR/SHAKEN caller ID verification, TCPA compliance, and DNC compliance.1 Plura supports customer compliance and does not absolve customers of their own obligations. Using Plura does not make the customer compliant with any standard.

Additional platform capabilities include the AI Predictive Dialer, managed workflows, business intelligence, and integrations with 50+ tools across CRM, calendar, attribution, and data enrichment categories.
Frequently Asked Questions
What Does TCPA Require You to Disclose on a Lead Form?
A clear and conspicuous disclosure should name the specific seller, describe the channels authorized (calls, texts, autodialed, prerecorded), state that consent is not a condition of purchase, and appear adjacent to the submit button. The disclosure cannot be buried in terms of service, cannot use a pre-checked box, and must be legible on mobile devices. Retain the exact language shown to the consumer at the time of consent as part of the consent record, because courts routinely order production of that specific text in TCPA litigation.
What Are the 5 Major Types of TCPA Violations?
The five major types are:
- Autodialed calls or texts to cell phones without prior express written consent
- Prerecorded voice calls to residential lines without consent
- Unsolicited fax advertisements
- Calls to numbers on the National DNC Registry without an applicable exemption
- Calls outside quiet hours (before 8 a.m. or after 9 p.m. in the called party’s local time)
Each type represents a separate theory of liability under 47 U.S.C. § 227, and a single campaign can trigger multiple types simultaneously.
How Much Is a TCPA Violation?
As noted above, statutory damages follow the structure in 47 U.S.C. § 227(b)(3), with a per-contact amount that can increase if a court finds willfulness. Each call or text counts as a separate violation, and class actions aggregate those individual claims.
Does Providing a Phone Number Create Consent to Call?
Providing a phone number for a transaction does not create consent for marketing calls or texts. Marketing calls and texts using an autodialer or prerecorded voice require prior express written consent under 47 CFR § 64.1200(f)(9). That consent must be a signed written agreement (electronic signatures qualify), must name the specific seller, must describe the channels authorized, and must state that consent is not a condition of purchase. Verbal opt-ins and pre-checked boxes do not meet this standard.
Who Is Exempt from TCPA Rules?
Political calls, survey calls, and calls from tax-exempt nonprofits are generally outside the TCPA’s telephone-solicitation definition because they are not made to encourage a purchase, rental, or investment. Healthcare and financial services informational calls may qualify for narrow exemptions under 47 CFR § 64.1200(a)(2). Exemptions are narrow and fact-specific, and the burden of proving an exemption applies sits with the caller. Consult qualified counsel before relying on any exemption.
Conclusion: Turning Consent Standards Into an Operational System
High-volume outbound programs succeed when they treat qualification and consent as separate requirements and build auditable consent into every workflow. Capture consent before qualification, store it in a structured record, and keep DNC controls active on every contact attempt.
Plura enforces consent capture, real-time DNC scrubbing, automated quiet hours, and immutable consent logging inside the platform on every outbound contact. As an FCC-licensed carrier, Plura issues branded caller ID and runs STIR/SHAKEN authentication at the carrier level. Plura supports customer compliance and does not replace customer obligations.
Check your ROI with Plura’s calculator
Review Plura plans and rates side by side
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.