The legal rules for a leads database come from several overlapping regimes: CAN-SPAM for commercial email, the TCPA and Telemarketing Sales Rule for phone and text outreach, at least 20 state privacy laws that give consumers rights over their data, the GDPR for anyone in the European Economic Area, and a set of security and breach-notification duties that apply regardless of channel. Penalties stack per message, per call, or per record, so the cost of a single sloppy campaign can run into six or seven figures. What follows walks through each obligation and where operators most often trip.
CAN-SPAM Rules for Commercial Email
Every commercial email sent from your database must carry a valid physical postal address and a clear way for the recipient to stop future messages.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business Opt-out requests must be honored within 10 business days. You cannot charge a fee, ask for extra information, or require anything beyond a reply email or a single-page visit to unsubscribe. Deceptive subject lines and misleading header information are separately prohibited.
The FTC treats each non-compliant message as a distinct violation, with penalties reaching $53,088 per email.1Federal Trade Commission. CAN-SPAM Act: A Compliance Guide for Business A blast to 10,000 contacts with a broken unsubscribe link is not one violation. It is theoretically 10,000.
TCPA and TSR: Phone and Text Outreach
The Telephone Consumer Protection Act restricts automated dialing and prerecorded voice messages. In Facebook, Inc. v. Duguid, the Supreme Court narrowed the autodialer definition to equipment that uses a random or sequential number generator, so systems dialing from a stored list generally fall outside it. The consent requirement for prerecorded voice calls, however, remains in full force.
The Telemarketing Sales Rule adds FTC-enforced duties on top. Call lists must be scrubbed against the National Do Not Call Registry every 31 days.2Federal Trade Commission. Telemarketers Required to Scrub Their Call Lists Every 31 Days Miss the window and your database almost certainly contains protected numbers. Calling them opens the door to $500 to $1,500 in statutory damages per call in civil suits.
A boundary worth marking: most business-to-business calls are exempt from the TSR. That exemption disappears if the calls involve nondurable office or cleaning supplies, personal purchases by individual employees, or charitable solicitations.3Federal Trade Commission. Complying with the Telemarketing Sales Rule A pure B2B database is not automatically safe.
Reassigned Numbers Safe Harbor
Numbers change hands, and calling a reassigned number without the new holder’s consent is a TCPA violation. The FCC’s Reassigned Numbers Database offers a safe harbor: query the database, receive a “no” response, and if that response is wrong, you are shielded from liability.4Federal Communications Commission. Reassigned Numbers Database The shield only works if you actually queried the database. Relying on a third-party data service does not qualify.
One-to-One Consent
The FCC adopted a rule requiring consumers to give separate written consent to each individual seller before receiving robocalls or robotexts. A comparison-shopping form can no longer produce blanket consent for dozens of companies. Each business needs its own checkbox and disclosure, and the resulting calls must be topically related to the site where consent was collected.5Federal Communications Commission. One-to-One Consent Rule for TCPA Prior Express Written Consent
The rule was scheduled to take effect January 27, 2025, but the FCC postponed the effective date pending judicial review.6Federal Communications Commission. FCC Postpones Effective Date of One-to-One Consent Rule However the litigation resolves, operators still building around blanket multi-seller forms should treat one-to-one as the baseline they will need.
AI Voices Under the TCPA
The FCC confirmed in February 2024 that AI-generated voices and voice cloning fall within the TCPA’s restrictions on artificial or prerecorded voice messages.7Federal Communications Commission. Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts Sounding human does not create a carve-out. You need prior express consent (prior express written consent for telemarketing), identification of the responsible entity at the start of the message, and opt-out methods for marketing calls.
The FTC separately polices deceptive practices in lead generation, including AI-assisted scoring. Lead generators must make truthful, substantiated claims about who they are, how consumer information will be used, and what the consumer receives. A company that knows or deliberately avoids knowing that a downstream partner is violating the TSR can be held liable for facilitating the violation.8Federal Trade Commission. If You’re Deceiving Consumers, the FTC Means Business: Exploring the Recent Settlement with MediaAlpha Willful ignorance about a partner’s conduct is not a defense.
Consent Logs and Five-Year Records
Collecting consent means nothing if you cannot prove it. The TSR requires sellers and telemarketers to retain records of all telemarketing activity for five years from the date each record is produced.9eCFR. 16 CFR 310.5 – Recordkeeping Requirements A complete consent record needs:
- The name and telephone number of the person who gave consent.
- A copy of the consent request in the exact format it was presented.
- The specific purpose for which consent was requested and granted.
- A copy of the consent the consumer provided.
- The date consent was given.
Each telemarketing call also has to be logged: calling number, called number, date, time, duration, script or prerecorded message used, and outcome (answered, dropped, transferred). Transferred calls require the destination number or IP address and the receiving company’s name.9eCFR. 16 CFR 310.5 – Recordkeeping Requirements Do-not-call requests must be recorded with the date of the request and the product or service being offered at the time.
Five years of granular, call-level records is a real infrastructure commitment. Regulators do not accept a CRM migration as an excuse for gaps.
State Privacy Laws
At least 20 states have enacted comprehensive consumer privacy laws, and the count keeps growing. The shared structure gives individuals the right to know what data you hold, the right to request deletion, and often the right to opt out of the sale or sharing of their information. If your database contains residents of these states, compliance is not optional, whatever state your servers sit in.
California’s CCPA, as amended by the CPRA, is the most developed example. Businesses must disclose on request the categories and specific pieces of personal information collected, the sources, and the third parties who received the data. Consumers can request deletion, subject to narrow exceptions such as legal compliance.10State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Agency enforcement penalties start at $2,500 per unintentional violation and $7,500 per intentional violation, adjusted annually for inflation.11California Legislative Information. California Civil Code 1798.155
The private right of action is separate. If unencrypted personal information is stolen because a business failed to maintain reasonable security, affected consumers can sue for up to $750 per incident.10State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) A poorly maintained database creates exposure on both tracks.
h3>Global Privacy Control Signals
Several state laws require businesses to honor automated opt-out signals sent by a user’s browser. Under California law, a Global Privacy Control signal is a legally valid request to stop the sale or sharing of personal data.12State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC) If your database ingests data through web forms or tracking pixels, your systems have to detect and act on GPC. Ignoring it is treated the same as ignoring a direct opt-out.
Data Broker Registration
A growing number of states require companies that buy, sell, or license consumer data to register as data brokers. If your business model involves acquiring lead data from third parties and reselling or sharing it, you may fall within these definitions. Requirements and fees vary by jurisdiction, and failing to register where required can trigger daily fines that accumulate quickly. Check the states where your leads reside before building a lead-sharing operation.
GDPR for EEA Leads
If your database contains residents of the European Economic Area, the GDPR applies regardless of where your company sits. Processing requires a lawful basis. For lead generation, the two most common are legitimate interest and direct consent. Consent under the GDPR has to be freely given, specific, informed, and unambiguous.13General Data Protection Regulation (GDPR). Consent Pre-checked boxes and bundled consent do not count.
The most severe infractions, including processing without a lawful basis, carry penalties up to 4% of total global annual turnover or €20 million, whichever is higher. A lower tier of up to 2% or €10 million applies to less severe violations.14General Data Protection Regulation (GDPR). Fines / Penalties You also need detailed records showing how each lead was acquired and what legal basis supports its processing. “We bought this list from a vendor” is not a lawful basis. Consent has to trace back to the individual.
Security and Breach Notification
The rules also dictate how you protect data. Encryption at rest and in transit is the minimum expectation across essentially every framework in play. Access controls, including multi-factor authentication, should scope permissions to what a role requires.
All 50 states have data breach notification laws. Timelines and thresholds vary, but the pattern is consistent: if unencrypted personal information is compromised, you have to notify affected individuals within a specified period after discovery. Some deadlines are as short as 30 days; others allow up to 60 or use a “most expedient time possible” standard. Many states require attorney general notification when affected individuals exceed a threshold, often 250 to 500 people, though some states set no minimum.
FTC Safeguards Rule
Lead generation companies that connect buyers and sellers may qualify as “financial institutions” under the FTC’s Safeguards Rule even if they do not think of themselves that way. The rule specifically covers “finders,” defined as companies that bring together buyers and sellers who then negotiate and close the deal themselves.15Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know If that fits, you owe mandatory encryption of customer information, a written information security program overseen by a qualified individual, and breach reporting.
Covered companies must notify the FTC no later than 30 days after discovering a security breach involving the unauthorized acquisition of unencrypted information for at least 500 consumers.15Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know Mortgage leads, insurance leads, and loan leads should assume the rule applies and build accordingly.
AI Scoring and Consumer Disclosures
If you use AI to score, rank, or profile leads in ways that affect whether someone receives credit, insurance, employment, or other significant outcomes, additional state duties are coming online. Colorado’s AI Act, effective February 2026, requires deployers of high-risk AI systems to notify consumers when such a system is a substantial factor in a consequential decision, allow correction of inaccurate data the system relied on, and offer human-reviewed appeal.16Colorado General Assembly. SB24-205 Consumer Protections for Artificial Intelligence Any business using AI to interact with consumers in Colorado also has to disclose that the counterpart is an AI system. Other states are expected to move in the same direction.