A Practitioner's Compliance Checklist for Pay-Per-Call and Lead Generation
Compliance in pay-per-call and lead gen is not a legal department problem you hand off once a year. It runs through every form, every call, every publisher contract. Get it wrong and you face TCPA class actions, CMS sanctions, FTC penalties, and advertisers pulling budgets. Here is how to operationalize it.
TCPA: consent is the whole game
The Telephone Consumer Protection Act governs calls and texts made with an autodialer or prerecorded/artificial voice. For marketing calls and texts to wireless numbers, you need prior express written consent (PEWC): a signed agreement (an electronic signature or checkbox counts) that names the seller, discloses that the consumer agrees to automated marketing contact, and states consent is not a condition of purchase.
Key points to operationalize:
- The disclosure language must sit next to the submit button, not buried in a linked privacy policy.
- Keep the consent record tied to the specific phone number, timestamp, IP, and the exact disclosure text shown.
- Scrub against the National Do Not Call Registry and your internal DNC list. PEWC overrides DNC, but only if you can prove it.
The one-to-one consent rule is dead — for now
The FCC's "one-to-one" consent rule would have banned bundled consent (one checkbox covering many sellers) and forced seller-by-seller consent. It was scheduled to take effect January 27, 2025.
On January 24, 2025, the Eleventh Circuit vacated the rule in Insurance Marketing Coalition Ltd. v. FCC, holding the FCC exceeded its authority by reading extra requirements into "prior express consent." The rule is not in force.
Do not treat that as a green light for sloppy bundling. Best practice still favors clear seller identification and a reasonable, transparent partner list. Advertisers in regulated verticals frequently require one-to-one consent contractually regardless of the FCC's status. Watch for any renewed FCC action.
Consent certificates: TrustedForm and Jornaya
A consent claim you cannot reproduce is worthless in litigation. Two tools dominate proof-of-consent:
- TrustedForm (ActiveProspect) drops a script on the form page and produces a session-replay certificate: the disclosure text the consumer saw, mouse and scroll behavior, timestamp, IP, browser, and URL at submission.
- Jornaya LeadiD issues a cryptographic token fingerprinting the consent event across the consumer journey, proving the event happened on a specific page at a specific time.
Practical guidance:
- Capture a certificate on every web lead. Store the cert ID with the lead record.
- In high-risk multi-buyer verticals (Medicare, ACA, final expense, P&C), buyers often demand both tokens. For single-buyer, lower-risk flows, one is usually enough.
- A token alone is not consent. It only proves what happened on the page. The disclosure on that page still has to be compliant.
CMS rules for Medicare and ACA marketing
If you generate or transfer Medicare Advantage or Part D leads, you are almost certainly a Third-Party Marketing Organization (TPMO) under CMS — defined to include anyone paid for lead generation, marketing, sales, or enrollment in the chain of enrollment.
What that requires:
- TPMO disclaimer. Use the CMS-mandated language, with your real numbers filled in. For TPMOs that do not represent every plan: "We do not offer every plan available in your area. Currently we represent [X] organizations which offer [Y] products in your area. Please contact Medicare.gov, 1-800-MEDICARE, or your local State Health Insurance Program to get information on all of your options." It must appear on marketing materials and be communicated verbally before benefits are discussed.
- Call recording. Record the entire call for any Medicare Advantage or Part D sales conversation, and retain recordings for 10 years in a HIPAA-compliant manner.
- Scope of Appointment. SOA is required before personal marketing appointments and documents which product types the beneficiary agreed to discuss. Lead generators usually do not collect SOA, but anyone handing off to a sales appointment needs to understand where it fits.
For ACA, CMS has separately tightened agent/broker consent and documentation rules; treat ACA marketing claims and consent with the same discipline.
State telemarketing laws (mini-TCPAs)
Federal compliance does not cover you at the state level. Several states have their own statutes, often with private rights of action.
- Florida (FTSA). The 2023 amendment (effective May 25, 2023) narrowed the autodialer definition from selection or dialing to selection and dialing, and clarified consent can be shown by an act like checking a box. It also added a 15-day pre-suit cure period for texts. It still requires consent for unsolicited sales calls.
- Oklahoma. Its mini-TCPA uses the same "automated system" language and remains a live litigation source.
- Other states (Washington, Maryland, and more) impose their own caller-ID, timing, and consent rules.
Build state logic into your dialing and disclosure rules, not just federal defaults.
Email compliance: CAN-SPAM
If your funnel uses email, CAN-SPAM applies to every commercial message.
- No false or misleading headers or subject lines.
- Identify the message as an ad where applicable.
- Include a valid physical postal address (street, USPS-registered PO box, or private mailbox).
- Provide a working opt-out, honor it within 10 business days, and keep the mechanism live for at least 30 days. Do not charge or demand extra info to unsubscribe.
- Maintain a suppression list and apply it across all sends.
Penalties run up to roughly $51,744 per violating email (inflation-adjusted), so suppression failures scale fast.
Creative, claims, and lead validation
Regulators and advertisers both police what the ad actually says.
- Review creative for unsubstantiated or misleading claims — "free," guaranteed savings, fake government affiliation, fake urgency. CMS additionally prohibits the use of Medicare branding/logos in misleading ways.
- Validate leads before billing or transfer: real phone, real consent record, no duplicates, no incentivized or co-registration consent where the advertiser prohibits it.
- Match the lead to the consented vertical. A health-insurance consent does not authorize a home-services call.
Operationalizing compliance
Turn the rules into repeatable process:
- Publisher vetting. Contract for compliance, require consent certificates, document traffic sources, and audit landing pages before activation. Ban incentivized and misrepresented traffic in writing.
- Consent audit trail. Store the disclosure text, cert ID, timestamp, IP, and phone for every lead, retrievable on demand. For Medicare, store recordings for 10 years.
- Creative approval. No publisher creative goes live without review and version-controlled approval records.
- Monitoring. Spot-check live landing pages and call recordings, watch complaint and litigation signals, and suspend publishers fast when something is off.
- DNC and suppression hygiene. Refresh scrubs on a schedule and log them.
Compliance is cheaper as a standing process than as a settlement. Build the audit trail before you need it.
This article is general information for operational planning, not legal advice. Consult qualified counsel for your specific situation.