The phone rings at 2 PM on a Tuesday. It's not a business prospect—it's an attorney representing a class-action lawsuit. Your team made 200 calls to leads who never gave proper consent, and now you're facing fines totaling $300,000. This nightmare scenario plays out more frequently than most MCA brokers realize.
In 2024 alone, the Federal Communications Commission (FCC) levied over $200 million in TCPA-related penalties against businesses making unsolicited calls. For merchant cash advance brokers operating in an industry built on phone outreach, understanding TCPA compliance isn't optional—it's survival.
The Telephone Consumer Protection Act carries penalties ranging from $500 to $1,500 per violation. Make 100 non-compliant calls? That's up to $150,000 in potential fines. The stakes couldn't be higher, and 2025 brings even stricter enforcement as state regulators join federal agencies in cracking down on MCA telemarketing rules violations.
This comprehensive guide will walk you through everything you need to know about TCPA compliance MCA operations, from understanding consent requirements to vetting your lead providers and building a bulletproof compliance program.
Understanding TCPA Basics: What MCA Brokers Must Know
The FCC TCPA rules were designed to protect consumers from unwanted telemarketing calls, and they apply directly to merchant cash advance brokers. Here's what you need to know:
Prior Express Written Consent Requirements
The cornerstone of TCPA compliance is obtaining prior express written consent before making autodialed or pre-recorded calls. For MCA brokers, this means:
- Written agreement: Verbal consent alone is insufficient. You need a clear, unambiguous written agreement.
- Specific disclosure: The consent must specifically authorize calls to the provided number.
- Signature requirement: Electronic or physical signatures that demonstrate clear authorization.
- No pre-checked boxes: Consent cannot be obtained through pre-checked boxes or passive agreement.
If you're purchasing leads from third-party vendors, the consent documentation must travel with those leads. This is where many MCA brokers get into trouble—assuming their lead provider handled consent properly without verification.
Autodialer and Artificial Voice Restrictions
Under current MCA telemarketing rules, using an automatic telephone dialing system (ATDS) or artificial/pre-recorded voice messages requires prior express written consent. Key restrictions include:
- ATDS definition: Any equipment that dials numbers automatically, even from a list
- Predictive dialers: These fall under ATDS and require written consent
- Pre-recorded messages: Even for calls answered by humans, pre-recorded messages need consent
- Click-to-call exceptions: Some platforms claim exemptions, but verify carefully
Time-of-Day Restrictions and DNC Compliance
Even with proper consent, MCA cold calling laws impose strict limitations:
- Calling hours: Calls only between 8 AM and 9 PM in the recipient's time zone
- Do Not Call compliance: Mandatory scrubbing against federal and state registries
- Internal DNC list: You must maintain and honor your own do-not-call list
- Revocation respect: When someone says "don't call again," immediate compliance is required
Violating time restrictions or DNC requirements can result in penalties even when you have initial consent—each violation compounds your risk.
DNC Compliance: Navigating Federal and State Requirements
Do Not Call compliance represents a second layer of TCPA protection, and it's where MCA brokers face significant exposure.
National Do Not Call Registry Requirements
The National Do Not Call Registry contains over 244 million phone numbers. MCA brokers must:
- Subscribe to the registry: Access costs vary based on area code needs ($66 per area code, with discounts for multiple codes)
- Scrub lists every 31 days: Leads older than 31 days must be re-scrubbed before calling
- Document scrubbing: Maintain records proving you scrubbed your lists
- Established business relationship exception: You may call existing customers for 18 months after the last transaction
This is where partnering with compliant lead sources becomes critical. Quality lead providers scrub their data against DNC registries before delivery, but you should verify this practice.
State-Specific DNC Lists
Beyond the federal registry, several states maintain their own Do Not Call lists with additional requirements:
- State registries: Florida, Indiana, Missouri, and others have separate lists
- Additional restrictions: Some states impose stricter calling hours or consent requirements
- Registration requirements: Your business may need to register with state programs
- Overlapping rules: You must comply with both federal and state requirements when they differ
State Attorney General offices actively prosecute DNC violations, often with more aggressive enforcement than federal agencies.
Internal DNC List Management
Federal law requires you to maintain an internal do-not-call list separate from the national registry:
- Immediate addition: Add numbers within a reasonable time (generally interpreted as same day)
- Permanent retention: Keep numbers on your list for at least five years
- Company-wide enforcement: All calling personnel must have access to and honor the list
- Documentation: Maintain records of when numbers were added and by whom
Failure to maintain an internal DNC list demonstrates willful non-compliance, which can increase penalties to the $1,500 maximum per violation.
Safe Harbor Provisions
The TCPA includes safe harbor provisions that can protect you from penalties if you make inadvertent mistakes:
- Written procedures: Document your DNC compliance procedures in writing
- Training programs: Provide training to all personnel involved in calling
- Recording procedures: Maintain records of your compliance efforts
- Corrective action: When violations occur, take immediate steps to prevent recurrence
These provisions won't protect intentional violations, but they can be your defense against honest mistakes—if you have the documentation to prove your good faith efforts.
Lead Provider Vetting for TCPA Compliance
Your compliance is only as strong as your weakest link, and for most MCA brokers, that weak link is their lead provider. Here's how to properly vet vendors:
Critical Questions to Ask Lead Providers
Before purchasing MCA leads, demand clear answers to these questions:
- Consent documentation: "Do you provide the actual consent agreement with each lead?"
- Consent language: "What exact language do consumers see when they provide consent?"
- Consent date: "How old is the consent, and is it still valid under current TCPA standards?"
- DNC scrubbing: "When was this data last scrubbed against the National DNC Registry?"
- State compliance: "Are these leads scrubbed against state DNC lists?"
- Lead age: "What is the actual age of these contacts from consent date?"
- Data sources: "Where did these leads originate, and can you provide proof of the consent process?"
If a lead provider can't or won't answer these questions clearly, walk away. The legal risk isn't worth any discount pricing. Our pre-scrubbed leads come with full consent documentation and compliance verification.
Red Flags to Avoid
Watch for these warning signs when evaluating lead providers:
- Vague consent claims: "All our leads are TCPA compliant" without documentation
- Too-good pricing: Extremely cheap leads often lack proper consent
- Aged data without re-verification: Leads over 90 days old should be re-verified
- Resistance to compliance questions: Legitimate providers expect these questions
- No DNC scrubbing proof: Cannot provide scrubbing dates or certificates
- Anonymous sourcing: Cannot or will not disclose where leads originated
Many MCA brokers have learned these lessons the hard way. One broker in California purchased 5,000 "TCPA compliant" leads at $2 each, only to face a class-action lawsuit because the consent forms didn't meet TCPA standards. The settlement cost $380,000—far more than premium compliant leads would have cost.
Consent Documentation Requirements
When you receive leads, you should receive accompanying documentation that includes:
- Original consent form: The actual agreement the consumer signed
- Timestamp: When consent was obtained
- IP address or location: Where the consent occurred
- Consent language: Exact wording the consumer agreed to
- Scope of consent: What types of calls were authorized
Store this documentation securely. If you're ever sued or investigated, this paperwork is your only defense. Without it, you're legally vulnerable regardless of what your lead provider claimed.
Building a Compliant MCA Calling Operation
Beyond vetting lead sources, you need internal systems and processes that ensure ongoing compliance. Here's how to build a bulletproof operation:
Documentation Best Practices
Create a comprehensive paper trail for every aspect of your calling program:
Call logs must include:
- Date and time of each call (with time zone noted)
- Phone number called
- Representative who made the call
- Outcome (answered, voicemail, no answer, DNC request)
- Lead source and consent verification
Consent records should contain:
- Original consent agreement
- Lead provider information
- DNC scrubbing certificates
- Internal compliance review notes
- Any follow-up verification performed
DNC management requires:
- All DNC requests logged immediately
- Source of DNC request (consumer, litigation, registry)
- Date added to internal list
- Confirmation of removal from active call lists
Many brokers use simple spreadsheets for this, but dedicated compliance software is more reliable as you scale.
CRM and Dialing System Compliance Features
Your technology stack should actively support compliance, not just track it:
Essential CRM features:
- Automatic DNC list integration
- Time-zone detection and calling hour enforcement
- Mandatory consent documentation fields
- Call recording with compliance flagging
- Automatic lead aging alerts
Dialing system requirements:
- DNC list scrubbing before each call
- Calling hour restrictions (8 AM-9 PM local time)
- One-call disconnect (no multiple calls to same number in one day)
- Call recording for quality and compliance review
Consider platforms that integrate with TrustDial verification services, which provide real-time phone number validation and additional consent verification layers.
Staff Training Requirements
Technology alone won't protect you—your team needs comprehensive training:
Initial training should cover:
- TCPA basics and why they matter
- DNC compliance procedures
- How to handle DNC requests during calls
- Proper consent verification before calling
- Time restrictions and other calling rules
- Documentation requirements
Ongoing training includes:
- Quarterly compliance refreshers
- Updates when regulations change
- Review of any compliance issues that arise
- Role-playing DNC request scenarios
Document all training sessions with sign-in sheets and testing to prove your good-faith compliance efforts.
The Compliance Checklist
Use this checklist before launching any new calling campaign:
| Compliance Item | Verification Method | Responsible Party | Completed |
|---|---|---|---|
| Leads have written consent documentation | Review consent forms | Compliance Officer | ☐ |
| DNC scrubbing completed within 31 days | Scrubbing certificate obtained | Data Manager | ☐ |
| State-specific DNC scrubbing performed | State registry verification | Data Manager | ☐ |
| Internal DNC list updated | System check | Operations Manager | ☐ |
| CRM configured with calling hour restrictions | System test | IT/Operations | ☐ |
| Call scripts reviewed for compliance | Legal review if needed | Marketing/Compliance | ☐ |
| Staff training documented | Training records filed | HR/Training Manager | ☐ |
| Call recording systems functional | Test recording review | IT/Operations | ☐ |
| Consent age verified (< 90 days preferred) | Lead age report | Data Manager | ☐ |
Real-World Compliance Scenarios
Understanding how TCPA violations occur in practice helps you avoid common pitfalls:
Scenario 1: The Recycled Lead Problem
A broker purchases leads from a vendor who sourced them from another vendor who got them from an affiliate network. The original consent was obtained 18 months ago through a generic "financial offers" form. The broker calls, and the consumer claims they never agreed to MCA calls.
The violation: Consent wasn't specific to MCA services, and the chain of custody makes verification impossible. Even though the broker believed the leads were compliant, they're liable.
The protection: Only purchase leads with verifiable, recent consent specific to business financing or MCA services. See our guide on lead sourcing questions for more details.
Scenario 2: The Time Zone Mistake
An East Coast MCA broker calls a California lead at 6:30 PM EST (3:30 PM PST). While it's legal calling hours on the East Coast, it's before 8 AM or after 9 PM in the consumer's time zone.
The violation: TCPA calling hours are based on the recipient's time zone, not yours.
The protection: Modern CRM systems can detect time zones automatically and prevent calls outside permitted hours. Manual verification is required for each call without this technology.
Scenario 3: The Ignored DNC Request
During a call, a business owner says, "Take me off your list." The sales rep notes it but continues calling from other lead lists since the request was "informal."
The violation: Any DNC request must be honored across all your calling lists immediately, regardless of how it's phrased.
The protection: Train staff that any variation of "don't call me," "remove me," or "stop calling" requires immediate DNC list addition and notification to all calling teams.
The FTC Telemarketing Sales Rule: Additional Requirements
Beyond TCPA compliance, MCA brokers must also comply with the FTC Telemarketing Sales Rule, which adds requirements:
- Caller ID accuracy: Display a working callback number
- Disclosure requirements: Clearly identify yourself and your company
- Payment restrictions: Limits on advance fees for business loan services
- Material misrepresentation prohibition: No false claims about funding likelihood or terms
The TSR works in conjunction with TCPA rules, creating multiple compliance obligations for every call you make.
Conclusion: Partner with Compliance-First Lead Providers
TCPA compliance isn't just about avoiding fines—it's about building a sustainable MCA business that won't be derailed by litigation. The regulatory environment will only get stricter in 2025 and beyond, with state regulators increasingly active and class-action attorneys more sophisticated.
Your compliance strategy must include three pillars:
- Verified consent: Only call leads with documented, recent, specific consent
- Rigorous DNC management: Scrub against all registries and honor all requests immediately
- Internal systems: Use technology and training to prevent violations before they occur
The cost of non-compliance far exceeds the investment in doing things right. A single class-action lawsuit can bankrupt an MCA brokerage, while the marginal cost of compliant leads versus non-compliant ones is minimal.
At Lead Slaps, we understand that your compliance is our responsibility. Every lead we provide comes with full consent documentation, regular DNC scrubbing, and the verification you need to call with confidence. We don't just claim compliance—we prove it with paperwork.
Ready to build your MCA business on a compliant foundation? Contact us for compliant leads that you can trust, or explore our compliant lead sources to find the right solution for your business.
Don't wait until you receive that first demand letter. Start your compliance journey today.
Frequently Asked Questions (FAQ)
What is the difference between TCPA and the National Do Not Call Registry?
TCPA is the federal law that regulates telemarketing calls, robotext messages, and automated dialing systems. It requires prior express written consent for certain types of calls. The National Do Not Call Registry is a specific program created under TCPA enforcement that allows consumers to opt out of telemarketing calls. Compliance requires both valid consent AND scrubbing your call lists against the DNC registry every 31 days.
Can I call MCA leads that are more than 90 days old?
You can call older leads if they provided consent and haven't registered on the DNC list, but risk increases significantly with lead age. Consent can become stale if circumstances change, and older leads are more likely to have joined DNC registries. Best practice: prioritize leads under 90 days old and re-verify consent for anything older. Always scrub against current DNC registries regardless of lead age.
What happens if I accidentally call someone on the DNC list?
A single inadvertent violation may be excused under "safe harbor" provisions if you can demonstrate written compliance procedures, regular training, and good-faith efforts to comply. However, multiple violations or patterns of non-compliance won't be protected. Document the incident, add the number to your internal DNC list immediately, and review how it happened to prevent recurrence.
Do I need consent if I'm calling business phone numbers?
This is a complex area. The TCPA exempts calls to business lines from some requirements, but there's significant legal debate about what constitutes a "business line" (especially for sole proprietors and small businesses). Many MCA leads are for small businesses using personal cell phones for business purposes. Safest approach: treat all numbers as requiring consent unless you can definitively verify they're dedicated business lines.
How long should I keep consent records and call logs?
Federal guidance recommends maintaining TCPA-related records for at least four years, though some states require longer retention. The statute of limitations for TCPA violations is generally four years, so keeping records for this period allows you to defend against claims. Many compliance experts recommend five to seven years for comprehensive protection. Store records securely with backup systems to prevent loss.
Ready to Buy High-Quality MCA Leads?
Get access to exclusive, verified merchant cash advance leads that convert.
View Our Lead Packages