July 21, 202610 min read

TCPA Compliance for MCA Brokers: How to Generate Leads Without Getting Sued in 2026

TCPA class-action lawsuits are shutting down MCA brokerages in 2026. This guide covers what every MCA broker must know about consent rules, lead vendor liability, and building a compliant lead generation operation.

tcpa compliancemca lead generationbroker compliancetcpa lawsuitsmca brokerlead generationregulatory compliance

If you run an MCA brokerage and your lead generation involves cold calls, text messages, or auto-dialed outreach, 2026 may be the most legally dangerous year you have ever operated in. The Telephone Consumer Protection Act -- the TCPA -- has returned to the center of the small business lending world, and the consequences for brokers who ignore it are severe: class-action lawsuits, six-figure settlements, and in the most serious cases, the forced closure of entire operations.

This is not a scare-tactic article. TCPA enforcement against MCA brokers and their lead vendors is a documented, accelerating trend. Understanding the law, knowing where your exposure sits, and fixing your processes before a demand letter arrives is the most important compliance step most brokers are not taking. Here is what you need to know.

What Is the TCPA and Why Does It Apply to MCA Brokers?

The Telephone Consumer Protection Act (TCPA) is a federal law passed in 1991 that restricts unsolicited telephone marketing. It covers calls, voicemails, fax broadcasts, and -- critically for modern MCA outreach -- SMS and text message campaigns. The law allows individuals and businesses to sue for $500 to $1,500 per violation. That per-message amount is what makes TCPA class actions so dangerous: a lead vendor who sent 50,000 noncompliant texts on your behalf could generate $75 million in statutory exposure before a single attorney fee is added.

The TCPA applies to MCA brokers because your business model depends on reaching merchants -- often through high-volume outreach, purchased lead lists, and third-party dialers. Every cold text, every robo-call, and every predictive dialer campaign is a potential TCPA violation if the recipient did not give proper prior express written consent.

For a plain-language breakdown of key terms, see our MCA glossary, which covers the regulatory vocabulary brokers encounter most often.

The Core TCPA Rules Every Broker Must Know

1. Prior Express Written Consent

Before you call or text a merchant using any automated technology -- a predictive dialer, an auto-dialer, an automated text platform -- you must have prior express written consent (PEWC). This means a signed agreement (digital signatures count) that clearly states the merchant agrees to receive marketing communications at the specific phone number provided, and that consent is not a condition of purchase or service.

Verbal consent does not satisfy PEWC for auto-dialed or pre-recorded calls. A merchant checking a box on a generic web form that says "I agree to the terms" does not satisfy PEWC unless the checkbox language specifically describes the type of calls and texts they will receive and names the company (or category of companies) that will contact them.

2. Autodialers and the ATDS Definition

The TCPA restricts use of an Automatic Telephone Dialing System (ATDS) without PEWC. After the Supreme Court's Facebook v. Duguid decision in 2021 narrowed the ATDS definition, some brokers believed predictive dialers were now safe. The picture is more complicated in 2026. Many state TCPA analogs -- California, Florida, and others -- use broader definitions that cover predictive and preview dialers regardless of the federal ruling. Operating in multiple states with a single dialing platform means you are potentially subject to the strictest state definition that applies.

3. The National Do Not Call Registry

Any number on the federal or state Do Not Call (DNC) registry cannot receive telemarketing calls unless the called party has given express permission. Scrubbing your lists against the DNC registry is not optional -- it is a minimum standard, and regulators consider failure to scrub an aggravating factor in enforcement actions. You must re-scrub lists before each outbound campaign, not just at the time of list purchase.

4. SMS and Text Message Rules

Text message marketing is subject to the same TCPA rules as phone calls when sent via an autodialer or mass-texting platform. In the MCA industry, where brokers commonly send bulk SMS campaigns to purchased merchant lists, this is an enormous source of exposure. Every single text sent without PEWC is a separate violation. A campaign of 10,000 texts to a non-consented list is 10,000 violations at $500 to $1,500 each.

Additionally, under FCC rules updated in 2024, each marketing text must include a clear opt-out mechanism. Failure to honor opt-out requests within 10 business days creates additional violation exposure.

Why 2026 Is Different: Class Actions Are Closing Brokerages

TCPA litigation against MCA brokers and their affiliated lead generation companies has intensified significantly since 2024. Several factors are converging:

  • TCPA plaintiffs' bar has matured. Specialized law firms that file TCPA class actions on a contingency basis have identified MCA lead generation as a fertile target. The volume of outbound contacts, the use of third-party lead vendors, and the lack of documented consent make MCA broker operations highly vulnerable.
  • FCC's 2024 one-to-one consent rule. The FCC's 2024 ruling required that consent for automated marketing calls be obtained on a one-to-one basis -- one consent per seller, not a blanket consent on a lead aggregator form that then sells the lead to dozens of buyers. This rule went fully into effect in January 2025 and immediately invalidated the consent language used by most major MCA lead vendors. Many brokers are still buying leads under consent practices that no longer comply.
  • State mini-TCPA laws are multiplying. Florida's Mini-TCPA (SB 1120), in effect since 2021, applies even stricter standards for automated calls and texts and allows private rights of action. Texas, Georgia, and other states have moved similar legislation in 2025 and 2026. A single campaign touching multiple states multiplies your exposure across different regulatory frameworks.
  • Vicarious liability is being applied to brokers. Courts are increasingly holding the ultimate beneficiary of the marketing call -- the MCA broker who bought the lead -- liable for TCPA violations committed by the lead vendor. "I didn't know my vendor was non-compliant" is not a defense that courts have consistently accepted.

The Lead Vendor Chain Problem

Most MCA brokers do not place illegal calls themselves. They buy leads from lead generation companies who, in turn, may have acquired those contacts through aggregator sites, affiliate networks, or their own outbound campaigns. The compliance problem runs deep in this chain.

Under the FCC's one-to-one consent rule, a merchant who filled out a generic business loan inquiry form in 2023 -- consent language that said "I agree to be contacted by up to 50 lenders" -- did not give valid PEWC to your brokerage under 2025 and 2026 standards. The lead vendor may still be selling this data as "consented." The broker buying and calling that lead is committing a TCPA violation.

Key questions to ask every lead vendor before purchasing:

  • What is the exact consent language shown to the prospect at the point of lead capture?
  • Does that consent language specifically name your company or category?
  • When was the consent obtained and does it meet the FCC's one-to-one standard?
  • Can you provide a screenshot or audit log of the consent collection page?
  • What is your policy for DNC scrubbing and how recent is the scrub?
  • What indemnification do you provide if a lead results in a TCPA claim?

If a vendor cannot answer these questions with documentation, do not buy their leads for automated outreach. You can still call them manually with a human dialing each number individually -- manual one-by-one calling generally falls outside ATDS restrictions -- but high-volume manual dialing is operationally impractical at scale.

Building a TCPA-Compliant MCA Lead Generation Operation

Inbound Leads Are the Safest Path

The cleanest TCPA compliance posture is generating inbound leads -- merchants who contact you first. Content marketing, SEO, Google Ads, and listing your brokerage on platforms like our funder directory put you in front of merchants who are actively looking for funding. Inbound contacts eliminate ATDS consent issues entirely because you are responding to an inquiry, not initiating an unsolicited commercial contact.

Consent Capture for Outbound

If your brokerage generates its own web leads, your consent capture form must meet the FCC one-to-one standard. The form must:

  • Name your brokerage specifically (not a generic reference to "lenders")
  • Describe that the merchant will receive automated calls and texts
  • List the phone number that will be contacted
  • State that consent is not required to receive services
  • Require an affirmative opt-in action (a pre-checked checkbox does not count)

Store the timestamp, IP address, form URL, and consent language version for every submission. If you are ever sued, this records retention is the foundation of your defense.

DNC Scrubbing and Suppression Lists

Build a suppression list that combines the federal DNC registry, state DNC lists for every state you operate in, and your own internal opt-out list. Scrub every outbound list against this combined suppression file before each campaign. Automate this process -- manual scrubbing is error-prone and courts do not view human error sympathetically.

Honor opt-out requests from every channel. If someone texts STOP, calls in to opt out, or sends an email requesting removal, they go on your suppression list the same day. Every channel feeds the same master suppression database.

Manual Dialing for Non-Consented Lists

If you have a list of prospects for whom you do not have PEWC, a human agent manually dialing each number one at a time -- no predictive dialer, no click-to-call automation that queues hundreds of numbers -- generally falls outside ATDS restrictions at the federal level. This is far lower volume but far lower risk. Reserve this approach for your highest-value targets where a direct human conversation is appropriate anyway.

Referral Networks as a Compliant Alternative

Referral partnerships with accountants, attorneys, insurance agents, and other business service providers generate pre-warmed leads without any cold outreach. The referring professional introduces you to a merchant who already knows they have a funding conversation coming. There is no TCPA exposure because you are responding to a warm referral introduction, not initiating unsolicited marketing.

For strategies on building these partnerships, see our guide on building an MCA broker referral network.

What to Do If You Receive a TCPA Demand Letter

TCPA demand letters often arrive from a plaintiff's attorney who represents a merchant -- or a professional TCPA plaintiff -- who received a call or text they claim was noncompliant. These letters typically demand a settlement payment to avoid litigation.

Your immediate steps:

  1. Do not respond to the demand letter without an attorney. Anything you say can be used against you. Refer the letter to legal counsel experienced in TCPA defense immediately.
  2. Preserve all records. Call logs, lead purchase records, consent documentation, dialer platform data, and text campaign records must be preserved. Destruction of records after notice of a claim is spoliation, which courts treat severely.
  3. Identify the lead source. Was the contact generated by your brokerage or purchased from a vendor? If the latter, your vendor's indemnification obligation comes into play. Notify the vendor and document the notification.
  4. Assess your consent documentation. If you have a valid PEWC on file for the complaining party, that is your primary defense. Pull it immediately.
  5. Evaluate settlement early. TCPA defense litigation is expensive. If your documentation is weak, a negotiated settlement is often less costly than a trial.

Technology Tools for TCPA Compliance

Several platforms have emerged to help MCA brokers manage TCPA compliance operationally:

  • Consent management platforms store, timestamp, and audit-trail all consent records with tamper-evident logs
  • DNC scrubbing APIs that plug into your CRM and automatically flag suppressed numbers before any outreach is triggered
  • Compliant dialing platforms that are specifically built to document every outbound call with the consent record that authorized it
  • Lead verification services that independently audit the consent documentation provided by lead vendors before you call

These tools add cost but are far cheaper than a TCPA class action. Treat compliance infrastructure as part of your cost of doing business in 2026.

MCA Brokers and the Broader Compliance Picture

TCPA compliance sits inside a larger compliance environment that MCA brokers must navigate in 2026. State commercial financing disclosure laws now apply in California, New York, Utah, Virginia, Georgia, Connecticut, Illinois, and New Jersey -- each requiring specific disclosures before a deal closes. For an overview of the state disclosure landscape, see our guide to MCA multi-state disclosure laws for 2026.

Brokers who are building compliant operations are also revisiting their ISO agreements with funders to confirm that TCPA representations and indemnification are addressed. If your ISO agreement does not address TCPA compliance obligations and indemnification, raise it with your funder contacts. For a breakdown of what to negotiate, see our guide on key ISO agreement clauses brokers must negotiate.

If you are still building out your funder panel and want to connect with verified funders who have compliant programs, create your broker account on MCA Directory to access our network.

Practical Takeaway

TCPA exposure is the single most dangerous legal risk most MCA brokers are carrying right now -- and most do not know it. The combination of the FCC's one-to-one consent rule, aggressive TCPA class-action litigation, and state-level mini-TCPA laws has made the lead generation practices that were standard in the MCA industry just a few years ago actively illegal today.

The brokers who survive and grow in this environment will be the ones who build compliant lead generation from the ground up: inbound-first strategies, verified consent records, DNC compliance automation, and rigorous lead vendor due diligence. The brokers who keep buying cheap lists and running autodialers without documented consent are sitting on a liability that could end their business with a single class certification.

Audit your lead generation operation today. If you cannot document valid PEWC for the lists you are calling, stop calling them until you can. The short-term cost in missed volume is minor compared to the cost of a TCPA settlement or judgment. Build your pipeline on inbound leads, referrals, and properly consented prospects -- and build the compliance documentation to prove it.

Find the right MCA funder for your deal

Search by revenue, credit score, positions, and more.

Search Funders →
SearchFunderPromosMarketplace