TCPA, Consent, and Lead Gen: A Marketing Compliance Checklist for PE Portfolio Companies
Growth buys the leads. Ops celebrates the dialer queue. Legal finds out when a demand letter lands, or when diligence asks for consent records nobody can produce. That is the quiet failure mode I see on TCPA compliance lead generation programs inside PE portfolio companies: paid media and SMS scale faster than consent management, and the board only hears about it when the hold narrative is already at risk.
I sit in the operator seat. My job is not to replace counsel. It is to keep growth from creating TCPA or FTC exposure that a partner will hate in the next IC memo. This is a practical keep / fix checklist for marketing compliance private equity portfolio companies that buy leads, run forms, and text prospects. It is not a vendor ranking, and it is not legal advice.
This article is an operator playbook for consent, paid lead gen, SMS, forms, and vendor handoffs. It is not legal advice, not a substitute for counsel, and not a guarantee of compliance outcomes. Laws and enforcement posture change. Have counsel review your specific flows, scripts, and contracts before you scale.
Impaxium runs growth and marketing compliance together: we audit the live stack (forms, SMS, lead sources, pixels, agency handoffs), then help PortCos and funds fix what creates board-level risk. For the broader HIPAA / FTC / TCPA / CAN-SPAM / FDIC map, start with our regulated industries compliance guide. Weigh our seat however you see fit.
Why PE boards care about TCPA and consent (even when legal "owns" it)
Founder-era marketing often treats consent as a checkbox on a landing page. PE hold periods treat it as inherited liability, diligence friction, and exit risk. Boards care for three boring reasons that still decide outcomes.
Diligence will ask for proof, not vibes. Buyers and lenders now ask whether lead forms, texts, and calls carry valid consent language, and whether purchased leads create TCPA exposure for the next owner. We covered that screen in marketing due diligence when buying a company. If you cannot produce consent artifacts, source maps, and revocation logs, you are negotiating from weakness even if volume looks fine.
Hold periods punish slow remediation. You do not get five quiet years to "clean up the list." You get a finite window. Scaling SMS or lead buys on soft consent burns that window twice: once in legal risk, once in the CAC story when you have to pause channels mid-hold.
Inherited vendors hide the risk. Agencies, lead aggregators, call centers, and "performance partners" often sit between the consumer and your CRM. If consent was captured for someone else, for a different use, or with a partner list nobody can audit, your PortCo still owns the blast radius. That is why consent management paid media is a fund-side topic, not only a CMO topic. Same pattern as inherited agencies we wrote about in when to fire a marketing agency: ownership and documentation beat polished decks.
TCPA and consent checklist for PE PortCos (keep / fix)
Score the live program, not the policy PDF. Use keep / fix the same way you would score CAC integrity. If a row is red and nobody owns a dated fix, treat scale as frozen until counsel and ops agree.
| Area | Keep (green) | Fix (red / amber) | |
|---|---|---|---|
| 01 | Consent capture | Affirmative, unbundled opt-in; clear seller identity; records of what was shown and when; consent not a condition of the core purchase where required | Pre-checked boxes; one checkbox for terms + marketing + SMS; vague "partners may contact you"; no screenshot or versioned language archive |
| 02 | Lead sources | Named sources with written consent flow review; PortCo can audit sample leads; no "exclusive" claims that collapse under scrutiny | Blind aggregator buys; shared leads; consent captured for a different brand or use; seller cannot produce the consumer-facing disclosure |
| 03 | SMS / dialer | Prior express written consent for marketing texts and autodialed calls; stop / help working; revocation honored through reasonable methods; suppression shared across vendors | Texting purchased numbers with no TCPA-grade consent; slow opt-out; vendor-specific suppression that does not sync; "transactional" labels on marketing content |
| 04 | Forms / LPs | Consent language adjacent to the action; mobile-readable; matches privacy policy; phone field triggers SMS disclosure when texts are planned | Buried hyperlinks as the only disclosure; different language per landing page with no control; phone collected "for contact" then used for marketing SMS |
| 05 | Vendors / agencies | Contract requires consent standards, audit rights, indemnities where appropriate, and PortCo ownership of lists and records; named compliance owner on both sides | Agency or lead vendor "handles compliance"; no audit rights; lists live only in vendor tools; no handoff packet for diligence |
| 06 | Records / board pack | Source map, consent versions, sample proofs, revocation log, and open remediation items in a diligence folder the OP can open cold | Slack threads as the archive; legal has a memo, growth has a spreadsheet, nobody can reconcile a single lead end to end |
For regulated industry lead gen compliance, treat red rows as operational freezes, not "Q4 projects." Healthcare-adjacent and financial PortCos should also read the pixel and claim sections in the broader compliance post and the healthcare agency context in performance marketing for healthcare. TCPA is not the only risk in those stacks, but it is the one that scales with every text and every purchased phone number.
Paid lead gen consent pitfalls (where volume hides liability)
Lead buys feel efficient until you ask one question: consent for whom, for what, captured how? Most failures I see are not cartoon villains. They are standard aggregator habits colliding with how TCPA and FTC theories actually work.
Consent captured for a different seller. The consumer opted in to Brand A or to a generic "home services network." Your PortCo is Brand B. Downstream buyers often assume transferability that the disclosure never granted. If your contract says the seller warrants TCPA compliance, that may help commercially. It does not automatically make the consumer experience compliant for your brand.
Shared and aged leads. A lead sold five times in forty-eight hours is a quality problem and a consent problem. Aged data with "we had consent once" is not a program. If you cannot see freshness, exclusive vs shared status, and the original disclosure, you are buying hope.
Partner lists and hyperlinked disclosures. Long partner schedules buried behind a link remain a litigation and enforcement conversation even after the FCC's one-to-one consent rule was vacated by the 11th Circuit and later removed. The underlying prior express written consent requirement did not disappear. Operators should not treat "the rule went away" as "blanket partner consent is fine." Link the high-level landscape to counsel and to our TCPA section in the compliance guide rather than improvising case law in a growth meeting.
Phone number as a soft conversion. Media teams love phone fields because dialers and SMS look cheap compared to auction CPC. If the form collected a number for a callback and the lifecycle team later blasts marketing texts, you have a consent mismatch. Fix the capture moment, or do not text.
FTC and deception sit next to TCPA. Misleading offer paths, undisclosed relationships, and privacy claims that conflict with pixel or partner sharing create parallel exposure. Marketing compliance private equity portfolio reviews should include claims and disclosures, not only SMS language.
Need a consent and lead-gen risk read before you scale SMS?
Impaxium audits live forms, SMS programs, lead sources, and agency handoffs for PortCos and funds, then pairs remediation with growth so you are not choosing between volume and a board-safe stack.
Explore marketing complianceSMS and TCPA: operator rules of thumb (high-level, not legal advice)
Counsel owns the legal standard. Operators own whether the stack matches what counsel thinks is happening. These rules of thumb keep growth meetings honest.
- Assume marketing SMS needs prior express written consent. If you are promoting an offer by text, treat consent as written, clear, and specific to automated marketing texts from an identified seller. Do not invent comfort from "they filled out a form."
- Match the disclosure to the use. Consent for a one-time appointment reminder is not consent for a weekly promo cadence. If product wants a new use, recapture or get counsel to bless the existing language.
- Make stop actually stop. Opt-out must work, and revocation should be honored through reasonable methods, not only a vendor's preferred keyword in one ESP. Sync suppression across agencies, dialers, and lead vendors. April 2025 FCC revocation expectations raised the operational bar. Build for it.
- Do not text purchased leads by default. If the lead seller cannot show a consumer-facing disclosure that covers your brand and SMS, park the numbers for voice or form follow-up only until counsel signs off. Volume is not a defense.
- Keep a sample proof kit. For each major flow: screenshot of the form as served, timestamped consent record fields, language version ID, and a sample lead that reconciles CRM to source. If you cannot assemble that in a day, you are not ready for diligence.
- Separate "we have a TCPA policy" from "the dialer is configured." Policies do not suppress lists. Configuration and QA do.
Again: statutory damages and class procedures are why this shows up in board packs. For publicly discussed ranges and the post-11th Circuit framing, use the Impaxium compliance guide and your counsel. Do not let a growth deck invent fine math.
Forms and landing pages: consent management for paid media
Consent management paid media starts on the page that captured the click, not in the CRM two weeks later. Landing pages are where most PortCos either get this right or bake in years of cleanup.
Put the SMS disclosure where the decision happens. If a phone field enables texts, the consumer should see who texts, that messages may be automated, message frequency if you state it, and that consent is not a condition of purchase where that rule applies. Tiny gray text three scrolls away fails the "unambiguous" test in practice even when someone liked the conversion rate.
Unbundle the ask. Terms of service acceptance, privacy policy acknowledgment, and marketing SMS consent are different decisions. One megacheckbox that says "I agree to everything" is a classic fix item.
Version the language. Every live LP variant should have a consent version ID stored with the lead. When legal updates copy, old leads keep their historical disclosure reference. Without versioning, you cannot defend what a consumer saw in March when a complaint arrives in September.
Align privacy policy and pixels. If the policy says you do not share personal information with advertising platforms, and the page fires a standard pixel stack, you have an FTC-shaped gap. Measurement upgrades help, but they do not replace honest consent copy.
Mobile first. If the disclosure collapses on mobile, the desktop PDF counsel approved is not the experience that matters.
Agency and lead-vendor contracts: handoffs that survive a board ask
Vendors will cheerfully say they are "TCPA compliant." Your job is to make that claim inspectable.
Write audit rights into the MSA. You need the right to review consumer-facing disclosures, sample leads, consent logs, and suppression handling. If the vendor refuses, that is information.
Require source transparency. Named publishers or acquisition methods beat "proprietary mix." Shared vs exclusive, freshness windows, and geography filters should be contractual, not Slack folklore.
Clarify who owns the list and the records. PortCo should own leads and consent artifacts. Agency tools can operate on them. The same ownership logic we use for ad accounts in agency keep / fix / replace applies here: if you cannot leave with the records, you do not control the risk.
Define prohibited uses. No silent SMS add-ons. No appending phone numbers from data append products into a marketing text stream without a counsel-approved basis. No "we'll just try a small blast."
Name a compliance owner on both sides. Growth PM plus vendor CSM is not enough when a complaint arrives. You want a person who can pull the proof kit without a three-week archaeology project.
Align incentives. If the vendor is paid only on volume, they will optimize volume. Tie acceptance to consent completeness and sales-qualified quality, not raw form-fills.
What to put in the board pack and diligence folder
Operating partners do not need a law review article. They need a folder they can open cold before the next board or before an LOI process heats up.
- One-page risk summary: channels in scope (paid lead gen, SMS, dialer, email), green / amber / red on the checklist table, and the top three remediations with owners and dates.
- Source map: every lead source and SMS vendor, volume share, exclusive vs shared, and whether consent flow was reviewed in the last 90 days.
- Consent version archive: current and prior LP / form language with dates live.
- Sample proof pack: 5-10 reconciled leads from each major source showing disclosure, timestamp, CRM fields, and any SMS events.
- Revocation and suppression design: how stop requests propagate across systems, with a recent test result.
- Contract extract: audit rights, warranties, indemnities, and ownership clauses for the top vendors (summary, not the full MSA dump).
- Open counsel questions: anything growth cannot resolve alone, dated, so the board sees process instead of silence.
Under LOI, fold this into marketing diligence early. Soft CAC with hard TCPA gaps is still a bad buy. On the hold side, the same folder is exit hygiene. PE advisory and fractional CMO seats exist because most PortCos lack a full-time owner for growth-plus-compliance.
What good looks like when you keep scaling
Good is not "we stopped growing." Good is measured growth on consent you can defend.
- Forms and SMS language versioned and tested on mobile.
- Lead buys limited to sources that survive a sample audit.
- Suppression shared; opt-outs honored quickly.
- Agency and aggregator contracts with audit rights and PortCo-owned records.
- Board pack that states risk and remediation without jargon theater.
Install the checklist first, then scale. Pausing a bad SMS program for two weeks beats explaining a demand letter in a board deck. Fund-side read: PE advisory. Single PortCo buyer for remediation: fractional CMO. Stack audit: marketing compliance or contact.
Frequently asked questions
What is TCPA compliance for lead generation in a PE portfolio company?
TCPA compliance for lead generation means your PortCo can show that marketing texts and autodialed calls rest on prior express written consent that matches the seller and the use, that opt-outs work, and that purchased leads were not simply assumed to be textable. It is an operational proof problem as much as a policy problem.
Why does marketing compliance matter for private equity portfolio companies?
Marketing compliance matters for private equity portfolio companies because consent and disclosure failures become diligence findings, hold-period distractions, and exit friction. Boards care when growth channels create liability that outlasts a quarterly CAC win.
How should PortCos handle consent management for paid media?
Handle consent management for paid media by versioning form language, placing SMS disclosures next to phone capture, unbundling marketing consent from terms acceptance, storing what the consumer saw, and freezing scale on any flow counsel has not reviewed.
Can we text leads we bought from an aggregator?
Not by default. You should text purchased leads only when counsel is satisfied that the consumer-facing consent covers your brand and SMS use, and when you can produce sample proof. Many aggregator flows do not clear that bar.
Did the 11th Circuit ending the FCC one-to-one consent rule mean partner-list consent is fine?
No. The 11th Circuit vacated the FCC's one-to-one consent rule, and the FCC later removed it, but prior express written consent requirements remain. Blanket partner-list practices are still a risk conversation. Read the landscape with counsel and the high-level summary in Impaxium's regulated industries compliance guide.
What belongs in a TCPA diligence folder for a PortCo?
A TCPA diligence folder should include a source map, consent version archive, sample reconciled leads, revocation and suppression design with a test result, vendor contract highlights, and a one-page green / amber / red summary with dated remediations.
How does Impaxium help with regulated industry lead gen compliance?
Impaxium helps with regulated industry lead gen compliance by auditing the live marketing stack, flagging consent and disclosure gaps, and tying remediation to growth operations so PortCos can keep acquiring without flying blind. Soft next steps: marketing compliance, PE advisory, and contact.
Close the gap before growth creates the board problem
TCPA, consent, and lead gen fail quietly until they fail loudly. The fix is not a longer privacy policy. It is a keep / fix checklist on consent capture, lead sources, SMS, forms, vendors, and records, owned by someone who can stop scale when a row turns red.
Run the table on your live flows this week. Put the proof kit in a diligence folder. Make vendors inspectable. When you want a second set of operator eyes across compliance and growth, start at marketing compliance, bring the fund lens through PE advisory, or contact Impaxium for a single-company diagnostic. Typical response is one business day. Growth should compound. Consent debt should not.
Get a senior operator on your growth
Paid media, tracking infrastructure, CRO, lifecycle, and SEO - built and run by the person doing the work.
Get a free growth audit