Insights

TCPA vs PECR: What Enterprise Buyers Need to Know

A clear, side-by-side breakdown of the two consent regimes every trans-Atlantic buyer needs to understand — and how Connexis handles both by default.

Kieran. F· 2 min read·17 August 2026

If you're buying calls on both sides of the Atlantic, you're operating under two different consent regimes at once. Getting this wrong isn't a fine — it's an existential risk. Here's the working knowledge every enterprise buyer needs.

The two regimes at a glance

TCPA (US)PECR (UK)
JurisdictionFederal · FCC + state AGsUK · ICO
Consent standardPrior express written consent (2013 order)Freely given, specific, informed (GDPR-aligned)
Penalty per violation$500–$1,500 per callUp to £500,000 or 4% global turnover
Private right of actionYes — class actionsNo — regulatory only
DNC scrubbing requiredNational DNC + internalTPS + internal
Consent record retention4 years minimumDuration of use + 6 years post

For TCPA, the consent record must show:

  • Clear, conspicuous disclosure that the consumer is agreeing to be called
  • Identification of the specific seller(s) authorised to call
  • Statement that consent isn't a condition of purchase
  • Signature (checkbox counts) with timestamp, IP, and user-agent
  • The URL / page where consent was captured

For PECR, the standard is closer to GDPR: consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give. The consumer should know exactly which entity is calling them and about what.

The Connexis compliance layer

Every call routed on Connexis carries a consent artefact by default:

  • TCPA + PECR consent captured at source with timestamp, IP, and user-agent
  • DNC + TPS + suppression scrubbing before the router matches to a buyer
  • STIR/SHAKEN attestation on US outbound traffic
  • Full call recording + 24-month retention, sector-tagged, DSAR-ready
  • Recorded consent read at pick-up on regulated verticals (Rehab, Medicare, Final Expense)

The regulator, the buyer, and internal QA all trust the same evidence. That's the point.

The three mistakes we see most

  1. Buying "opt-in" data at scale. If you can't produce the consent artefact per call, you don't have consent. Aged data from a "TCPA-compliant list" is not a defence.
  2. Trusting third-party lead-gen forms. If a publisher captured consent for a "financial services quote" and you're calling about a specific mortgage refinance, that consent may not cover your call.
  3. Skipping DNC on internal suppression. A prior customer who's asked not to be contacted still counts. Internal DNC is not optional.

If you're stress-testing your current pay-per-call stack against these two regimes, book a compliance review →.

Ready to route calls?

Post a campaign or place your supply on Connexis.

Talk to the desk