TCPA vs PECR: What Enterprise Buyers Need to Know
A clear, side-by-side breakdown of the two consent regimes every trans-Atlantic buyer needs to understand — and how Connexis handles both by default.
If you're buying calls on both sides of the Atlantic, you're operating under two different consent regimes at once. Getting this wrong isn't a fine — it's an existential risk. Here's the working knowledge every enterprise buyer needs.
The two regimes at a glance
| TCPA (US) | PECR (UK) | |
|---|---|---|
| Jurisdiction | Federal · FCC + state AGs | UK · ICO |
| Consent standard | Prior express written consent (2013 order) | Freely given, specific, informed (GDPR-aligned) |
| Penalty per violation | $500–$1,500 per call | Up to £500,000 or 4% global turnover |
| Private right of action | Yes — class actions | No — regulatory only |
| DNC scrubbing required | National DNC + internal | TPS + internal |
| Consent record retention | 4 years minimum | Duration of use + 6 years post |
What "consent" actually needs to include
For TCPA, the consent record must show:
- Clear, conspicuous disclosure that the consumer is agreeing to be called
- Identification of the specific seller(s) authorised to call
- Statement that consent isn't a condition of purchase
- Signature (checkbox counts) with timestamp, IP, and user-agent
- The URL / page where consent was captured
For PECR, the standard is closer to GDPR: consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give. The consumer should know exactly which entity is calling them and about what.
The Connexis compliance layer
Every call routed on Connexis carries a consent artefact by default:
- TCPA + PECR consent captured at source with timestamp, IP, and user-agent
- DNC + TPS + suppression scrubbing before the router matches to a buyer
- STIR/SHAKEN attestation on US outbound traffic
- Full call recording + 24-month retention, sector-tagged, DSAR-ready
- Recorded consent read at pick-up on regulated verticals (Rehab, Medicare, Final Expense)
The regulator, the buyer, and internal QA all trust the same evidence. That's the point.
The three mistakes we see most
- Buying "opt-in" data at scale. If you can't produce the consent artefact per call, you don't have consent. Aged data from a "TCPA-compliant list" is not a defence.
- Trusting third-party lead-gen forms. If a publisher captured consent for a "financial services quote" and you're calling about a specific mortgage refinance, that consent may not cover your call.
- Skipping DNC on internal suppression. A prior customer who's asked not to be contacted still counts. Internal DNC is not optional.
If you're stress-testing your current pay-per-call stack against these two regimes, book a compliance review →.