Compliance · Pay-Per-Call

Inbound Isn't Automatically TCPA-Safe: The Questions I Ask Every Publisher

A consumer dialing your number isn't telemarketing. What made them dial might be.

By Wali Zuberi · BPO · Contact Centers · AI · October 1, 2026

People often describe inbound pay-per-call as "TCPA-safe" because a consumer placing a call isn't telemarketing under the Telephone Consumer Protection Act. That's true as far as it goes. But many inbound calls are triggered by outbound activity: a text, a callback, a ringless voicemail, or an outbound dial that turns into a live transfer. That activity is regulated, and statutory damages run $500 per violation, up to $1,500 if the violation is willful or knowing.

My test for any call is simple. If this caller complained tomorrow, could we show within an hour exactly how and why they called? These are the questions I ask publishers so the answer is yes.

How is each source generated?

Search, social, display, TV or radio, IVR, SMS, outbound dialing or transfers. The answer decides which rules apply. I also want a source ID on every call so I can pause one source without shutting down the whole publisher.

Where is the consent, and who does it name?

For telemarketing that uses an autodialer or a prerecorded voice, the FCC requires prior express written consent. That means a signed agreement, electronic signatures included, that clearly authorizes the seller to contact a specific number and says consent isn't a condition of purchase. I ask for an independent consent certificate per lead (for example, TrustedForm or Jornaya), ideally with a session replay. I also check that my company, or the seller I'm buying for, is actually named. A form listing hundreds of "partners" is a liability.

Does the consent match the call?

The phone number on the certificate should match the caller ID or the number dialed, within an agreed freshness window.

Are you holding to one-to-one consent anyway?

The FCC's one-to-one consent rule was vacated by the Eleventh Circuit in January 2025. Seller-specific consent is still the easiest standard to defend, and I prefer partners who kept it.

What do you scrub, and how do you handle opt-outs?

That covers the National Do Not Call Registry, internal DNC lists, the FCC's Reassigned Numbers Database and known-litigator lists. Under FCC rules that took effect in 2025, consumers can revoke consent by any reasonable means, and the revocation must be honored within ten business days. State laws in places like Florida, Oklahoma and Maryland add their own requirements.

Is your texting registered?

SMS should run on registered A2P 10DLC campaigns or other carrier-approved routes. Grey routes tell me something about the rest of the operation.

Can you produce evidence for a specific call within a day or two?

If not, I don't buy from that source.

What will you sign?

I look for representations of lawful, consented traffic; indemnification backed by insurance; no undisclosed sub-publishers; the right to reject or claw back non-compliant calls; audit rights; and creative approval before launch.

Good publishers already work this way and are glad to be asked. Asking for evidence doesn't shrink supply. It filters for partners worth keeping.

General industry commentary, not legal advice. Consult qualified counsel about your program.

A longer version of this piece is published on ZW Global Group.

Wali Zuberi

Wali Zuberi — BPO · Contact Centers · AI. Rawalpindi-based operator with 17+ years in sales, BPO and pay-per-call contact centers. Leads Alrehman Communication LLC and ARC LLC Technologies within the ZW Global Group ecosystem.