Database Reactivation
Reactivating Bought Leads: What You Can and Cannot Send
The most expensive mistake in reactivation is treating a bought list and a first-party list as the same asset. They are not, and the difference is not about how old they are.
Spent 8 years running operations for a startup studio that launched more than a dozen companies. Leads CRM, automation, AI assistants, websites, and delivery infrastructure at Agency Logics.
Published
Why a bought lead is a different asset
When someone fills in your form, they saw your name and a disclosure naming your business. When someone fills in a comparison form, they saw a form belonging to somebody else, and whatever it said about who might contact them. Those are different consent positions even though both end up as a row in your CRM with a phone number in it.
| Origin | SMS marketing | Email marketing | Notes |
|---|---|---|---|
| Your own form, with a marketing disclosure naming you | Generally yes | Yes | The strongest position. No expiry on prior express written consent |
| Past customer who transacted with you | Generally yes, if consent was captured | Yes | A transaction is not automatically SMS marketing consent |
| Third-party lead where the disclosure named you | Possibly, if you can produce the record | Yes | You must be able to show what the consumer saw |
| Shared comparison form, no named recipients | Treat as no | Usually yes under CAN-SPAM | The most common and most risky category |
| Scraped, appended or purchased contact data | No | High risk | No consent exists to rely on |
The record is the asset, not the phone number
The practical test is simple: if a complaint arrived tomorrow, could you produce the disclosure that person saw and the timestamp they agreed to it? If your lead seller cannot supply that on request, you do not have documented consent, you have a phone number and an assumption.
Three things most published guidance gets wrong
- "The FCC one-to-one rule bans third-party lead consent." It would have substantially restricted it, but it never took effect. The Eleventh Circuit vacated it on 24 January 2025 in Insurance Marketing Coalition Ltd. v. FCC, the FCC did not appeal, and the language was deleted in 2025. A great deal of content still says it took effect in January 2026. It did not. Detail in the TCPA rules.
- "Leads over a year old are safe to text." There is no age at which consent you never had appears, and no expiry on consent you did get. Age is the wrong axis entirely.
- "We have an established business relationship, so we are covered." The Do Not Call established business relationship exemption covers live calls only. It does not exempt autodialed or prerecorded calls and texts, which is what a bulk SMS reactivation campaign sends.
What to actually do with a bought list
"Do not text it" is not the same as "it is worthless." There are three legitimate routes, in order of how much value they tend to return.
- Run it as email first. Commercial email is governed by CAN-SPAM, which requires accurate headers, a clear commercial purpose, a physical address and a working unsubscribe honored promptly. That is a materially lower bar than TCPA consent for SMS, and it lets you work the list while you sort the rest out.
- Run a consent-capture campaign. Use the email channel to ask people to opt in to texts, with a real disclosure naming your business. Everyone who opts in moves into the first-party segment permanently, which is a durable asset rather than a one-off send.
- Use it for ad audience matching. Uploading a customer list to build a matched or lookalike audience is a different legal question from sending a message to it, and it extracts value from a list you cannot text.
- Go back to the seller for the consent records. Worth doing once. A seller who can produce timestamped disclosures naming you has just upgraded a chunk of your database. A seller who cannot has told you something important about the rest of what they sell.
What this means for segmentation
All of this is why segmentation happens by consent origin first and behaviour second, before anybody writes a message. If your CRM does not record how each contact entered the database, that is the first thing to fix, and it is usually recoverable from form records, lead-seller invoices and integration logs. How to segment a CRM properly, and what to send once you have.
The carrier layer, which is separate from the legal one
Even where consent is solid, nothing sends without A2P 10DLC registration. Since 1 February 2025 US carriers block unregistered traffic outright rather than throttling it. Registration is also where a bought list becomes visible: campaign review asks how you collected consent, and a publicly reachable opt-in form URL is the single most common reason campaigns get rejected.
Common questions
- Can I text leads I bought from a lead seller?
- It depends on what the consent language on the original form actually said and whether your business was identified as a recipient. Consent obtained by a third party can be valid, but it has to have been consent to receive marketing from you, and you need to be able to produce the record of it. If nobody can show you the disclosure the consumer saw, treat the list as unconsented for SMS marketing purposes.
- Does the FCC one-to-one consent rule stop this?
- No, because that rule is not in force. The Eleventh Circuit vacated it on 24 January 2025 in Insurance Marketing Coalition Ltd. v. FCC, the FCC did not appeal, and the language was deleted in 2025. Reporting that it took effect in January 2026 is wrong. The pre-2023 prior express written consent standard governs instead, which is a lower bar than one-to-one but is still a real bar.
- Is an old bought lead safer than a recent one?
- Age is not the deciding factor and treating it as one gets businesses into trouble in both directions. The TCPA sets no expiry on prior express written consent, so a three-year-old properly consented contact may be fine while a lead bought last week under vague shared-form language may not be. What matters is the origin and the record, not the date.
- What about the established business relationship exemption?
- It is narrower than most people think. The Do Not Call established business relationship exemption, 18 months after a transaction and 3 months after an inquiry, covers live calls only. It does not exempt autodialed or prerecorded calls and texts, which is exactly what a bulk SMS campaign sends. Relying on it for a reactivation text is a common and expensive misreading.
- So what can I do with a bought list?
- Email is generally the lower-risk channel and is governed by CAN-SPAM rather than the TCPA, so a compliant commercial email with a working unsubscribe is usually available where SMS is not. You can also use the list for ad audience matching, and you can run a consent-capture campaign that asks people to opt in before any SMS. What you should not do is drop a bought list into an SMS blast and hope.
Sources
- 1.Insurance Marketing Coalition Ltd. v. FCC, Eleventh Circuit, 24 January 2025 The decision vacating the FCC one-to-one consent rule.
- 2.FTC, Do Not Call provisions for telemarketers and sellers Established business relationship windows, and the limit that they cover live calls.
- 3.FTC, CAN-SPAM Act compliance guide for business The requirements governing commercial email, referenced above as the lower-risk channel.
Find out how much of your database you can actually contact
The usable share is almost always smaller than the row count and larger than owners fear once consent origin is properly reconstructed. It is an audit question, and it comes before any campaign is written.
Apply For a Growth Partnership