The Laws That Protect You From Getting Spammed
You wanted a quote on car insurance.
You filled out a form. Maybe you clicked a checkbox. Maybe you didn't read the fine print. Within 24 hours, your phone rang six times. Three different companies texted you. Your inbox filled with emails from brands you've never heard of.
Welcome to the lead generation industry. Your information just got sold.
This isn't a bug. It's the business model. And while the law does protect you, the protections are messier than you'd expect.
The Big One: TCPA
The Telephone Consumer Protection Act has been around since 1991. It's the main federal law that limits who can call and text you.
The basics:
Telemarketers can't call you before 8am or after 9pm. They need written consent before sending you robocalls or automated texts. And if you ask them to stop, they have to stop.
Violations aren't cheap. Companies face penalties of $500 to $1,500 per illegal call or text. Class action lawsuits have exploded in 2025. More than 1,000 class actions were filed in the first half of 2025 alone. Real estate company Keller Williams paid $40 million in recent litigation.
The problem? Consent. Or more specifically, how easily companies manufacture it.
The Consent Farm Problem
Here's how it works.
You visit a website that promises to "match you with providers." You enter your phone number. Somewhere in the fine print, there's a disclosure that says something like: "By clicking submit, you agree to receive calls from our marketing partners."
Those partners? There could be 30 of them. Or 50. You just consented to all of them with one click.
The FTC calls these sites consent farms. They use "dark patterns" to trick you into giving permission you didn't understand.
In January 2024, the FTC shut down a lead generator called Response Tree. The company ran at least 50 websites that looked like helpful comparison tools. They were actually consent farms. $7 million settlement. Permanent ban from the industry.
The One-to-One Rule That Almost Was
The FCC tried to fix this.
In December 2023, they proposed a new rule: companies would need "one-to-one" consent. That means you'd have to agree to each company separately. No more blanket checkboxes covering dozens of partners.
It was supposed to take effect January 27, 2025.
Three days before the deadline, the 11th Circuit Court struck it down. The court ruled the FCC exceeded its authority. The lead generation industry exhaled. The loophole stayed open.
This is the legal reality: consent farms aren't illegal by default. They're just litigation bait. Companies that do it sloppily get sued. Companies that do it carefully keep rolling.
The Do Not Call Registry
The simplest protection you have is the National Do Not Call Registry.
Go to DoNotCall.gov or call 1-888-382-1222. Registration is free. Once you're on the list, telemarketers must scrub your number from their call lists within 31 days.
As of September 2025, the registry has over 258 million active phone numbers.
Violations carry fines of up to $50,120 per call.
But there are exceptions. Political calls are allowed. Charities are allowed. Companies you've done business with in the past 18 months are allowed. And if you "consented" via a website form, that company might argue you invited their call.
California's Extra Protection
If you live in California, you have additional rights under the CCPA (California Consumer Privacy Act).
You can tell companies to stop selling your personal information. The law requires businesses to provide a "Do Not Sell or Share My Personal Information" link. They have to honor your opt-out request.
Starting January 2026, there's even a centralized "Delete Request and Opt-Out Platform" where you can opt out of data brokers in one place.
Penalties for CCPA violations: $2,500 to $7,500 per violation.
Other states are following California's lead. Texas expanded its telemarketing laws in September 2025 to cover text messages. Virginia's new rules take effect in January 2026.
What You Can Do Right Now
1. Register for the Do Not Call list DoNotCall.gov. It takes two minutes.
2. Read before you click If a form says "marketing partners," assume the worst. Your info is getting shared.
3. Use the "STOP" command Text STOP to any number that texts you. Companies must honor this. As of April 2025, the FCC requires them to process your opt-out within 10 days.
4. Report violations File complaints at DoNotCall.gov or with the FTC. Enough complaints lead to enforcement.
5. Exercise your state rights If you're in California, use the "Do Not Sell" links. If companies ignore you, the state AG wants to know.
The system is messy. The laws overlap. The loopholes are real.
But your consent still matters. You have more leverage than you think.
The trick is knowing when you gave it away.
Understanding your rights is the first step to protecting them. At Pulse, we believe financial literacy isn't just about money. It's about the systems that touch your money, your data, and your time.
Don't want to miss our next deep dive? Subscribe to the Pulse newsletter.
