
Consent Recording Requirements · September 28, 2026 · GrowthPros
Is it illegal to subscribe someone to a mailing list?
Yes — adding someone to a mailing list without consent violates TCPA and GDPR. Learn the 2025 one-to-one consent rules, penalties, and how to fix non-co...

Key Facts
- Adding someone to a mailing list without explicit consent is illegal under both TCPA and GDPR, with GDPR fines reaching €20 million or 4% of global annual revenue.
- The FCC closed the 'lead generator loophole' on January 27, 2025, requiring one-to-one prior express written consent for telemarketing, per compliance guidance.
- TCPA violations cost $500 each, or up to $1,500 for willful violations — and consent must now name exactly one seller, legal analysis confirms.
- One FCC enforcement case involved consent disclosures buried in a hyperlink covering 5,329 entities, rule analysis shows.
- Legal experts estimate roughly 25% of TCPA threat letters can be shut down at the initial stage with proper proof of consent, industry experts report.
- Consent records — disclosure text, timestamp, IP address, and named party — should be retained for at least 5 years to satisfy legal defense requirements.
- Pre-checked consent boxes and bundled consent for unrelated purposes are explicitly prohibited under GDPR, compliance guides warn.
The Short Answer: Yes, Without Consent It's Illegal
Adding someone to a mailing list without their explicit consent is illegal under both TCPA and GDPR regulations. The FCC's lead generator loophole rules, effective January 27, 2025, now require one-to-one prior express written consent for telemarketing, while GDPR mandates freely given, specific, informed, and unambiguous consent for email marketing. Violations can result in fines of up to €20 million or 4% of global annual revenue under GDPR, and TCPA allows for statutory damages of $500 per violation, or up to $1,500 for willful violations.
Businesses that purchase leads face heightened exposure under these rules, especially since the FCC's January 27, 2025 effective date closed the lead generator loophole that previously allowed consent to be shared across multiple sellers. Under the new framework, consent must be obtained for one specific seller at a time and must be logically and topically related to the original interaction—for example, consent given on a mortgage quote site cannot be used for auto loan marketing without additional consent. This means leads obtained under older, broader consent rules may no longer be compliant and require re-verification before use.
To remain compliant, businesses must maintain comprehensive consent records including disclosure text, timestamp, IP address, and the named contacting party, with experts recommending retention for at least five years to satisfy legal defense requirements. GrowthPros addresses these requirements by delivering every lead with an attached consent trail, ensuring lists are DNC-scrubbed, and confirming that reactivation campaigns only target pre-existing, opted-in relationships. Their process builds FCC one-to-one consent compliance from the start, helping clients avoid the legal and reputational risks associated with improper consent practices.
- Get exclusive, consent-recorded leads by niche with AI follow-up in under five minutes
- Reactivate your dormant opted-in lists using multi-channel AI sequences
- Book a 15-minute qualification call to discuss compliant lead generation for your business
What 'Valid Consent' Actually Means in 2025
For years, lead generators collected a single checkbox click and sold it to dozens — sometimes thousands — of businesses. That era officially ended on January 27, 2025, and if you're still buying leads without documented consent, you're holding liability, not opportunity.
The FCC's one-to-one consent rule, passed on December 13, 2023 by a 4-1 vote, closes what regulators called the "lead generator loophole" — the practice of bundling consumer consent and distributing it across multiple businesses. Under the rule, prior express written consent under the TCPA must now be obtained for one seller at a time, as legal analysis from Bradley explains. A consumer who fills out a form for a mortgage quote has consented to hear from that mortgage provider — not from a car dealership, a solar company, and a roofing contractor.
The rule imposes three core requirements on valid consent:
- Named, singular consent: consent must identify exactly one seller — no sharing across multiple businesses.
- Topical relevance: consent must be "logically and topically related" to the website where it was granted, per compliance guidance from Gryphon — mortgage-site consent can't authorize car loan marketing.
- Clear, conspicuous disclosure: the consumer must clearly see who will be contacting them — no buried fine print.
That last requirement has teeth. In one enforcement case cited by Honigman's legal team, consent disclosures were buried in a hyperlink covering 5,329 entities — a practice the new rule is explicitly designed to end. Pre-checked boxes, bundled consent for unrelated purposes, and hidden disclosures are all prohibited.
There's also a transition problem businesses often miss: leads collected under the old rules may no longer be compliant. Legal experts note that older consents likely won't meet the 2025 requirements, meaning businesses must re-verify and update consent for existing lead inventories.
This is why documentation matters as much as collection. The burden of proof falls on the contacting party, and industry experts recommend retaining consent records — disclosure text, timestamp, IP address, and named contacting party — for at least five years. That's the same standard GrowthPros applies to every lead it delivers: each one arrives with its full consent trail attached, built to one-to-one consent requirements from the start, so buyers aren't left reconstructing compliance after the fact.
Why Consent Records Are Your Legal Shield
The burden of proof falls on the sender when facing TCPA or GDPR allegations, making defensible consent records not just a best practice but a legal necessity. To withstand scrutiny, these records must contain four critical elements: the exact disclosure text presented to the consumer, a precise timestamp of when consent was given, the IP address associated with the interaction, and the named contacting party to whom consent was granted. Industry experts confirm that maintaining this level of detail for at least 5 years is essential to satisfy legal defense requirements against claims, as consent can be challenged long after initial contact.
Without such documentation, businesses are vulnerable to costly enforcement actions and reputational harm. GrowthPros ensures every lead delivered includes this comprehensive consent trail, directly addressing the regulatory shift toward one-to-one consent under the FCC’s lead generator loophole rules effective January 27, 2025. These records serve as tangible proof that consent was freely given, specific, and logically related to the original interaction—key requirements under both TCPA and GDPR frameworks. Notably, legal experts estimate that roughly 25% of TCPA threat letters can be shut down at the initial stage when proper proof of consent is immediately available, underscoring the tangible value of meticulous recordkeeping.
- Disclosure text: The exact language shown to the consumer at opt-in
- Timestamp: Date and time of consent, down to the second
- IP address: The digital origin of the consent action
- Named contacting party: The specific business authorized to contact
- Retention period: Minimum 5-year storage for legal defensibility
For businesses navigating reactivation campaigns or purchasing leads, this level of documentation transforms compliance from a theoretical obligation into a practical shield. GrowthPros integrates these requirements into its lead delivery process, ensuring each contact arrives with an auditable consent record that supports immediate, lawful outreach. By prioritizing verifiable consent over assumptions, companies not only reduce litigation risk but also build trust with consumers who increasingly expect transparency in how their data is used. In an environment where regulatory scrutiny is intensifying, robust consent records are no longer optional—they are the foundation of sustainable, compliant growth.
How to Fix Non-Compliant Leads and Lists
If you're sitting on leads collected before January 27, 2025, the uncomfortable truth is that many of them probably no longer qualify as compliant. Legal analyses of the FCC's new rules were blunt about this: consent that was valid under the old framework will likely no longer be appropriate once the order is in effect. The fix isn't panic — it's a systematic remediation pass.
Re-verify older consents first. Consent obtained under pre-2025 rules may not meet the 2025 requirements, especially if it was bundled, pre-checked, or shared across multiple buyers. For each lead, confirm you can produce the disclosure text, timestamp, IP address, and the named contacting party. If you can't, treat the lead as cold.
Scrub against the DNC before any outbound contact. Whether you're calling, texting, or reactivating a dormant CRM list, DNC-scrubbing happens before the first touch — not after. This is standard practice at compliant lead vendors like GrowthPros, where lists are scrubbed and consent-recorded before delivery, but it applies equally to lists you already own.
Honor opt-outs immediately and permanently. Under the TCPA, the burden of proof falls on the sender to maintain consent records and update them when consumers opt out. Ignoring a revocation isn't a gray area — it's a violation. And keep those records: experts recommend retaining consent documentation for at least 5 years to satisfy legal defense requirements.
Use double opt-in for email. GDPR compliance guides recommend a confirmation email after form submission to verify active, affirmative consent — and it protects you from typo'd addresses and bot submissions. The stakes justify the friction: GDPR fines reach €20 million or 4% of global annual turnover.
Here's a quick audit checklist for your current lead sources:
- Does every lead have a consent record — disclosure text, timestamp, IP address, and named contacting party?
- Was consent obtained for your business specifically, or bundled across multiple sellers?
- Is the consent logically and topically related to what you're now marketing?
- Has the list been DNC-scrubbed since its last use?
- Are opt-outs synced across SMS, voice, and email — permanently?
One more reason to take remediation seriously: legal experts estimate that roughly 25% of threat letters can be shut down at the initial stage when you can produce proper proof of consent. Documentation isn't paperwork — it's your defense. If a lead source can't back its consent trail, the cheapest fix is replacing it before it becomes a liability.
How GrowthPros Delivers Compliance-Ready Leads
Understanding the rules is one thing; buying leads that actually comply with them is another. Since the FCC's one-to-one consent rules took effect on January 27, 2025, the quality of a lead matters less than the quality of its paper trail — and that's exactly where most lead marketplaces fall apart.
The regulatory logic is straightforward: consent must be specific to one seller, logically related to the original interaction, and free of buried disclosures, as legal analysis of the FCC's lead generator rules makes clear. The FCC passed these rules 4–1 in December 2023 specifically to close what it called the "lead generator loophole" and stop consent abuse by unscrupulous robotexters and robocallers. Consent collected under older rules may no longer be sufficient — businesses are expected to re-verify during the transition.
This is why every GrowthPros lead arrives with its consent trail attached. Each record includes the disclosure text the consumer saw, the timestamp, the IP address, and the named contacting party. That's not a nice-to-have: under the TCPA, the burden of proof falls on the caller to maintain consent records before any call or text — and experts recommend retaining those records for at least five years to mount a legal defense.
What compliance-ready delivery looks like in practice:
- Consent records on every lead — disclosure text, timestamp, IP, and named party, delivered alongside the contact rather than on request.
- DNC-scrubbed lists before any outbound contact, with opt-outs honored immediately and permanently across SMS, voice, and email.
- Reactivation campaigns target only pre-existing, opted-in relationships — never cold lists.
- Capped-shared leads max out at two buyers, never marketplace-style distribution across five or more.
That last point matters more than buyers realize. One enforcement case cited by FCC rule analysis involved consent disclosures covering 5,329 entities buried in a hyperlink — the exact scenario the new rules were written to eliminate. Marketplace leads that get sold to a handful of buyers sit uncomfortably close to that line.
The payoff is tangible. According to telecommunications attorneys, roughly 25% of TCPA threat letters can be shut down at the initial stage when a business can produce proper preparation and proof of consent. Having a system in place to collect, manage, and categorize lead forms is the difference between a defensible file and an expensive assumption.
Compliance isn't a disclaimer at the bottom of the lead — it's the lead. If you want consent-recorded, DNC-scrubbed leads followed up inside five minutes, book the 15-minute qualification call at growthpros.marketing. It's free, honest about fit, and commits you to nothing.
Frequently Asked Questions
Is it actually illegal to add someone to a mailing list without asking them?
Yes. Under GDPR, email marketing requires freely given, specific, informed, and unambiguous consent, and pre-checked boxes or bundled consent are prohibited. For calls and texts, the TCPA requires prior express written consent, and the FCC's rules effective January 27, 2025 now mandate one-to-one consent for telemarketing.
What are the fines if I contact someone without proper consent?
GDPR violations can cost up to €20 million or 4% of global annual turnover, whichever is higher. Under the TCPA, statutory damages run $500 per violation and up to $1,500 for willful violations — which is why legal experts recommend keeping consent records for at least 5 years to mount a defense.
What changed with the FCC's new lead generator rules in 2025?
The FCC closed the 'lead generator loophole' on January 27, 2025: consent must now be obtained for one specific seller at a time, be logically and topically related to the original interaction, and be disclosed clearly — no buried fine print. In one enforcement case, consent disclosures covered 5,329 entities in a hyperlink — exactly the practice the new rule ends.
Are the leads I bought before 2025 still compliant?
Probably not. Legal analyses are blunt: consent valid under the old framework will likely no longer be appropriate once the order is in effect. You should re-verify each lead's consent record — disclosure text, timestamp, IP address, and named contacting party — and treat any lead you can't document as cold.
What do I need to keep on file to prove someone consented?
Four things: the exact disclosure text shown to the consumer, a precise timestamp, the IP address of the consent action, and the named contacting party who was authorized to reach out. Industry experts recommend retaining these records for at least 5 years — with proper documentation, roughly 25% of TCPA threat letters can be shut down at the initial stage.
Is a pre-checked box or single checkbox enough for consent?
No. GDPR requires an active, affirmative action — pre-ticked boxes are explicitly prohibited, and you can't bundle unrelated purposes into one click. For telemarketing, unchecked opt-in boxes with clear, purpose-specific labels naming exactly who will contact the consumer are the compliant standard, and double opt-in confirmation emails are recommended for email lists.
Your Lead List Isn't Just Data—It's Your Legal Shield
As we've seen, the rules around consent have fundamentally changed—adding someone to a mailing list without explicit, documented permission isn't just risky, it's illegal under both TCPA and GDPR, with fines that can reach millions. The FCC's one-to-one consent rule, effective January 27, 2025, closed the lead generator loophole, meaning businesses can no longer rely on bundled or outdated consent. What protects you isn't just good intentions—it's ironclad records: disclosure text, timestamp, IP address, and the named contacting party, retained for at least five years. GrowthPros builds this compliance into every lead we deliver, ensuring your outreach is not only fast and targeted but legally defensible from the first touch. If you're sitting on leads that may no longer qualify or want to reactivate dormant lists the right way, the next step is simple. Book a 15-minute qualification call to see how compliant, consent-recorded leads can fuel your growth without the liability.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.