
Consent Recording Requirements · September 28, 2026 · GrowthPros
What four things are required for consent to be valid?
Learn the four elements of valid prior express written consent under TCPA rules — plus how to document consent so it holds up in court. Protect your lea...

Key Facts
- Valid TCPA consent requires four elements: signed written agreement, named seller authorization, identified phone number, and no purchase condition, per FCC compliance guidance.
- 2,788 TCPA cases were filed in 2024 — a 67% year-over-year jump — per litigation data.
- 80% of TCPA cases are class actions, with average settlements exceeding $6.6 million according to industry data.
- TCPA statutory damages run $500–$1,500 per violation with no aggregate cap, and the burden of proof rests entirely on the caller per compliance experts.
- Pre-checked consent boxes are invalid under the FCC's 2012 rule amendments — consumers must take affirmative action per implementation guidance.
- The Eleventh Circuit vacated the FCC's one-to-one consent rule, but naming specific sellers remains best practice per the vacatur analysis.
- Over 240 million numbers sit on the DNC Registry, and FCC rules require scrubbing at least every 31 days per FCC rules.
Why Lead Buyers Can't Afford Invalid Consent
The legal and financial risks of invalid consent are no longer theoretical — they are playing out in courtrooms at an accelerating pace. In 2024 alone, 2,788 TCPA cases were filed, marking a 67% year-over-year increase, while Q1 2025 saw 507 class actions, more than double the same period last year. With statutory damages ranging from $500 to $1,500 per violation and no aggregate cap, even modest calling campaigns can expose businesses to millions in liability. The average class action settlement now exceeds $6.6 million, turning compliance failures into existential threats.
Critically, liability under the TCPA falls squarely on the entity that places the call — not the lead generator. This means businesses purchasing leads with incomplete or poorly documented consent trails are not buying qualified prospects; they are acquiring litigation exposure. A single call made without provable prior express written consent can trigger a lawsuit, and because 80% of TCPA cases are filed as class actions, the financial consequences scale rapidly. For lead buyers, the cost of invalid consent isn’t just regulatory — it’s a direct hit to profitability and operational stability.
To be legally valid under the TCPA’s prior express written consent (PEWC) standard — required for marketing calls using autodialers or prerecorded messages — four core elements must be present. First, there must be a written agreement bearing the consumer’s signature, which under the E-SIGN Act includes compliant electronic signatures. Second, the agreement must clearly authorize the specific seller to deliver telemarketing messages using an automatic telephone dialing system (ATDS) or artificial/prerecorded voice. Third, it must identify the exact telephone number being authorized for contact. Fourth, the consent cannot be conditioned on the purchase of any goods, services, or property — meaning consumers must not be required to agree to calls as a condition of completing a transaction.
While clear and conspicuous disclosure is often treated as a separate requirement, it functions as a critical presentation standard that ensures the above elements are apparent to a reasonable consumer — not buried in fine print, hyperlinks, or scrollable sections. GrowthPros embeds these components into every lead by attaching disclosure text, a UTC timestamp with millisecond precision, the consumer’s IP address, and the name of the authorized contacting party — creating a consent record designed to meet both regulatory and evidentiary standards. Without this foundation, even a seemingly qualified lead carries unacceptable risk for the buyer.
The Four Elements of Valid Prior Express Written Consent
A single missing checkbox can turn a lead list into a six-figure liability. Under the TCPA, valid prior express written consent — the "gold standard" for telemarketing compliance — requires four specific elements defined in FCC rules at 47 CFR 64.1200(f)(9). Miss one, and the consent is legally worthless.
1. A written agreement bearing the consumer's signature. The consent must be a written agreement signed by the person called. Electronic signatures count, provided they meet E-SIGN Act standards under 15 U.S.C. Section 7001. Critically, the FCC prohibits pre-checked boxes per its 2012 rule amendments — the consumer must take affirmative action.
2. Clear authorization naming the specific seller. The agreement must clearly authorize a named seller to deliver marketing calls or texts using an autodialer or prerecorded voice. Generic language like "our partners" does not qualify — the consent must identify who is authorized to contact the consumer.
3. Identification of the exact phone number. The written agreement must specify the telephone number the consumer authorizes to be called, and that number must match the number actually dialed. A consent form that captures a name but no number provides no protection.
4. Consent that is not a condition of purchase. The consumer cannot be forced to agree to marketing calls to buy a product or service. Consent must be genuinely optional.
A fifth cross-cutting requirement governs presentation: the disclosure must be clear and conspicuous — apparent to a reasonable consumer without scrolling, not buried in fine print or hyperlinks. Courts have rejected consent hidden in scrollable text boxes.
The stakes explain why this matters. TCPA statutory damages run $500–$1,500 per violation with no aggregate cap, 80% of TCPA cases are filed as class actions, and average class settlements exceed $6.6M according to industry litigation data. And the burden of proof rests entirely on the caller — if you cannot prove consent existed at the time of the call, courts presume non-compliance, as compliance guidance for lead generators makes clear.
That burden is why documentation matters as much as the form itself. A defensible consent record should capture:
- The exact disclosure text shown to the consumer
- A precise timestamp and the consumer's IP address
- The full page URL and user agent string
- The named contacting party authorized to call
This is why GrowthPros attaches a complete consent trail — disclosure text, timestamp, IP, and named party — to every lead it delivers, so buyers can verify all four elements before dialing. As one compliance guide puts it, without properly obtained and documented permission, you are not selling leads — you are selling liability.
The Fifth Requirement Hiding in Plain Sight: Clear and Conspicuous Disclosure
You can nail all four elements of valid consent — signature, seller authorization, phone number, no purchase condition — and still lose in court because of where your disclosure text sat on the page. That's the fifth requirement hiding in plain sight: under 47 CFR 64.1200(f)(9), consent language must be clear and conspicuous, meaning apparent to a reasonable consumer. Courts have found consent buried in scrollable text boxes fails this standard, and pre-checked boxes are flatly prohibited under the FCC's 2012 rule amendments (per eConsent.org's implementation guide).
The disclosure must appear in close visual proximity to the consent checkbox, and it must be visible without scrolling (per the PEWC compliance guide). Burying the seller's name behind a hyperlink or tucking it into terms of service doesn't count. Practical specs from technical implementation guidance include:
- Minimum 12px font size for disclosure text
- WCAG AA contrast ratio (4.5:1) against the background
- Mobile-tested down to 375px screen width
- Disclosure placed directly beside the checkbox, never below the fold
The stakes make this worth engineering carefully. TCPA statutory damages run $500–$1,500 per violation with no aggregate cap, and 80% of TCPA cases are filed as class actions averaging settlements over $6.6M (per litigation data). Remember: the burden of proof rests with the caller — if you can't show the disclosure was visible, courts presume non-compliance (as one compliance guide puts it).
The FCC's one-to-one consent rule — which would have required separate consent for each individual company — was vacated by the Eleventh Circuit in Insurance Marketing Coalition v. FCC (per the vacatur analysis). Common law consent now governs, meaning a person who "clearly and unmistakably" states willingness to receive calls suffices, with no strict requirement for individual seller identification (per eConsent.org).
But treating the vacatur as permission to use vague "our partners" language is a mistake. Naming specific sellers remains best practice — it strengthens your consent record and survives any future regulatory reversal. This is why GrowthPros attaches the named contacting party to every lead's consent trail, and why exclusive or capped-shared lead models keep consent clean: when a lead was generated for your business specifically, the disclosure naming you as the seller is unambiguous.
The presentation standard is the difference between a consent record that holds up in court and one that becomes exhibit A. Build it into the form from the start, not bolted on afterward.
How to Prove Consent: Documentation That Holds Up in Court
How to Prove Consent: Documentation That Holds Up in Court
Courts require concrete proof that consent existed at the exact moment of contact — not just a promise that it was obtained. The burden of proof rests entirely on the caller, meaning if you cannot demonstrate valid consent, courts will presume non-compliance. Industry research confirms that TCPA statutory damages range from $500 to $1,500 per violation with no aggregate cap, and 80% of cases are filed as class actions averaging over $6.6 million in settlements.
To withstand legal scrutiny, consent records must include specific metadata that validates the authenticity and context of the consumer’s action. Critical elements to capture are the consumer’s IP address, a precise UTC timestamp with millisecond precision, the full user agent string, the page URL and referrer, and all form field values submitted at the time of consent. Technical guidelines emphasize that tamper-evident artifacts like SHA-256 hashes or session recordings further strengthen the evidentiary value of these records. This level of detail ensures that if challenged, you can reconstruct the exact conditions under which consent was given.
As one expert notes, a verification certificate documents what happened — it does not ensure that what happened was compliant. A certificate may confirm a form was submitted, but it does not validate whether the disclosure was clear and conspicuous, whether pre-checked boxes were used (which invalidate consent under FCC rules), or whether the consumer truly understood what they were authorizing. Therefore, the underlying consent process must be designed correctly from the outset — documentation alone cannot fix a flawed collection method.
Retention period is equally critical. Because TCPA violations carry a four-year statute of limitations, consent records should be retained for five or more years to ensure coverage across the full liability window, including potential delays in litigation. Compliance sources recommend this buffer to account for filing lags and class action certification timelines. Destroying records too early exposes businesses to preventable risk, especially when dealing with high-volume lead flows.
Finally, any lead missing even one required consent element — whether it’s a blank timestamp, incomplete user agent data, or an unclear disclosure — should never be called. Best practices state unequivocally: if consent is questionable or incomplete, do not contact that lead. The cost of a single TCPA violation far exceeds the value of any lead, and calling without verifiable consent turns an asset into immediate liability. GrowthPros ensures every lead delivered includes a complete, court-ready consent trail — because in telemarketing compliance, documentation isn’t just helpful; it’s the only thing standing between you and a lawsuit.
What Compliant Lead Buying Looks Like in Practice
Knowing the four elements of valid consent only matters if you act on them — and for lead buyers, that action happens before you ever pick up the phone. The company making the call bears primary TCPA liability, not the company that generated the lead, which means buyers share equal exposure with generators. With 2,788 TCPA cases filed in 2024 — a 67% year-over-year jump — and average class settlements exceeding $6.6 million, the lead you buy without a consent trail isn't a lead at all. It's a liability transfer with your name on it.
So what does compliant lead buying actually look like in practice? It comes down to four non-negotiables, each mapping directly onto the consent elements.
- Demand a complete consent trail on every lead before purchase: disclosure text, an accurate timestamp, IP address, and the named contacting party. A valid consent record requires exactly these elements — the disclosure language, the consumer's affirmative action, a timestamp, and source details like the full URL and IP address.
- DNC-scrub before any outbound contact. Over 240 million numbers sit on the DNC Registry, and FCC rules require scrubbing at least every 31 days. A lead that passes through this filter is the only lead worth dialing.
- Honor revocation keywords immediately. The FCC's April 2025 rules treat "stop," "quit," "cancel," "unsubscribe," "opt out," "revoke," and "end" as triggers for immediate and permanent revocation — across SMS, voice, and email.
- Prefer exclusive or tightly capped leads. The Eleventh Circuit vacated the FCC's one-to-one consent rule, but naming specific sellers remains best practice — and exclusive leads keep consent cleaner and simpler than leads sold across open marketplaces.
Remember: the burden of proof rests entirely with the caller. If you cannot prove consent existed at the time of contact, courts presume non-compliance — and every dial carries $500 to $1,500 in statutory exposure.
This is the model GrowthPros was built on. Every lead arrives consent-recorded — disclosure text, timestamp, IP, and named contacting party attached — DNC-scrubbed before delivery, with opt-outs honored immediately and permanently. Exclusive and capped-shared leads go to a hard maximum of two buyers, never dumped into a shared inbox. And because speed decides outcomes, every delivered lead gets AI voice, SMS, and email follow-up inside a five-minute window, 24/7 — included with every lead, not an upsell.
The promise is the process, not a guarantee: qualified, consent-recorded leads followed up inside the promised window. Exclusive leads by niche, followed up in minutes — including the leads you already paid for. Book the free 15-minute qualification call at growthpros.marketing and see what a clean consent trail looks like on a real lead.
Frequently Asked Questions
What are the four required elements for valid prior express written consent under the TCPA?
Valid prior express written consent requires: a written agreement with the consumer’s signature, clear authorization naming the specific seller, identification of the exact telephone number authorized for contact, and consent that is not conditioned on the purchase of goods or services. These four elements are defined in FCC rules at 47 CFR 64.1200(f)(9) and are required for marketing calls using autodialers or prerecorded messages.
Is clear and conspicuous disclosure a separate requirement for valid TCPA consent?
While clear and conspicuous disclosure is not one of the four core elements, it is a fifth cross-cutting requirement that governs how the consent language is presented. The disclosure must be apparent to a reasonable consumer without scrolling, not buried in fine print or hyperlinks, and must meet technical standards like minimum 12px font size and WCAG AA contrast ratio.
Can I use pre-checked boxes to obtain consent for telemarketing calls?
No, the FCC explicitly prohibits pre-checked boxes under its 2012 rule amendments. Consent requires affirmative action by the consumer — they must actively check the box themselves. Pre-checked boxes invalidate consent regardless of other elements being present.
What happens if I call a lead without being able to prove valid consent existed at the time of the call?
If you cannot prove consent existed at the time of the call, courts will presume non-compliance and the burden of proof falls entirely on you as the caller. Each violation carries statutory damages of $500 to $1,500 with no aggregate cap, and 80% of TCPA cases are filed as class actions averaging over $6.6 million in settlements.
Does the FCC’s one-to-one consent rule still require separate consent for each individual company?
No, the Eleventh Circuit vacated the FCC’s one-to-one consent rule in Insurance Marketing Coalition v. FCC, meaning common law consent now governs and individual seller identification is not strictly required. However, naming specific sellers remains a best practice to strengthen consent records and prepare for potential regulatory changes.
What metadata should I capture to prove consent in court if challenged?
To withstand legal scrutiny, consent records must include the consumer’s IP address, a precise UTC timestamp with millisecond precision, the full user agent string, the page URL and referrer, and all form field values submitted at the time of consent. Tamper-evident artifacts like SHA-256 hashes further strengthen the evidentiary value.
Four Elements, One Verdict: Build Your Consent Trail Before You Dial
Valid consent under the TCPA comes down to four non-negotiables: a signed written agreement, clear authorization naming the specific seller, the exact phone number being authorized, and consent that is never a condition of purchase — all presented through clear and conspicuous disclosure. Miss one element, and the consent is legally worthless, no matter how promising the lead looked. Remember that the burden of proof rests entirely with the caller, and with 80% of TCPA cases filed as class actions averaging settlements over $6.6 million, an unprovable consent trail is a liability with your name on it. Your next steps are practical: audit every lead source for the four elements, demand complete consent records before purchase, DNC-scrub before dialing, and retain documentation for at least five years. If a lead's consent is incomplete, don't call it — the math never works in your favor. GrowthPros delivers every lead with its full consent trail attached — disclosure text, timestamp, IP, and named contacting party — so verification happens before the first dial, not in a courtroom. Book the free 15-minute qualification call at growthpros.marketing and see what a court-ready consent record looks like on a real lead.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.