
Consent Recording Requirements · September 28, 2026 · GrowthPros
What is an opt-in email list?
Learn what an opt-in email list really means, what counts as valid consent under CAN-SPAM, TCPA & GDPR, and how to keep proof with every lead.

Key Facts
- CAN-SPAM penalties reach up to $53,088 per violating email under the FTC's opt-out framework.
- TCPA violations cost up to $1,500 per call or text, with a four-year statute of limitations for plaintiffs.
- The burden of proving consent sits with the company making the call, not the lead generator.
- Valid consent records must capture timestamps, IP addresses, and exact opt-in language.
- The FCC's one-to-one consent rule, adopted December 2023, was struck down by the Eleventh Circuit in January 2025.
- Pre-checked boxes fail GDPR's requirement for clear, unambiguous affirmative consent.
- Confirmed opt-in verifies address validity and affirms consent, according to Salesforce's compliance team.
The Consent Gap: Why Most Lead Buyers Are Exposed
Most lead buyers believe they're compliant because their lead vendor said the contacts "opted in." That assumption is where the legal exposure begins.
Here's the uncomfortable reality: US email law doesn't actually require opt-in consent. Under the FTC's CAN-SPAM compliance framework, email operates on an opt-out basis — you can send until someone asks you to stop. But the moment you pick up the phone or send a text, everything changes. Calls and texts fall under the TCPA's prior-consent regime, and the penalties are severe: up to $53,088 per violating email under CAN-SPAM, and up to $1,500 per call or text in TCPA statutory damages — with a four-year statute of limitations giving plaintiffs' attorneys a long window to come after you (ActiveProspect's TCPA analysis).
The burden of proof sits with you, not the vendor who sold you the lead. As TCPA compliance guidance makes clear, the company making the call or sending the text must be able to prove consent existed — and lead generators aren't the ones holding that liability. Meanwhile, most lead sources deliver contacts as a bare name, number, and email address, with no verifiable trail of what the consumer actually agreed to, when, or with whom.
That gap becomes acute when you look at what regulators now expect a consent record to contain:
- The exact disclosure language the consumer saw at opt-in
- A timestamp and IP address proving when and where consent occurred
- The named party the consumer agreed to be contacted by
The FCC's one-to-one consent direction — adopted in December 2023, then struck down in January 2025 — may no longer be legally mandated, but as Cooley's attorneys noted, the TCPA remains "a major source of class action litigation," and consent trails per-seller are the emerging standard regardless. Consent must also be logically and topically related to the interaction that prompted it — a consumer who asked about auto insurance didn't consent to a roofing call.
This is why GrowthPros attaches a full consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead before delivery. When the burden of proof is yours, a lead without a consent trail isn't an asset. It's an unpriced liability sitting in your CRM.
What Actually Counts as Opt-In — And What Doesn't
What Actually Counts as Opt-In — And What Doesn't
True opt-in requires active, verifiable permission through a clear affirmative action. HubSpot defines it as contacts submitting their email address with the expectation of receiving marketing messages, while Salesforce emphasizes sending only to those who agreed to join a mailing list. This standard excludes passive assumptions or implied agreement.
Several common practices invalidate consent and create legal exposure. Purchased lists, data from enrichment tools, or contacts sourced from event-organizer distributions do not meet opt-in criteria because the individual never agreed to hear from your specific brand. Similarly, forms completed on another company’s website, verbal consent without documentation, and pre-checked boxes fail to constitute valid permission under GDPR, CASL, and HubSpot’s requirements, as they lack a specific, unambiguous affirmative action.
The legal landscape further underscores why opt-in is the safer operational standard. While the US operates under CAN-SPAM’s opt-out baseline — where prior consent isn’t federally required but opt-outs must be honored within 10 business days — Canada’s CASL and the EU’s GDPR/ePrivacy mandate prior opt-in consent for all commercial electronic messages. GrowthPros, based in Halifax, Nova Scotia, adheres to CASL’s stricter opt-in rules as a foundation, ensuring every lead includes a verifiable consent record with disclosure text, timestamp, IP address, and the named contacting party. This approach not only satisfies the burden of proof for senders but also aligns with best practices like double opt-in, which Salesforce confirms validates address accuracy and affirms consent. By building consent trails into every lead — whether freshly sourced or reactivated from pre-existing opted-in relationships — GrowthPros provides businesses with legally defensible data that exceeds the minimum requirements in any jurisdiction.
The Consent Record: What Must Be Captured and Retained
Saying someone opted in is easy. Proving it years later, when a plaintiff's attorney or a regulator asks, is where most senders fail — because they never captured the right evidence at sign-up.
The legal burden sits squarely with the sender. Under opt-in frameworks, senders "must keep evidence of the consent and provide proof if challenged," according to L-Soft's guidance on opt-in laws. TermsFeed's analysis of email marketing legal requirements echoes this: consent records should include timestamps, IP addresses, and the specific consent language presented at opt-in. In practice, that means four elements:
- The disclosure text exactly as the contact saw it at sign-up
- A timestamp proving when consent occurred
- The IP address tied to the submission
- The named party the consumer agreed to be contacted by
Why retain records this long? TCPA violations carry statutory damages of up to $1,500 per call or text with a four-year statute of limitations, and class actions can reach millions. That's why consent management tools like TrustedForm Retain store consent certificates for up to five years — evidence needs to outlive the litigation window. Critically, legal analysis of TCPA compliance notes the burden of proof stays with the company making the call or text, not the lead generator. A lead buyer without the consent trail is the one exposed.
This is why GrowthPros attaches the full consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead it delivers. The buyer receives proof, not just a phone number.
Double opt-in strengthens the record further. L-Soft strongly recommends double opt-in even where legislation doesn't require it, and Salesforce's compliance team calls confirmed opt-in an industry best practice that verifies the address was valid at sign-up and affirms consent. As Salesforce's Anne Wetzel puts it, confirmed opt-in "verifies that the subscriber's address was valid at the time of sign up and affirms their consent" — safeguarding data hygiene and boosting engagement.
The pattern is clear: consent you can't document is consent you don't legally have. Senders who capture disclosure text, timestamp, IP, and named party at sign-up — and retain them for years — hold proof when challenged. Senders who rely on a bare email address hold an assumption.
One-to-One Consent: The Rule That Was Adopted, Then Struck Down
For a few months in 2024, the entire lead generation industry was bracing for a rule that would have rewritten how consent works. Then, weeks before it took effect, a federal appeals court pulled the plug.
In December 2023, the FCC adopted its one-to-one consent order, requiring consumers to grant prior express written consent for robocalls and robotexts one seller at a time — explicitly prohibiting a single consent from covering a "daisy-chain of 'partners'" (https://www.cooley.com/news/insight/2024/2024-01-09-fcc-adopts-new-tcpa-rules-for-lead-generated-communications). The rule was set to become effective January 27, 2025 (https://www.pitchit.ai/tcpa-compliance). The contemplated compliant pattern was a checkbox list where consumers separately choose each seller they agree to hear from.
On January 24, 2025, the Eleventh Circuit struck the mandate down in Insurance Marketing Coalition, ruling that the FCC lacked authority to redefine consent requirements — so the one-to-one mandate will not move forward (https://activeprospect.com/blog/tcpa-tools/). The court didn't endorse vague consent; it simply said the FCC couldn't unilaterally change what "consent" means under the TCPA.
The stakes remain enormous either way. TCPA violations carry statutory damages of up to $1,500 per call or text, with a four-year statute of limitations, and class actions routinely produce settlements or judgments in the millions (https://activeprospect.com/blog/tcpa-tools/). As Cooley's attorneys warned, the TCPA already fuels major litigation, and plaintiffs' lawyers constantly pressure-test the marketplace for new targets (https://www.cooley.com/news/insight/2024/2024-01-09-fcc-adopts-new-tcpa-rules-for-lead-generated-communications).
The FCC also closed another loophole in February 2024, ruling that AI-generated synthetic voices count as an "artificial or prerecorded voice" restricted by the TCPA (https://www.pitchit.ai/tcpa-compliance). If you're using AI voice follow-up — as many lead buyers now do — the consent trail behind each contact matters more, not less.
This is why GrowthPros treats one-to-one consent as built in from day one, even though the mandate was struck down. Every lead carries a consent record — disclosure text, timestamp, IP address, and the named contacting party — so buyers know exactly what each contact agreed to and when. That's exceeding the current legal floor, not merely complying with it.
The practical takeaways from the one-to-one saga:
- Consent must be logically and topically related to the interaction that prompted it — you can't stretch a car insurance inquiry into unrelated marketing (https://www.cooley.com/news/insight/2024/2024-01-09-fcc-adopts-new-tcpa-rules-for-lead-generated-communications).
- The burden of proof for consent sits with the company making the call or text, not the lead generator — which is why the consent trail must travel with the lead (https://www.pitchit.ai/tcpa-compliance).
- Consent records should include timestamps, IP addresses, and the specific consent language presented at opt-in (https://www.termsfeed.com/blog/legal-requirements-email-marketing/).
A struck-down rule doesn't erase the direction regulators were heading — it just removes the deadline. Businesses that already capture per-seller consent trails are positioned for whatever version of the rule returns.
How GrowthPros Builds the Consent Trail Into Every Lead
When a regulator or a plaintiff's attorney asks you to prove a lead consented, "the lead generator told me so" is not a defense. Under TCPA rules, the burden of proof for consent stays with the company making the call or text — not the company that sourced the lead. That reality shapes how GrowthPros builds every lead it delivers.
The process starts before a single outbound touch. Every list is DNC-scrubbed prior to contact, and each lead is qualified and time-stamped before delivery. Consent is treated as active and verifiable, never assumed — consistent with the standard that passive silence or a missing opt-out does not constitute valid opt-in consent.
What arrives in your CRM is the evidence file, not just a name and number. Each lead carries a full consent record:
- The exact disclosure text the contact saw and agreed to
- A timestamp showing when consent was given
- The contact's IP address
- The named party who obtained the consent
This maps directly to what compliance guidance requires: senders must keep evidence of consent and provide proof if challenged, with records that include timestamps, IP addresses, and the specific consent language presented at opt-in. Consent-certificate platforms like TrustedForm Retain store this documentation for up to five years — because the legal exposure window is long. TCPA violations can run to $1,500 per call or text, and class actions routinely reach millions.
Opt-out handling is where many lead operations quietly fail. CAN-SPAM gives senders 10 business days to honor an opt-out and bars reselling those addresses. GrowthPros treats that ceiling as a floor: opt-outs are honored immediately and permanently, across SMS, voice, and email, with no re-contact through a side channel.
Reactivation follows the same logic. Dormant-list campaigns run only against pre-existing, opted-in relationships a client already owns — never cold or purchased lists, which do not meet opt-in requirements under any standard. The FCC's one-to-one consent direction was struck down in early 2025, but GrowthPros builds to that pattern anyway — consent tied to a specific seller, not a daisy-chain of partners.
The result is simple: the consent trail attached to your lead is your legal shield. When the burden of proof lands on you — and under the TCPA, it does — you already have the disclosure text, the timestamp, the IP, and the named party in hand.
Frequently Asked Questions
What does 'opt-in' actually mean for an email list, and why is it important?
Opt-in means contacts actively submitted their email address with the expectation of receiving marketing messages, requiring a clear affirmative action rather than passive assumption or implied consent. This standard is critical because consent you can't document is consent you don't legally have, and lead buyers bear the burden of proof if challenged.
Does US federal law require opt-in consent for marketing emails?
No, under the CAN-SPAM Act, the US operates on an opt-out basis for email — prior consent is not federally required, but senders must honor opt-out requests within 10 business days. However, opt-in is legally mandatory in Canada under CASL and in the EU under GDPR/ePrivacy.
What specific information must be captured to prove valid consent for marketing communications?
Valid consent requires four elements: the exact disclosure text the consumer saw at opt-in, a timestamp proving when consent occurred, the IP address tied to the submission, and the named party the consumer agreed to be contacted by. These components form the consent record that senders must retain to meet their burden of proof.
Why can't I rely on purchased lists or data from enrichment tools for compliant marketing?
Purchased lists, data from enrichment tools, and contacts sourced from event-organizer distributions do not meet opt-in criteria because the individual never agreed to hear from your specific brand. Consent is not transferable — forms completed on another company’s website or verbal consent without documentation also fail to constitute valid permission.
What happened to the FCC's one-to-one consent rule for calls and texts, and should I still follow it?
The FCC adopted a one-to-one consent rule in December 2023 requiring prior express written consent for robocalls/robotexts one seller at a time, but the Eleventh Circuit struck it down in January 2025, ruling the FCC lacked authority to redefine consent under the TCPA. Although no longer legally mandated, capturing per-seller consent trails remains an emerging standard and best practice for legal defensibility.
How does GrowthPros ensure the leads they sell include legally defensible consent?
GrowthPros attaches a full consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead before delivery, and scrubs all lists against the DNC prior to contact. This practice ensures buyers receive proof of consent, not just contact information, meeting the sender's burden of proof under TCPA and other regulations.
Consent You Can Prove Is the Only Consent That Counts
The gap between "the vendor said they opted in" and "here is the proof" is where lead buyers get burned. US email law may run on opt-out, but the moment you call or text, the TCPA's prior-consent regime applies — with statutory damages of up to $1,500 per call or text and a four-year window for plaintiffs to come knocking. The burden of proof sits with you, not the lead generator, which means a lead without a documented consent trail isn't an asset; it's an unpriced liability sitting in your CRM. Before your next lead purchase, ask one question: does every contact arrive with the disclosure text, timestamp, IP address, and named contacting party attached? If the answer is no, you're holding an assumption, not evidence. GrowthPros builds that consent record into every lead it delivers — qualified, time-stamped, and DNC-scrubbed before it ever reaches your CRM. Book a free 15-minute qualification call to see what proof-backed leads look like for your niche. No commitment — just an honest look at fit.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.