Consent Recording Requirements · September 28, 2026 · GrowthPros

What is meant by written consent?

Learn what written consent means under TCPA after the FCC's 2025 1:1 consent rule. Get compliance requirements for lead buyers and avoid $500-$1,500 per...

Flat illustration of a signed consent document with a checkmark and 1:1 consumer-seller link in lime and olive brand colors, headlined Written Consent.

Key Facts

  • TCPA statutory damages run $500 to $1,500 per violation, with no proof of actual injury required under federal law.
  • The FCC's 1:1 Consent Rule took effect January 27, 2025, requiring individual consent for each specific seller.
  • Bundled consent — one checkbox covering dozens of unknown businesses — is no longer valid under the 2025 rule.
  • Since April 11, 2025, businesses must honor opt-outs through any reasonable method within 10 business days.
  • A clarification message must be sent within 5 minutes of a consumer's revocation request.
  • Consent and opt-out documentation should be retained at least 4 years, matching the TCPA statute of limitations.
  • 62% of bank survey respondents feared the revoke-all rule would force them to stop fraud alerts.

For decades, "written consent" meant little more than a checked box on a web form — until the FCC rewrote the rules in a way that made millions of purchased leads legally radioactive overnight.

Under the Telephone Consumer Protection Act (TCPA), businesses must obtain prior express written consent before sending marketing text messages, making marketing robocalls, or sending fax advertisements. That consent must follow a "clear and conspicuous" disclosure judged by the reasonable consumer standard, as legal analyses of the rule explain. Notably, the requirement applies only to marketing communications — informational messages fall outside it, according to TCPA compliance guidance.

The 1:1 Consent Rule changed everything on January 27, 2025. The FCC's new rule narrowed the definition of valid written consent in two critical ways, per BCLP's analysis of the rule:

  • Consent must be given individually for each specific seller — one consumer, one business, one consent.
  • Consent must be "logically and topically associated" with the website where it was collected.
  • Bundled consent — one checkbox covering dozens of unknown businesses — is no longer valid.

The FCC framed the rule as closing the "lead generator loophole," which previously allowed consent given to one business to be extended to unassociated businesses without the consumer's knowledge, as the same analysis notes.

This creates a serious problem for lead buyers. If you purchased leads through comparison sites or shared marketplaces where consumers clicked a single consent box covering multiple sellers, those leads may no longer carry valid consent — and calling or texting them exposes you to TCPA statutory damages of $500 to $1,500 per violation, per consumer, with no proof of actual injury required under 47 U.S.C. § 227(b)(3), as compliance experts detail.

The stakes are compounded by uncertainty. The 11th Circuit heard arguments in Insurance Mktg. Coalition Ltd. v. FCC challenging whether the FCC exceeded its TCPA authority, and post-Loper Bright, courts no longer must defer to the FCC's interpretations — though the Hobbs Act still channels review to appellate courts.

For lead buyers, the practical takeaway is simple: demand a consent trail for every lead. Providers like GrowthPros attach disclosure text, timestamp, IP address, and the named contacting party to each lead delivered, because under the 1:1 framework, consent that can't be documented is consent that doesn't exist.

A single text message to a consumer who never consented can cost you $500. Multiply that by a few thousand contacts in a lead campaign, and "we thought they opted in" becomes a seven-figure liability.

The TCPA doesn't require anyone to prove harm. Under 47 U.S.C. § 227(b)(3), statutory damages run $500 per violation — rising to $1,500 when the violation is willful or knowing — and consumers can sue through a private right of action without showing any actual injury. A lead list of 2,000 contacts with defective consent is, on paper, a $1–3 million exposure.

This is why consent documentation isn't a nice-to-have. It's the entire defense. When a class action lands, the question isn't whether the consumer was annoyed — it's whether you can produce proof they agreed, and to whom. Under the FCC's 1:1 Consent Rule effective January 27, 2025, that proof must show consent to a specific named seller, not a bundled list of partner businesses.

A defensible consent record includes:

  • The exact disclosure text the consumer saw before consenting
  • A timestamp showing when consent was given
  • The consumer's IP address at the moment of consent
  • The named contacting party — the specific seller the consumer agreed to hear from

Retention matters as much as capture. Because the TCPA statute of limitations runs four years, legal guidance recommends retaining consent and opt-out documentation for at least 4 years. A record deleted at year two is functionally the same as a record that never existed.

The stakes sharpen under the newer revocation rules, too. Since April 11, 2025, businesses must honor opt-out requests made through any reasonable method — including keywords like "stop" and "revoke" — within 10 business days, and process revocations on day 11 or later can trigger litigation. Every opt-out request needs the same audit trail as the original consent.

This is the standard GrowthPros builds into every lead it delivers: each contact arrives with its consent trail attached — disclosure text, timestamp, IP address, and named contacting party — so the buyer, not the marketplace, holds the proof. In a regulatory environment where a lead without documentation is a plaintiff with a subpoena, the consent record is the product.

Revocation Is the Rule Nobody Is Watching (But Everyone Should Be)

Getting consent is only half the compliance equation — the other half, and the one most businesses are fumbling, is what happens when a consumer says "stop." Effective April 11, 2025, the FCC's new TCPA revocation rules fundamentally changed how opt-out requests must be handled, and the stakes are steep: TCPA statutory damages run $500 to $1,500 per violation, with no proof of actual injury required, according to BCLP's legal analysis.

Under the new framework, businesses must honor opt-out requests made through any reasonable method — not just a designated text keyword or a buried unsubscribe link. That includes standardized keywords like "stop," "revoke," and "cancel," as detailed in Troutman's breakdown of the revised rules. Once a request arrives, the clock starts:

  • Process the revocation within 10 business days of receipt
  • Send a clarification message within 5 minutes of the request
  • Honor any reasonable communication method, not just official channels
  • Retain opt-out documentation for at least 4 years, matching the TCPA statute of limitations

Those timelines come from BCLP's analysis of the April 2025 opt-out rules, which notes that processing a request even one day late — on the 11th business day or after — can expose a business to litigation under ActiveProspect's review of the enforcement landscape.

Puja Amin, Partner at Troutman Amin LLP, puts it bluntly: "Everyone's very focused on the 1 to 1 consent rules, which they should be and they ought to be. But these new revocation rules, they are just massive, and I'm not hearing enough folks talk about this and that's scary." Her point is that consent capture gets all the attention while revocation — the mechanism that determines whether you keep violating after someone says no — goes unwatched.

Yet Amin also offers reassurance: many companies will find compliance manageable through "a simple adjustment in their communication and internal DNC system's settings." Tammy Glover Fowler, Legal & Compliance Director at Contact Center Compliance, agrees that modern systems make the 10-business-day window very achievable in practice.

The gap between "massive" and "manageable" comes down to system design. If your opt-out handling is manual, scattered across platforms, or dependent on someone checking an inbox, you're exposed. If it's automated — keywords parsed instantly, suppression lists updated across SMS, voice, and email, and every request timestamped — compliance becomes a setting, not a scramble.

That's the standard we hold our own lead pipeline to at GrowthPros: opt-outs are honored immediately and permanently across every channel, and each lead carries its full consent trail so the record exists before anyone asks for it. Whether you source leads in-house or buy them, the principle is the same — revocation is where TCPA compliance is won or lost, and it deserves the same rigor as consent itself.

The FCC's 1:1 Consent Rule, effective January 27, 2025, fundamentally rewrote what valid written consent looks like by requiring individual consent for each specific seller and mandating that consent be "logically and topically associated" with the original website interaction. This closed the "lead generator loophole" that previously allowed broad consent given to one business to be extended to unassociated businesses without the consumer's knowledge. For comparison shopping sites, the rule demands individual seller checkboxes or clickthrough consent links that let each business obtain specific authorization through non-prohibited methods.

Every consent request must be preceded by a clear and conspicuous disclosure meeting the reasonable consumer standard — language a typical person would actually notice and understand. The consent record itself must capture the disclosure text, timestamp, IP address, and the named contacting party to create an audit-ready trail. GrowthPros builds this documentation into every lead delivery because TCPA statutory damages range from $500 to $1,500 per violation, per consumer, without requiring proof of actual injury.

  • Individual seller consent checkboxes or clickthrough links on comparison sites
  • Disclosure text, timestamp, IP address, and named party on every record
  • Revocation honored through any reasonable method within 10 business days
  • Standardized opt-out keywords (stop, quit, end, revoke, opt-out, cancel, unsubscribe)
  • Documentation retained for at least four years to match the TCPA statute of limitations

A critical operational distinction remains: prior express written consent is required only for marketing text messages, marketing robocalls, and fax advertisements — not for informational communications. The FCC's Consumer Policy Division has specifically addressed this boundary in utility and text messaging contexts. Meanwhile, revocation rules effective April 11, 2025, require businesses to process opt-outs within 10 business days and send a clarification message within five minutes of the request.

Legal uncertainty persists. The Insurance Marketing Coalition v. FCC case (11th Cir., No. 24-10277) argues the FCC exceeded its TCPA authority with the 1:1 Consent Rule, and post-Loper Bright, courts no longer must defer to FCC interpretations of the statute. Yet the Hobbs Act still channels review of FCC final orders to appellate courts. Prudent businesses build to the stricter standard regardless — treating every consent as if it will be challenged in court, because the cost of non-compliance dwarfs the cost of compliance.

Buying Leads Without Buying Liability: What to Demand From a Lead Provider

When buying leads, you're not just purchasing contact information—you're inheriting the consent risk attached to every record. Under federal telemarketing regulations, written consent must include specific elements: disclosure text, timestamp, IP address, and the named contacting party, as required for valid prior express written consent under the TCPA. Industry analysis confirms that maintaining this documentation for at least four years is critical to align with the TCPA statute of limitations and defend against potential claims.

Without these components, every call or message you make could trigger statutory damages of $500 to $1,500 per violation—no proof of actual injury required. Legal experts emphasize that the FCC's 1:1 Consent Rule, effective January 27, 2025, now demands individual consent for each specific seller, eliminating the ability to rely on bundled or shared consent across multiple businesses. This means lead buyers can no longer assume consent transfers; they must verify it was obtained directly and specifically for their outreach.

To mitigate this risk, every lead should arrive DNC-scrubbed with its full consent trail attached—disclosure text, timestamp, IP, and named contacting party—ensuring compliance from the first point of contact. GrowthPros delivers leads as a product with this consent record built in, sourced only after a clear and conspicuous disclosure and qualified before delivery. Compliance technology providers note that honoring revocation requests within 10 business days is equally critical, and systems must be updated to process opt-outs through any reasonable method, including standardized keywords like "stop" or "revoke."

This is why GrowthPros integrates AI-powered follow-up within five minutes of lead delivery—voice, SMS, and email—to engage prospects while consent is fresh and contact likelihood is highest. Each lead lands in your CRM with its consent documentation intact, whether sourced exclusively or reactivated from your own opted-in list. The process eliminates guesswork: no shared inboxes, no ambiguous consent chains, and no exposure to liability from poorly documented leads.

If you're buying leads today, demand proof of consent—not just a phone number. Official FCC guidance reinforces that written consent is required only for marketing communications, making accurate classification and documentation essential. To see how consent-recorded, qualified leads with five-minute AI follow-up work in your niche, book a free 15-minute qualification call. It’s an honest conversation about fit—no pressure, no guarantees, just clarity on how to buy leads without buying liability.

Frequently Asked Questions

What does 'written consent' mean under the TCPA for marketing messages?
Under the TCPA, 'written consent' means prior express written consent obtained after a clear and conspicuous disclosure, required before sending marketing text messages, making marketing robocalls, or sending fax advertisements. This consent must be specific to each seller and logically associated with the website where it was given, as defined by the FCC's 1:1 Consent Rule effective January 27, 2025.
How did the FCC's 1:1 Consent Rule change written consent requirements in 2025?
The FCC's 1:1 Consent Rule, effective January 27, 2025, requires individual consent for each specific seller and mandates that consent be 'logically and topically associated' with the website where it was collected, eliminating bundled consent that previously allowed one checkbox to cover multiple businesses. This change closed the 'lead generator loophole' where consent to one business could be extended to unassociated sellers without consumer knowledge.
What happens if I call or text a lead without valid written consent under the TCPA?
Each unauthorized marketing call or text can result in TCPA statutory damages of $500 to $1,500 per violation, per consumer, with no proof of actual injury required. A list of 2,000 improperly consented leads could expose a business to $1–3 million in liability, making consent documentation essential for defense.
What must a valid consent record include to comply with TCPA rules?
A valid consent record must include the exact disclosure text the consumer saw, a timestamp of when consent was given, the consumer's IP address at the moment of consent, and the named contacting party—the specific seller the consumer agreed to hear from. Retaining this documentation for at least four years is critical to align with the TCPA statute of limitations.
How quickly must businesses honor a consumer's opt-out request under the TCPA revocation rules?
Businesses must honor opt-out requests made through any reasonable method—including keywords like 'stop,' 'revoke,' or 'cancel'—within 10 business days of receipt. A clarification message must also be sent within five minutes of the request, and failure to comply can trigger litigation under TCPA.
Is written consent required for informational messages like appointment reminders or fraud alerts?
No, prior express written consent is required only for marketing text messages, marketing robocalls, and fax advertisements—not for informational communications. The TCPA distinguishes between marketing and informational messages, with the latter not triggering consent requirements under federal telemarketing rules.

Turn Compliance Risk Into Your Competitive Edge

Understanding what written consent truly means under the TCPA is no longer just a legal checkbox—it’s the foundation of sustainable lead generation. The FCC’s 1:1 Consent Rule and updated revocation requirements have raised the bar: consent must be specific, documented, and honored with precision, or businesses face steep statutory damages with no proof of harm required. For lead buyers, this means every record must carry a verifiable trail—disclosure text, timestamp, IP address, and the named seller—to transform liability into defensible, high-intent opportunities. GrowthPros builds this compliance directly into every lead we deliver, ensuring your outreach starts with proof, not guesswork. If you’re ready to buy leads that come with consent records attached—and the confidence to use them—book your free 15-minute qualification call to see how consent-recorded, AI-followed leads work in your niche.

This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.

Start

More booked calls. Not more form fills.

Tell us your niche and your goal. We will show you realistic volume, exclusivity options, and what follow-up looks like on a live call — no pressure, no 40-page deck.