Lead-gen compliance is unglamorous and expensive to get wrong. TCPA violations run $500 to $1,500 per call or text, and class actions in this space regularly reach eight figures. The FCC's one-to-one consent direction — requiring disclosure specific to each named seller, obtained before contact, and documented well enough to survive a challenge — has been delayed, but the trajectory is toward stricter requirements, not looser ones.
The practical takeaway: build consent capture into every form from day one, not after launch.
What a defensible record looks like
It is not a checkbox and a hope. A consent record that holds up contains the specific disclosure text the person actually saw, the timestamp, the IP address, and the named party authorized to contact them. "Consent given" is not the same as "here is exactly what they agreed to, when, and on what basis."
That is why every lead that moves through our platform carries its full trail: the disclosure shown, the timestamp, the source channel, and the scrub status. It is boring infrastructure. It is also the difference between a nuisance complaint and a defensible position.
Two operational rules
First, DNC scrubbing before any outbound contact — not after, not "we check periodically." Second, opt-outs that actually work across every channel you use: reply STOP to an SMS, an email unsubscribe, a voice prompt. A revocation that is honored in one channel and ignored in another is still a violation.
This is not legal advice — TCPA exposure warrants actual legal review before you scale any outbound program. But if your lead provider cannot show you a consent record on demand, that is the audit finding you want to find first.