Skip to main content

One-to-One Consent and the TCPA: What Lead Buyers Should Have in Place

Consent language buried under a submit button is not consent. Here is what a defensible consent record actually contains — and the six questions to ask any lead vendor before the first invoice.

Compliance  ·  Published May 12, 2026  ·  9 min read

If your business calls or texts consumers who filled out a form somewhere on the internet, the consent behind that form is your legal exposure — not the vendor's. Buyers routinely discover this the hard way, usually in a demand letter that references a call they never personally placed.

This guide covers what a defensible consent record looks like in practice, what to retain, and how to pressure-test a vendor before money changes hands. It is a summary of how we operate, not legal advice; your counsel should review your specific programme.

Why consent standards tightened

For most of the last decade, a single checkbox next to a list of two hundred "marketing partners" was treated by parts of the industry as adequate consent. Regulators, courts and plaintiffs' firms have spent several years steadily narrowing that interpretation, and the direction of travel is unambiguous: consent should be specific, informed and traceable to one seller the consumer would actually recognise.

The practical consequence is that the old model — one form, one checkbox, a hyperlinked partner list, and the record sold to whoever bids — has become a liability with a long tail. Statutory damages under the TCPA run to hundreds or thousands of dollars per call or text, and class actions aggregate quickly.

Rules change. The regulatory picture around consent, including the FCC's one-to-one consent rulemaking and subsequent litigation, has shifted repeatedly. Confirm the current requirements with counsel before you rely on any summary, including this one.

What counts as prior express written consent

Strip away the argument and the durable elements look like this:

  • A clear and conspicuous disclosure. The consent language sits where a reasonable person will see it — above or immediately adjacent to the submit button, in readable type, not collapsed behind a link or set in six-point grey.
  • An identified seller. The consumer should be able to tell who will be contacting them. A link to a list of hundreds of "trusted partners" does not meaningfully identify anyone.
  • An affirmative act. An unchecked box the consumer ticks, or an equivalent unambiguous action. Pre-checked boxes and consent-by-continuing are not affirmative acts.
  • Disclosure of automated technology. If autodialed calls, prerecorded messages or artificial voice will be used, say so.
  • No conditioning on purchase. Consent to marketing calls cannot be a condition of buying the product.
  • A stated scope. What the consumer will receive — calls, texts, email — and, sensibly, that message rates may apply.

None of this reduces conversion as much as marketers fear. In our own testing across insurance and finance funnels, moving disclosures from a collapsed footer to a visible block above the submit button changed completion rates by less than two percentage points, and materially improved downstream contact rates — because people who knew they would be called were less surprised when the phone rang.

The evidence you need to retain

Consent you cannot prove is functionally the same as consent you never obtained. A complete record generally includes:

ElementWhy it matters
Certificate (TrustedForm or Jornaya LeadiD)Independent third-party evidence of the session, including a replay of the page as the consumer saw it
Timestamp and IP addressEstablishes when and roughly where the submission originated
Exact disclosure textProves what the consumer actually agreed to, not what the current version of the page says
Page URL and referring sourceTraces the record back to the campaign and creative that produced it
Field-level submission dataShows the consumer entered their own information rather than it being pre-populated

Retain these for at least the period your counsel recommends — commonly four to five years, reflecting the statute of limitations for TCPA claims. Retention is cheap; reconstruction after the fact is impossible.

Six questions to ask a lead vendor

  1. Do you own the traffic source, or are you buying from a network? If they cannot name the property, they cannot control the disclosure on it.
  2. Can I see a live example of the form, right now? Not a screenshot. The current page, on the current domain.
  3. Is my brand named in the consent language? If not, ask what standard they think they are meeting.
  4. Will you provide the certificate on every record? The answer should be yes, automatically, not on request.
  5. What is your suppression and DNC process? National registry, state registries, internal opt-out list, and how quickly opt-outs propagate.
  6. What happens if I am sued over a record you sold me? Look for a written indemnity with real substance, and check whether the entity behind it has any assets.

A vendor who answers all six comfortably is not necessarily perfect, but a vendor who bristles at the questions has told you what you needed to know.

Getting your own house in order

Vendor diligence only covers half the risk. Your own dialling and messaging practices matter just as much:

  • Scrub against the National Do Not Call Registry and applicable state registries before the first attempt, and re-scrub on a schedule.
  • Maintain an internal do-not-call list, honour requests promptly, and make sure it propagates across every dialer, CRM and third-party caller you use.
  • Respect calling-hour restrictions in the consumer's time zone, and check state rules — several are stricter than the federal 8am–9pm window.
  • Record and retain calls where your state law permits, and follow two-party consent rules where it does not.
  • Train agents on identification requirements: who is calling, on whose behalf, and how to opt out.

Treat compliance as an operating system rather than a document. The businesses that get into trouble are rarely the ones without a policy — they are the ones whose policy stopped matching what the dialer actually did eighteen months ago.

Need this handled for you? Leads Registry builds and runs acquisition programmes for U.S. businesses in regulated categories. Book a strategy call.

FAQ

Related questions

The TCPA does not set an expiry on written consent, but consent for a specific seller and purpose becomes harder to defend the older it gets, and some states and platform policies impose their own limits. Many buyers apply an internal freshness window of 30 to 90 days for outbound dialling and treat older records differently.

Neither is required by statute. What is required is that you can prove consent. Third-party certification is simply the most practical, widely accepted way to do that, and it carries more weight than a screenshot from your own vendor.

In practice, the party that placed the call is the first defendant, and that is usually the buyer. Indemnities can shift cost afterwards, but they do not stop you being named. Diligence before purchase is worth more than contract language after.

Keep reading

More from the Leads Registry team

Ready to turn traffic into booked revenue?

Tell us your target cost per acquisition and the states you sell in. We will come back with a channel plan, a volume forecast and a pilot budget — usually within two business days.