ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

How do you document informed consent?

Back to InsightsHow do you document informed consent?

How do you document informed consent?

Key Facts

  • TCPA lawsuit filings rose more than 60% in 2025 compared to the prior year
  • 78–80% of TCPA cases are filed as class actions
  • Statutory damages run $500 per unsolicited text and up to $1,500 for knowing violations
  • 2,000 non-consented texts could theoretically expose a business to around $1 million
  • Consent must be retained for at least four years, the TCPA statute of limitations
  • Opt-out requests must be honored within 10 business days
  • Consent is tied to the specific person and purpose and cannot be inherited through purchased or rented lists

Introduction

Getting consent from a customer is one thing. Proving you had it — months or years later, in front of a regulator or a class-action attorney — is something else entirely. That gap between "they said yes" and "here is the documented record of exactly how, when, and to what they agreed" is where most consent compliance programs fail.

The stakes are higher than many business owners realize. TCPA violations carry penalties of $500 to $1,500 per violation with no cap per case, and litigation data shows TCPA lawsuit filings rose more than 60% in 2025 compared to the prior year. Roughly 78–80% of those cases are filed as class actions, meaning a single weak consent record can multiply across thousands of contacts. As one compliance analysis puts it plainly: "Maintaining detailed and accurate records of consent is your strongest defense in the event of a TCPA complaint or legal dispute."

The rules are also shifting. Effective April 11, 2025, an updated FCC rule treats consent as revoked across all channels and purposes when a consumer opts out through any reasonable means — and businesses must honor that revocation within 10 business days. Meanwhile, a Fifth Circuit ruling accepting oral consent for automated calls applies only within that circuit, leaving most of the country under traditional written-consent standards.

For service businesses running outreach from a CRM — reactivation campaigns, renewal reminders, win-back calls — the practical question isn't whether consent matters. It's how to document it inside the systems you already use. A well-built system should log consent automatically rather than relying on human memory, and consent must stay tied to the specific person and purpose, since it cannot be inherited by buying or renting a list.

At its core, defensible consent documentation comes down to a few non-negotiable elements:

  • A time-stamped record of exactly when consent was given and how it was captured
  • The exact consent language and disclosures the consumer actually saw or heard
  • The consumer's contact details, kept tied to the specific purpose of consent
  • Retention of records — including opt-outs — for at least four years, the TCPA statute of limitations

At CallMyCustomers, we run outreach only from lists of real customers with every message approved by the owner, so consent documentation is a foundation of the work, not an afterthought. In the sections that follow, we break down exactly how to capture, store, and retrieve consent records within your existing CRM — before a dispute ever asks you to produce them.

Key Concepts

When a customer says "yes" to your outreach, that word only protects your business if you can prove it happened — exactly when, how, and what they agreed to. Consent documentation is the difference between a defensible record and a $500-per-message liability.

The stakes are rising fast. According to a 2025 year-end litigation report, TCPA lawsuit filings rose more than 60% over the prior year, with 78–80% of cases filed as class actions. Statutory damages run $500 per unsolicited text and up to $1,500 for knowing violations — meaning 2,000 non-consented texts could theoretically expose a business to around $1 million.

So what does a valid consent record actually contain? Legal guidance is consistent: consent must be documented, time-stamped, and retained to prove compliance in a dispute. Your CRM should capture:

  • The exact date and time consent was given, plus the capture method (web form, text opt-in, paper form)
  • The verbatim consent language the customer saw, including required disclosures like "Text STOP to opt-out"
  • Session metadata — IP address, device data — that makes the record independently verifiable
  • Opt-out requests, tracked by channel and retained for at least four years, the TCPA statute of limitations

A few nuances matter. Even where courts accept oral consent — the Fifth Circuit's recent ruling applies only within that circuit — legal experts advise that oral consent should be carefully documented and independently verifiable, and capturing written consent anyway remains the safer practice. Voice recordings alone don't qualify as written consent unless they meet E-SIGN Act requirements, according to compliance guidance on SMS marketing.

Consent is also tied to the person and the specific purpose — you can't buy, rent, or share a list and inherit consent with it, as TCPA compliance analysis makes clear. And since April 2025, an FCC rule treats revocation through any reasonable channel as applying across all channels and purposes, per BCLP's analysis of the new opt-out rules.

The practical takeaway: automate the logging rather than relying on human memory. This is why services like CallMyCustomers build consent capture directly into the outreach workflow — every message is owner-approved and every opt-out honored immediately, so the record exists before the first call goes out, not after a complaint arrives.

Best Practices

A consent record you can't produce is, legally speaking, a consent that never happened. With TCPA lawsuits rising more than 60% in 2025 alone and 78–80% of cases filed as class actions, your documentation process matters as much as the consent itself, according to recent litigation analysis.

Capture consent automatically at the point of origin. Your CRM should log consent the moment it happens — not rely on someone remembering to enter it later. As compliance guidance puts it, the system should "log consent automatically rather than relying on human memory." That means timestamping, method of capture, and the exact language the customer agreed to, all stored together.

Default to written consent even where oral consent is technically permitted. The Fifth Circuit's 2026 ruling accepting oral consent applies only within that circuit, and "documenting consent in writing anyway remains the safer practice," per risk management experts.

A complete consent record in your CRM should include:

  • Exact date and time of consent, plus the collection method (web form, SMS opt-in, paper form)
  • The verbatim consent language and disclosures shown to the customer
  • Purpose-specific linkage — consent tied to this customer and this use, never transferable to another list or campaign
  • An audit trail with IP or session data where available

Watch the details that invalidate otherwise valid consent. Legal compliance guidance warns that pre-ticked checkboxes "do not constitute prior express written consent because the customer made no 'express' action." Keep boxes unchecked, include required disclosures like "consent is not a condition of purchase," and consider a double opt-in confirmation text for an extra written record.

Handle opt-outs with the same rigor. Since April 2025, FCC rules treat a revocation through any reasonable channel as revoking consent across all channels and purposes. Your system must honor opt-outs within 10 business days, send any required clarification within 5 minutes, and retain opt-out documentation for at least four years — the TCPA statute of limitations — per BCLP's compliance analysis.

For service businesses running reactivation outreach from an existing customer list, this is exactly why working from real customer relationships — with every message approved and opt-outs honored immediately — beats renting cold lists where consent can't be verified. When CallMyCustomers runs a campaign, the consent trail lives in the client's own customer history, which is the strongest documentation there is. Detailed, accurate consent records are your strongest defense in a dispute — build your CRM process accordingly.

Implementation

Knowing the rules is one thing; building consent documentation into your CRM is where most businesses either succeed or expose themselves to risk. With TCPA lawsuits rising more than 60% in 2025 versus the prior year, according to a year-end litigation report, implementation details matter more than ever.

Start by making your CRM capture consent automatically at the point of origin. Every record should include the exact date and time of consent, the collection method, and the precise language the customer agreed to — because legal guidance is clear that written consent must be documented, time-stamped, and retained to prove compliance in disputes.

Don't rely on human memory or manual notes. As compliance experts recommend, your system should "log consent" automatically, enforce sending windows, and parse opt-outs by intent. Automation handles the scale; people handle the judgment calls.

Default to written consent, even where oral consent may suffice. The Fifth Circuit recently accepted oral consent for automated calls, but that ruling only applies within its circuit, and calls outside that jurisdiction may still require traditional written consent. Where you do capture consent orally, it should be carefully documented and independently verifiable.

Your CRM implementation checklist should include:

One practical note: a double opt-in — a confirmation text requiring a "YES" reply — adds an additional written confirmation layer on top of any collection method, and it's inexpensive insurance.

This is why working from lists of real, known customers changes the compliance picture entirely. When a service like CallMyCustomers runs reactivation outreach, every message goes out under the business's approved script with consent records and opt-outs already handled — the documentation exists before the first call, not reconstructed after a complaint.

With violations running $500 to $1,500 each and no cap per case, the math is unforgiving — 2,000 non-consented texts can approach $1M in theoretical exposure. Build the audit trail first, then run the campaign.

Conclusion

Good consent documentation isn't paperwork for its own sake — it's the difference between a defensible outreach program and a six-figure class action. And the stakes keep rising: TCPA lawsuit filings climbed more than 60% in 2025 alone, with 78–80% of cases filed as class actions, according to litigation tracking data.

The core takeaways are simple. Every consent record needs a timestamp, the exact language the customer agreed to, the method of capture, and the contact details involved. Retain those records — and your opt-out documentation — for at least four years, the TCPA statute of limitations, as legal analysts at BCLP note. And even where courts now accept oral consent, Holland & Knight's analysis makes clear that written, verifiable documentation remains the safer practice.

Your next steps:

  • Audit your CRM for the five essentials: timestamp, consent language, capture method, contact details, and retention period (4–5 years).
  • Automate opt-out tracking across every channel, since the FCC's April 2025 rule treats revocation through any reasonable means as revoking all channels and purposes.
  • Confirm consent is tied to the specific person and purpose — consent is not transferable, and you can't inherit it by buying or renting a list.
  • Layer in a double opt-in where feasible; a confirmation reply provides an additional written confirmation on top of any capture method.

The math alone justifies the effort. Statutory damages run up to $500 per unsolicited text and $1,500 per willful violation, meaning 2,000 non-consented texts could theoretically expose a business to $1 million. Weak consent records are the single most fixable gap in most TCPA defenses.

If you'd rather not build this machinery yourself, CallMyCustomers handles outreach from your existing customer list under the same principle — explicit, documented consent at booking, opt-outs honored immediately, and every message approved by you before it goes out. Compliance and repeat revenue aren't competing goals; a permission-based reactivation program starts with getting the documentation right.

Frequently Asked Questions

What specific elements must a valid consent record include to be defensible in a TCPA dispute?
A defensible consent record must include the exact date and time of consent, the method of capture (e.g., web form, SMS opt-in), the verbatim consent language and disclosures shown to the consumer, and session metadata like IP address where available. These elements ensure the record is independently verifiable and tied to the specific person and purpose, as required by TCPA compliance guidance.
How long must businesses retain consent and opt-out records to comply with TCPA regulations?
Consent and opt-out documentation must be retained for at least four years, which aligns with the TCPA statute of limitations. Some providers, like TrustedForm, retain records for five years as an added safeguard against legal exposure.
Does the Fifth Circuit's 2026 ruling accepting oral consent for automated calls apply nationwide?
No, the Fifth Circuit's ruling accepting oral consent for automated calls applies only within that circuit. Businesses operating outside this jurisdiction may still be subject to traditional written consent requirements, so documenting consent in writing remains the safer practice for multi-state operations.
What does the FCC's April 2025 rule change mean for handling consumer opt-outs?
Effective April 11, 2025, the FCC rule treats a consumer's opt-out through any reasonable channel as revoking consent across all channels and purposes. Businesses must honor such revocations within 10 business days and send any required clarification message within 5 minutes of receipt.
Why can't businesses inherit consent when buying or renting a contact list?
Consent is tied to the specific individual and the purpose for which it was given and cannot be transferred, inherited, or assumed when sharing, purchasing, or renting lists. Using third-party lists without verifiable, purpose-specific consent exposes businesses to TCPA liability.
Is a voice recording alone sufficient to prove written consent under the TCPA?
No, voice recordings alone do not qualify as written consent under the TCPA unless they meet E-SIGN Act requirements, including consumer disclosures and a record that can be accurately retained and reproduced. Courts have found recordings insufficient without these elements.

Your Strongest Defense Is a Well-Kept Record

Consent you can't prove is consent that never happened — at least in the eyes of a regulator or a class-action attorney. The essentials are straightforward: capture a time-stamped record with the exact consent language, the method of capture, and the contact details tied to a specific purpose; honor opt-outs across every channel within 10 business days; and retain everything for at least four years. With TCPA filings up more than 60% in 2025 and 78–80% of cases filed as class actions, per year-end litigation data, weak records are the single most fixable gap in most defenses. Your next step is a simple audit: pull up any customer in your CRM and ask whether you could produce a complete consent record in minutes, not days. If the answer is no, fix that before your next campaign goes out. Or let CallMyCustomers handle it — we run outreach only from your list of real customers, with explicit consent captured at booking, opt-outs honored immediately, and every message approved by you first. Start with a free list review and see what your dormant customers are worth.

Stay in the Loop