Back to insights
Checking Compliance Practices

How can we recognize that someone has consented?

Unprovable consent isn't a lead — it's a liability. TCPA filings rose 67% in 2024, with $500–$1,500 per violation. Learn the three signals that prove co...

How can we recognize that someone has consented?

How can we recognize that someone has consented?

Key Facts

  • TCPA filings surged 67% year-over-year in 2024 to 2,788 cases, with average class action settlements exceeding $6.6 million according to litigation data.
  • Florida, California, and Texas generated 58% of 2024 TCPA filings despite representing only 27.6% of the U.S. population per geographic analysis.
  • 31–41% of TCPA cases originate from repeat serial plaintiffs who target unprotected consent forms industry research shows.
  • The Sixth Circuit's four-part test asks whether an ordinary user would recognize they're entering a binding agreement when they click submit per court precedent.
  • Pre-ticked checkboxes fail TCPA compliance because the customer made no affirmative action FCC guidance confirms.
  • Litigation-grade consent certificates cost $0.15–$0.50 each and should be retained five-plus years to cover the four-year statute of limitations compliance research recommends.
  • Revoking consent on one message chain applies to the entire phone number, not just that specific campaign FCC analysis explains.

Every text you send without provable consent is a potential lawsuit in waiting. Under the TCPA, statutory damages run $500–$1,500 per violating message, and there's no cap on aggregate damages. A single non-compliant campaign can snowball fast.

The numbers back this up. TCPA filings jumped 67% year-over-year in 2024, reaching 2,788 cases, and average class action settlements now exceed $6.6 million. The TCPA has become, as one defense attorney put it, "the biggest cash cow in history" for the plaintiff's bar.

Here's the part most lead buyers miss: the burden of proof sits entirely on you, the sender. If a consumer claims they never agreed to hear from you, you have to produce documentation showing they did. Verbal consent doesn't cut it for marketing texts, and neither does a pre-ticked checkbox, because the customer took no affirmative action.

That's why an unprovable lead isn't an asset — it's a liability wearing a lead's costume. As industry analysis puts it: without permission that's properly obtained and meticulously documented, "you are not selling leads. You are selling liability."

The risk concentrates where you might not expect. Florida, California, and Texas accounted for 58% of 2024 filings despite holding just 27.6% of the population. And 31–41% of cases come from repeat, serial plaintiffs who know exactly what an unprotected consent form looks like.

So what does recognizable consent actually look like? Courts now judge your forms by objective design signals, not intentions. The Sixth Circuit's four-part test asks whether an ordinary user would recognize they're entering a binding agreement when they hit submit — based on page layout, how close the disclosure sits to the action button, typography, and what a reasonable consumer expects from that kind of transaction.

The signals that protect you share a common thread: an affirmative act, clearly disclosed, and time-stamped:

  • An unchecked box the user actively ticks — never pre-populated
  • Disclosure visible without scrolling, adjacent to the submit button, in type at least as large as surrounding text
  • A double opt-in confirmation, like a "YES" reply that creates a second written record
  • Language that names the specific sender, purpose, and technology — not vague phrases like "our partners" or "any purpose"
  • Retained logs with timestamp, IP, URL, and the exact disclosure language, kept five-plus years to cover the four-year statute of limitations

This is the standard we hold ourselves to at Worqd. Our own booking funnel requires explicit consent — "I agree to be contacted about my request" — before anyone hears from us, and our fast follow-up systems only work on contacts we can prove agreed to be contacted. When you're generating leads at speed, consent recognition has to be built in from the first click, not bolted on after the first lawyer's letter arrives.

Guessing about consent means every message carries a price tag you can't see. Recognizing it — and proving it — turns those same messages back into what you paid for: revenue.

The Three Signals That Prove Someone Consented

When a regulator, a court, or a plaintiff's attorney asks "how do you know they consented?", you need a better answer than "they filled out our form." The good news: every credible source on consent recognition converges on the same three signals.

Valid consent starts with something the person actually did — an unchecked box they ticked, a typed name, an e-signature, or a "YES" reply to a confirmation message. Under the TCPA's Prior Express Written Consent standard, the signature must come "via affirmative action," and pre-ticked boxes fail because the customer never did anything at all. Silence and implied consent don't count either — current FCC guidance treats pre-checked boxes and implied consent as unacceptable.

A strong pattern is double opt-in: after signup, a confirmation message requiring a "YES" reply creates a second written record of agreement. This is why Worqd's own booking funnel asks for an explicit "I agree to be contacted about my request" rather than assuming interest from a form submission.

Courts now judge consent forms by objective design tests. The Sixth Circuit's four-part conspicuousness test asks one central question: would an ordinary user recognize they're entering a binding agreement? The test examines page layout, proximity to the submit button, typography, and whether the transaction type suggests contractual obligations.

The practical checklist from compliance research on valid consent forms:

  • Disclosure visible without scrolling, adjacent to the signature mechanism
  • Font at least as large as surrounding text — 6-point or smaller is deemed problematic
  • No click-through hyperlinks hiding essential disclosure
  • The form submits even if the optional consent checkbox is left unticked

The FCC standard is that disclosure must be "apparent to a reasonable consumer" — never buried in fine print, per Orrick's analysis of the FCC's lead generator order.

Here's the part most businesses miss: the burden of proof rests entirely on the sender, not the consumer. If challenged, you must produce time-stamped records showing exactly what the person saw and did — timestamp, IP, URL, and the exact disclosure language. Third-party documentation tools capture this litigation-grade evidence for roughly $0.15–$0.50 per certificate, and records should be retained five or more years given the four-year statute of limitations.

The stakes justify the discipline. TCPA filings rose 67% year-over-year in 2024, with average class action settlements exceeding $6.6 million, and statutory damages of $500–$1,500 per violation with no cap on aggregate exposure. Without properly obtained and meticulously documented permission, you're not generating leads — you're generating liability.

What 'Clear and Conspicuous' Actually Looks Like to a Court

Courts don't guess whether consent language was visible enough — they apply a test. In Dahdah v. LowerMyBills.com, the Sixth Circuit established a four-part conspicuousness framework that now functions as a practical checklist for anyone evaluating a consent form.

The court's central question is simple: would an ordinary user recognize they're entering a binding agreement when they click submit? The four factors answer it from different angles:

  • Page design and layout — disclosures sit on an uncluttered backdrop, not camouflaged among other visual elements.
  • Proximity to the action button — consent text appears close to the submit button, not orphaned at the bottom of the page.
  • Typography and contrast — fonts and colors enhance visibility rather than bury the disclosure in fine print.
  • Situational expectations — the type of transaction leads a reasonable consumer to anticipate contractual obligations.

Interestingly, the court upheld consent language positioned beneath the submit button — but explicitly warned this is no safe harbor. Above-button placement with bold typography remains the most defensible approach, and as one analysis of the ruling puts it, compliance certainty delivers better ROI than litigation defense.

The FCC's standard reinforces this: disclosure must be apparent to a reasonable consumer — not buried, barely visible, in fine print, or accessible only through a hyperlink, according to Orrick's analysis of the FCC order. Practical signals include disclosure visible without scrolling, font at least as large as surrounding text (6-point or smaller is problematic), and forms that still submit when the optional consent box is left unticked.

Certain phrases invalidate consent outright. An industry guide to TCPA consent flags vague seller identifications like "our partners," overbroad scope like "any purpose" or "forever," missing technology disclosures (no mention of "autodialed" or "prerecorded"), and condition-of-purchase phrasing. Getting this wrong is expensive: TCPA filings rose 67% year-over-year in 2024, and average class action settlements exceed $6.6 million.

Finally, consent is channel-specific. Under U.S. rules, email marketing operates on an opt-out model under CAN-SPAM, while marketing texts and autodialed calls require prior express written consent — verbal agreement is explicitly insufficient. A checkbox that covers "contact me" generally won't satisfy SMS rules; each channel needs its own clear authorization.

This is why Worqd's booking funnel asks visitors to affirm a specific statement — "I agree to be contacted about my request" — rather than burying consent in a terms-of-service link. When you're checking a provider's compliance practices, that kind of narrow, affirmative, channel-aware language is exactly the signal to look for.

Capturing consent is only half the job. What you do with it afterward — how you handle opt-outs, and how well you can prove consent ever existed — is where most businesses get into trouble.

Consent is not a one-time event. According to TCPA guidance on SMS marketing, even after someone agrees to receive your texts, a later opt-out request legally requires you to stop sending. There is no grace period and no "one last message."

One of the most misunderstood rules: when a consumer revokes consent on one message thread, that revocation applies to the entire phone number, not just the specific campaign or chain where they opted out. As Orrick's analysis of the FCC's consent order explains, you cannot keep texting that number from a different campaign or sequence.

This has a practical consequence for your systems. If your opt-out handling is siloed by campaign, a "STOP" reply in one workflow may not suppress the number in another — and every message sent after revocation carries statutory damages of $500 to $1,500 per violation, per litigation data on TCPA exposure.

If a dispute ever reaches court, the consumer does not have to prove they didn't consent. The sender must prove they did. That means your records are your only defense — and "we think they filled out a form" is not a record.

Litigation-grade documentation means capturing, for every consent event:

  • The exact timestamp of the consent action
  • The IP address and URL where consent was given
  • The exact disclosure language shown at that moment
  • Session evidence such as clicks or replay, where available

Third-party tools like TrustedForm and Jornaya TCPA Guardian generate these certificates for roughly $0.15–$0.50 each — a trivial cost against an average TCPA class action settlement exceeding $6.6 million, according to industry compliance research.

The TCPA carries a four-year statute of limitations, and statutory damages have no aggregate cap — 10,000 non-compliant calls can mean $5M–$15M in exposure. The standard recommendation is to retain consent certificates for at least five years, comfortably past the window in which a claim can be filed. Certificates should also be claimed immediately after capture, not retrieved later.

This is why consent management is increasingly a systems question, not a legal footnote. Effective setups pair channel-specific consent logs with automated opt-out management, as compliance implementation guides recommend, so revocation propagates everywhere instantly.

At Worqd, this is the standard we build follow-up around: permission-aware outreach where every consent is documented and every opt-out stops communication across the board. When you evaluate any growth partner, ask to see their consent records and opt-out workflow — a provider that can't produce timestamped proof isn't just sloppy, they're handing you liability.

Knowing what valid consent looks like is one thing — building a funnel that produces it, every time, is another. Here is a practical checklist you can apply to your lead funnel today, grounded in what courts and regulators actually look for.

1. Use an unchecked, optional checkbox with full disclosure beside it. Pre-ticked boxes fail because the customer made no affirmative action, and the form must still submit if the consent box is left unticked. Position the disclosure visibly without scrolling, near the submit button, in a font at least as large as the surrounding text — this matches the Sixth Circuit's four-part conspicuousness test, which asks whether an ordinary user would recognize they're entering a binding agreement (per the court's analysis).

2. Add double opt-in confirmation. A follow-up email or SMS asking for a "YES" reply creates an additional written record of agreement and works with every collection method (consent experts recommend this as a strong signal).

3. Write consent language that names the specific sender and purpose. Vague seller IDs like "our partners," overbroad scope like "any purpose," and missing technology disclosure are recognized red flags for invalid consent. Say who will contact them, how, and why.

4. Keep channel-specific, time-stamped logs. The burden of proof rests entirely on the sender, so litigation-grade documentation — timestamp, IP, URL, and exact disclosure language — is what proves consent existed. Retain records 5+ years, since the statute of limitations runs 4 years.

5. Audit quarterly. Quarterly audits of consent setup catch implementation errors before they become liability — especially important given that TCPA filings rose 67% year-over-year in 2024, with average class action settlements exceeding $6.6M.

Your quarterly audit should verify:

  • Every consent checkbox starts unticked and the form submits without it
  • Disclosure sits adjacent to the action button, in readable type, with no essential terms hidden behind hyperlinks
  • Consent is captured separately per channel — email, SMS, and phone each need their own record
  • Opt-outs stop all communications immediately, since revocation on one chain applies to the entire number
  • Logs capture timestamp, IP, URL, and the exact disclosure language shown

This is exactly how we at Worqd build outreach and booking funnels for clients: permission-aware by design, with explicit consent captured at the point of booking — "I agree to be contacted about my request" — and details used only to prepare for the call. Because we run the whole path from first click to booked call, consent signals are built into the funnel itself rather than bolted on afterward. As one industry analysis put it, without properly documented permission, "you are not selling leads — you are selling liability."

Want a funnel that books calls without selling liability? Book a Growth Call at worqd.com/book — more demand, faster follow-up, better creative, all on a compliant foundation.

Frequently Asked Questions

Does a pre-ticked checkbox count as consent?
No. Pre-ticked boxes fail because the customer took no affirmative action, and current FCC guidance treats both pre-checked boxes and implied consent as unacceptable. Valid consent requires an affirmative act — an unchecked box the user actively ticks, a typed name, an e-signature, or a "YES" reply — per TCPA guidance on SMS marketing consent.
Who has to prove consent if a dispute goes to court — me or the customer?
The burden of proof sits entirely on you, the sender. If a consumer claims they never agreed, you must produce time-stamped records — timestamp, IP, URL, and the exact disclosure language shown — which is why compliance research calls an unprovable lead "liability, not an asset."
What does 'clear and conspicuous' consent language actually look like to a court?
Courts apply an objective test. The Sixth Circuit's four-part conspicuousness test asks whether an ordinary user would recognize they're entering a binding agreement, judging page layout, proximity to the submit button, typography, and what the transaction type suggests — per the court's analysis. Disclosure should be visible without scrolling, in type at least as large as surrounding text, with nothing essential hidden behind a hyperlink.
Is verbal consent good enough for marketing texts?
No. Under U.S. rules, marketing texts and autodialed calls require prior express written consent — verbal agreement is explicitly insufficient, while email under CAN-SPAM runs on an opt-out model instead, per DLA Piper's data protection handbook. Each channel needs its own clear authorization, so a generic "contact me" checkbox won't satisfy SMS rules.
If someone replies STOP to one campaign, can I keep texting them from another?
No. When a consumer revokes consent on one message thread, that revocation applies to the entire phone number — not just the specific campaign — so you cannot keep texting from a different sequence, per Orrick's analysis of the FCC's consent order. Every message sent after revocation carries statutory damages of $500–$1,500 per violation.
How risky is it really to text leads without documented consent?
Very. TCPA filings rose 67% year-over-year in 2024 to 2,788 cases, with average class action settlements exceeding $6.6 million and statutory damages of $500–$1,500 per violation with no aggregate cap — 10,000 non-compliant calls can mean $5M–$15M in exposure, per litigation data on TCPA exposure. Third-party documentation tools cost roughly $0.15–$0.50 per certificate, a trivial cost against that risk.

Consent You Can Prove Is Growth You Can Keep

Recognizing consent comes down to three signals: an affirmative act the person actually took, disclosure a court would call clear and conspicuous, and time-stamped documentation you can produce on demand. Get all three right, and every lead in your funnel is an asset. Miss one, and you're holding liability — with TCPA filings up 67% year-over-year and average class action settlements topping $6.6 million, guessing is the most expensive option on the table. The good news: this is fixable. Start with the checklist above — unticked boxes, adjacent disclosure, double opt-in, channel-specific logs, instant opt-out propagation — and run your first quarterly audit this month. And if you'd rather have consent built into the funnel from the first click, that's how we work at Worqd: permission-aware outreach, documented consent at booking, and follow-up that only touches contacts who provably said yes. Want a funnel that books calls without selling liability? Book a Growth Call at worqd.com/book — more demand, faster follow-up, better creative, on a compliant foundation.

Want help putting this into action?

Book a Growth Call

Stay in the Loop