Back to insights
Checking Compliance Practices

How do I write written consent?

Learn how to write compliant written consent for lead generation. Get the 5 must-have elements, a practical checklist, and TCPA rules to protect your bu...

How do I write written consent?

How do I write written consent?

Key Facts

Vague consent language in lead generation forms can expose businesses to significant TCPA risks, as overly broad or hidden disclosures fail to meet legal standards. When consent is not explicitly tied to specific sellers or communication methods, it creates a liability gap that courts and regulators are increasingly scrutinizing. According to industry research, hyperlinked lists of sellers are likely non-compliant, while selectable checkboxes for buyers remain a safer approach.

The FCC’s proposed one-to-one consent rule, originally set for January 27, 2025, was vacated by the courts just days before its effective date. However, its influence persists, shaping today’s compliance expectations. The rule emphasized that consent must name the specific seller and outline how consumers will be contacted—principles that remain critical for avoiding violations. Even without the formal rule, experts advise treating “clear and conspicuous disclosure” as non-negotiable.

Businesses that neglect these standards risk costly penalties and reputational damage. For example, recordkeeping requirements mandate retaining consent data for five years, while opt-out mechanisms must process requests within 10 business days. Failure to meet these benchmarks can trigger TCPA lawsuits, which averaged $500 per violation in 2023.

  • Obtain prior express written consent (PEWC) with specific seller identification.
  • Use selectable checkboxes for multi-buyer scenarios, not hyperlinked lists.
  • Ensure opt-out processes are immediate and user-friendly.

Worqd’s approach to lead generation prioritizes compliance by embedding clear consent language into every interaction. Their AI SDRs and lead-handling workflows are designed to capture explicit, actionable consent, aligning with the best practices highlighted by compliance experts. By focusing on transparency and precision, businesses can mitigate risks while building trust with prospects.

Consumers today demand transparency, and compliant written consent is the foundation of ethical lead generation. Research shows that 78% of legal disputes over lead generation stem from unclear or incomplete consent processes, underscoring the need for precision according to industry research. Here’s how to structure a legally sound consent statement.

Every compliant consent statement must include clear and conspicuous disclosure. This means explicitly stating the specific seller who will contact the consumer and the purpose of the communication. For example, a form might read, “You agree to receive robocalls from [Seller Name] about [Product/Service]” as outlined in regulatory guidelines. Hyperlinked seller lists are likely non-compliant, while selectable checkboxes for multiple buyers may be acceptable.

The statement must also align with topically related content. A consumer who requests information about HVAC services should not later receive unsolicited calls about financial planning. This alignment reduces legal risk and builds trust per compliance experts.

Key elements include:

  • An affirmative action—such as a checked box—without pre-checked options
  • A straightforward revocation method, like a one-click unsubscribe link
  • Retention of records for at least five years, as mandated by the FCC

Finally, ensure all contact types (email, SMS, voice) have separate checkboxes to avoid assumptions about consumer preferences as recommended by compliance tools. For businesses like Worqd, which prioritize personalized B2B outreach, these steps reinforce trust while adhering to evolving standards.

Recordkeeping and Opt-Outs: The Compliance Details Most Teams Miss

When it comes to writing a compliant written consent statement, the operational details are just as crucial as the initial consent language. Recordkeeping requirements dictate that businesses must retain detailed records of consent for at least five years, including the specific consent language, list of buyers, consumer's affirmative agreement, date and time of consent, and the consumer's signature or agreement method.

This level of detail is essential for ensuring compliance and minimizing legal risks. As part of its compliance efforts, businesses should also implement robust systems for honoring opt-outs, with a maximum timeframe of 10 business days for processing such requests.

In addition to recordkeeping and opt-out procedures, businesses must also ensure that every contact with a consumer is topically related to their initial request for information. This means that communication content should be carefully crafted to avoid any potential violations of the TCPA.

Some key considerations for compliant recordkeeping and opt-outs include:

  • Retaining records of consent for a minimum of five years
  • Honoring opt-out requests within 10 business days
  • Sending non-promotional confirmation messages within 5 minutes of an opt-out request

By prioritizing these operational details, businesses like Worqd can help ensure that their lead generation efforts are not only effective but also compliant with relevant regulations. Automated compliance solutions can also play a critical role in managing the collection, storage, and documentation of consumer consent, making it easier for businesses to stay on the right side of the law. With the right approach to recordkeeping and opt-outs, businesses can minimize their risk of non-compliance and focus on driving growth through effective lead generation strategies.

Consent language is where most lead funnels quietly fail — not because the form is broken, but because the words next to the checkbox don't hold up. Here's a checklist you can run against your forms today.

Start with plain-language disclosure. Your consent statement must clearly and conspicuously tell people they're agreeing to receive calls or texts — and from whom. According to legal analysis of the FCC's one-to-one consent rules, hyperlinked lists of sellers are likely non-compliant, while selectable lists may be acceptable. Name yourself as the contacting party, in the sentence itself.

Use one checkbox per consent type. TCPA guidance recommends separate checkboxes for each communication type and warns against pre-checked boxes. A single box bundled with your terms of service doesn't cut it — and bundling is exactly what regulators look for.

Log consent details automatically. Records should capture the exact consent language shown, the date and time, and how the consumer agreed — and compliance guidance requires retaining them for a minimum of five years. Nik Thakorlal of LeadsHook recommends phone verification to create what he calls an "unbreakable chain of proof".

Your audit checklist:

  • Disclosure names the specific seller and communication type — no vague "partners" language
  • Each consent type gets its own, un-checked box
  • Follow-up content stays topically related to what the person actually asked about
  • Every message includes a simple opt-out — email link or "STOP" for SMS
  • Opt-outs are processed within 10 business days, with confirmation inside 5 minutes

That last point matters more than most teams realize. FCC guidance sets a maximum of 10 business days to process opt-out requests, and requires non-promotional confirmation messages within 5 minutes. Build revocation into every follow-up template before launch, not after your first complaint.

Walk your own funnel as a prospect. Read the checkbox text out loud. If you can't tell who will contact you, what they'll contact you about, and how to make it stop, rewrite it until you can.

Worqd applies this to its own booking funnel: the growth call form requires an explicit "I agree to be contacted about my request" checkbox, and states plainly that your details are used only to prepare for the call — one consent, one purpose, one named party. That's the standard worth copying, whether you're a local service business or a national B2B team.

Frequently Asked Questions

What are the must-have elements of a compliant written consent statement?
Your consent statement needs clear and conspicuous disclosure naming the specific seller and communication type (e.g., "You agree to receive robocalls from [Seller Name] about [Product/Service]"), an affirmative action like an unchecked checkbox, a simple revocation method, and topically related follow-up content. Legal analysis of the FCC's consent rules shows vague "partners" language is what gets businesses in trouble.
Can I use a hyperlinked list of sellers on my lead form, or do I need checkboxes?
Hyperlinked lists of sellers are likely non-compliant, while selectable checkboxes for each buyer remain the safer approach. Industry research recommends listing each buyer separately so consumers can select or deselect them, with the disclosure covering only the selected buyers.
Wasn't the FCC's one-to-one consent rule cancelled? Do I still need to follow it?
Yes — the rule was vacated by the courts on January 24, 2025, just days before its January 27 effective date, but its principles still shape compliance expectations. Compliance guidance still recommends naming the specific seller and outlining how consumers will be contacted, since courts and regulators continue scrutinizing vague consent.
How long do I need to keep consent records, and what exactly should I log?
You must retain consent records for a minimum of five years, capturing the exact consent language shown, the list of buyers, the consumer's affirmative agreement, the date and time of consent, and how the consumer agreed. Recordkeeping requirements treat this documentation as essential for defending against TCPA claims.
How quickly do I have to honor opt-out requests?
Opt-out requests must be processed within a maximum of 10 business days, and a non-promotional confirmation message should be sent within 5 minutes of the request. FCC guidance also requires every message to include a simple opt-out, like an email link or "STOP" for SMS.
Can I use one checkbox for all contact types, like email, SMS, and calls together?
No — each contact type (email, SMS, voice) should get its own separate, un-checked checkbox, and you should never bundle consent with your terms of service. TCPA guidance warns that pre-checked boxes and bundling are exactly what regulators look for. Worqd applies this standard in its own booking funnel: one checkbox, one purpose, one named party.

Securing Trust Through Transparent Consent: Key Takeaways for Compliance and Growth

Writing compliant written consent isn't just about avoiding penalties—it's about building trust and ensuring your lead generation efforts withstand legal and reputational scrutiny. Clear, specific language that names the seller, outlines communication methods, and includes actionable opt-out mechanisms is non-negotiable. As the FCC’s vacated one-to-one consent rule shows, regulators prioritize transparency, and businesses that prioritize this gain a competitive edge. By auditing your forms for explicit checkboxes, topically aligned content, and robust recordkeeping (like retaining consent data for five yearshttps://www.growform.co/fcc-lead-generation-rules-how-to-ensure-compliance-with-1-1-consent/), you mitigate risks while fostering consumer confidence. For teams like Worqd, compliance isn’t a checkbox—it’s a foundation for sustainable growth. Take the next step: review your consent processes today, and ensure every interaction aligns with both legal standards and the trust your prospects deserve.

Want help putting this into action?

Book a Growth Call
Topicswritten consent statementTCPA written consent requirementsone-to-one consent rulelead generation complianceprior express written consentconsent language for lead forms

Stay in the Loop