What's the difference between informed consent and expressed consent?
Understand informed consent vs. expressed consent for outbound marketing. Learn express vs. implied consent rules under GDPR, TCPA, and CASL to stay com...

What's the difference between informed consent and expressed consent?
Key Facts
- Informed consent isn't a separate legal category — it's a quality standard that valid express consent must meet under GDPR's 'freely given, specific, informed, and unambiguous' test, according to compliance research.
- Canada's CASL can fine corporations up to $10 million per violation, applied based on where the recipient sits, not where you send from, per email marketing compliance analysis.
- TCPA violations cost $500 each, trebled to $1,500 for willful violations, multiplied across every call or text in a campaign, according to ActiveProspect's consent analysis.
- Just 317 B2B emails triggered a $1.1 million penalty and five years of litigation in the Compu-Finder case, B2B compliance records show.
- Canadian implied consent expires after only two years post-purchase or six months after an inquiry, so old contacts may already be off-limits, per email consent law breakdowns.
- Email consent never carries over to SMS — each channel needs its own recorded permission, B2B consent practitioners warn.
- A well-built preference center cut one company's unsubscribe rate by 35%, showing consent discipline improves deliverability, not just compliance, per consent management guidance.
Why Consent Confusion Is Costing You Leads (and Sleep)
You finally get budget approved for outbound follow-up — email sequences, SMS reminders, maybe some database reactivation on the cold contacts sitting in your CRM. Then someone on the team asks, "Wait, are we actually allowed to message these people?" and the whole plan stalls.
That hesitation is costing you leads. Every day a warm inquiry sits untouched, it decays. But moving fast without clear consent is worse — because the penalties for getting it wrong are severe, and the rules are murkier than most teams realize.
Here's the first thing to understand: "informed consent" is not a separate legal category for outbound marketing. None of the major frameworks treat it that way. Instead, the compliance world runs on express consent versus implied consent — and "informed" is a quality standard that valid express consent must meet. Under GDPR, consent must be "freely given, specific, informed, and unambiguous," which is why pre-checked boxes and vague opt-in language fail the test. The person has to know what they're agreeing to, from whom, and on which channel.
The stakes for getting this wrong are not theoretical:
- Canada's CASL carries fines up to $10 million per violation for corporations, and it applies based on where your recipient sits — not where you send from.
- The TCPA allows statutory damages of $500 per violation, trebled to $1,500 for willful violations — multiplied across every call or text in a campaign.
- GDPR fines can reach 4% of revenue, and regulators expect you to keep proof of consent on file.
Still think B2B is a safe harbor? Consider the Compu-Finder case: 317 B2B emails triggered five years of litigation, an original $1.1 million penalty, and an appeal that dragged on until June 2020. Three campaigns. Five years.
And the ground keeps shifting. The FCC's stricter one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 before it ever took effect, while the FCC separately reinstated its prior express written consent standard in August 2025. If your compliance picture depends on which headline you read last, you don't have a compliance picture.
This is exactly why consent discipline belongs inside your follow-up process, not in a legal memo nobody reads. When Worqd builds outreach and lead reactivation programs, the starting point is permission-aware communication — explicit agreement captured at the point of contact, recorded per person and per channel — because fast follow-up only works when it's allowed to happen.
So before you compare "informed" versus "expressed" consent, you need the right frame. Let's fix that.
The Real Distinction: Expressed Consent Is the How, Informed Is the Standard
Here's the insight that untangles this whole debate: expressed consent tells you how someone said yes, while "informed" tells you whether that yes actually counts. They're not two competing types of consent — they work together.
Start with the spectrum. Express consent means someone clearly agrees: filling out a subscription form, checking an opt-in box, or actively selecting "Yes, send me updates." Implied consent means the sender assumes permission — an email handed over via a contact form, a purchase, or a business card exchange. According to email marketing compliance research, a business card is explicitly not consent for marketing email, and relying on implied consent is "no longer safe" under most modern privacy laws.
Now layer "informed" on top. GDPR requires consent to be "freely given, specific, informed, and unambiguous" — pre-ticked boxes don't qualify, and neither does vague language. As consent management guidance puts it, "Subscribe to our weekly email about email deliverability" works; "Stay updated" fails. The FCC's (later vacated) one-to-one consent rule echoed this, requiring consent that was "specific to the brand, informed and opt-in," per the IAPP's analysis.
Consent is also channel-specific — a single "yes" on a contact record doesn't cover everything:
- Email (CAN-SPAM): no prior consent required — it's an opt-out model, with opt-outs honored within 10 business days.
- Texts: express consent required, and express written consent for marketing texts.
- Marketing calls: express written consent under the TCPA's prior express written consent standard.
Per DLA Piper's US electronic marketing guide, these tiers are distinct legal requirements. And as B2B compliance practitioners bluntly note, email consent never carries over to SMS. "It never has."
The US rules are also in active flux. The Fifth Circuit held in February 2026 that oral consent suffices for marketing robocalls, striking down the FCC's written-consent rule — yet the FCC had already reinstated its prior express written consent standard in August 2025. With a three-way circuit split, TCPA attorneys advise most callers to keep capturing full written consent. The stakes justify caution: TCPA damages run $500 per violation, trebled to $1,500 for willful violations, according to ActiveProspect's consent analysis.
The practical takeaway: get express, informed, channel-specific consent every time, in writing, with records. This is how Worqd structures its own booking funnel — every inquiry requires explicit agreement ("I agree to be contacted about my request"), with details used only to prepare for that call. When regulators and courts disagree, the strictest standard is the only safe one.
What Valid Expressed Consent Actually Looks Like in Practice
Knowing the difference between informed and expressed consent only matters if you can put it into practice. The good news: the law translates into a short, concrete checklist — and once you follow it, compliance stops being a guessing game.
For US calls and texts, the strictest benchmark is the TCPA's prior express written consent (PEWC) standard. According to compliance guidance from ActiveProspect, valid PEWC has four mandatory elements:
- Documented in writing or electronic format — a signed agreement, not a verbal "sure."
- Clear and conspicuous disclosure — the person can plainly see what they're authorizing.
- Revocation rights disclosed — they know how to take consent back.
- Obtained before any automated outreach — consent comes first, campaigns second.
Two details trip up even careful teams. Consent cannot be a condition of purchase, and electronic signatures under the E-SIGN Act — checking a box or clicking a button — count as valid written consent, per the same TCPA analysis. Getting this wrong is expensive: statutory damages run $500 per violation, trebled to $1,500 for willful violations.
Language is where most consent flows fail. "Stay updated" or a pre-checked box doesn't cut it — GDPR demands consent that is "freely given, specific, informed, and unambiguous," as PropelGrowth's breakdown of email consent law explains. Compare "Subscribe to our weekly email about email deliverability" with a vague opt-in: the first names the channel, the frequency, and the topic. That's what informed looks like inside expressed consent.
A working example: Worqd's own booking funnel requires visitors to actively check "I agree to be contacted about my request" before a growth call can be scheduled, and states that details are used only to prepare for that conversation. The scope is narrow, the action is affirmative, and the purpose is stated in plain words — a pattern any business can copy onto its own forms today.
Then keep the proof. Best practice per B2B consent management research is recording source, legal basis, timestamp, channel scope, and expiry date for every contact — because in Canada and Australia, the sender bears the burden of proving consent existed. For TCPA contexts, retain documentation up to five years.
Finally, the gold-standard shortcut: apply the strictest standard to everyone. As Mailflow Authority's consent guidance puts it, if you collect express opt-in consent with double confirmation and process unsubscribes immediately, you satisfy GDPR, CASL, CAN-SPAM, and Australia's Spam Act simultaneously. One strict workflow beats four jurisdiction-specific ones — and it builds the kind of trust that makes fast, permission-aware follow-up actually convert.
Build a Consent Practice You Can Prove — Not Just Promise
Collecting consent is only half the job. The half that actually gets companies fined is suppression — failing to honor revocations, expiry dates, and opt-outs after the fact. As one compliance analysis puts it, "Suppression gaps cause more damage than missing consent forms."
The fix starts with records you can prove, not promises you make. Every contact in your CRM should carry a consent record with specific fields, and practitioners recommend capturing at minimum:
- Source — where and how the consent was collected
- Legal basis — express, implied, or legitimate interest
- Timestamp in UTC
- Channel scope — email consent never carries over to SMS
- Expiry date, especially for Canadian implied consent
For email specifically, deliverability experts advise also logging the IP address, form URL, user agent, and the exact consent text shown at signup. Retention matters too: keep email consent records for the relationship duration plus three years, and TCPA documentation for up to five years.
Expiry dates deserve special attention if you email Canadian contacts. Under CASL, implied consent lasts two years after a purchase and only six months after an inquiry — and fines can reach $10 million per violation. A contact who asked about your services seven months ago may already be off-limits.
Revocation is where enforcement bites hardest. US rules effective April 2025 require opt-out instructions in every marketing text and honoring do-not-call requests within ten business days. Under CAN-SPAM, email opt-outs must be processed within the same ten-business-day window, though Gmail, Yahoo, and Microsoft now demand one-click unsubscribe processed within two days for bulk senders.
This discipline pays off beyond avoiding fines. Good consent management is good deliverability — engaged, opted-in lists keep spam complaints under the 0.1% real ceiling that mailbox providers enforce. And giving people granular choices works: a well-built preference center cut one company's unsubscribe rate by 35%, because contacts who can downshift from weekly emails to monthly ones don't leave entirely.
This is exactly why permission-aware follow-up sits at the core of how Worqd runs outreach and lead conversion — consent captured at the first touchpoint, honored across every channel, and recorded so clients never have to guess whether a contact said yes. When your records prove consent and your suppression lists work instantly, compliance stops being a risk and starts being an advantage.
How Permission-Aware Follow-Up Turns Consent Into More Booked Calls
Here's the uncomfortable truth most teams miss: slow, sloppy follow-up and weak consent practices usually come from the same root — treating every lead like a name on a list to blast. Fix the consent layer, and your response speed improves with it, not despite it.
The numbers back this up. Gmail, Yahoo, and Microsoft now require bulk senders to offer one-click unsubscribe and process opt-outs within two days, with spam complaints kept under 0.3% — and 0.1% treated as the real ceiling. As one practitioner puts it, good consent management is good deliverability practice — they're the same thing. A permission-aware follow-up system reaches inboxes; a template blast gets filtered, flagged, or ignored.
This is exactly how Worqd approaches the path from first click to booked call. The booking funnel requires an explicit opt-in — "I agree to be contacted about my request" — before anything else happens, and states plainly that details are used only to prepare for the call. That's express consent done right: specific, informed, and documented before a single message goes out.
From there, speed and compliance reinforce each other. AI SDRs qualify every inquiry in under 60 seconds, 24/7, because the contact just gave you a clear "yes" — you're responding to interest, not manufacturing it. Database reactivation only touches contacts with a real consent basis, since implied consent in Canada expires after just two years after a purchase or six months after an inquiry. And B2B outreach runs on personalized, permission-aware messages under a documented legitimate interest assessment — because under GDPR, no assessment on file means no defense. None of this slows growth; it targets it.
Before your next campaign, run a quick self-audit:
- Check your forms — every opt-in should be unchecked by default, specific about channel and purpose, and never a condition of purchase.
- Check your records — each contact needs source, legal basis, timestamp, channel scope, and expiry date on file.
- Check your suppression lists — opt-outs honored within 10 business days under CAN-SPAM, and remember that suppression gaps cause more damage than missing consent forms.
- Check your channel mapping — email consent never carried over to SMS, so verify each channel separately.
The teams that win aren't choosing between compliance and speed. They're collecting a clean "yes" at the top of the funnel, responding in seconds, and spending their follow-up effort only where permission actually exists. Clean consent and aggressive response speed aren't in tension — they're the same system working properly.
Frequently Asked Questions
Is 'informed consent' a separate legal category I need to worry about for outbound marketing?
What's the real difference between express consent and implied consent in practice?
Does email consent cover me for SMS and calls too?
What does valid express written consent actually require for texts and calls under the TCPA?
I heard a court ruled oral consent is enough for marketing calls — can I stop collecting written consent?
What consent records do I actually need to keep, and for how long?
A Clean 'Yes' Is the Fastest Path to a Booked Call
The informed versus expressed consent debate turns out to be the wrong question. Expressed consent is the how — a clear, active, documented yes — and 'informed' is the standard that makes that yes count. Get it right and you satisfy GDPR, CASL, CAN-SPAM, and the TCPA with one strict workflow: unchecked boxes, specific language, channel-by-channel permission, and records that prove source, timestamp, scope, and expiry. Get it wrong and the bill can run to $10 million per violation under CASL. The real payoff isn't just avoiding fines — opted-in contacts actually respond, which is why Worqd builds every funnel on explicit consent captured at the first touchpoint, then follows up in seconds while the interest is warm. Your next step is simple: audit your forms, your records, and your suppression lists this week. And if you'd rather have one partner handle the whole path from first click to booked call — permission-aware from day one — book a free growth call and see where your follow-up is leaking.
Want help putting this into action?
Book a Growth Call