
How do you document informed consent?
Key Facts
- TCPA violations carry statutory damages of $500 to $1,500 per violation, with no proof of actual injury required.
- Tiger Natural Gas settled a class action for $3.7 million over recordings of 27,000+ potential customers without consent.
- The FCC's Opt-Out Rule, effective April 11, 2025, requires honoring consent revocation in any reasonable manner.
- Businesses must honor opt-out requests within ten business days, with only one clarification message allowed.
- 38 states plus D.C. follow one-party consent, while 13 states require all-party consent for call recording.
- TCPA opt-out documentation should be retained for at least four years, matching the statute of limitations.
- Healthcare organizations must retain call recordings for a minimum of six years to comply with HIPAA requirements.
Why Consent Documentation Is Your Legal Safety Net
A single undocumented phone call can cost more than an entire campaign earns. That is not a hypothetical risk — it is the arithmetic of the Telephone Consumer Protection Act (TCPA), where violations carry statutory damages of $500 to $1,500 per violation, per class member, with no requirement to prove actual injury. Plaintiffs do not need to show harm. They only need to show the call happened without proper consent — and if you cannot produce records, you cannot defend yourself.
The Tiger Natural Gas case makes the stakes concrete. In 2019, the company settled a class action for $3.7 million after allegedly recording conversations with more than 27,000 potential customers without consent under California's two-party consent law. That settlement was not driven by aggressive sales tactics or misleading scripts — it was driven by a consent documentation failure.
This is why consent records must exist before a campaign launches, not after a claim arrives. Retroactively assembling evidence is nearly impossible, and courts expect businesses to demonstrate that consent was obtained, disclosed, and honored at the time of contact. The FCC's Opt-Out Rule, effective April 11, 2025, raises the bar further: consumers can revoke consent in any reasonable manner, and businesses must honor that revocation within ten business days. Documentation of those requests should be retained for at least four years to align with the TCPA statute of limitations.
A defensible consent record captures several elements:
- Where the contact came from and what permission exists — list source, consent type, and when it was granted
- What was disclosed on the call, including AI disclosure and opt-out handling
- How and when opt-outs were logged and honored, including DNC requests carried across campaigns
- How long records are kept, matched to the applicable statute of limitations
Consent documentation is your evidence — the only thing standing between a routine campaign and a six-figure claim. This is why My AI Call Center reviews list source and consent records before any campaign launches, and plainly tells clients when a list will not support the campaign. Bought lists without clear permission records are flagged, and in most cases declined, because a list you cannot document is a liability, not an asset. The cheapest time to verify consent is before the first call, when the only cost is a review — not $1,500 per contact after the fact.
What Valid Consent Documentation Must Include
A consent record is only as good as what it can prove months or years later — when a dispute arises, "we asked and they said yes" carries no weight without documentation. That's why defensible consent records capture specific components at the moment consent occurs, not reconstructed afterward.
Start with the basics: every record should document the list source, the consent status of each contact, and how and when consent was obtained. This is the same discipline My AI Call Center applies before any campaign launches — list source and consent records are reviewed up front, and lists without clear permission records are flagged or declined. If you cannot trace where a contact came from and what they agreed to, you cannot defend the call.
Jurisdiction matters just as much as the record itself. For call recording, 38 states plus D.C. follow one-party consent, while 13 states require all-party consent — including California, Florida, Illinois, and Pennsylvania. When calls cross state lines, legal experts consistently recommend following the strictest applicable law, because getting this wrong is expensive: the Tiger Natural Gas case settled for $3.7 million over recordings involving more than 27,000 potential customers under California's two-party consent law, according to documented case analysis.
Revocation records deserve equal attention. The FCC's Opt-Out Rule, effective April 11, 2025, requires businesses to honor consent revocation made in any reasonable manner, within ten business days — you can no longer restrict opt-outs to a single keyword. A clarification message is permitted only once, within five minutes of the request, and must contain no marketing content.
Finally, retention timelines make the record defensible:
- TCPA opt-out documentation: retain at least four years, matching the TCPA statute of limitations.
- Healthcare call recordings: retain a minimum of six years to comply with HIPAA.
- Disclosures and scripts: document the exact language used and when it was delivered on every call.
- Audit trails: review recorded calls periodically to verify disclosures were correctly implemented.
The stakes justify the rigor. TCPA violations carry statutory damages of $500 to $1,500 per violation, with no requirement to prove actual injury — so a complete, timestamped record is your best defense.
How My AI Call Center Records and Stores Consent
My AI Call Center records and stores consumer consent documentation through a systematic process designed to meet regulatory requirements while supporting campaign effectiveness. Every campaign begins with a list and consent review where source and permission records are checked before launch, and bought lists without clear consent documentation are flagged or declined. This upfront verification ensures only approved, permissioned, or reviewed lists are used for outbound calling.
AI disclosure is delivered on every call prior to any substantive conversation, informing recipients that the call is AI-assisted and allowing them to request a human or opt out. Keyword opt-outs using STOP or REVOKE are logged immediately upon detection, triggering an automatic halt to further calls to that number. Do Not Call (DNC) requests are similarly captured and carried into client records to prevent future contact across campaigns. Call recording only occurs when disclosure is provided and explicit consent is obtained from the recipient, aligning with jurisdictional requirements.
Each completed campaign produces detailed opt-out and DNC logs alongside dispositioned contact lists that reflect outcomes such as confirmed, qualified, or opted out. For TCPA-related opt-out requests, documentation is retained for at least four years to comply with the statute of limitations, as noted in regulatory guidance. Healthcare clients benefit from extended retention periods of six years for call recordings to meet HIPAA requirements, with configurable data tiers available to balance compliance needs and data minimization principles. This structured approach ensures consent is not only obtained but verifiably documented and honored throughout the customer lifecycle.
Building a Consent Audit Trail You Can Defend
Building a Consent Audit Trail You Can Defend
Creating a defensible audit trail for informed consent starts with establishing clear, written disclosure policies that specify exactly how and when notifications are delivered to recipients. These policies should outline consent requirements by jurisdiction and include standardized scripts to ensure consistency across all outbound calls, reducing the risk of human error during disclosure delivery. As legal experts recommend, documenting the disclosure process and training staff on its execution helps ensure consistent implementation and supports compliance efforts (https://www.vonage.com/resources/articles/call-recording-disclosure/).
To further minimize variability in consent disclosure, My AI Call Center implements automated disclosure systems that deliver pre-recorded messages at the start of every outbound call before any substantive conversation begins. This approach ensures that recipients receive the required notice about AI-assisted calling and their right to opt out, aligning with TCPA requirements and the FCC's Opt-Out Rule effective April 11, 2025. Automated systems reduce reliance on agent memory and help maintain uniform compliance across campaigns (https://www.vonage.com/resources/articles/call-recording-disclosure/).
Regular audits of recorded calls are essential to verify that disclosures are being delivered correctly and consistently. By reviewing a sample of calls periodically, organizations can identify deviations from approved scripts or disclosure timing and address them promptly. This proactive monitoring helps prevent systemic issues and demonstrates due diligence in compliance efforts, which is critical when defending consent documentation in regulatory inquiries or legal proceedings (https://www.vonage.com/resources/articles/call-recording-disclosure/).
Finally, implementing configurable data retention tiers allows businesses to balance compliance needs with data minimization principles. Depending on jurisdictional requirements and use case, organizations can retain AI summaries only, summary plus transcription, or full call recordings. For TCPA-related opt-out requests, documentation should be retained for at least four years to align with the statute of limitations, while healthcare clients may require six-year retention to meet HIPAA standards (https://www.bclplaw.com/en-US/events-insights-news/the-tcpas-new-opt-out-rules-take-effect-on-april-11-2025-what-does-this-mean-for-businesses.html; https://www.withallo.com/blog/call-recording-compliance). This tiered approach supports both legal defensibility and responsible data management.
Frequently Asked Questions
How long do I need to keep records of consent and opt-out requests?
What happens if someone revokes consent in the middle of a call or replies with something other than "STOP"?
Do I need consent from everyone on the call before recording it?
What should a defensible consent record actually include?
How much can poor consent documentation actually cost my business?
Can I just ask for consent verbally and keep it simple, or do I need written records?
Your Consent Records Are Your Campaign’s Armor
Documenting informed consent isn’t just about checking a compliance box—it’s the foundation of every defensible outbound campaign. From capturing list source and consent status at the point of contact to honoring revocations within ten business days under the FCC’s new Opt-Out Rule, each record serves as evidence when regulators or plaintiffs come calling. Retaining TCPA-related opt-out documentation for at least four years and healthcare call recordings for six years isn’t optional; it’s what separates a managed risk from a multimillion-dollar settlement. My AI Call Center builds this protection into every campaign by reviewing list permissions upfront, logging opt-outs in real time, and retaining records aligned with legal timelines—so you can confirm, qualify, and connect without exposing your business to avoidable liability. If your current process relies on memory or after-the-fact reconstruction, it’s time to strengthen your audit trail. Learn how the FCC’s Opt-Out Rule changes consent revocation requirements effective April 11, 2025 and ensure your documentation keeps pace.