CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Consent Verification Process

What happens if you don't give consent?

Back to InsightsWhat happens if you don't give consent?

What happens if you don't give consent?

Key Facts

The High Cost of Non-Compliance

A $12.75 million penalty can arrive with a single press release — and it can land on companies that believed their data practices were routine. When consent is missing, the cost of non-compliance is no longer theoretical.

General Motors learned this the hard way. The automaker paid $12.75 million in civil penalties after California regulators found it sold the driving data of hundreds of thousands of consumers without their knowledge or consent, according to the California Attorney General's office. The penalty included a five-year ban on selling driving data to consumer reporting agencies and a requirement to delete retained data within 180 days absent express consent.

California Attorney General Rob Bonta made the principle bluntly clear: "General Motors sold the data of California drivers without their knowledge or consent... companies can't just hold on to data and use it later for another purpose." Consent collected for one purpose does not cover another.

The pattern extends well beyond GM. Since 2022, California regulators have issued 14 CCPA enforcement actions totaling at least $25 million in fines. Each violation can cost up to $2,663 — or $7,988 if it was intentional or involved minors under 16. And critically, the removal of the 30-day cure period means businesses now face immediate penalties unless they fix issues proactively.

The contact center industry carries its own share of this weight. According to compliance industry analysis, disclosure and consent failures in financial services contact centers contributed to $3.07 billion in CFPB penalties in 2023 alone. Navient paid $1.85 billion in a multistate settlement tied partly to contact center scripting and disclosure breakdowns.

The numbers tell a consistent story about where regulators are looking:

  • 12 out of 14 CCPA enforcement actions involved "Do Not Sell or Share" opt-out violations
  • Consumers can sue for data breaches caused by inadequate security, with statutory damages of $107–$799 per incident
  • New obligations include annual cybersecurity audits and documented risk assessments

Opt-out failures are the most common trigger for enforcement — a fact that shapes how any outbound calling operation should be built. This is why My AI Call Center checks list source and consent records before any campaign launches, logs and honors opt-outs immediately, and flags bought lists that lack clear permission records. As customer service expert Shep Hyken puts it, "The cost of a bad customer experience is not just the lost customer — it is every customer that person tells." Reputational damage compounds the financial hit.

The lesson from these cases is simple: verifying consent before the first call costs far less than defending the calls after the fact.

My AI Call Center's Compliance Framework

When California regulators hit General Motors with a $12.75 million penalty for selling driving data without consent, the message was unmistakable: consent is not optional. For any organization running outbound calls, the cost of ignoring that message keeps climbing.

The enforcement trend confirms it. Since 2022, regulators have levied at least $25 million in fines across 14 CCPA enforcement actions, and 12 of those 14 involved "Do Not Sell or Share" opt-out failures. That is why My AI Call Center builds its compliance framework around consent verification before a single call connects — not as an afterthought, but as the foundation of every campaign.

List verification comes first. Every campaign runs against an approved, permissioned, or reviewed contact list, never an indiscriminate cold list. The team checks list source and consent records before launch, and bought lists without clear permission records are flagged and, in most cases, declined. As the company puts it plainly: "We tell you if the list will not support the campaign, before you spend anything."

AI-driven consent checks monitor every interaction. Industry research shows that AI compliance tools can monitor 100% of call and text communications, and the same standard applies across every campaign here. Each call opens with an AI disclosure, recipients can ask to speak with a human, and consent status is verified in the conversation itself — not assumed from a static list.

Opt-out mechanisms are transparent and immediate. Given that opt-out failures drive most enforcement actions, the framework treats "no" as final. Keyword opt-outs like STOP and REVOKE are honored instantly, every opt-out is logged, and DNC requests carry into client records across all campaigns. Recording is optional and only happens with disclosure and consent.

Before any campaign launches, the script, disclosure, opt-out handling, and escalation path go through client approval — nothing launches until you approve. The framework also builds audit readiness into every campaign:

  • Named outcome reports with disposition codes, including opted out
  • Opt-out and DNC logs maintained for every campaign
  • Data never shared, sold, or used to train shared models
  • HIPAA-compliant communication standards on clinic campaigns

None of this removes the client's responsibility to seek appropriate legal guidance — requirements vary by location, industry, and consent status. But by verifying lists before launch, monitoring every call, and honoring opt-outs instantly, My AI Call Center gives clients a defensible compliance posture instead of a hope-and-pray approach. The company reports what actually happened, no invented metrics or inflated numbers, so the audit trail reflects reality.

The regulatory landscape for consent in AI-driven call centers is becoming increasingly stringent. Non-compliance can result in hefty penalties and legal repercussions, making it crucial for organizations to implement robust consent verification processes. My AI Call Center, known for its managed outbound calling service, ensures that every campaign runs against approved, permissioned, or reviewed contact lists, never indiscriminate cold calling. This approach mitigates risks and aligns with best practices in compliance.

My AI Call Center's process begins with a thorough pre-campaign list review. This step involves scrutinizing the list source and consent records, ensuring that all contacts have given explicit permission to be called. According to industry experts, 12 out of 14 CCPA enforcement actions involved "Do Not Sell or Share" opt-out violations, underscoring the need for rigorous consent verification. This review ensures that only legitimate contacts are reached, adhering to regulatory standards and maintaining consumer trust.

The company employs AI disclosure protocols that are crucial for transparency and compliance. On every call, recipients are informed that the call is AI-assisted. They are also given the option to request a human representative or opt out entirely. This proactive approach aligns with AI compliance tools that monitor 100% of call and text communications, reducing the risk of non-compliance and associated penalties.

Real-time opt-out handling is another critical component of My AI Call Center's process. Consumers can use keyword opt-outs like STOP and REVOKE, which are immediately logged and honored. This ensures that once a contact opts out, they are not contacted again for any campaign. Additionally, all opt-out requests and DNC (Do Not Call) logs are respected across all campaigns and carried into client DNC records.

To further enhance compliance, My AI Call Center implements several best practices:

  • Prioritize opt-out mechanisms by ensuring clear, accessible, and functional opt-out options in all communications.
  • Conduct regular compliance audits, including annual cybersecurity audits and documented risk assessments.
  • Leverage AI-driven compliance tools to monitor and address compliance issues in real-time.
  • Ensure transparent data handling practices, obtaining explicit consent from consumers before using their data.
  • Monitor regulatory changes and adjust compliance practices accordingly.

By adopting these proactive steps, My AI Call Center not only complies with regulatory requirements but also builds trust with consumers. The focus on list discipline, transparent communications, and real-time opt-out handling sets a standard for ethical and compliant outbound calling practices.

Frequently Asked Questions

What happens if you call someone without their consent?
You can face immediate regulatory penalties — CCPA fines run up to $2,663 per violation, or $7,988 if intentional or involving minors. Since the 30-day cure period was removed, businesses can be hit with fines as soon as a violation is found, and regulators have already levied at least $25 million in fines across 14 CCPA enforcement actions since 2022.
Can I use data collected for one purpose later for another purpose?
No. California Attorney General Rob Bonta made that clear after General Motors paid $12.75 million for selling driving data without consent: 'companies can't just hold on to data and use it later for another purpose.' Consent is purpose-specific, so a list gathered for one campaign can't be reused without fresh permission.
What happens if I ignore an opt-out request?
Opt-out failures are the most common trigger for enforcement — 12 of 14 CCPA enforcement actions involved 'Do Not Sell or Share' opt-out violations. Ignoring a STOP or REVOKE request can expose you to fines and lawsuits, so honoring opt-outs immediately is critical.
Is it ever okay to call a bought list without clear permission records?
No — My AI Call Center flags bought lists that lack clear permission records and declines them in most cases. The risk isn't worth it: disclosure and consent failures in financial services contact centers contributed to $3.07 billion in CFPB penalties in 2023.
How does My AI Call Center verify consent before launching a campaign?
It reviews list source and consent records before launch, verifies consent during the call with an AI disclosure, and honors opt-outs like STOP and REVOKE instantly. The script, disclosure, opt-out handling, and escalation path must be approved before anything launches.
Can consumers sue if their data is used without consent?
Yes — under CCPA, consumers can sue for data breaches caused by inadequate security, with statutory damages of $107–$799 per incident. That's on top of regulatory fines, which is why consent verification and security audits matter.

Consent First, Calls Second — The Order That Protects You

The message from regulators is hard to miss: consent failures now carry million-dollar consequences. GM's $12.75 million penalty, $25 million in CCPA fines since 2022, and $3.07 billion in contact-center-related CFPB penalties in 2023 all point to the same lesson — opt-out and consent failures trigger most enforcement actions. Verifying consent before the first call costs a fraction of defending the calls after the fact. That's why list discipline matters as much as script quality: check list sources, confirm permission records, disclose AI on every call, honor STOP and REVOKE instantly, and keep audit-ready logs of every opt-out. If your current process assumes consent instead of verifying it, that's the gap to close first. My AI Call Center builds this discipline into every campaign — lists are reviewed before launch, and we'll tell you plainly if a list won't support the campaign before you spend anything. Not sure whether your list and consent records would pass review? Book a free campaign review and find out before a regulator does.

Get campaign planning tips