Marketing Communications Toolkit: TCPA, CAN-SPAM, and Consent Records

By ·

Marketing communications carry the largest per-message statutory damages exposure in ordinary commercial practice, and the liability turns almost entirely on records nobody was asked to keep. This toolkit works the TCPA - what counts as an automatic telephone dialing system after Facebook v. Duguid, what prior express written consent requires, and why prerecorded voice and text messages are treated differently from live calls. It covers do-not-call obligations and internal suppression lists, then CAN-SPAM's requirements for commercial email and why they are less demanding but more frequently breached. It sets out the consent capture record that determines every case, revocation handling, vendor flow-down, and the state statutes that impose stricter rules than federal law.

IP and Technology > Privacy Data Security | Toolkit | Published 15 February 2024 - Updated 5 November 2024 | Casey Scott McKay - marksy.us

Summary. Marketing communications carry the largest per-message statutory damages exposure in ordinary commercial practice, and the liability turns almost entirely on records nobody was asked to keep. This toolkit works the TCPA — what counts as an automatic telephone dialing system after Facebook v. Duguid, what prior express written consent requires, and why prerecorded voice and text messages are treated differently from live calls. It covers do-not-call obligations and internal suppression lists, then CAN-SPAM's requirements for commercial email and why they are less demanding but more frequently breached. It sets out the consent capture record that determines every case, revocation handling, vendor flow-down, and the state statutes that impose stricter rules than federal law.

Keywords: TCPA · prior express written consent · automatic telephone dialing system · Facebook v Duguid · prerecorded voice · text message marketing · do not call registry · internal suppression list · Telemarketing Sales Rule · CAN-SPAM requirements · opt-out mechanism · header and subject line accuracy · state mini TCPA statutes · consent capture records · revocation handling · vendor flow down · statutory damages exposure · class action risk · one-to-one consent · wireless numbers


Start Here

A company sends a promotional text campaign to two hundred thousand numbers from its customer database.

Six weeks later it is a defendant in a putative class action. The theory is straightforward: the messages went to wireless numbers, they were sent using equipment the plaintiff says is an automatic dialer, and the company cannot show prior express written consent for the class.

The exposure is statutory damages per message, trebled for wilful violations. Two hundred thousand messages at the statutory minimum is a number that gets a chief executive's attention, and the company's defence depends entirely on a consent record it never built.

That is the shape of nearly every marketing communications case. Not a hard legal question — a records question, asked years after the records could have been created.

This toolkit answers three questions.

  1. What consent is required, for which channel? The standards differ, and text messaging carries the strictest.
  2. What must the record show? Who consented, to what, when, how, and through what interface.
  3. What breaks a programme? Revocation not honoured, vendors not controlled, and lists acquired without provenance.

If you read only one thing, read Permission to Reach Someone. It sets out the exposure arithmetic and the consent standards side by side.


The TCPA

The statute. 47 U.S.C. § 227 restricts calls and texts to wireless numbers made using an automatic telephone dialing system or an artificial or prerecorded voice, and restricts prerecorded calls to residential lines.

The regulations. 47 C.F.R. § 64.1200 implements it, including the definitions of prior express consent and prior express written consent.

The private right of action. Statutory damages per violation, trebled for wilful or knowing violations, with no cap. Aggregated across a campaign, the exposure is what makes this the highest-risk area in ordinary marketing.

What an automatic telephone dialing system is. Facebook v. Duguid holds that the definition requires equipment with the capacity to store or produce telephone numbers using a random or sequential number generator. Equipment that dials from a stored list without such a generator is not an ATDS.

Which narrowed the statute considerably — but did not eliminate the exposure, because the prerecorded and artificial voice provisions apply regardless of the dialing equipment, and because text messages are treated as calls.

Prerecorded voice is the residual exposure. A prerecorded marketing message to a wireless number requires prior express written consent whatever equipment placed it.

Barr v. American Association of Political Consultants severed an exception without invalidating the restriction, confirming the statute's continued operation.

Campbell-Ewald v. Gomez addressed both mootness by unaccepted settlement offer and the limits of derivative immunity for contractors — relevant because vendors send most marketing messages.

Vicarious liability. A seller can be liable for messages sent by a vendor on its behalf under agency principles, which is why vendor control is a compliance requirement and not merely a contractual preference.


Consent Standards

Prior express written consent is required for marketing calls and texts to wireless numbers using an ATDS or a prerecorded or artificial voice.

What it requires. A written agreement, signed by the consumer, that clearly authorises the seller to deliver advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice; that specifies the telephone number to which messages may be delivered; and that includes a clear and conspicuous disclosure informing the consumer that they are authorising such messages and that consent is not a condition of purchase.

Signature includes electronic signature under 15 U.S.C. § 7001, so a web form works — provided the disclosure and the capture meet the standard.

Consent is not a condition of purchase. That disclosure is mandatory and its absence invalidates the consent.

Pre-checked boxes do not work. Consent must be affirmative.

Bundled consent is scrutinised. A single checkbox consenting to terms, privacy policy, and marketing messages is weaker than a separate, specific consent.

One-to-one consent. Consent obtained on a comparison or lead-generation site that purports to cover many unnamed sellers is a recurring enforcement and litigation target; consent identifying the specific seller is materially stronger.

Prior express consent — without "written" — suffices for non-marketing informational messages, and providing a number in connection with a transaction generally constitutes it for messages closely related to that transaction.

Transactional versus marketing. A shipping notification is informational. A shipping notification with a promotional offer appended is marketing, and the whole message is treated as such.

Revocation. A consumer may revoke consent by any reasonable means, and the revocation must be honoured promptly across all channels covered by it. A programme that honours "STOP" but not an email revocation is exposed.

Duration. Consent does not expire by rule, but stale consent — obtained years ago, for a different brand, through an interface nobody can reproduce — is practically unusable.


Do Not Call and Suppression

The national registry. 47 C.F.R. § 64.1200(c) restricts telemarketing calls to registered numbers, and the Telemarketing Sales Rule at 16 C.F.R. § 310.4 imposes parallel obligations.

The established business relationship exemption permits calls for a defined period following a purchase or inquiry, subject to the consumer not having asked to be placed on the internal list.

The internal do-not-call list is mandatory. 47 C.F.R. § 64.1200(d) requires written procedures, training, recording of requests, honouring them within a defined period, and retention.

The internal list is the more common failure. Registry scrubbing is usually automated; internal suppression frequently is not, particularly across brands, systems, and vendors.

Suppression must be enterprise-wide. A request to one brand generally suppresses across affiliated entities where the consumer would reasonably expect it.

Calling time restrictions apply, and they follow the consumer's time zone rather than the caller's.

Identification requirements. Caller identity, the seller's name, and the purpose must be disclosed promptly.

The Telemarketing Sales Rule adds requirements on disclosures, misrepresentations, payment methods, and recordkeeping for telemarketing generally, under the authority of 15 U.S.C. § 6102.

Safe harbour. 47 C.F.R. § 64.1200(c) provides a safe harbour for a call made in error where the caller has established procedures, trained personnel, maintains lists, uses a version of the registry obtained within the required period, and monitors compliance. Building to the safe harbour is the practical objective.


CAN-SPAM

The statute. 15 U.S.C. § 7701 and following govern commercial electronic mail, with the operative requirements at 15 U.S.C. § 7704 and the implementing rule at 16 C.F.R. § 316.1.

It is an opt-out regime. Unlike the TCPA, prior consent is not required to send commercial email. That is why compliance costs less and why breaches are more common — nobody treats email as a consent problem.

The requirements. Accurate header information. A subject line that is not deceptive. Identification of the message as an advertisement, unless the recipient consented. A valid physical postal address. A clear and conspicuous opt-out mechanism. Honouring opt-outs within ten business days. And no sending to an address that has opted out.

No harvesting or dictionary attacks. Address collection by automated means from websites, and automated generation of addresses, are aggravated violations.

No false or misleading transmission information, including relaying through unauthorised systems.

Transactional or relationship messages are exempt from most requirements, but the primary purpose test governs: a message whose primary purpose is commercial is a commercial message regardless of transactional content appended to it.

Enforcement. 15 U.S.C. § 7706 gives enforcement to the regulator, state attorneys general, and internet access services. There is no general private right of action, which is the principal reason CAN-SPAM exposure is smaller than TCPA exposure.

Preemption is partial. State laws are preempted except those prohibiting falsity or deception, which is where state claims survive.

The sender question. Where multiple parties advertise in a single message, the rule provides for designating a single sender, and the designation must be made properly or all of them are senders.

Practical programme. A single suppression list applied across all sending systems and all vendors, opt-out honoured in far less than ten days, accurate headers, real postal address, and the advertisement identification where consent was not obtained.


State Statutes

Several states impose obligations stricter than federal law, and they are where recent litigation has concentrated.

State mini-TCPA statutes. A number of states have enacted their own telephone solicitation statutes with definitions of automated equipment broader than the federal one after Facebook v. Duguid, private rights of action, and their own consent requirements.

Which means the federal narrowing did not narrow the exposure. A campaign compliant with the TCPA may violate a state statute whose ATDS definition reaches ordinary list-based dialers.

Curfews and frequency limits. Some state statutes restrict calling hours more narrowly than federal rules and limit the number of contacts within a period.

Consent disclosure requirements vary, and some states require specific language beyond the federal disclosure.

Recording and monitoring. Two-party consent states require all-party consent to record calls, and the analysis extends to session recording and chat transcription on websites under wiretapping statutes including 18 U.S.C. § 2511 and state analogues.

Which has produced a substantial wave of session-replay litigation, distinct from marketing messaging but arising from the same data practices.

Automatic renewal and negative option statutes apply where messaging promotes subscriptions.

Comprehensive privacy statutes add rights to opt out of targeted advertising and sale or sharing of personal data, which interacts with marketing preferences. See State Privacy Compliance Toolkit.

Practical approach. Build to the strictest applicable standard rather than maintaining state-by-state variants, unless the volume justifies segmentation. The operational cost of variant handling usually exceeds the benefit.


The Consent Record

The single artefact that decides these cases, and the one most companies do not have.

What it must capture, per consent event. The identifier consented — the specific phone number or email address. The channel and message types consented to. The exact disclosure text presented, verbatim. The interface version identifier. The timestamp. The source — which form, which campaign, which page. The method of assent — checkbox ticked, button clicked, keyword texted. The IP address or device identifier where available. And any subsequent revocation with its timestamp and channel.

The disclosure text is the element most often missing. Companies retain "consented: yes" and cannot show what the consumer was told. Under 47 C.F.R. § 64.1200 the content of the disclosure is what makes the consent valid, so its absence is fatal.

Version the interface. Screenshots of each consent flow version, with dates, so that a consent from three years ago can be tied to the flow that produced it. This mirrors the online contract formation problem exactly. See Online Terms and Consumer Contracts Toolkit.

Retention. Longer than the limitations period for the claims, which for statutory claims across multiple jurisdictions means years beyond what a marketing system typically retains.

Portability across systems. Consent captured in one system and used by another must travel with its record. Most failures occur at this boundary — a consent obtained on a website, exported to a messaging platform, arriving as a phone number with no provenance.

Purchased and appended lists. A list acquired from a third party carries no usable consent record. Treat acquired lists as unconsented unless the seller can produce per-record consent evidence meeting the standard, which almost none can.

Lead generation. Consent obtained on a comparison site listing many sellers is the weakest common form, and one-to-one consent identifying the specific seller is materially stronger.

Audit it. Quarterly, pull a random sample of numbers from the active marketing list and attempt to produce the full consent record for each. The percentage that succeed is the programme's real compliance rate, and it is usually a surprise.


Revocation and Suppression

The rule. Consent may be revoked by any reasonable means, and the revocation must be honoured.

Any reasonable means. "STOP" by text, a reply to an email, a call to customer service, a request in a chat session, a form submission, or an in-person statement to an employee. A programme that recognises only one channel is exposed.

Speed. Promptly for the TCPA, and within ten business days for email under 15 U.S.C. § 7704. Build to the shorter.

Scope. A revocation of marketing consent covers marketing across the channels it reasonably reaches. A consumer who says "stop texting me" has not necessarily revoked email consent, and one who says "stop contacting me" has revoked everything.

Enterprise-wide. Across brands, business units, systems, and vendors, where the consumer would reasonably expect it.

One suppression list. A single authoritative source consulted by every sending system before every send, including vendor systems. Multiple lists produce the classic failure where suppression in one system does not reach another.

Do not re-add. A suppressed identifier re-entering through a new list acquisition or a re-import is the most common cause of post-revocation messages, and the suppression check must run at import as well as at send.

Record it. Revocation timestamp, channel, wording, and the systems to which it propagated.

Test it. Periodically send a revocation through each available channel and verify that messaging stops everywhere within the target period.

Customer service is the weak point. Verbal revocations to a representative frequently die in a call note. Train for it and instrument the capture.


Vendors

Most marketing messages are sent by someone other than the brand, and the brand is liable for them.

Vicarious liability. Agency principles reach the seller for messages sent on its behalf, and Campbell-Ewald v. Gomez confirms that a contractor's derivative immunity is limited.

Which means vendor selection is a compliance decision. A vendor with poor consent hygiene transfers its exposure to the brand.

Contract terms. Representations that all contacts have valid consent meeting the applicable standard. An obligation to provide consent records on request within a short period. Compliance with the brand's suppression list before every send. A prohibition on list appending or acquisition without approval. Audit rights. Indemnity, uncapped or with a high sub-limit, because the exposure is per message. Insurance requirements. Immediate suspension rights. And record retention obligations surviving termination.

Do not accept "we are compliant." Require the record format and test it. A vendor that cannot produce a consent record for a sampled number is not compliant regardless of its representations.

Suppression flow. The brand's suppression list must reach the vendor before every campaign, and revocations captured by the vendor must return to the brand.

Lead generators. The highest-risk category. Consent obtained on a third-party site, purportedly covering the brand, with a disclosure the brand has never seen. Require the specific disclosure text, the flow screenshot, and per-lead records — and be prepared to reject leads that lack them.

Affiliates and partners. Messaging sent by an affiliate promoting the brand can create liability for the brand. Contract for it and monitor it.

Platform intermediaries. Messaging platforms have their own terms and their own compliance requirements, and violating them results in account termination independently of any legal claim.

Offboarding. On termination, the vendor's copy of the contact list and the consent records must be dealt with — returned, retained under obligation, or destroyed — and the treatment recorded.


Litigation Defence

The complaint. A putative class action, usually filed after a single campaign, with a named plaintiff whose number appears on the list.

First step: pull the consent record for the named plaintiff. If it is complete — identifier, disclosure text, interface version, timestamp, source, method — the individual claim is defensible and class certification is harder.

If it is not complete, the case is about damages exposure and settlement value rather than about liability.

Standing. TransUnion v. Ramirez requires a concrete injury for statutory claims, and the analysis for unwanted messages varies by circuit and by the nature of the intrusion alleged.

Class certification. The strongest defence is individualised issues on consent — where consent was obtained through many different flows over many years, common questions may not predominate. That defence depends on having heterogeneous but documented consent, which is an odd but real advantage of a well-recorded programme.

The ATDS defence. After Facebook v. Duguid, equipment that dials from a stored list without a random or sequential number generator is not an ATDS. Establish what the sending system actually does, technically, with a declaration from someone who knows.

But check the message type. Prerecorded or artificial voice messages are restricted regardless of the equipment, and the Duguid defence does not reach them.

And check the state statutes, whose definitions may be broader than the federal one.

Revocation defences. Where the plaintiff revoked and messages continued, the case is about the suppression architecture, and the technical explanation of why a suppression failed is the whole defence.

Settlement dynamics. Per-message statutory damages across a large class produce settlement values driven by class size rather than by merits, which is why the consent record's completeness matters more than any legal argument.


Building the Programme

A channel matrix. For each channel — voice, text, email, push, direct mail — the applicable rules, the consent standard, the disclosure required, the opt-out mechanism, and the suppression scope. One page, and it governs everything.

A consent capture standard. The disclosure text, the interface placement, the assent mechanic, and the record fields. Applied to every form, every landing page, and every vendor flow.

A single suppression source of truth, consulted at send and at import, across every system and every vendor.

A revocation intake. Every channel a consumer might use, routed to the suppression list, with a target that beats the shortest applicable deadline.

A vendor programme. Selection criteria, contract terms, record format requirements, suppression flow, and periodic testing.

A list acquisition policy. No purchased or appended lists without per-record consent evidence meeting the standard, which in practice means almost none.

A campaign gate. Before every send: consent basis confirmed, suppression applied, disclosure and identification present, sending window checked, and sign-off recorded.

A quarterly audit. Sample identifiers from the active list, produce the full consent record for each, and report the success rate. That number is the programme.

A revocation test. Send a revocation through each channel and verify propagation.

Training. Marketing on the consent standard, customer service on revocation capture, and procurement on vendor requirements.

An incident process. When a send goes to suppressed identifiers or unconsented numbers, stop, quantify, preserve, and assess — because the exposure is per message and every hour of continued sending compounds it.


Worked Example: Rebuilding a Programme

A retailer with four million email addresses, nine hundred thousand mobile numbers, three sending systems, and two agencies.

The audit. A sample of two hundred mobile numbers is drawn. Full consent records — identifier, disclosure text, interface version, timestamp, source, method — exist for thirty-one. For the rest, the record is a flag in a database with no provenance.

Which is the finding that reframes the project. The company believed it had nine hundred thousand consented numbers; it can prove roughly fifteen per cent.

The remediation. New consent capture instrumented across every form, capturing the full record set. A re-permission campaign to the unproven numbers, using a compliant disclosure, with those who do not respond moved to an email-only programme.

The suppression rebuild. Three lists consolidated into one authoritative source, consulted by every system at send and at import. A revocation intake covering text keywords, email replies, web form, call centre, and chat, all routing to the same list.

The vendor work. Both agencies required to consult the suppression list before every send, to return revocations, and to produce consent records on request within two business days. One agency cannot meet the record requirement and is replaced.

The list policy. Two appended list purchases discontinued.

The state analysis. Mini-TCPA statutes in three states where the retailer has significant customer bases have broader equipment definitions than the federal standard after Facebook v. Duguid. The programme is built to the strictest standard rather than segmented.

The email programme. Reviewed against 15 U.S.C. § 7704. Postal address corrected, opt-out honoured within twenty-four hours rather than ten days, and advertisement identification added where consent was not obtained.

Eighteen months later. A demand letter arrives on behalf of a putative class. The consent record for the named plaintiff is complete, including the disclosure text and the flow screenshot from the date of capture. The matter resolves individually.

The cost. A quarter of engineering and analyst time, one agency change, and a re-permission campaign that reduced the mobile list by two thirds — which the marketing team resisted and which was the point.


Common Mistakes

Consent recorded as a flag. "Opted in: true" with no disclosure text, no timestamp, and no source proves nothing.

No interface versioning. The company cannot show what a consumer saw when they consented three years ago.

Bundled consent. A single checkbox covering terms, privacy, and marketing is weaker than separate consents and is challenged routinely.

Pre-checked boxes. Not affirmative consent, in any channel.

Missing the "consent is not a condition of purchase" disclosure, which 47 C.F.R. § 64.1200 requires and whose absence invalidates the consent.

Multiple suppression lists. A revocation honoured in one system and not another is the most common cause of post-revocation messages.

Suppression checked at send but not at import, so a re-imported list resurrects suppressed identifiers.

Verbal revocations lost in call notes.

Purchased and appended lists treated as consented.

Lead generation consent covering unnamed sellers, which is the weakest common form and an active enforcement target.

Assuming Facebook v. Duguid ended the exposure. Prerecorded voice provisions apply regardless of equipment, and state statutes have broader definitions.

Marketing content appended to transactional messages, which converts the whole message to marketing.

Vendor representations accepted without testing. A vendor that cannot produce a record for a sampled number is not compliant.

Retention shorter than the limitations period, so the consent record is deleted before the claim arrives.

No campaign gate, so a send goes out without anyone confirming the consent basis or applying suppression.

Recording calls and sessions without all-party consent in two-party states, which is a separate and substantial exposure under 18 U.S.C. § 2511 and state analogues.


Diligence Questions

How many contactable identifiers are there, by channel?

For a random sample of twenty, can the full consent record be produced? Identifier, disclosure text, interface version, timestamp, source, method. This single test tells more than any policy review.

Are there interface version screenshots tied to consent dates?

Is there a single authoritative suppression list? Which systems consult it, at send and at import?

How are revocations captured, across which channels, and how quickly do they propagate?

Have any lists been purchased or appended? With what consent evidence?

Which vendors send on the company's behalf? What do their contracts require, and have their records been tested?

Is lead generation used? Whose disclosure, and is it one-to-one?

Which state statutes apply given the customer footprint, and has the programme been built to the strictest?

Are calls or web sessions recorded? With what consent, in which states?

Any TCPA or state statutory claims, demands, or class actions in the last five years, and how were they resolved?

What is the retention period for consent records, and does it exceed the limitations periods?


Questions Clients Ask

Can we text our existing customers? For marketing, you need prior express written consent meeting the 47 C.F.R. § 64.1200 standard — a signed agreement identifying the number, authorising automated marketing messages, and disclosing that consent is not a condition of purchase. Having a customer relationship is not consent.

They gave us their number at checkout. Is that consent? For transactional messages closely related to that purchase, generally yes. For marketing, no.

Doesn't Facebook v. Duguid mean we are fine? It narrowed the ATDS definition. It did not touch the prerecorded voice provisions, and several state statutes define automated equipment more broadly.

How long does consent last? There is no expiry by rule. Practically, consent you cannot document is unusable, and consent obtained years ago through an interface you cannot reproduce is effectively unproven.

Can we buy a list? You can buy the data. You cannot buy usable consent, because the record has to show what that consumer was told and when.

What about lead generation? Consent obtained on a third-party site covering many unnamed sellers is the weakest common structure. Insist on one-to-one consent naming your company, with the disclosure text and the flow screenshot.

Someone replied "stop" to an email. Does that count? Revocation may be by any reasonable means. Yes, it counts, and it must reach the suppression list.

Do we need consent for email? No. 15 U.S.C. § 7704 is an opt-out regime — but the accuracy, identification, address, and opt-out requirements still apply, and state deception claims survive preemption.

Can we append marketing to a shipping notice? If the primary purpose becomes commercial, the whole message is commercial and the requirements apply.

Our agency sends the messages. Are we liable? Generally yes, under agency principles, and Campbell-Ewald v. Gomez limits contractor immunity.

Can we record our calls? In two-party consent states, only with all-party consent. The same analysis extends to website session recording under 18 U.S.C. § 2511 and state wiretapping statutes.

What is the single most valuable thing we can do? Instrument the consent record — disclosure text, interface version, timestamp, source, method — at capture. Everything else in this toolkit depends on it.


The One-Page Position

Marketing communications position — [company], [date]. Contactable identifiers: email [N], mobile [N], voice [N]. Consent records complete on a sampled basis: [N] per cent of mobile, [N] per cent of email; sample of [N] drawn [date]. Consent capture instrumented since [date]; fields captured [list]; interface versions archived from [date]. Suppression: [single / multiple] lists; consulted at send [yes/no] and at import [yes/no]; revocation channels supported [list]; median propagation [N] hours against a target of [N]. Revocation test last run [date], result [pass/fail by channel]. Vendors sending on the company's behalf: [N]; contracts with record and suppression obligations [N]; records tested [date], [N] passed. Lead generation: [used / not]; one-to-one consent [yes/no]. Acquired lists: [N] in the period, [discontinued]. State analysis: mini-TCPA statutes assessed for [states]; programme built to [strictest / segmented]. Email programme reviewed against 15 U.S.C. § 7704 on [date]; opt-out honoured within [N] hours. Call and session recording: [consent basis], states assessed [date]. Claims in the period: [N], resolved [summary]. Recommended actions: [instrument the disclosure text field / consolidate suppression / re-permission the unproven mobile list / replace vendor X / discontinue appended lists].


Working With Other Advisers

Marketing operations, who own the sending systems and the lists. This is the function that has to change, and the change is technical rather than legal.

Engineering, who instrument the consent capture and the suppression checks. Both are small changes with disproportionate value.

Data and analytics, who can run the sample audit that produces the programme's real compliance rate.

Procurement, for vendor contract terms and for the record-testing requirement that turns representations into verifiable obligations.

Customer service leadership, whose representatives receive verbal revocations that currently die in call notes.

Privacy counsel, because the same data is subject to consumer rights and processor obligations under the comprehensive privacy statutes, and the preference infrastructure should serve both. See Standing Up a Multi-State Privacy Compliance Program.

Litigation counsel, engaged at the demand letter stage rather than at the class certification stage, because the first act is producing the named plaintiff's consent record.

Insurance brokers, because statutory damages exposure of this kind is frequently excluded or sub-limited, and knowing the position before a claim is worth doing.


Cadence

At every new consent form or flow. Disclosure text reviewed, record fields confirmed, interface version archived.

Before every campaign. Consent basis confirmed for the segment, suppression applied, disclosure and identification present, sending window checked, sign-off recorded.

Weekly. Revocation queue reviewed for propagation failures.

Monthly. Vendor suppression synchronisation verified.

Quarterly. Sample audit producing the consent record success rate; revocation test across every channel; vendor record test.

Annually. State statute review against the customer footprint; retention period check against limitations periods; channel matrix refresh; training for marketing, service, and procurement.

On any list acquisition proposal. Consent evidence demanded per record, and the proposal declined if it cannot be produced.

On any incident. Sending stopped, exposure quantified per message, records preserved, and the root cause traced to the control that failed.


A Closing Note

This is the area where the gap between what a company believes and what it can prove is widest.

Marketing teams describe their lists as opted in. The database says so. And when a demand letter arrives and someone asks for the disclosure text that a particular consumer saw on a particular date, the answer is that nobody kept it — because nobody was ever asked to.

The fix is not legal work. It is four fields captured at the moment of consent, one suppression list consulted everywhere, a revocation intake that covers every channel a consumer might actually use, and a quarterly sample that tells the truth about how the programme is performing.

Companies that do those things settle individual claims. Companies that do not settle classes.


What This Costs

Consent record instrumentation. A few days of engineering to add the disclosure text, interface version, source, and method fields to the capture event. The single highest-return item in this toolkit.

Interface archiving. An automated screenshot on deploy, stored with the version identifier. An hour of build pipeline work.

Suppression consolidation. A project rather than a task where multiple systems exist, and unavoidable — the alternative is a structural failure that recurs.

Revocation intake. Routing from every channel to the suppression list, plus training for customer service. Modest.

The quarterly audit. An analyst day, and the number it produces is what makes the case for everything else.

Vendor changes. Contract amendments, record testing, and occasionally a vendor replacement.

The re-permission campaign. Real revenue impact, because the list shrinks. This is the cost the business feels and the one that has to be argued for on exposure grounds.

Against all of that: statutory damages per message. A single campaign to a few hundred thousand unproven identifiers produces a theoretical exposure larger than most marketing budgets, and settlement values in this area are driven by class size rather than by the merits.

That arithmetic is the whole argument, and it is worth putting in front of the business in exactly those terms — messages sent, multiplied by the statutory minimum, against the cost of four fields and one list.


And one framing that lands with finance when nothing else does: an unprovable consent record is not an asset with a compliance question attached. It is a contingent liability sitting in a marketing database, sized by the number of rows in it.


Sized that way, the remediation budget approves itself, and the marketing team's objection to a smaller list stops being a debate about growth and becomes a debate about which rows the company can actually stand behind.


A Suggested Reading Path

For the channel rules:

  1. Permission to Reach Someone
  2. Building a Marketing Communications Compliance Program
  3. Outbound Marketing Compliance Checklist

For the privacy overlay:

  1. The State Privacy Wave
  2. State Privacy Compliance Toolkit
  3. Marketing Privacy Compliance Checklist

For the advertising content:

  1. Promotions and Advertising Compliance Toolkit
  2. Endorsements, Influencers, and the Law of Paid Praise

Primary Authorities

| Authority | Proposition | |---|---| | 47 U.S.C. § 227 | TCPA restrictions and private right of action | | 47 C.F.R. § 64.1200 | Implementing rules; consent definitions; internal lists | | 15 U.S.C. § 7701 | CAN-SPAM findings and policy | | 15 U.S.C. § 7704 | Commercial email requirements | | 15 U.S.C. § 7706 | Enforcement; no general private right | | 16 C.F.R. § 316.1 | CAN-SPAM rule definitions | | 16 C.F.R. § 310.4 | Abusive telemarketing practices | | 15 U.S.C. § 6102 | Telemarketing rulemaking authority | | 15 U.S.C. § 7001 | Electronic signatures | | 15 U.S.C. § 45 | Unfair or deceptive practices | | 18 U.S.C. § 2511 | Interception; session recording exposure | | Facebook v. Duguid | ATDS definition | | Barr v. American Association of Political Consultants | Severance of the exception | | Campbell-Ewald v. Gomez | Mootness; contractor immunity limits | | ACA International v. FCC | Set aside of prior ATDS guidance | | TransUnion v. Ramirez | Concrete injury for statutory claims |


Forms and Templates

The consent capture record is the operative artefact in this practice, and it is a data structure rather than a document — which is why so few companies have one. The Portfolio Inventory Template adapts well to it: one row per consent event, with the identifier, the channel, the exact disclosure text presented, the interface version, the timestamp, the source, the scope of consent, and any revocation. That table is the entire defence in a marketing class action, and it has to be built at capture time because it cannot be reconstructed. The License Agreement Template supplies the vendor architecture — scope, audit rights, indemnity, and termination — that the flow-down obligations require, because Campbell-Ewald v. Gomez confirms that a vendor's immunity is limited and agency principles reach the seller. The Cease and Desist Template is relevant in the other direction, where a company's brand is being used in messaging it did not authorise.


Related Toolkits and Checklists

The State Privacy Compliance Toolkit covers the consumer rights and processor obligations that apply to the same marketing data, and the two programmes should be built together because they share the consent and preference infrastructure. The Outbound Marketing Compliance Checklist runs the channel rules and evidence steps in order. The Promotions and Advertising Compliance Toolkit covers what the messages may say, as distinct from whether they may be sent. And the Cybersecurity Governance and Disclosure Toolkit covers the vendor risk framework that the messaging vendor relationship sits inside.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Marketing communications outcomes turn on the channel, the consent record, and the jurisdictions. Marksy is not a law firm.

Read this article on Marksy