
What four things are required for consent to be valid?
Key Facts
- Every text sent without valid consent costs $500 — up to $1,500 if willful — with no proof of harm required under TCPA statutory damages.
- One non-compliant campaign to 10,000 contacts creates theoretical exposure of $5 million to $15 million according to TCPA risk analysis.
- TCPA class action filings jumped roughly 95% year-over-year through mid-2025 per recent legal filings data.
- Pre-ticked consent checkboxes are invalid — consumers must actively check an unchecked box for consent to count under the express consent standard.
- Consent records must be retained at least 5 years federally, and some states require up to 10 years per federal retention rules.
- 84% of consumers reported opting in to receive business texts in 2025 according to a recent survey.
- The FCC's one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 before it ever took effect per court ruling coverage.
Why Texting Without Valid Consent Is a $500-Per-Text Mistake
Every text you send without valid consent could cost you up to $1,500 — and the person suing you doesn't have to prove they were harmed at all. That's not a worst-case scenario invented to scare you; it's the statutory damages structure built into the Telephone Consumer Protection Act.
Under the TCPA, statutory damages run $500 per text, climbing to $1,500 for willful violations. No proof of actual harm is required — a consumer who received one unwanted promotional text has standing to claim damages. And plaintiffs' attorneys know it: TCPA class action filings are up roughly 95% year-over-year through mid-2025.
The math scales fast. One non-compliant campaign sent to 10,000 contacts creates theoretical exposure of $5 million to $15 million. For a small business, that's not a fine — it's an extinction-level event.
Why lead-driven businesses are in the danger zone
Home services, dental practices, law firms, and other businesses that buy or generate leads face a specific problem: speed-to-lead texting now happens automatically. The moment a form fill or missed call comes in, software fires off a text. Speed wins jobs — but speed also multiplies exposure when consent wasn't captured correctly at the source.
Several common practices make these businesses especially vulnerable:
- Purchased lead lists — contacts who "agreed to be contacted by partners" don't satisfy TCPA requirements for your specific business
- Assuming a phone number on a form equals consent to text — it doesn't
- Pre-ticked consent boxes, which are invalid because the consumer must actively check an unchecked box
- Reliance on verbal consent, which doesn't satisfy the written standard for marketing texts
There's another layer of risk most owners miss: vendor liability. You can be held responsible for texts sent by third parties or lead generators on your behalf if they didn't collect valid consent, keep records, or honor opt-outs.
This is exactly why consent has to be designed into the response system, not bolted on afterward. A service like CallMyLeads collects explicit consent during the booking flow, keeps appointment reminders free of promotional content so they qualify under the lower informational standard, and honors opt-outs automatically. Fast response and compliance aren't competing goals — but only when consent is treated as a requirement, not an afterthought.
The good news is that valid consent isn't complicated. It comes down to four specific criteria, and every one of them is within your control.
The Four Requirements: Prior, Express, Written, and Clear Authorization
Understanding what makes consent legally valid is critical before sending any marketing text. Under the TCPA, valid consent for promotional messages requires prior express written consent, which breaks down into four specific requirements: prior, express, written, and clear authorization. Each element must be met for consent to hold up under regulatory scrutiny, and missing just one can expose businesses to significant liability.
The first requirement is prior — consent must be obtained before any marketing text is sent. This means businesses cannot assume permission based on a past interaction or purchase; agreement must be secured in advance of the first promotional message. Sending texts before obtaining consent violates the TCPA regardless of intent, and courts consistently treat timing as a non-negotiable factor in validity. For service-based businesses using automated lead response, this means capturing consent at the point of opt-in, not after initial contact.
Second, consent must be express — an affirmative, unambiguous act of agreement. This means the consumer must take a clear action, such as actively checking an unchecked box, to indicate consent. Pre-ticked or pre-populated checkboxes do not qualify, as they fail to demonstrate a deliberate choice. The FCC and courts have repeatedly ruled that silence, inaction, or default settings cannot constitute express consent for marketing texts under federal law.
Third, consent must be written and capable of being recorded as a signed record. Under the E-SIGN Act, this includes electronic formats like a completed web form, a text message reply containing keywords like “YES,” or a telephone keypress sequence. Voice recordings alone are no longer sufficient to meet the “written” standard, as regulatory guidance emphasizes the need for a tangible, auditable trail. Businesses must ensure their opt-in methods produce a record that can be stored and retrieved if challenged.
Finally, consent must include clear authorization — language that explicitly authorizes the specific business to send marketing messages. The agreement must identify the sender by name and disclose that the consumer agrees to receive advertisements or telemarketing calls or texts. Vague references to “partners” or “affiliates” are insufficient, especially given the legal risks associated with broad consent clauses. Each business must be named clearly at the point of opt-in to satisfy the “clear authorization” requirement under 47 CFR § 64.1200(f)(9).
Certain practices commonly mistaken for valid consent do not meet TCPA standards. Verbal consent, while acceptable for informational texts, does not satisfy the written requirement for marketing messages. A phone number collected from a business card or public directory implies no agreement to receive promotional texts. Similarly, purchased lead lists where contacts agreed to be contacted by “partners” do not transfer valid consent to a specific seller. Relying on any of these methods risks non-compliance, with TCPA statutory damages reaching $500 per violation — or $1,500 for willful acts — and no proof of actual harm required by courts. A single non-compliant campaign to 10,000 contacts could therefore result in theoretical exposure of $5 million to $15 million.
For businesses using lead-response automation, distinguishing between transactional and marketing texts is essential. Appointment confirmations, reminders, and service updates may qualify under the lower prior express consent standard if they contain no promotional content. However, any message intended to advertise, sell, or promote goods or services must be preceded by prior express written consent that meets all four criteria. Integrating compliant opt-in language into booking flows and lead capture forms ensures that follow-up messages remain both effective and lawful. By structuring every consent request around prior, express, written, and clear authorization, businesses can protect themselves from costly violations while maintaining trust with their audience. A recent analysis found that 84% of consumers reported opting in to receive business texts in 2025, underscoring the importance of getting consent right from the start. Similarly, industry guidance notes that consent records must be retained for at least five years federally, with some states requiring up to ten, making proper documentation not just a legal necessity but a long-term operational imperative. For companies like CallMyLeads that automate lead response and booking, embedding these consent standards into every touchpoint helps ensure that speed-to-lead never comes at the expense of compliance. Regulatory breakdowns confirm that clear sender identification and specific purpose disclosure are non-negotiable elements of valid consent, reinforcing that transparency isn’t just ethical — it’s legally required. Ultimately, treating consent as a foundational step rather than a formality allows businesses to engage leads quickly, confidently, and within the bounds of the law.
The Disclosure Stack That Makes Consent Hold Up
Getting the opt-in itself right is only half the battle. Even a properly checked box can fall apart in court if the disclosures around it are incomplete — and with TCPA statutory damages running $500 to $1,500 per text, the details matter (PossibleNOW, Complete Guide to TCPA Compliance for Text Messages).
Every opt-in needs a full stack of supporting disclosures. According to compliance guidance from PossibleNOW, a valid consent mechanism must include:
- Clear and conspicuous disclosure of what the consumer is agreeing to
- Identification of the specific sender — your business, not a vague category
- A statement that consent is not a condition of purchase
- Notice that texts are sent using automated technology
- SMS-specific disclosures: message frequency, message and data rates, and STOP/HELP instructions
CTIA messaging rules reinforce the same requirements, covering who is texting, message types, estimated frequency, and opt-out mechanics (Message IQ). Burying any of this in fine print weakens the whole record.
The type of message also determines the consent standard. Informational texts like appointment reminders need only prior express consent, which can be given verbally, via text, or through a web form. Marketing texts require the full prior express written consent standard — and the informational exemption disappears the moment a reminder includes promotional content (Text-Em-All). This distinction matters for appointment-heavy businesses: a reminder saying "Your cleaning is Tuesday at 10am" is fine, but "Your cleaning is Tuesday — ask about our whitening special!" converts it into marketing.
The regulatory landscape shifted recently, too. The FCC adopted a "one-to-one consent" rule in late 2023 requiring separate written consent for each seller, but the Eleventh Circuit vacated it in January 2025 before it took effect (Message IQ). That means a single opt-in can technically cover multiple sellers today — but broad "partners" clauses remain risky, since purchased lead lists where contacts "agreed to be contacted by partners" don't satisfy TCPA requirements for your specific business (Message IQ).
Courts look for a documented consent record, not a perfect send history — but vendor liability is real. Businesses can be held responsible when third-party partners fail to collect valid consent or honor opt-outs (PossibleNOW). That's why services like CallMyLeads build consent collection directly into the booking flow and keep reminder texts strictly transactional, so every message sits on the correct legal footing from the first send.
How to Implement Compliant Consent in Your Lead Response Flow
Implementing compliant consent in your lead response flow starts with capturing the essentials at the moment of opt-in. Every record should include the consumer’s name, phone number, the exact consent language presented, a timestamp, the source or channel of the lead, and verification details like IP address or device ID to support validity under TCPA standards. This documentation must be retained for at least five years, as federal rules require, though some states mandate longer periods and many businesses keep records indefinitely as a safeguard.
Honoring opt-outs is just as critical as obtaining consent. Consumers may revoke permission through any reasonable method — whether replying STOP, sending an email, using a web form, or making a verbal request — and businesses must process these requests within 10 business days. Automating this step ensures no messages slip through after a lead has opted out, reducing risk of costly violations that can reach $500 per text or $1,500 for willful violations under TCPA statutory damages.
Timing and list hygiene also play a key role in compliance. Texts should only be sent between 8 a.m. and 9 p.m. in the recipient’s local time zone to respect quiet-hour rules, and contact lists must be scrubbed against the National Do Not Call Registry at least every 31 days for telemarketing campaigns. These practices, combined with clear disclosure at opt-in — including sender identification, message frequency, data rates, and opt-out instructions — help ensure consent meets the four-part standard: prior, express, written, and clear authorization.
For businesses using automated lead response, CallMyLeads builds these requirements into its booking flow by collecting explicit consent upfront, honoring opt-outs instantly and automatically, and maintaining A2P 10DLC registration to comply with carrier regulations. This approach keeps transactional messages like appointment confirmations free of promotional content so they qualify under the prior-express-consent standard, while marketing messages only go out after valid written consent is secured — protecting both the business and the lead’s experience.
Frequently Asked Questions
What are the four requirements for valid consent under the TCPA for marketing text messages?
Does a pre-ticked checkbox count as valid consent for sending marketing texts?
Can I use verbal consent to send promotional text messages to customers?
If I buy a lead list where people agreed to be contacted by 'partners,' can I text them about my services?
What disclosures must be included when collecting consent for text messaging?
How long do I need to keep records of consumer consent for text messaging?
Consent Done Right Is a Competitive Advantage, Not a Checkbox
Valid consent comes down to four things: it must be prior, express, written, and clearly authorize your specific business to send marketing texts. Miss one element — a pre-ticked box, a verbal yes, a vague "partners" clause — and every text that follows carries up to $500 in statutory damages, or $1,500 for willful violations, with no proof of harm required. With TCPA class actions up roughly 95% year-over-year, according to recent litigation data, the businesses that win are the ones that build consent into their lead response from the first touchpoint. Your next step: audit every opt-in form and lead source against the four criteria, confirm your disclosure stack is complete, and verify opt-outs are honored automatically. If your lead flow moves too fast to manage that manually, CallMyLeads collects explicit consent during booking, keeps reminders strictly transactional, and honors opt-outs instantly — so speed-to-lead never costs you compliance. Ready to respond in seconds without the legal risk? Book a free 15-minute scoping call at callmyleads.app.