This is not legal advice. It is an operational description of what a usable consent record contains and how to evaluate one, written by people who generate leads for a living. Rules change, they vary by state and by channel, and your obligations depend on facts we do not know. Talk to your own counsel about what applies to your business.

Most agencies inspect a lead vendor on price, volume, and quality. Very few inspect the consent trail, which is unfortunate, because it is the only part of the transaction that cannot be fixed later. Price can be renegotiated. Quality can be tuned with filters. A consent record either exists, in a specific form, captured at a specific instant, or it does not, and no amount of goodwill afterward creates one.

Why it cannot be reconstructed afterward

Consent is an event. A person was shown a specific piece of language on a specific page at a specific moment and took a specific action. Everything about that is perishable. The page gets redesigned. The disclosure wording gets edited by a marketer improving conversion. The form moves to a new domain. The vendor upstream changes.

If nobody captured the state of that moment as it happened, then a year later the best anyone can produce is a description of what the form probably said, plus an assertion that the prospect probably agreed to it. That is a story, not a record, and the difference becomes extremely obvious at the exact moment you need it not to be.

This is also why the question is worth asking before you buy rather than after a complaint. Afterward, you are asking a vendor to produce something they either built the infrastructure to capture or did not. There is no middle answer, and finding out at that point is finding out too late.

What a defensible consent record contains

A record worth having answers six questions about one moment. Any one of them missing weakens the whole thing.

  • Exactly what was shown. The full disclosure text the prospect actually saw, stored verbatim and versioned, not a template and not a description. If the language changed in March, the record from February should reflect February.
  • Who was named. Whether the disclosure named the party who would be calling, and how. This is the part most often handled loosely, and it is the part that matters most to a buyer who was not the entity named.
  • When. A precise timestamp of the agreement itself, not the time the record was exported or delivered.
  • Where from. The IP address the submission came from, and the full URL of the page, including the variant if the page was being tested.
  • What action was taken. What the prospect did to agree: a checkbox, a button with the disclosure above it, or something else. An affirmative action is a different thing from a pre-checked box.
  • Enough context to be credible. The user agent, and ideally how long the prospect spent on the form. A submission completed in under a second is worth knowing about, and only the capture side can tell you.

Two structural properties matter as much as the fields. The record should be stored per lead rather than per campaign, so producing it means retrieving one object rather than reasoning about which template was live that week. And it should be retrievable by lead id on request, quickly, without a project.

The single best diagnostic. Pick one lead you already bought, at random, and ask the vendor for its consent record. Not their policy, not a sample, that specific lead. How long it takes and what comes back tells you more than any questionnaire. A vendor who returns the stored record in a day is operating differently from one who sends you a PDF about their compliance commitment.

The questions to ask a vendor

Ask these before the first invoice. The answers are more informative than anything on a rate card.

Do you generate this demand yourself, or do you buy it? Everything else follows from this. A vendor who owns the acquisition can produce the consent record because they built the form. A vendor who buys records is dependent on whoever is upstream, and that dependency can run several layers deep. Ask how many layers there are between the form and you.

Show me the disclosure language, as shown. Read it yourself rather than accepting a summary. Look at who is named, how the calling party is identified, and whether a prospect would plausibly understand what they were agreeing to. If the answer is a screenshot of a design mockup rather than the stored text, that is an answer too.

How is the language versioned? Pages get edited. A vendor who cannot tell you which version of the disclosure a given lead saw is telling you the record is not really per lead.

Is consent captured at acquisition or added later? There is only one right answer, and the wrong one is rarely stated out loud. Ask what the capture actually stores, in field names.

What happens when a prospect asks not to be contacted? Covered below, and worth asking as a separate question because the answer is frequently vague.

Can I have this in the agreement? Retrieval on request, a response time, and the resale policy. A vendor whose compliance posture is real will write it down. A vendor whose posture is a marketing claim will explain why writing it down is unnecessary.

How suppression and opt-out should work

Consent and suppression are two halves of the same system, and buyers usually inspect only the first half. Suppression is what happens after someone says no, and it is where sloppy operations produce the complaints that cost real money.

Applied before delivery

A suppressed number should never reach a buyer at all. Checking at delivery time rather than at capture time is the difference between a policy and a control.

Moves in both directions

An opt-out given to your agent has to reach the vendor, and one given to the vendor has to reach you. A one-way list is half a system.

Outlives the record

Suppression must survive the deletion of the lead it came from. Deleting a record and forgetting that the person opted out is how a company contacts someone twice.

Ask how a request is honored across programs rather than only within the one it arrived in. A prospect who opts out of a final expense program has not agreed to hear from a Medicare program next month, and a vendor whose suppression is per campaign will do exactly that. Ask how fast it takes effect, in hours rather than in adjectives. And ask what channel coverage it has, because an opt-out from a text message and an opt-out from a phone call are frequently handled by two different systems that do not talk to each other.

What to keep on your own side

The vendor record is not a substitute for your own. You are the one making the calls, so keep a parallel trail that is yours.

  • Store the consent block you received. The single most common mistake a buyer makes with a lead payload is saving the contact fields and discarding the consent fields because nothing in the CRM had a place for them. Make a place.
  • Store the lead id. It is how you ask for the underlying record later. Without it, a request becomes a search by phone number across an unknown period.
  • Log every attempt. Time, channel, outcome, and agent. Your own dial log is the record of what you did, which is a separate question from what the prospect agreed to.
  • Run your own suppression list. Internal, honored across every campaign and every source, updated the moment an agent hears a request rather than at the end of a shift.
  • Decide a retention window. Keeping everything forever is a decision, not a default, and it is worth making deliberately in both directions: long enough to answer a question, short enough that you are not holding personal data nobody needs.
  • Train the moment, not the policy. Agents need one clear instruction about what to do when somebody says stop calling, and it should not involve a form they fill in later.

Why owned acquisition changes this conversation

Everything above is harder when the seller did not generate the demand. Not because resellers are careless, but because they are answering questions about a form they did not build, on a page they do not control, using language they did not write. The chain of custody is real and it degrades with each link.

Solved Marketing runs its own campaigns, its own creative, and its own landing pages, which means the consent trail is ours to produce rather than ours to request from somebody else. Every lead carries the disclosure identifier, the disclosure text, the timestamp, the IP address, the page URL, the user agent, and how long the prospect spent on the form, and the stored record for any lead id is available on request. Internal suppression and opt-out state is applied before a lead is ever delivered, not after.

We would rather you did not take that on faith. Ask us for the consent record on a specific lead and compare the turnaround against whoever else you buy from. The compliance page describes what is captured and how, and the consent fields are documented field by field so you can see exactly what arrives before you receive anything at all.

And then talk to your own counsel. Everything here describes how to evaluate a record and how to keep one. What the law requires of your business, in your states, for your channels, is a question for a lawyer who knows your facts.