On this page
Consent is not a checkbox, it is a record. The question a court asks is not whether the merchant agreed to something but whether you can show what they saw, when, and that they took a deliberate action on it. Almost every consent problem is a record problem wearing a wording costume.
| Element | Weak version | What holds |
|---|---|---|
| Who may call | "Us and our marketing partners" | The calling company named, or a linked list |
| What may happen | Silent on automation | Calls and texts, including automated technology |
| How it was given | Pre-ticked box, or consent bundled into terms | An unticked box or a submit action tied to visible text |
| What was captured | A flag in a database | Timestamp, IP, page URL, and the disclosure text as shown |
Why the named-party element is the one that matters
A merchant who agreed to hear from "trusted funding partners" has agreed to hear from nobody in particular. When the call comes from a name they have never seen, the consent has to carry the weight of a party the merchant could not have identified — and that is the argument plaintiff-side firms build cases on.
This is also the practical difference between an exclusive lead and an aggregated one. A lead generated on a page that names one buyer can name that buyer in the disclosure. A lead sold to five brokers cannot, which is why aggregated consent language is always vague — the vagueness is structural, not sloppy.
What our own disclosure does
- Sits visibly above the submit button, not behind a terms link.
- Says that calls and texts may be made, including with automated technology.
- Is agreed to by submitting the application, which is an affirmative act.
- Is captured with the timestamp, the IP, the page URL and the disclosure text as it was rendered that day.
The last one is the part vendors skip. Disclosure text changes; the record has to hold the version the merchant actually saw, not the version on the page today. If a vendor cannot produce the historic text, they cannot prove what was agreed.
What consent does not do
It does not survive a revocation you did not record. A merchant who says "stop calling me" has revoked, in any reasonable form, on any channel — and continuing after that is the fact pattern that turns a nuisance into a claim. Suppression has to be immediate and it has to be across every channel, not just the one they said it on.
Questions brokers ask
Does a lead vendor need written consent for me to call?
For calls to a wireless number using automated technology, yes — prior express written consent, with the disclosure visible and agreed by an affirmative act. Manual dialling of a business number sits differently, but the safe operating assumption on a mobile-verified lead is that written consent is what you are relying on, so it has to exist and it has to be producible.
Is "our trusted partners" enough to name the caller?
It is the weakest form of consent in common use. Consent to an unnamed party is consent the merchant could not have evaluated, and it is the specific wording plaintiff firms build cases around. A named buyer, or a linked and dated list of buyers, is what holds.
What consent record should a vendor be able to produce?
Timestamp, IP address, the URL of the page, and the disclosure text exactly as it was rendered to that merchant on that day. Anything less is a database flag asserting consent rather than evidence of it.
How long should consent records be kept?
Longer than the limitation period you could be sued within, which in practice means four years or more. Storage is cheap and the record is the entire defence, so there is no version of this where deleting them early is the right call.
Does a pre-ticked consent box work?
No. Consent has to be an affirmative act. A pre-ticked box, or consent buried inside accepted terms rather than shown at the point of submission, is the version that gets thrown out.
Reference
How each criterion is enforcedIncluding the one-time-code step, which is the record that the number was live and in the merchant’s hand.
