Skip to main content
VA Horizon
Book a Call
Compliance

Consent Documentation for Agency Outreach: What Actually Holds Up

Quick answer

A defensible consent record for agency BD outreach needs to be specific and retrievable, not a general belief that your process is compliant. That means: when consent or opt-in was given, what channel it covers (call, text, or email), which specific contact it applies to, and for EU targets, a documented Legitimate Interest Assessment showing the GDPR three-part test was actually applied.

Each channel in this compliance cluster carries its own requirement, TCPA wireless consent for calls and texts per dnc.com, a 30-day internal DNC honor window per leadcompliant.com, CAN-SPAM's opt-out and physical-address rules for email per sender.net, and GDPR's legitimate-interest test for EU contacts per salesforceeurope.com. One record does not cover all of them.

Why "We Believe We're Compliant" Isn't a Record

Every compliance question that actually reaches an agency, whether from a prospect's complaint or a closer look at a scaling BD program, comes down to the same demand: show the record. A general belief that a purchased contact list, a scraped directory, or a legacy CRM database was compliant when it was assembled is not a record. It's an assertion, and it's the weakest possible position to be in if that assertion is ever challenged.

Four Different Channels, Four Different Requirements

This compliance cluster covers four distinct rules, and a single blanket consent claim doesn't satisfy all of them at once. TCPA wireless consent, covered in the companion guide, requires prior express written consent for automated calls and texts to wireless numbers, per dnc.com. Internal Do Not Call obligations require honoring a stop request within 30 days, per leadcompliant.com, and apply the moment anyone asks to stop, independent of whether formal consent was ever given in the first place. CAN-SPAM governs cold email specifically, with its own opt-out window and physical-address requirement, per sender.net. And GDPR's legitimate-interest basis, for contacts based in the EU, requires a documented three-part test, not consent in the TCPA sense at all, per salesforceeurope.com. A record built for one of these doesn't automatically cover the others.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

What a Record Actually Needs to Specify

For calls and texts: when consent was obtained, for what type of contact, and from what number, retrievable for a specific contact on request. For cold email: confirmation the message included a working opt-out mechanism and a real physical address, and that any opt-out received was honored within 10 business days. For EU-based prospects: a documented Legitimate Interest Assessment showing the purpose, necessity, and balancing test was actually run for that outreach, not just assumed to pass. For any channel: a log of every opt-out or stop request, tagged with date and channel, checked against your suppression list before every new contact attempt.

Why a Transcript Is the Strongest Version of a Consent Record

A verbal claim of consent, or a general note that "this contact opted in at some point," is hard to retrieve and easy to dispute after the fact. A written, timestamped transcript of the actual exchange is neither. It shows exactly what was said, when, to which number, and by whom, without relying on anyone's memory. This is the structural reason VA Horizon runs agency BD outreach over SMS through a Human + AI SDR model on the VA Horizon Private CRM: every conversation is preserved as a transcript, not summarized after the fact, and that transcript functions as the consent record itself, specific to the exact contact in question.

A Practical Multichannel Checklist

  1. For calls and texts: confirm your consent record specifies contact type, not just that the number was on a list.
  2. For cold email: confirm your unsubscribe mechanism actually works and your opt-out window is 10 business days, not longer.
  3. For EU prospects: confirm you have a documented Legitimate Interest Assessment for the specific outreach, not a general belief legitimate interest applies.
  4. Across every channel: log opt-outs immediately, tagged with date and channel, and suppress future contact everywhere, not just on the channel the request arrived through.
  5. If you outsource outreach, ask the vendor directly what record they can produce for a specific contact on each channel they use, not what their general compliance policy claims.
ChannelWhat Governs ItWhat the Record Needs to Show
Calls and texts (wireless)TCPAPrior express written consent: when given, for what contact type, from what number. See dnc.com.
Any channel, after a stop requestInternal DNC obligationThe opt-out logged and honored within 30 days. See leadcompliant.com.
Cold emailCAN-SPAMWorking opt-out mechanism, honored within 10 business days, plus a real physical address on every send. See sender.net.
EU-based contactsGDPR legitimate interestA documented Legitimate Interest Assessment: purpose, necessity, balancing. See salesforceeurope.com.

These are four separate requirements, not interchangeable versions of the same rule. A record built for one channel doesn't satisfy the others.

What this means for you

  • A defensible consent record is specific and retrievable for a given contact, not a general belief that your outreach process is compliant.
  • This cluster covers four distinct requirements, TCPA consent, the internal DNC 30-day window, CAN-SPAM's email rules, and GDPR legitimate interest for EU contacts, and a record for one doesn't automatically cover the others.
  • A full, timestamped transcript is a stronger consent record than a verbal claim or a general process description, because it's retrievable and specific to the actual contact.
  • VA Horizon's SMS-first Human + AI SDR model preserves a transcript behind every conversation, which functions as the consent record itself.

Sources

The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

What does a defensible consent record for agency outreach need to include?
A specific, retrievable record tied to the actual contact: when consent or opt-in happened, what channel it covers, and for EU contacts, a documented Legitimate Interest Assessment. A general belief the outreach was compliant does not hold up the same way.
Does one consent record cover calls, texts, email, and EU outreach at once?
No. Each is governed by a different rule, TCPA for calls and texts, the internal DNC 30-day window for any stop request, CAN-SPAM for email, and GDPR legitimate interest for EU-based contacts. A record built for one channel doesn't satisfy the others.
Why is a transcript a stronger consent record than a verbal claim?
A transcript is retrievable and specific to the exact contact: what was said, when, and to which number. A verbal claim relies on memory and is far easier to dispute after the fact.
How does VA Horizon document consent for agency new-business meetings?
Every conversation runs over SMS between a Human + AI SDR and a prospect on the VA Horizon Private CRM, and the full exchange is preserved as a timestamped transcript, which functions as the consent record itself.

A transcript behind every conversation, not a claim.

Book a 15-minute call and see how VA Horizon's SMS-first Human + AI SDR model documents consent behind every agency new-business meeting, published at $250 to $450 per meeting plus one $300 setup fee.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement