Why "We Believe We're Compliant" Isn't a Record
Every compliance question that actually reaches an agency, whether from a prospect's complaint or a closer look at a scaling BD program, comes down to the same demand: show the record. A general belief that a purchased contact list, a scraped directory, or a legacy CRM database was compliant when it was assembled is not a record. It's an assertion, and it's the weakest possible position to be in if that assertion is ever challenged.
Four Different Channels, Four Different Requirements
This compliance cluster covers four distinct rules, and a single blanket consent claim doesn't satisfy all of them at once. TCPA wireless consent, covered in the companion guide, requires prior express written consent for automated calls and texts to wireless numbers, per dnc.com. Internal Do Not Call obligations require honoring a stop request within 30 days, per leadcompliant.com, and apply the moment anyone asks to stop, independent of whether formal consent was ever given in the first place. CAN-SPAM governs cold email specifically, with its own opt-out window and physical-address requirement, per sender.net. And GDPR's legitimate-interest basis, for contacts based in the EU, requires a documented three-part test, not consent in the TCPA sense at all, per salesforceeurope.com. A record built for one of these doesn't automatically cover the others.
What a Record Actually Needs to Specify
For calls and texts: when consent was obtained, for what type of contact, and from what number, retrievable for a specific contact on request. For cold email: confirmation the message included a working opt-out mechanism and a real physical address, and that any opt-out received was honored within 10 business days. For EU-based prospects: a documented Legitimate Interest Assessment showing the purpose, necessity, and balancing test was actually run for that outreach, not just assumed to pass. For any channel: a log of every opt-out or stop request, tagged with date and channel, checked against your suppression list before every new contact attempt.
Why a Transcript Is the Strongest Version of a Consent Record
A verbal claim of consent, or a general note that "this contact opted in at some point," is hard to retrieve and easy to dispute after the fact. A written, timestamped transcript of the actual exchange is neither. It shows exactly what was said, when, to which number, and by whom, without relying on anyone's memory. This is the structural reason VA Horizon runs agency BD outreach over SMS through a Human + AI SDR model on the VA Horizon Private CRM: every conversation is preserved as a transcript, not summarized after the fact, and that transcript functions as the consent record itself, specific to the exact contact in question.
A Practical Multichannel Checklist
- For calls and texts: confirm your consent record specifies contact type, not just that the number was on a list.
- For cold email: confirm your unsubscribe mechanism actually works and your opt-out window is 10 business days, not longer.
- For EU prospects: confirm you have a documented Legitimate Interest Assessment for the specific outreach, not a general belief legitimate interest applies.
- Across every channel: log opt-outs immediately, tagged with date and channel, and suppress future contact everywhere, not just on the channel the request arrived through.
- If you outsource outreach, ask the vendor directly what record they can produce for a specific contact on each channel they use, not what their general compliance policy claims.
| Channel | What Governs It | What the Record Needs to Show |
|---|---|---|
| Calls and texts (wireless) | TCPA | Prior express written consent: when given, for what contact type, from what number. See dnc.com. |
| Any channel, after a stop request | Internal DNC obligation | The opt-out logged and honored within 30 days. See leadcompliant.com. |
| Cold email | CAN-SPAM | Working opt-out mechanism, honored within 10 business days, plus a real physical address on every send. See sender.net. |
| EU-based contacts | GDPR legitimate interest | A documented Legitimate Interest Assessment: purpose, necessity, balancing. See salesforceeurope.com. |
These are four separate requirements, not interchangeable versions of the same rule. A record built for one channel doesn't satisfy the others.
What this means for you
- A defensible consent record is specific and retrievable for a given contact, not a general belief that your outreach process is compliant.
- This cluster covers four distinct requirements, TCPA consent, the internal DNC 30-day window, CAN-SPAM's email rules, and GDPR legitimate interest for EU contacts, and a record for one doesn't automatically cover the others.
- A full, timestamped transcript is a stronger consent record than a verbal claim or a general process description, because it's retrievable and specific to the actual contact.
- VA Horizon's SMS-first Human + AI SDR model preserves a transcript behind every conversation, which functions as the consent record itself.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
- dnc.com, Are B2B Calls Exempt From TCPA Regulations?
- LeadCompliant, Business-to-Business Telemarketing Rules
- sender.net, CAN-SPAM Act Compliance Guide
- salesforceeurope.com, What Is Legitimate Interest for GDPR Cold Email? B2B Rules
