Signature Framework · Flagship Model

The Consent Ledger

The one artifact most lifecycle programs are missing — and the reason a program survives the audit instead of guessing the rule.

Here is the artifact most lifecycle programs are missing: one register, one row per consent relationship per channel, that answers a single question for any contact you message. On what basis are we texting or emailing this person, and can we prove it?

I call it the Consent Ledger. Five columns: the touch and channel, the consent basis, the timestamp and source of consent, the opt-out state, and an audit reference that points to the stored proof. Maintain it across SMS and email and your program can survive a compliance audit, because for every message you send you can name the legal basis, produce the record, and show that any opt-out was honored. That is the whole claim. What follows is how each column maps to the law it answers to.

The framework is mine. The legal facts under it are not, so I have cited each one to its primary source and kept my own judgment marked as opinion, separate from the statute.

The failure is evidentiary, not intentional

Most teams do not get sued because they never asked for consent. They get a demand letter, a carrier suspension, or an audit request, and then they cannot prove what consent they had, for which number or address, captured when and how. The consent usually existed. The record of it did not. Teams treat consent as a checkbox at signup instead of a record to be maintained, mapped, and produced on demand, and the gap does not show until someone asks to see the file.

SMS and email make the gap worse because they are almost never governed by the same team. Different tools, different capture forms, different opt-out plumbing, and two separate legal regimes sitting underneath. A single ledger across both channels is the artifact that is missing from most stacks, and it is missing precisely because no one owns the seam between them.

What the law actually requires

Four regimes govern lifecycle messaging in the United States and, for anyone serving EU readers, a fifth. The Consent Ledger exists to make all of them answerable from one place.

Texts run on the TCPA. The Telephone Consumer Protection Act of 1991 is codified at 47 U.S.C. § 227 (statute). It restricts autodialed and prerecorded calls and texts to wireless numbers without the called party's prior express consent. Courts and the FCC treat an SMS text as a "call" under the statute, so every marketing text you send lives under it. The FCC's implementing rules sit at 47 CFR § 64.1200 (rule), and they draw a line that the ledger's "consent basis" column has to track: informational autodialed texts need prior express consent, while marketing texts need the stricter prior express written consent.

That written standard, defined at 47 CFR § 64.1200(f), is specific. It requires a written agreement, signed by the person being called (an electronic signature counts under E-SIGN), that clearly authorizes marketing messages by autodialer or prerecorded voice and that names the specific phone number authorized. The agreement cannot be a condition of purchase, and it has to carry a clear and conspicuous disclosure. So the record you keep is not "they subscribed." It is a signed, number-specific, clearly-disclosed authorization, and your ledger either points to that document or it does not.

A cautionary case: the rule that lived thirteen months

This is why I build programs to keep the record, not to satisfy any one version of the rule.

On December 13, 2023, the FCC adopted an order (FCC 23-107, order) meant to close the lead-generator loophole. It redefined prior express written consent to require one-to-one consent: consent to a single identified seller at a time, for messages logically and topically tied to the interaction that produced it. It was published in the Federal Register in January 2024 (89 FR 5098, notice) with a compliance date of January 27, 2025. Teams across the industry spent a year rebuilding consent flows to meet it.

The rule never took effect. On January 24, 2025, three days before the compliance date, the Eleventh Circuit vacated the one-to-one requirement in Insurance Marketing Coalition Ltd. v. FCC (case), holding that the FCC had exceeded its authority because the rule conflicted with the ordinary common-law meaning of prior express consent. The FCC did not fight it. In September 2025 the agency issued a final rule formally deleting the vacated language and reinstating the prior definition (FCC final rule). The operative marketing-consent standard today is the pre-2024 one: a single signed, clearly-disclosed, number-specific written authorization, with no one-seller-at-a-time restriction.

Do not build your program to the one-to-one rule. The Eleventh Circuit vacated it and the FCC repealed the language, so on the record above it no longer governs. Build to the durable standard the vacatur left standing, and build to keep the record, because that is the part every version of the rule kept asking for. A program tuned to a specific regulation ages as fast as the regulation. A program that maintains the evidence survives the churn, since TCPA, CAN-SPAM, CTIA, and GDPR all end at the same question: show me the consent.

Email runs on CAN-SPAM. Commercial email is governed by the CAN-SPAM Act of 2003, 15 U.S.C. § 7704 (statute), and the FTC's implementing rule at 16 CFR Part 316 (rule). The obligations are stable and worth stating plainly (FTC guide): no false headers, no deceptive subject lines, identify the message as an ad, include a valid physical postal address, and give a clear opt-out. You have to honor an opt-out within 10 business days, keep the opt-out mechanism working for at least 30 days after you send, and you cannot make opting out cost a fee, personal data, or any step beyond a reply or a single web page. The ledger's opt-out column is where those deadlines get tracked instead of assumed.

Carriers run on CTIA. Above the statute, application-to-person text programs answer to the carrier layer through the CTIA Messaging Principles and Best Practices (current edition May 2023, PDF). These are not law. Carriers enforce them anyway, and non-compliance gets your messages filtered or your campaign suspended, which is a deliverability failure with the same practical result as a legal one. CTIA expects an appropriate level of consent before you message, a clear call-to-action that discloses program identity, message frequency, and rate implications, and working opt-out that honors STOP and its recognized variants plus plain-language requests. Your consent record should capture the exact call-to-action language a contact saw, because that is what a carrier reviews.

EU readers run on GDPR. For EU data subjects, consent is one of six lawful bases under GDPR Article 6 (Art. 6). Where you rely on it, it has to meet the Article 4(11) definition, "freely given, specific, informed and unambiguous" (Art. 4), and the Article 7 conditions (Art. 7): you must be able to demonstrate the consent, the request must be clearly distinguishable and in plain language, withdrawal must be as easy as giving it, and pre-ticked boxes or silence do not count. The word that matters for the ledger is demonstrate. GDPR does not ask whether you believe you had consent. It asks you to show it.

The five columns

The Consent Ledger is one register with a row for each consent relationship, per channel. It is not a legal requirement and it does not replace a consent-management platform. It is the operating model that makes the obligations above auditable instead of aspirational.

ColumnWhat the row recordsThe law it answers
Touch / channel The specific lifecycle touch and its channel, SMS or email, because the two carry different legal regimes TCPA (§ 227); CAN-SPAM (§ 7704)
Consent basis Which basis authorizes this touch: TCPA prior express written consent for marketing SMS, prior express consent for informational, CAN-SPAM commercial posture for email, or a GDPR Art. 6 basis for EU subjects 47 CFR § 64.1200(f); CAN-SPAM; GDPR Art. 6
Timestamp & source of consent When and how consent was captured: the form, the call-to-action language, the checkbox state, the device or IP, and the exact number or email authorized § 64.1200(f) signed and number-specific; CTIA CTA; GDPR demonstrable
Opt-out state Current status (active, opted-out, never-consented), plus the timestamp and channel of any opt-out event CAN-SPAM 10-business-day honor; CTIA STOP handling; GDPR withdrawal
Audit reference A pointer to the retained evidence: the stored consent record, the version or screenshot of the call-to-action, the opt-out log entry, so the row is provable rather than asserted CAN-SPAM recordkeeping; GDPR demonstrate

The audit reference column is the one teams skip and the one that decides an audit. The first four columns describe what you believe. The fifth is what you can hand to a regulator, a carrier, or opposing counsel. A ledger without it is a spreadsheet of good intentions. A ledger with it is a defense.

Where to start

You do not need a new platform to begin. Start with the channel that carries the most legal risk, which for most programs is marketing SMS, and reconstruct the five columns for your live audiences from what you already have: the consent flow, the opt-out logs, the ESP and SMS platform exports. The reconstruction itself is the audit. The rows you cannot fill are the exposure, and they are cheaper to find now than in a demand letter.

The regulation will move again. The one-to-one rule proved that a standard can be adopted, rebuilt for, and vacated inside about thirteen months. The programs that came through it intact were not the ones that guessed the rule correctly. They were the ones that kept the record, so that whatever the rule turned out to be, they could open the ledger and show their work.


This is an operational framework and my professional opinion, not legal advice, and reading it does not create a lawyer-client relationship between us. The law here changes, and it varies by jurisdiction and by the specifics of your situation, so nothing on this page is a substitute for advice on your own program. Before you rely on any of it, take it to a qualified attorney who can look at your actual facts.

Drafted with AI assistance; researched, edited, and verified by Jennifer Gallo LeBlanc.

← Back to Insights