Signature Framework · #1

The Consent Ledger

One register, one row per consent relationship per channel: the basis on which you message a contact, and the stored proof that you can produce it.

Here is the artifact most lifecycle programs are missing: one register, one row per consent relationship per channel, that answers a single question for any contact you message. On what basis are we texting or emailing this person, and can we prove it?

I call it the Consent Ledger. Five columns: the touch and channel, the consent basis, the timestamp and source of consent, the opt-out state, and an audit reference that points to the stored proof. Maintain it across SMS and email and your program can survive a compliance audit, because for every message you send you can name the legal basis, produce the record, and show that any opt-out was honored. That is the whole claim. What follows is how each column maps to the law it answers to.

The framework is mine. The legal facts under it are not, so I have cited each one to its primary source and kept my own judgment marked as opinion, separate from the statute.

The failure is evidentiary, not intentional

Most teams do not get sued because they never asked for consent. They get a demand letter, a carrier suspension, or an audit request, and then they cannot prove what consent they had, for which number or address, captured when and how. The consent usually existed. The record of it did not. Teams treat consent as a checkbox at signup instead of a record to be maintained, mapped, and produced on demand, and the gap does not show until someone asks to see the file.

SMS and email make the gap worse because they are almost never governed by the same team. Different tools, different capture forms, different opt-out plumbing, and two separate legal regimes sitting underneath. A single ledger across both channels is the artifact that is missing from most stacks, and it is missing precisely because no one owns the seam between them.

What the law actually requires

Three regimes govern lifecycle messaging in the United States and, for anyone serving EU readers, a fourth. The Consent Ledger exists to make all of them answerable from one place.

Texts run on the TCPA. The Telephone Consumer Protection Act of 1991 is codified at 47 U.S.C. § 227 (statute). It restricts autodialed and prerecorded calls and texts to wireless numbers without the called party's prior express consent. Courts and the FCC treat an SMS text as a "call" under the statute, so every marketing text you send lives under it. The FCC's implementing rules sit at 47 CFR § 64.1200 (rule), and they draw a line that the ledger's "consent basis" column has to track: informational autodialed texts need prior express consent, while marketing texts need the stricter prior express written consent.

That written standard, defined at 47 CFR § 64.1200(f), is specific. It requires a written agreement, signed by the person being called (an electronic signature counts under E-SIGN), that clearly authorizes marketing messages by autodialer or prerecorded voice and that names the specific phone number authorized. The agreement cannot be a condition of purchase, and it has to carry a clear and conspicuous disclosure. So the record you keep is not "they subscribed." It is a signed, number-specific, clearly-disclosed authorization, and your ledger either points to that document or it does not.

A cautionary case: the rule that lived thirteen months

This is why I build programs to keep the record, not to satisfy any one version of the rule.

On December 13, 2023, the FCC adopted an order (FCC 23-107, order) meant to close the lead-generator loophole. It redefined prior express written consent to require one-to-one consent: consent to a single identified seller at a time, for messages logically and topically tied to the interaction that produced it. It was published in the Federal Register in January 2024 (89 FR 5098, notice) with an effective date of January 27, 2025. Teams across the industry spent a year rebuilding consent flows to meet it.

The rule never took effect. On January 24, 2025, three days before the effective date, the Eleventh Circuit vacated the one-to-one requirement in Insurance Marketing Coalition Ltd. v. FCC (case), holding that the FCC had exceeded its authority because the rule conflicted with the ordinary common-law meaning of prior express consent. In July 2025 the FCC issued an order (DA 25-621, order) deleting the vacated language and reinstating the prior definition; the conforming final rule was published and took effect August 29, 2025 (90 FR 42137, final rule). The operative marketing-consent standard today is the pre-2024 one: a single signed, clearly-disclosed, number-specific written authorization, with no one-seller-at-a-time restriction.

Do not build your program to the one-to-one rule. The Eleventh Circuit vacated it and the FCC repealed the language, so on the record above it no longer governs. Build to the durable standard the vacatur left standing, and build to keep the record, because that is the part every version of the rule kept asking for. A program tuned to a specific regulation ages as fast as the regulation. A program that maintains the evidence survives the churn, since TCPA, CAN-SPAM, CTIA, and GDPR all end at the same question: show me the consent.

Email runs on CAN-SPAM. Commercial email is governed by the CAN-SPAM Act of 2003, 15 U.S.C. § 7704 (statute), and the FTC's implementing rule at 16 CFR Part 316 (rule). The obligations are stable and worth stating plainly (FTC guide): no false headers, no deceptive subject lines, identify the message as an ad, include a valid physical postal address, and give a clear opt-out. You have to honor an opt-out within 10 business days, keep the opt-out mechanism working for at least 30 days after you send, and you cannot make opting out cost a fee, personal data, or any step beyond a reply or a single web page. The ledger's opt-out column is where those deadlines get tracked instead of assumed.

Carriers run on CTIA. Above the statute, application-to-person text programs answer to the carrier layer through the CTIA Messaging Principles and Best Practices (current edition May 2023, PDF). These are not law. Carriers enforce them anyway, and non-compliance gets your messages filtered or your campaign suspended, which is a deliverability failure with the same practical result as a legal one. CTIA expects an appropriate level of consent before you message, a clear call-to-action that discloses program identity and rate implications, a confirmation message that states the frequency on any recurring program, and working opt-out that honors STOP and its recognized variants plus plain-language requests. Your consent record should capture the exact call-to-action language a contact saw, because that is what a carrier reviews.

EU readers run on GDPR. For EU data subjects, consent is one of six lawful bases under GDPR Article 6 (Art. 6). Where you rely on it, it has to meet the Article 4(11) definition, "freely given, specific, informed and unambiguous" (Art. 4), and the Article 7 conditions (Art. 7): you must be able to demonstrate the consent, the request must be clearly distinguishable and in plain language, withdrawal must be as easy as giving it; and Recital 32 adds that silence, pre-ticked boxes, or inactivity do not constitute consent. The word that matters for the ledger is demonstrate. GDPR does not ask whether you believe you had consent. It asks you to show it.

The five columns

The Consent Ledger is one register with a row for each consent relationship, per channel. It is not a legal requirement and it does not replace a consent-management platform. It is the operating model that makes the obligations above auditable instead of aspirational.

ColumnWhat the row recordsThe law it answers
Touch / channelThe specific lifecycle touch and its channel, SMS or email, because the two carry different legal regimesTCPA (§ 227); CAN-SPAM (§ 7704)
Consent basisWhich basis authorizes this touch: TCPA prior express written consent for marketing SMS, prior express consent for informational, CAN-SPAM commercial posture for email, or a GDPR Art. 6 basis for EU subjects47 CFR § 64.1200(f); CAN-SPAM; GDPR Art. 6
Timestamp & source of consentWhen and how consent was captured: the form, the call-to-action language, the checkbox state, the device or IP, and the exact number or email authorized§ 64.1200(f) signed and number-specific; CTIA CTA; GDPR demonstrable
Opt-out stateCurrent status (active, opted-out, never-consented), plus the timestamp and channel of any opt-out eventCAN-SPAM 10-business-day honor; CTIA STOP handling; GDPR withdrawal
Audit referenceA pointer to the retained evidence: the stored consent record, the version or screenshot of the call-to-action, the opt-out log entry, so the row is provable rather than assertedCAN-SPAM recordkeeping; GDPR demonstrate

The audit reference column is the one teams skip and the one that decides an audit. The first four columns describe what you believe. The fifth is what you can hand to a regulator, a carrier, or opposing counsel. A ledger without it is a spreadsheet of good intentions. A ledger with it is a defense.

Where to start

You do not need a new platform to begin. Start with the channel that carries the most legal risk, which for most programs is marketing SMS, and reconstruct the five columns for your live audiences from what you already have: the consent flow, the opt-out logs, the ESP and SMS platform exports. The reconstruction itself is the audit. The rows you cannot fill are the exposure, and they are cheaper to find now than in a demand letter.

The regulation will move again. The one-to-one rule proved that a standard can be adopted, rebuilt for, and vacated inside about thirteen months. The programs that came through it intact were not the ones that guessed the rule correctly. They were the ones that kept the record, so that whatever the rule turned out to be, they could open the ledger and show their work.


This is an operational framework and my professional opinion, not legal advice, and reading it does not create a lawyer-client relationship between us. The law here changes, and it varies by jurisdiction and by the specifics of your situation, so nothing on this page is a substitute for advice on your own program. Before you rely on any of it, take it to a qualified attorney who can look at your actual facts.

Drafted with AI assistance; researched, edited, and verified by Jennifer Gallo LeBlanc.

Sources

Every source is primary: the statute, the codified rule, the agency's own order, the court's own opinion, or the standards body's own publication. Accessed 2026-09-02.

  1. Office of the Law Revision Counsel, U.S. House of Representatives — "47 U.S.C. § 227, Restrictions on use of telephone equipment." The TCPA as codified. Subsection (b)(1)(A)(iii) is the prohibition the paper describes: it is unlawful to make a call using an automatic telephone dialing system or an artificial or prerecorded voice to a wireless number other than for an emergency purpose or with the called party's prior express consent. https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title47-section227&num=0&edition=prelim
  2. Electronic Code of Federal Regulations — "47 CFR § 64.1200, Delivery restrictions," current text. The FCC's implementing rules, and the line the ledger's consent-basis column tracks: (a)(1) requires prior express consent for autodialed calls and texts to wireless numbers, while (a)(2) requires prior express written consent when the message includes an advertisement or constitutes telemarketing. Paragraph (f)(9) carries the written-consent definition quoted in the paper — a signed written agreement, the specific telephone number authorized, a clear and conspicuous disclosure, no condition of purchase, and electronic signature. As of the access date the section contains no one-to-one-consent or "logically and topically associated" language. https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200
  3. Office of the Law Revision Counsel, U.S. House of Representatives — "15 U.S.C. § 7001, General rule of validity" (E-SIGN Act). The federal law behind § 64.1200(f)(9)(ii)'s "applicable federal law": a signature or record "may not be denied legal effect, validity, or enforceability solely because it is in electronic form." https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title15-section7001&num=0&edition=prelim
  4. Federal Communications Commission — "Targeting and Eliminating Unlawful Text Messages; Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991; Advanced Methods to Target and Eliminate Unlawful Robocalls," Second Report and Order, FCC 23-107, adopted December 13, 2023. The order that closed the lead-generator loophole by requiring written consent "from one seller at a time," and that added the requirement that consented-to messages be "logically and topically associated with the interaction that prompted the consent." https://docs.fcc.gov/public/attachments/FCC-23-107A1.pdf
  5. Federal Register — "Targeting and Eliminating Unlawful Text Messages, Implementation of the Telephone Consumer Protection Act of 1991, Advanced Methods To Target and Eliminate Unlawful Robocalls," final rule, 89 FR 5098, published January 26, 2024. The publication of FCC 23-107, and the source of the date the industry rebuilt toward: the rule set most of its amendments effective March 26, 2024, but made the amendment to 47 CFR 64.1200(f)(9) — the one-to-one consent language — effective January 27, 2025. https://www.federalregister.gov/documents/2024/01/26/2023-28832/targeting-and-eliminating-unlawful-text-messages-implementation-of-the-telephone-consumer-protection
  6. U.S. Court of Appeals for the Eleventh Circuit — "Insurance Marketing Coalition Ltd. v. Federal Communications Commission," No. 24-10277, decided January 24, 2025 (127 F.4th 303). The vacatur: the court granted the petition and vacated Part III.D of the 2023 order — both the one-to-one-consent restriction and the "logically and topically associated" restriction — holding the FCC exceeded its statutory authority because the restrictions impermissibly conflict with the ordinary statutory meaning of "prior express consent," a term Congress used against its settled common-law meaning. Footnote 2 is also the paper's support for treating a text as a "call": the statute does not mention text messages, but the FCC has interpreted "call" to include them. https://media.ca11.uscourts.gov/opinions/pub/files/202410277.pdf
  7. Federal Communications Commission, Consumer and Governmental Affairs Bureau — "Order," DA 25-621, adopted and released July 14, 2025. The repeal: this order deletes the revised § 64.1200(f)(9) adopted in 2023 and reinstates the prior version, whose full text appears in its Appendix. Its note 9 is the support for the paper's claim that the rule never took effect — the Commission had postponed the revised rule's effective date, and it never went into effect. https://docs.fcc.gov/public/attachments/DA-25-621A1.pdf
  8. Federal Register — "Delete, Delete, Delete; Targeting and Eliminating Unlawful Text Messages; Rules and Regulations Implementing of the Telephone Consumer Protection Act of 1991; Advanced Methods To Target and Eliminate Unlawful Robocalls," final rule, 90 FR 42137, published and effective August 29, 2025. The publication of DA 25-621 and the date the conforming rule took effect. https://www.federalregister.gov/d/2025-16641
  9. Office of the Law Revision Counsel, U.S. House of Representatives — "15 U.S.C. § 7704, Other protections for users of commercial electronic mail." The operative CAN-SPAM requirements the paper states: accurate header information, a non-deceptive subject heading, clear and conspicuous identification that the message is an advertisement, a valid physical postal address, a functioning return address or opt-out mechanism, and the ten-business-day deadline to honor an opt-out. https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title15-section7704&num=0&edition=prelim
  10. Electronic Code of Federal Regulations — "16 CFR Part 316, CAN-SPAM Rule." The FTC's implementing rule, promulgated under 15 U.S.C. 7701–7713. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-316
  11. Federal Trade Commission — "CAN-SPAM Act: A Compliance Guide for Business." The regulator's own plain-language statement of the obligations, and the source for the two deadlines the ledger's opt-out column tracks: honor an opt-out request "within 10 business days," keep the opt-out mechanism able to process requests "for at least 30 days after you send your message," and charge no fee, demand no personally identifying information beyond an email address, and require no step beyond a reply email or visiting a single page on a website. https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business
  12. CTIA — "Messaging Principles and Best Practices," May 2023. The carrier layer. §1 and §2.3 are the support for "these are not law" — a set of voluntary best practices that "do not constitute or convey legal advice." §5.1.1 gives the call-to-action disclosures (program or product description, originating numbers, the specific identity of the organization represented, opt-in and any fees or charges); §5.1.2.1 adds the recurring-program confirmation elements, including the frequency of the messaging and any associated fees. §5.1.2 is the consent record the ledger's timestamp-and-source column is built to hold: timestamp of consent acquisition, acquisition medium, the captured language and action used to secure consent, the campaign, the IP address, and the number consented for. §5.1.3 covers opt-out — standardized STOP wording, plus normal-language requests (stop, end, unsubscribe, cancel, quit, "please opt me out") that should also be read and acted upon. §7 is the enforcement consequence: providers deploy filters against unwanted messages, and under §7.2.4 may suspend or disconnect traffic at their discretion. https://api.ctia.org/wp-content/uploads/2023/05/230523-CTIA-Messaging-Principles-and-Best-Practices-FINAL.pdf
  13. EUR-Lex — "Regulation (EU) 2016/679 (General Data Protection Regulation)," consolidated text. Article 6(1) lists the six lawful bases, consent being the first; Article 4(11) is the definition quoted, "freely given, specific, informed and unambiguous"; Article 7 carries the three conditions the paper names — the controller "shall be able to demonstrate that the data subject has consented," the request must be "clearly distinguishable from the other matters" and in "clear and plain language," and it "shall be as easy to withdraw as to give consent." https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02016R0679-20160504
  14. EUR-Lex — "Regulation (EU) 2016/679," as published in the Official Journal L 119, 4 May 2016. Cited for Recital 32 only, which the consolidated text above omits: consent requires "a clear affirmative act," and "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
← Back to Insights