Consent records that survive an audit
"They agreed to texts" is not a record. Here is what a consent record needs to contain, channel by channel, so it holds up when someone asks.
"They agreed to texts" is not a record. Here is what a consent record needs to contain, channel by channel, so it holds up when someone asks.
Consent is the foundation under most of modern collections. Texts, emails, calls to a cell phone, autodialed calls, electronic disclosures: each rests on the consumer having agreed to something, and each comes with a rule about what that agreement has to look like. The problem is that agencies collect consent in the moment and record it as a checkbox. When the moment is questioned, a checkbox is not evidence.
A consent record has to answer five questions about a specific consumer and a specific channel: what did they agree to, when, how, from what, and can we prove it hasn't changed. Here is what that means for each channel.
What has to be captured: the number consented to, the exact disclosure shown or read (the wording, not a summary), the date and time, the method (web form with IP and user agent, a verbal consent with the recording and its timestamp, a reply to an opt-in message), and the scope (is this consent to texts about this debt, all debts, or ongoing?). What breaks it: an opt-out that was honored late, or not at all. Every text-consent record needs a matching opt-out record with the same fields, and the system needs to refuse the send, not just log the request.
Regulation F gives a safe harbor for email that turns on where the address came from: the consumer used it to communicate with the collector, or the creditor used it with the consumer within the required window and the consumer was given notice and a chance to opt out. The record needs to say which path you relied on, with dates. If the address came from a skip-trace vendor, you are outside the safe harbor, and your record should say that too, honestly, so nobody later claims otherwise.
Prior express consent for autodialed or prerecorded calls needs the same five elements, plus the number itself and who provided it (the consumer, on the original application, on a call). Consent given to the original creditor generally carries to the collector for that debt; consent given for one debt does not carry to another. Your record has to be per number and per debt, and it has to be revocable by any reasonable means, which means every channel your consumer could use to say "stop calling" has to feed the same record.
Delivering a validation notice or any required disclosure electronically depends on E-SIGN consent: the consumer agreed to receive it that way, was told what hardware and software they'd need, and demonstrated they could access it. The record is the consent, the disclosure of requirements, and the demonstration (for example, the consumer opened a test message). Agencies that email validation notices on the strength of a checkbox alone are the ones who lose this argument.
Not "do you have consent." They pick ten consumers who complained and ask for each one's consent history for each channel, in order, with the disclosures as shown. Then they compare it with the communication log. Every message sent after an opt-out, and every message before a consent, is a finding. Run that test on yourself before they do: pick ten consumers at random, pull the records, and see whether the story holds together without anyone explaining it.
A checkbox is not evidence. A consent record answers what, when, how, from what, and whether it has changed.
Resolvah records every consent and every revocation this way, per channel and per number, and refuses the send when the record says no. Our compliance overview at resolvah.com/law covers the rest.
This is how we think — and how Resolvah works. See it for yourself.
Thirty minutes, a real operator, and the actual product. No script.