TCPA Consent Records for Insurance Agents: What to Keep and How Long
10 min read · July 29, 2026
Every agent I know says the same sentence when TCPA comes up: “my leads are consented.” Then I ask a follow-up that ends the conversation. Show me.Not the vendor's marketing page — the record for one specific number you dialed last week.
Almost nobody can. And that gap is the whole problem, because in a TCPA dispute consent you cannot produce is functionally identical to consent you never had. The burden sits on the party that placed the call. That is you, not the vendor, not the IMO.
This post is about the boring half of compliance that nobody writes about: the file. What a real consent record contains, who has to keep it, how revocation changes it, how long it has to survive, and how to audit what you have in about fifteen minutes. I am an agent writing for agents — if you have an actual demand letter in hand, close this tab and call a TCPA attorney.
Why the record is the entire defense
Statutory TCPA damages run $500 per violation and up to $1,500 per violation if the conduct is found willful. There is no cap on the count. One number dialed nine times over a month is not one problem; it is potentially nine.
What makes this asymmetric is how the fight actually plays out. The consumer's side of the file is easy to assemble — their carrier records show the calls came in. Your side requires you to affirmatively produce evidence that you had permission. If your answer is “the lead came from a vendor who says they collect consent,” you have produced nothing. You have described a business relationship.
So the correct mental model is not “am I compliant.” It is “can I document that I was compliant, per call, years later.” Those are very different systems.
What a defensible consent record actually contains
A lead row is not a consent record. A consent record is a snapshot of a moment: what a specific person saw on a specific screen at a specific second, and what they agreed to. Here is the field list I would want to be able to produce for any number in my system.
| Field | Why it matters | Priority |
|---|---|---|
| Exact disclosure text | Proves what was agreed to, word for word | Critical |
| Timestamp | Anchors consent before the first dial | Critical |
| Phone number as submitted | Ties the consent to the number you dialed | Critical |
| Business named in the disclosure | Consent runs to a named party, not to anyone | Critical |
| Form URL or landing page | Lets you reconstruct the page as shown | High |
| IP address / device | Corroborates a real human submission | High |
| Source and vendor ID | Traces bad batches back to their origin | High |
| Revocation date, if any | Marks the moment consent stopped existing | Critical |
Read that list against whatever you dial from today. If your CRM stores name, phone, state, and “source: Facebook,” you do not have consent records. You have contact records with a note about where they came from.
The named-party problem agents keep tripping over
Consent is not a general permission slip to be sold insurance. It runs to whoever the disclosure said could call. When a form says the consumer agrees to be contacted by “our partners,” the interesting question is whether you are demonstrably one of them and whether you can show the partner list as it existed on the day the form was submitted.
The FCC pushed a stricter one-to-one consent standard that would have required consent to name a single seller. A federal appeals court vacated it before it took effect in early 2025, so the older, looser framework still governs. Plenty of agents took that as an all-clear. I read it differently: the rule went away, but the argument did not. A plaintiff's lawyer will still ask why a consumer who filled out one form heard from six agencies, and a disclosure naming a vague partner category is still a weaker exhibit than one naming you.
Practical version: when you evaluate a lead source, ask to see the actual form and the actual consent language, not a description of it. If the disclosure is buried, pre-checked, or points at an unbounded partner list, price that risk in before you buy — the same discipline covered in the broader TCPA compliance rules for agents.
Revocation: the part that has actually changed
Here is where current rules bite hardest, and where I see the most agent exposure.
A consumer can revoke consent through any reasonable means. Not a written form, not a specific keyword, not a portal. If they say “stop calling me” on a live call, that is revocation. If they reply STOP to a text, that is revocation. If they tell your assistant, that is revocation. Once received, the request has to be honored within ten business days.
Two things follow from that, and both are workflow problems rather than legal ones.
- Revocation crosses channels.A prospect who opts out of your texts has, in most readings, revoked for calls on the same subject too. Treating your SMS opt-out list and your dial suppression list as separate systems is how a “compliant” agent places a violating call. I went through the messaging side of this in the TCPA rules for texting insurance leads.
- Ten business days is a ceiling, not a target. The redial that generates the lawsuit almost never happens on day nine. It happens forty minutes later, because the request lived in your short-term memory and the dialer did not know. Log it while the prospect is still on the line.
And record the revocation the same way you record consent: date, time, channel, exact words if you have them, and who received it. A revocation with no timestamp is unprovable in both directions — you cannot show you honored it promptly, and you cannot show when the clock started.
How long to keep everything
Federal TCPA claims run on a four-year statute of limitations. That clock starts at the call, not at the consent. So the retention question is not “how old is this lead” — it is “how long has it been since the last time I dialed this number.”
| Record | Keep for | Clock starts at |
|---|---|---|
| Consent record | 5 years (4 minimum) | Last call placed to that number |
| Call log / disposition | 5 years | The call itself |
| Scrub record | 5 years | The scrub |
| Internal do-not-call entry | Indefinitely | Never delete it |
| Call recordings | Per your state rules | The call |
The internal do-not-call row is the one people get wrong. Purging opt-outs to “clean up the database” is the single worst database hygiene decision an agent can make, because the number comes back on a list you buy two years from now and you dial it with a clean conscience and a dirty record. Suppression entries are permanent. They are the cheapest rows you will ever store.
Note also that some state telemarketing statutes carry their own retention and recordkeeping requirements that run differently from the federal clock. If you are licensed across several states, check the mini-TCPA regimes in the states you dial rather than assuming federal is the ceiling. It usually is not.
Where these records should live
The unglamorous truth is that most agents keep consent evidence in three places that all decay: a vendor portal they will lose access to when they stop buying, a folder of CSV exports, and their memory.
| Where it lives | Holds up under pressure? | Failure mode |
|---|---|---|
| Vendor portal only | No | Access ends when the relationship does |
| CSV exports in a folder | Weak | No link to the calls you actually placed |
| Spreadsheet you maintain | Weak | Editable, undated, no per-call trail |
| CRM attached to the dialer | Yes | Only as good as what you capture at import |
The reason the last row wins is not that CRMs are magic. It is that consent evidence is only useful when it is joined to the call log. “Here is a consent file” and “here is a call log” are two exhibits a lawyer has to argue connect. “Here is the record for this call, including the consent basis that existed at the time” is one exhibit that answers itself. That join is precisely the thing a spreadsheet cannot do once you are dialing at volume.
What to demand from a lead source, in writing
You are not being difficult by asking these. Any vendor operating properly answers them in a sentence each, and the ones who get evasive have told you what you needed to know.
- Will you provide the full consent record per lead, on request, in a file I keep? Portal access is not the same as delivery.
- What exact disclosure text was shown, and can I see a capture of the page? Ask for the artifact, not a paraphrase.
- Am I named, and how many other parties were? This determines how exclusive the consent actually is.
- How long do you retain the evidence? If they purge at twelve months and TCPA claims run four years, their retention policy is your liability.
- What happens to my access if I stop buying? The most common way agents lose their defense is churning off a vendor.
Take the answers in email, not on a call. The email is itself a record. And if a source cannot clear this bar, that is a signal worth acting on well before it becomes a litigator on your dial list.
The fifteen-minute audit
Do this today. Pick one number you dialed in the last two weeks and try to assemble its file. Time yourself.
- Can I produce the exact disclosure text that number agreed to?
- Can I show a timestamp proving consent predates my first call?
- Was my business, or an entity I can tie myself to, named in that disclosure?
- Can I show the number was scrubbed, and when?
- If they had asked me to stop on call two, where would that live and would it have blocked call three?
- Will all of the above still exist four years from now if I switch vendors tomorrow?
If assembling that takes more than fifteen minutes for one number, the honest conclusion is that you could not do it for two hundred under deadline. That is the actual state of most agent operations, including plenty of very good producers. It is not a discipline failure. It is what happens when the record-keeping lives outside the tool that places the call, so every entry costs a deliberate act of will at exactly the moment you are trying to move fast.
The fix is structural, not motivational. Capture consent fields at import so they are attached before the first dial. Log revocation in the same system that decides whether to place the next call. Keep the suppression list permanent. Then compliance becomes a property of the workflow instead of a tax on it, which is the same principle behind running a disciplined call cadence — the system remembers so you do not have to.
Consent, scrubs, and calls in one record
FEXmagnet keeps consent fields, DNC checks, opt-outs, and the full call log joined to every number — so the file assembles itself. A compliance-first CRM and single-line power dialer built for licensed agents. From $29/mo, no contracts.
See Plans & Pricing