Consent and Lead Data: What Personal Injury Firms Should Require From Lead Providers
What personal injury firms should require from lead providers on consent and data: consent records, named-firm consent, opt-outs, retention and security.

The short answer
Personal injury firms should require consent that names the firm, covers every channel the firm will use, and comes with a record showing where, when and how the consumer agreed. They should also require opt-outs to be shared between provider and firm, clear limits on how consumer data is used, and secure handling of injury and health details. Your firm is usually the one making the call, so your firm needs the evidence.
Key takeaways
- When your firm calls or texts a third-party lead, your firm carries contact risk. A provider's reassurance isn't enough.
- A consent record should show the source, timestamp, exact wording, the companies named and the channels covered.
- Named-firm consent is the safest standard, even though the federal one-to-one rule was vacated.
- Opt-outs must travel between provider and firm, across every system that could contact the consumer.
- Injury and health details are sensitive data. Limit, secure and delete them on a schedule.
- None of this replaces your own counsel's review of consent, contact practices and contracts.
Why does consent matter so much to a firm buying leads?
Because your firm is usually the one reaching out. With web form leads, your intake team makes the call and sends the texts. With live transfers and signed retainers, the provider handles the first contact, but your firm follows up. Either way, your firm is contacting a consumer on the strength of consent someone else collected.
The Telephone Consumer Protection Act (TCPA) and state telemarketing laws allow consumers to bring claims for unwanted calls and texts, and statutory damages under the TCPA are set per violation. At the volume third-party programs run, a consent problem can become expensive quickly. That's why the brand-safe answer to “is this lead consented?” is never “the provider said so.” It's “here's the record.”
What is a consent record?
A consent record is the evidence showing how, when and to whom a consumer agreed to be contacted. A complete one includes:
- The source. The page, form or call where consent was given.
- The timestamp. When the consumer agreed — which should line up with when the lead was created and delivered.
- The exact wording. The consent language the consumer actually saw or heard, not a summary of it.
- Who was named. The specific companies the consumer agreed to hear from.
- The channels covered. Calls, texts, email and, where relevant, automated or artificial-voice contact.
- Independent evidence. Many providers use third-party session-recording or certification tools that capture the form interaction as it happened.
If a provider can't produce this for a specific lead on request, you don't have a consent record. You have a claim.
Where do federal consent rules stand?
In December 2023, the Federal Communications Commission (FCC) adopted a rule aimed at lead generators, often called the one-to-one consent rule. It would have required consent to be given to one identified seller at a time, rather than to a list of “marketing partners.” In January 2025, a federal appeals court vacated the rule before it took effect, and the earlier consent standard continues to apply at the federal level.
That doesn't settle the question for your firm. State telemarketing laws can impose their own requirements, carriers apply their own rules to text messaging, and the regulatory picture can change. Many firms have chosen to require named-firm consent anyway, because it's the clearest evidence that a consumer wanted to hear from them specifically. Have your own counsel confirm the current position for your firm and markets.
What should you require from a lead provider?
1. Consent that names your firm
The strongest consent identifies your firm by name. Vague references to “our partners” or “participating attorneys” make it much harder to show the consumer agreed to hear from you.
2. A consent record for every lead, on request
Require the provider to produce the full consent record for any lead you ask about, quickly. Test it early: ask for records on a sample of leads during the first weeks of a program.
3. A defined retention period
Consent disputes can surface long after a lead is delivered. Agree how long the provider keeps consent records and how you'll access them if a question comes up later.
4. Channel coverage that matches your contact plan
If your call cadence includes texts or automated follow-up, the consent needs to cover them. If the provider screens callers with AI voices, ask how consent addresses artificial-voice contact.
5. Forms and creative that match the record
The consent wording in the record should match what's on the live form and in the ads. Ask for screenshots of the forms and landing pages, and check them against the records you receive.
6. Opt-outs that travel both ways
If a consumer tells the provider to stop, your firm needs to know. If they tell your firm, the provider needs to know. Agree how and how fast opt-outs and suppression requests are shared, and make sure they reach every system that could contact the consumer.
7. Limits on how consumer data is used
Your agreement should say whether the provider can share, resell or reuse the consumer's information. If the lead is sold to your firm alone, the data shouldn't be going anywhere else.
8. Secure handling of sensitive details
Injury details and health information are sensitive. Leads should arrive through secure integrations, not email attachments or shared spreadsheets, and both sides should know who can access them.
What are the consent red flags?
- “Our marketing partners” language. Consent that doesn't name your firm, or names a long list of companies.
- Records that never arrive. A provider that can't or won't produce consent records for specific leads.
- Timestamps that don't add up. Consent dated long before the lead was delivered, or after the first contact.
- Leads sent by email or spreadsheet. Consumer data moving through unsecured channels.
These sit alongside the broader 8 questions to ask any personal injury lead provider.
What should go in the contract?
Talk to your counsel about how the agreement addresses:
- Consent standard and evidence. What consent the provider must obtain and what records it must provide.
- Data use and sharing. Whether the provider may share or resell consumer information.
- Opt-out handling. How suppression requests are exchanged and how quickly.
- Responsibility. How the parties allocate responsibility if a consent problem arises.
How should your firm handle lead data?
Consent is only half of it. Once a lead reaches your firm, your firm is holding sensitive information.
- Collect what intake needs. More data means more exposure.
- Keep it in secure systems. Use your CRM and case management tools with controlled access — not inboxes, chat threads or general-purpose AI tools.
- Set retention and deletion rules. Decide how long you keep lead data you don't sign, and delete it on schedule.
- Honour opt-outs everywhere. Make sure a “stop” reaches every system and person that could contact the consumer.
How Sanguine Legal Solutions approaches consent
When Sanguine Legal Solutions vets a provider, we look at its consent approach — how consent is captured, what it covers and whether records are available — alongside its traffic, creative and delivery method. Vetting reduces uncertainty. It isn't a legal certification, and it doesn't replace your firm's own compliance review.
We also keep ourselves out of the data flow. Sanguine doesn't receive, store or transfer consumer lead data to make an introduction. That's part of our model: Vet. Test. Deliver. Manage. Learn more about how we vet and test lead sources.
Sanguine Legal Solutions does not sell leads. No leads pass through us. If your firm chooses a provider we introduce, you contract and work directly with that provider.
Frequently asked questions
Want a closer look at a provider's consent approach?
Sanguine Legal Solutions reviews how providers capture consent as part of vetting — without ever handling consumer lead data. We don't sell leads. Talk to us about the sources you're considering.
Book a CallThis article is general commercial information, not legal advice. Sanguine Legal Solutions is not a law firm and does not advise on TCPA, telemarketing, privacy or data protection law. Regulatory requirements change and vary by jurisdiction; the information here reflects the position at the date of publication. Each law firm and provider is responsible for its own legal, ethical, privacy and regulatory compliance and should obtain advice from qualified counsel. Provider vetting reflects information available at the time and is not a legal certification. Sanguine does not guarantee provider performance, lead quality, retained cases or return on spend.



