Vet the Source9 min read

Consent and Lead Data: What Personal Injury Firms Should Require From Lead Providers

What personal injury firms should require from lead providers on consent and data: consent records, named-firm consent, opt-outs, retention and security.

Stack of printed documents in a deep blue folder on a concrete desk in a bright glass office

The short answer

Personal injury firms should require consent that names the firm, covers every channel the firm will use, and comes with a record showing where, when and how the consumer agreed. They should also require opt-outs to be shared between provider and firm, clear limits on how consumer data is used, and secure handling of injury and health details. Your firm is usually the one making the call, so your firm needs the evidence.

Key takeaways

  • When your firm calls or texts a third-party lead, your firm carries contact risk. A provider's reassurance isn't enough.
  • A consent record should show the source, timestamp, exact wording, the companies named and the channels covered.
  • Named-firm consent is the safest standard, even though the federal one-to-one rule was vacated.
  • Opt-outs must travel between provider and firm, across every system that could contact the consumer.
  • Injury and health details are sensitive data. Limit, secure and delete them on a schedule.
  • None of this replaces your own counsel's review of consent, contact practices and contracts.

Where do federal consent rules stand?

In December 2023, the Federal Communications Commission (FCC) adopted a rule aimed at lead generators, often called the one-to-one consent rule. It would have required consent to be given to one identified seller at a time, rather than to a list of “marketing partners.” In January 2025, a federal appeals court vacated the rule before it took effect, and the earlier consent standard continues to apply at the federal level.

That doesn't settle the question for your firm. State telemarketing laws can impose their own requirements, carriers apply their own rules to text messaging, and the regulatory picture can change. Many firms have chosen to require named-firm consent anyway, because it's the clearest evidence that a consumer wanted to hear from them specifically. Have your own counsel confirm the current position for your firm and markets.

What should you require from a lead provider?

1. Consent that names your firm

The strongest consent identifies your firm by name. Vague references to “our partners” or “participating attorneys” make it much harder to show the consumer agreed to hear from you.

2. A consent record for every lead, on request

Require the provider to produce the full consent record for any lead you ask about, quickly. Test it early: ask for records on a sample of leads during the first weeks of a program.

3. A defined retention period

Consent disputes can surface long after a lead is delivered. Agree how long the provider keeps consent records and how you'll access them if a question comes up later.

4. Channel coverage that matches your contact plan

If your call cadence includes texts or automated follow-up, the consent needs to cover them. If the provider screens callers with AI voices, ask how consent addresses artificial-voice contact.

5. Forms and creative that match the record

The consent wording in the record should match what's on the live form and in the ads. Ask for screenshots of the forms and landing pages, and check them against the records you receive.

6. Opt-outs that travel both ways

If a consumer tells the provider to stop, your firm needs to know. If they tell your firm, the provider needs to know. Agree how and how fast opt-outs and suppression requests are shared, and make sure they reach every system that could contact the consumer.

7. Limits on how consumer data is used

Your agreement should say whether the provider can share, resell or reuse the consumer's information. If the lead is sold to your firm alone, the data shouldn't be going anywhere else.

8. Secure handling of sensitive details

Injury details and health information are sensitive. Leads should arrive through secure integrations, not email attachments or shared spreadsheets, and both sides should know who can access them.

What should go in the contract?

Talk to your counsel about how the agreement addresses:

  • Consent standard and evidence. What consent the provider must obtain and what records it must provide.
  • Data use and sharing. Whether the provider may share or resell consumer information.
  • Opt-out handling. How suppression requests are exchanged and how quickly.
  • Responsibility. How the parties allocate responsibility if a consent problem arises.

How should your firm handle lead data?

Consent is only half of it. Once a lead reaches your firm, your firm is holding sensitive information.

  • Collect what intake needs. More data means more exposure.
  • Keep it in secure systems. Use your CRM and case management tools with controlled access — not inboxes, chat threads or general-purpose AI tools.
  • Set retention and deletion rules. Decide how long you keep lead data you don't sign, and delete it on schedule.
  • Honour opt-outs everywhere. Make sure a “stop” reaches every system and person that could contact the consumer.

How Sanguine Legal Solutions approaches consent

When Sanguine Legal Solutions vets a provider, we look at its consent approach — how consent is captured, what it covers and whether records are available — alongside its traffic, creative and delivery method. Vetting reduces uncertainty. It isn't a legal certification, and it doesn't replace your firm's own compliance review.

We also keep ourselves out of the data flow. Sanguine doesn't receive, store or transfer consumer lead data to make an introduction. That's part of our model: Vet. Test. Deliver. Manage. Learn more about how we vet and test lead sources.

Sanguine Legal Solutions does not sell leads. No leads pass through us. If your firm chooses a provider we introduce, you contract and work directly with that provider.

Frequently asked questions

Want a closer look at a provider's consent approach?

Sanguine Legal Solutions reviews how providers capture consent as part of vetting — without ever handling consumer lead data. We don't sell leads. Talk to us about the sources you're considering.

Book a Call

This article is general commercial information, not legal advice. Sanguine Legal Solutions is not a law firm and does not advise on TCPA, telemarketing, privacy or data protection law. Regulatory requirements change and vary by jurisdiction; the information here reflects the position at the date of publication. Each law firm and provider is responsible for its own legal, ethical, privacy and regulatory compliance and should obtain advice from qualified counsel. Provider vetting reflects information available at the time and is not a legal certification. Sanguine does not guarantee provider performance, lead quality, retained cases or return on spend.

Keep reading

Related articles

Next move

Want a clearer view of your next lead source?

Talk with the lead gen guys about your market, intake capacity and growth goals.

Let's Talk

People · Partnerships · Performance · Progress