Skip to content
ComplyMynt
All articles

TCPA

The consent record you cannot produce is the one you needed

· 7 min read

A defensible record has the language shown, the timestamp, the source, and the version. Most stacks store one of the four.

In a TCPA dispute, the question is never whether you had a checkbox. It is whether you can produce, for one specific person on one specific date, the exact language they agreed to.

A defensible record contains four elements: the verbatim disclosure text shown, a trustworthy timestamp, the capture source including page and campaign, and a version identifier for the consent language itself.

Most stacks store a boolean. When the language changes — and it always changes — the record becomes unfalsifiable and therefore worthless.

Retention matters just as much. Keep records for the full limitations period plus a margin, and make sure revocation is recorded with the same fidelity as the original consent.

Test the process, not the schema: pick a real record at random and try to produce the packet in under an hour. If you cannot, neither can your counsel.

Want this checked on your product?

We run the same review across privacy, consent, accessibility, AI disclosure, and public security surfaces — and ship the remediation.

Request an audit

Keep reading