Table of content
TL;DR:
Consent management is how you capture, store, honor, and prove a prospect's permission to be contacted. For outbound teams it covers email, phone, SMS, and social. Cookie banners are a different problem with a different toolset.
- Consent lives at the contact level. You need a legal basis recorded per person, per channel, per country. Cookie tooling never produces that record.
- The rules split four ways. US email allows cold outreach with a working opt-out. Canada does not. The EU allows it under legitimate interest, if you document the reasoning first.
- Your opt-out list matters more than your opt-in list. Suppression gaps cause more damage than missing consent forms.
- Store five fields per contact: source, legal basis, timestamp, channel scope, and expiry date.
- Salesforce and HubSpot already ship consent objects. Plenty of outbound teams never switch them on.
This is operator guidance from a data platform, not legal advice. Loop in counsel before you change policy.
An SDR marks a prospect as "do not contact" in Outreach. Three weeks later, a different rep buys a list, imports the same person into Salesloft, and fires a five-touch sequence at them.
The prospect complains. Legal asks for the consent record. Nobody has one.
That story plays out at a lot of Series B and Series C companies, and the fix is never a bigger tool budget. It's a shared definition of what your team counts as permission, written down once and enforced in one place.
I've watched teams spend six figures on a privacy platform that handles cookie banners beautifully. It did nothing for the 40,000 prospects sitting in their sequencer. Consent management for outbound is a separate discipline. Same word, different job.
What consent management means for an outbound team
Consent management is the process of capturing a person's permission to be contacted and recording how and when you got it. Then you apply it across every sending tool. Then you produce proof on demand.
For a website, that means cookie choices. For outbound, it means four questions your system should answer about any contact in under a minute:
- Where did this record come from? A form fill, a conference badge scan, a data provider, or a scrape.
- What legal basis lets us contact them? Express consent, implied consent, or legitimate interest.
- Which channels does that basis cover? Email consent does not carry over to SMS. It never has.
- Has it expired or been withdrawn? And if withdrawn, did every tool get the memo?
Answer those four and you have a working program. Miss one and you have a spreadsheet.
Question three trips up more teams than the other three combined. Teams treat consent as a single yes or no flag on the contact record. Then a rep texts someone who only ever agreed to email, and the company picks up TCPA exposure nobody priced in.
The consent rules that apply to B2B outbound
Four regimes cover almost everything a global outbound team touches. Each one draws the line in a different place.
1. United States: email and phone follow different laws
The CAN-SPAM Act does not require consent before you send a cold email. It requires accurate headers, a real physical address, honest subject lines, and a working opt-out you process within 10 business days.
Phone is stricter, and getting worse. The federal Do Not Call Registry largely exempts business-to-business calls placed to business lines. Mobile numbers are the trap. Courts and the FCC treat a personal cell as a residential line, even when the person uses it purely for work. Dial one with anything resembling an autodialer and you're in TCPA territory.
Two developments matter for anyone building a calling program right now:
- One-to-one consent is dead. The Eleventh Circuit vacated the FCC's rule in January 2025, and the FCC reinstated the older prior express written consent standard in August 2025.
- Revocation rules took effect April 2025. Callers must honor opt-outs made through any reasonable method, including the words stop, quit, revoke, opt out, cancel, unsubscribe, and end. The narrower "one revocation cuts off all topics" piece sits under a waiver running to January 31, 2027.
State law stacks on top. Florida, Oklahoma, Maryland, Washington, and New Jersey run mini-TCPA statutes with their own penalties. Some of those state do not call laws carry no B2B carve-out at all. Calling hours follow the prospect's time zone, not yours. That single detail causes more violations than any other.
2. Canada: CASL treats silence as a no
CASL flips the US model. You need consent before the first message, either express or implied.
Implied consent is the one outbound teams live on. It applies on three conditions. The person published their email address in plain sight. No statement next to it refuses commercial messages. And your message relates to their role. The CRTC spells out the conditions in its guidance on implied consent. Read the wording closely. Relevance to the recipient's job is a requirement, not a nice-to-have.
Implied consent also expires. Two years after a purchase or contract. Six months after an inquiry.
And the burden of proof sits with you, not the recipient. The CRTC expects screenshots or contemporaneous records showing where you found the address, on what date, and that no opt-out statement sat next to it. Penalties reach $10 million per violation for corporations.
One case is worth knowing by name. In 2014 a Quebec training company called Compu-Finder sent 317 emails to other businesses. It argued the B2B exemption covered them, and failing that, conspicuous publication. The CRTC rejected both. Public availability of an address sits at a lower bar than conspicuous publication, and relevance to the recipient's role has to hold as well. The original $1.1 million penalty came down to $200,000, and the Federal Court of Appeal dismissed the appeal in June 2020. Five years of litigation over three campaigns. Our full CASL breakdown covers the reasoning in detail.
That ruling changes how you buy data. If your provider can't tell you where a Canadian record came from, you can't defend it. This is the whole argument for compliant B2B data over cheap volume.
3. EU and UK: legitimate interest, written down
GDPR doesn't ban cold email. Article 6(1)(f) lets you process business contact data under legitimate interest, and Recital 47 names direct marketing as a qualifying purpose.
The catch is documentation. You need a Legitimate Interest Assessment covering three tests:
- Purpose: why you're contacting this person specifically.
- Necessity: why email is the right and least intrusive channel.
- Balance: whether your business interest outweighs their privacy rights.
No assessment on file means no defense during an ICO or CNIL inquiry. You lose the argument before it starts.
The same reasoning covers phone, and GDPR rules for cold calling follow a similar documentation standard. Then the ePrivacy Directive layers national rules on top, and they diverge sharply:
- France and the Netherlands take a permissive view of B2B email sent to corporate addresses.
- Germany's UWG sets a high bar and generally expects consent even between businesses.
- Poland is stricter still, and often expects consent outright.
My honest read: if you sell into DACH, treat legitimate interest as a floor rather than a green light. Generic 500-contact blasts into Germany are a bad bet regardless of what your LIA says. I'd rather send 40 researched emails there than 400 templated ones.
4. Everywhere else: check before the first send
Australia's Spam Act requires consent and carries daily penalties. Singapore runs a Do Not Call registry that covers business numbers, which catches teams off guard. Brazil's LGPD borrows heavily from GDPR. California adds its own layer through CCPA compliance for any record tied to a resident there.
You don't need to memorize all of it. You need a country field on every contact and a policy table your ops team owns. You can't apply different rules to a segment you can't identify.
The consent record: five fields every contact needs
This is the part that decides whether you pass an audit.
A consent record isn't a checkbox. It's a small set of fields captured at the moment the record enters your system, because retrofitting them later never works:
Add a sixth field if you sell into Canada: a link to the screenshot or vendor attestation backing the implied consent claim. Compu-Finder lost partly because it couldn't produce that evidence.
What to do: make these fields required on import. Not optional. Not filled in later. If a CSV lands without a source and a legal basis, the import fails. That single rule prevents the bulk of the mess.
I'd also version the record rather than overwrite it. When someone opts out and later opts back in, you want both events with timestamps. A single flag flips twice and erases its own history.
Suppression is where outbound programs break
Consent capture is the easy half. Suppression is the half that gets companies fined.
Think of it as four layers, and check each one separately:
- Global suppression. People who said stop, across every channel and every brand you own.
- Channel suppression. Someone who opted out of SMS but still reads your email. Honor the wrong scope and you lose pipeline you had every right to keep.
- Domain suppression. Current customers, open deals, partners, competitors, and anyone legal told you to leave alone.
- Regional suppression. DNC registries, state lists, and country-level blocks.
Now the deadlines, and they don't agree with each other. CAN-SPAM gives you 10 business days to process an email opt-out. CASL gives you the same 10. Gmail, Yahoo, and Microsoft are far less patient: bulk senders need RFC 8058 one-click unsubscribe and must process opt-outs within two days.
Those inbox rules bite harder than the statutes do, which is why email deliverability tools now sit inside the compliance conversation. Send 5,000 or more messages a day to consumer domains and the rules turn hard. Google and Microsoft now reject non-compliant mail outright with 550 errors. They used to route it quietly to spam. Keep spam complaints under 0.3% as measured in Google Postmaster Tools, and honestly, treat 0.1% as your real ceiling. Cold campaigns run hot.
The failure mode I see repeatedly: suppression lives in the sequencer, not the CRM. Rep leaves. Tool gets swapped. List gets re-imported. The opt-outs vanish, and nobody notices until someone complains. That's one more way bad CRM data quietly turns into legal exposure.
Suppression belongs in the system of record. Every sending tool reads from it.
Consent management tools for B2B outbound teams
No single product covers this. You're assembling a stack, and each layer does one job. Where these sit inside a wider RevOps tech stack depends on who owns compliance at your company.
1. Consent management platforms
OneTrust, Osano, TrustArc, Usercentrics, Didomi, and Ketch dominate this category. They're strong at cookie banners, preference centers, privacy notices, and data subject requests.
What they don't do is govern your sequencer. A CMP records that someone updated preferences on your website. Getting that signal into Outreach before a rep sends touch four is your integration work, not theirs.
Buy one if you run a website with EU traffic and need audit trails for DSARs. Don't buy one expecting it to fix outbound.
2. CRM-native consent objects
This is the layer teams skip, and it's usually the cheapest win available.
Salesforce ships a privacy consent data model with objects for Individual, Contact Point Consent, Communication Subscription, and Data Use Legal Basis. Those records don't count against your storage limit. HubSpot offers subscription types plus legal basis fields on the contact record.
Both let you model consent per person, per channel, per purpose. Both sit unused in a lot of orgs because nobody owned the setup.
What to do: before you evaluate a single vendor, ask your Salesforce admin whether anyone switched on Contact Point Consent. The answer is often no.
3. DNC scrubbing and telephony compliance
Calling programs need list scrubbing against the National DNC Registry plus state registries. PossibleNOW, DNC.com, and Contact Center Compliance handle this. Cadence matters: a 31-day scrub cycle is standard practice.
Your dialer needs three things too. An internal DNC list. Calling windows set by the prospect's time zone. And recording consent capture in two-party states.
4. Sequencers and dialers
Outreach, Salesloft, Apollo, and HubSpot Sequences all support unsubscribe handling and opt-out sync. Support and configuration are different things.
Check three settings in whatever you run:
- Does an opt-out write back to the CRM, or does it live only in the tool?
- Does the unsubscribe apply to the account, the person, or the whole domain?
- Does bounce and complaint data flow into a suppression list automatically?
If any answer is no, you have a leak.
5. Your data provider
This layer decides how much of the rest you can defend. A record with no provenance can't carry a legal basis, and no amount of downstream tooling fixes that.
The questions worth asking are the same ones that separate a serious B2B data provider from a reseller. Where did this record come from? How recently did you verify it? Can you show me the sourcing basis for a Canadian or German contact?
SMARTe uses real-time B2B data verification rather than serving records from a static file. That covers 289M+ verified B2B contacts across 200+ countries, under SOC 2 Type II certification with GDPR and CCPA alignment.
Real-time verification matters here for one specific reason: job change tracking. A person who left the company two quarters ago carries no valid basis on their old address. B2B data decay is how suppression lists drift out of sync with reality.
Nine rules for a consent program that survives an audit
- Capture legal basis at import, never after. Going back to add basis onto 80,000 old records is a project nobody finishes.
- Make the CRM your system of record for suppression. Every sending tool reads from it. No exceptions for a rep's personal list.
- Separate consent by channel. Email, phone, and SMS get their own fields.
- Set expiry dates on implied consent. Six months for a Canadian inquiry, two years for a transaction. Automate the removal.
- Log withdrawal events, don't overwrite them. Regulators ask when someone opted out, not just whether they did.
- Write the LIA before you launch the campaign, not after the complaint. One page per campaign type is enough.
- Scrub phone lists on a fixed cycle. Put it on a calendar and give it an owner.
- Train reps on the three-second version. If a prospect says stop in any form, on any channel, mark it and move on. No clever re-engagement, and no rebuilding the same list through a different outbound prospecting motion.
- Run a quarterly reconciliation. Pull opt-outs from every sending tool and compare against the CRM. The delta is your risk.
Rule nine is the one I'd start with if you only do one thing this quarter. It takes an afternoon and it tells you how bad the problem is.
A 30-day consent audit you can run this quarter
Week one: find the gap. Export opt-outs from every sending tool, dialer, and form into one sheet. Match against your CRM suppression list. The count that exists in one place but not the other is your live exposure. In the audits I've sat through, that delta usually lands between 3% and 15% of the opt-out file.
Week two: test your records. Pull a random sample of 100 contacts. For each one, try to name the source, the legal basis, and the capture date. If your hit rate lands under 50%, stop buying tools and fix imports first.
Week three: switch on what you own. Turn on the consent objects already sitting in Salesforce or HubSpot. Map source, basis, timestamp, channel, and expiry. Your admin can do this in a day.
Week four: close the door. Write the import validation rule that rejects any record missing a source or a legal basis. Backfill what you can prove. Quarantine what you can't, and don't sequence it.
What clean consent records buy you
Consent management gets framed as a legal burden. I'd argue the opposite. Teams with clean permission records send fewer emails to more people who want them, and their reply rates show it.
Bad data forces you to guess. Guessing produces the 2,000-contact blast, the complaint, and the deliverability collapse that follows.
A prospect who trusts that stop means stop is a prospect you can go back to in eighteen months when their budget cycle turns. Compu-Finder spent five years in litigation over three email campaigns. The records it couldn't produce cost far more than the records would have.
That's the real return here. Not fine avoidance. Permission to keep talking to your market.
See how SMARTe finds verified mobile numbers in your target accounts, with sourcing you can defend.




