Compliance

Who is liable when a vendor calls on a client’s behalf?

Updated

Under the TCPA both sides of the arrangement are exposed, on two different theories. The entity that physically places the call is directly within the statute, and the seller whose offer the call is about may be vicariously liable under federal common law agency principles for a third-party telemarketer’s violations — including through apparent authority and ratification. Liability is not something a service agreement moves from one party to the other.

For an agency running this across several clients at once, that has a specific consequence that has nothing to do with contracts: consent runs to the entity named on the form, so a consent record cannot be pooled across clients even in principle. That constraint shapes the architecture more than any clause does.

This is not legal advice

Everything here describes what a named FCC order, statute or regulation says, with a link so you can read it yourself. It is not a legal opinion, it does not review your contracts, your consent records or your client list, and it does not tell you that your arrangement is safe. Those are questions for a TCPA attorney looking at your actual agreements.

If a vendor places the calls, is the vendor exposed or the client?

Both, and by different routes. Section 227(b) reaches the person who makes the restricted call, so the entity operating the dialler is inside the statute on its own account. There is no version of “we were only the supplier” that helps, because supplying the call is what makes you the one making it.

The seller is reached separately. In its 2013 DISH Network declaratory ruling the FCC concluded that although “a seller does not generally ‘initiate’ calls made through a third-party telemarketer within the meaning of the TCPA, it nonetheless may be held vicariously liable under federal common law principles of agency for violations of either section 227(b) or section 227(c)”[1], and that a seller may be liable where a telemarketer acted with apparent authority, or where the seller ratified the acts by knowingly accepting their benefits.

$500
Per violation under § 227(b)(3) — or actual monetary loss, whichever is greater. A court may increase the award to not more than three times that amount
Source: 47 U.S.C. § 227(b)(3)
More than one
Calls within a 12-month period required before the separate § 227(c)(5) private right of action is available
Source: 47 U.S.C. § 227(c)(5)
Two theories
Direct liability for the entity making the call, and vicarious liability for the seller — neither displaces the other
Source: FCC 13-54, Declaratory Ruling

Note what the apparent-authority limb describes: a call placed under the client’s brand, stating the client’s name as the responsible party, sourced from the client’s own registration page. That is not an edge case in this category — it is the normal configuration, and it is what the client is buying. Saying so out loud is more useful to a buyer than a reassurance that avoids it.

Because the consent names somebody, and the somebody is the point. The FTC’s Telemarketing Sales Rule requires, for prerecorded telemarketing, an express written agreement that “evidences the willingness of the recipient of the call to receive calls that deliver prerecorded messages by or on behalf of a specific seller”[2], carrying that person’s telephone number and signature. The FCC’s written-consent definition works the same way. A specific seller is not a category of seller.

What travels with the client, and what an agency operating for several clients has to keep separate
ArtifactScopeWhy
The consent recordOne named client, never pooledConsent runs to the entity named on the form. A registrant who agreed to one business has not agreed to another.
The name stated at the start of the callThe same named clientThe identification duty attaches to the entity responsible for initiating the call, and it should match the name on the form.
The suppression listTravels with the client — and is also enforced across everythingAn opt-out belongs to the person who gave it. Honouring it only inside one campaign is the failure mode, not the safeguard.
Registrant data, recordings and transcriptsSiloed per clientThe client's registrants are the client's, and a shared pool is a consent problem before it is a privacy one.
Do-not-call requestsHonoured “for 5 years from the time the request is made”47 CFR § 64.1200(d)(6). The rule is an obligation to honour the request, not a records-retention period.
One seller
A written agreement has to evidence willingness to receive calls “by or on behalf of a specific seller” — not a category of seller
Source: 16 CFR § 310.4(b)(1)(v)
5 years
How long a do-not-call request must be honoured, from the time the request is made
Source: 47 CFR § 64.1200(d)(6)
10 business days
The outer limit for processing a revocation — a ceiling in the rule, not a service level to aim at
Source: 47 CFR § 64.1200(a)(10)

The practical shape of that is unglamorous. Numbers, sender identity and data live per client rather than in one shared pool, an opt-out arriving on any channel propagates everywhere rather than staying where it landed, and revocation is honoured as an instruction rather than argued with — the rule allows a reasonable time not to exceed ten business days[3], which is a ceiling rather than a target.

What should an agency ask before putting a client's name on the calls?

These are questions rather than requirements, because an agency that walks into a vendor conversation with them learns more than one that walks in with a checklist. They are also the questions we expect to be asked, which is the more honest reason to publish them.

1

Whose number do the calls and texts come from, and who owns it on the way out?

A number tied to the vendor rather than to the client is a switching cost dressed as an integration. Ask what happens to it, and to the reputation attached to it, if the relationship ends.

2

Is the sender identity per client, or shared?

The name stated at the start of the call should be the client's registered entity, matching the name on the consent form. A shared identity across clients is the arrangement the named-seller rule is least comfortable with.

3

Are registrant data, recordings and transcripts siloed per client?

Ask where one client's data physically sits relative to another's, and what a request to delete it actually deletes. Then ask the same question about what happens on cancellation.

4

Does the suppression list travel with the client?

If a registrant opts out, that instruction belongs to them and to the client they gave it to. Ask whether it is exportable, whether it survives the end of the engagement, and whether it is enforced at dial time rather than at list-build time.

5

Who controls the script, and can the client see it before it runs?

A vendor who lets anybody inject unreviewed content into an outbound artificial-voice call has removed the one control that is entirely within their power. Ask who can change what, and who approves.

6

What is the non-solicit position on the client relationships?

Not a compliance question, but the one agencies raise first and vendors answer last. It belongs in the same conversation because it is decided by the same document.

One more, which decides more than it looks like it should: how a vendor is packaged is a compliance decision. A managed service and a self-serve tool are the same technology with different control surfaces, and the difference shows up in who can switch a safeguard off.

The same capability, two shapes — what changes about control
ControlRun as a managed serviceHanded over as a self-serve tool
Who reviews the consent formReviewed per client before anything dialsWhoever edits the registration page, with nobody reading it
Who controls the dial-time gatesThe operator of the serviceThe buyer, who can usually switch them off
Can “no consent record, no dial” be enforced?Yes, as a hard refusalOnly if it is built as non-optional — otherwise no
How many defective forms are possibleOne per client onboarded, each of them seenOne per buyer, unbounded and unseen

Does an indemnification clause solve this?

It does something narrower than the search for a template implies. An indemnity allocates cost between two parties who signed it. It does not decide who a plaintiff names, it does not bind a regulator, and it is worth whatever the indemnifying party is worth on the day the bill arrives.

Why there is no template on this page

A clause detached from the facts of an arrangement is the exact shape of document that reads like legal advice and is not, and publishing one would invite somebody to paste it into a contract without counsel. We are also not going to advertise an indemnity we have not agreed with you: what sits in a specific agreement is a negotiation between the parties to it, and pre-announcing a position on a web page is how vendors end up bound to something they have not thought through.

What is worth discussing with counsel is narrower and duller than a template: who warrants the consent record for each number, what happens when it cannot be produced, who controls the script, how the indemnities run in both directions, and whether the insurance either party carries responds to a claim of this kind at all — a question for the insurer rather than an assumption. Those are the terms that decide outcomes; the boilerplate rarely does.

The prior question is usually the more useful one. Where a consent record is captured per client, produced on demand and enforced at dial time, most indemnity arguments never start, because the fact pattern they exist to allocate does not occur. What that record has to contain is set out on what your opt-in form must say.

Frequently asked questions

Whether the underlying calls are lawful at all is a different question, answered on is it legal to call and text registrants, and the rules that bind an artificial-voice call regardless of consent are on TCPA and AI voice calls. If you run this for other people’s clients, the agency page is for agencies. Once more, plainly: this page is not legal advice and it does not assess anyone’s compliance posture.

JB
Justas Butkus

Founder & Operator, CallHush

Founder and operator of CallHush. The offer is one sentence: you run a webinar, and we increase your show-up rate and your post-webinar sales with an AI voice and SMS system. CallHush has no closed clients yet — the first engagement is a pilot run as a split of the client’s own registrant list, and nothing on this site is presented as a client result.

View all articles