Compliance
Who is liable when a vendor calls on a client’s behalf?
Updated
Under the TCPA both sides of the arrangement are exposed, on two different theories. The entity that physically places the call is directly within the statute, and the seller whose offer the call is about may be vicariously liable under federal common law agency principles for a third-party telemarketer’s violations — including through apparent authority and ratification. Liability is not something a service agreement moves from one party to the other.
For an agency running this across several clients at once, that has a specific consequence that has nothing to do with contracts: consent runs to the entity named on the form, so a consent record cannot be pooled across clients even in principle. That constraint shapes the architecture more than any clause does.
This is not legal advice
If a vendor places the calls, is the vendor exposed or the client?
Both, and by different routes. Section 227(b) reaches the person who makes the restricted call, so the entity operating the dialler is inside the statute on its own account. There is no version of “we were only the supplier” that helps, because supplying the call is what makes you the one making it.
The seller is reached separately. In its 2013 DISH Network declaratory ruling the FCC concluded that although “a seller does not generally ‘initiate’ calls made through a third-party telemarketer within the meaning of the TCPA, it nonetheless may be held vicariously liable under federal common law principles of agency for violations of either section 227(b) or section 227(c)”[1], and that a seller may be liable where a telemarketer acted with apparent authority, or where the seller ratified the acts by knowingly accepting their benefits.
Note what the apparent-authority limb describes: a call placed under the client’s brand, stating the client’s name as the responsible party, sourced from the client’s own registration page. That is not an edge case in this category — it is the normal configuration, and it is what the client is buying. Saying so out loud is more useful to a buyer than a reassurance that avoids it.
Why can't one consent record cover more than one client?
Because the consent names somebody, and the somebody is the point. The FTC’s Telemarketing Sales Rule requires, for prerecorded telemarketing, an express written agreement that “evidences the willingness of the recipient of the call to receive calls that deliver prerecorded messages by or on behalf of a specific seller”[2], carrying that person’s telephone number and signature. The FCC’s written-consent definition works the same way. A specific seller is not a category of seller.
| Artifact | Scope | Why |
|---|---|---|
| The consent record | One named client, never pooled | Consent runs to the entity named on the form. A registrant who agreed to one business has not agreed to another. |
| The name stated at the start of the call | The same named client | The identification duty attaches to the entity responsible for initiating the call, and it should match the name on the form. |
| The suppression list | Travels with the client — and is also enforced across everything | An opt-out belongs to the person who gave it. Honouring it only inside one campaign is the failure mode, not the safeguard. |
| Registrant data, recordings and transcripts | Siloed per client | The client's registrants are the client's, and a shared pool is a consent problem before it is a privacy one. |
| Do-not-call requests | Honoured “for 5 years from the time the request is made” | 47 CFR § 64.1200(d)(6). The rule is an obligation to honour the request, not a records-retention period. |
The practical shape of that is unglamorous. Numbers, sender identity and data live per client rather than in one shared pool, an opt-out arriving on any channel propagates everywhere rather than staying where it landed, and revocation is honoured as an instruction rather than argued with — the rule allows a reasonable time not to exceed ten business days[3], which is a ceiling rather than a target.
What should an agency ask before putting a client's name on the calls?
These are questions rather than requirements, because an agency that walks into a vendor conversation with them learns more than one that walks in with a checklist. They are also the questions we expect to be asked, which is the more honest reason to publish them.
Whose number do the calls and texts come from, and who owns it on the way out?
A number tied to the vendor rather than to the client is a switching cost dressed as an integration. Ask what happens to it, and to the reputation attached to it, if the relationship ends.
Is the sender identity per client, or shared?
The name stated at the start of the call should be the client's registered entity, matching the name on the consent form. A shared identity across clients is the arrangement the named-seller rule is least comfortable with.
Are registrant data, recordings and transcripts siloed per client?
Ask where one client's data physically sits relative to another's, and what a request to delete it actually deletes. Then ask the same question about what happens on cancellation.
Does the suppression list travel with the client?
If a registrant opts out, that instruction belongs to them and to the client they gave it to. Ask whether it is exportable, whether it survives the end of the engagement, and whether it is enforced at dial time rather than at list-build time.
Who controls the script, and can the client see it before it runs?
A vendor who lets anybody inject unreviewed content into an outbound artificial-voice call has removed the one control that is entirely within their power. Ask who can change what, and who approves.
What is the non-solicit position on the client relationships?
Not a compliance question, but the one agencies raise first and vendors answer last. It belongs in the same conversation because it is decided by the same document.
One more, which decides more than it looks like it should: how a vendor is packaged is a compliance decision. A managed service and a self-serve tool are the same technology with different control surfaces, and the difference shows up in who can switch a safeguard off.
| Control | Run as a managed service | Handed over as a self-serve tool |
|---|---|---|
| Who reviews the consent form | Reviewed per client before anything dials | Whoever edits the registration page, with nobody reading it |
| Who controls the dial-time gates | The operator of the service | The buyer, who can usually switch them off |
| Can “no consent record, no dial” be enforced? | Yes, as a hard refusal | Only if it is built as non-optional — otherwise no |
| How many defective forms are possible | One per client onboarded, each of them seen | One per buyer, unbounded and unseen |
Does an indemnification clause solve this?
It does something narrower than the search for a template implies. An indemnity allocates cost between two parties who signed it. It does not decide who a plaintiff names, it does not bind a regulator, and it is worth whatever the indemnifying party is worth on the day the bill arrives.
Why there is no template on this page
What is worth discussing with counsel is narrower and duller than a template: who warrants the consent record for each number, what happens when it cannot be produced, who controls the script, how the indemnities run in both directions, and whether the insurance either party carries responds to a claim of this kind at all — a question for the insurer rather than an assumption. Those are the terms that decide outcomes; the boilerplate rarely does.
The prior question is usually the more useful one. Where a consent record is captured per client, produced on demand and enforced at dial time, most indemnity arguments never start, because the fact pattern they exist to allocate does not occur. What that record has to contain is set out on what your opt-in form must say.
Frequently asked questions
Not in the sense the question usually means. The vendor is directly exposed because it is the entity placing the call, and being the vendor is what makes it the maker rather than a defence. Separately, the FCC's 2013 DISH Network declaratory ruling held that a seller who does not itself initiate calls may still be vicariously liable under federal common law agency principles for a third-party telemarketer's violations of section 227(b) or 227(c). Two exposures, not one transferred exposure.
No, and this is the sharpest operational constraint for anyone running calls for more than one business. Consent runs to the entity named on the form. A registrant who consented to one coach has not consented to a different coach, and has not consented to the agency in the abstract. It has to be captured per client, in that client's own name, and it cannot be pooled or reused.
It allocates cost between the parties who signed it. It does not decide who a plaintiff names, it does not stop a regulator, and it is worth whatever the indemnifying party is worth when the bill arrives. We do not publish an indemnity template, because a clause detached from the facts of an arrangement is exactly the kind of document that reads like legal advice and is not.
That is a commercial question we treat as settled rather than a legal reading. Our assistant identifies itself as an assistant on every call, the client's own registered entity name is stated as the party responsible, and the client sees the scripts. An arrangement where the person answering the phone is misled is an arrangement where the client carries a risk they were never shown.
Section 227(b)(3) provides for actual monetary loss or $500 per violation, whichever is greater, and a court may increase the award to not more than three times that amount for a willful or knowing violation. A separate private right of action for do-not-call violations under section 227(c)(5) requires more than one telephone call within any 12-month period. The TCPA is a per-call statute, which is why the consent record rather than the call script is the control that matters.
No, and it is not written to. It describes what named orders, statutes and regulations say, with links so you can read them yourself. It does not review your contracts, your consent records or your client list, and it is not legal advice.
Whether the underlying calls are lawful at all is a different question, answered on is it legal to call and text registrants, and the rules that bind an artificial-voice call regardless of consent are on TCPA and AI voice calls. If you run this for other people’s clients, the agency page is for agencies. Once more, plainly: this page is not legal advice and it does not assess anyone’s compliance posture.
Founder & Operator, CallHush
Founder and operator of CallHush. The offer is one sentence: you run a webinar, and we increase your show-up rate and your post-webinar sales with an AI voice and SMS system. CallHush has no closed clients yet — the first engagement is a pilot run as a split of the client’s own registrant list, and nothing on this site is presented as a client result.
View all articles