Skip to main content
VA Horizon
Book a Call
Compliance

Who’s Liable When an Agency Runs a Client’s Outreach Campaign and It Breaks CAN-SPAM or TCPA

Quick answer

Two doctrines answer this from opposite directions, and neither hands the whole answer to one side. Under CAN-SPAM, per sender.net, liability for a commercial email campaign cannot be outsourced to an ESP, cold-email tool, or agency partner, meaning the underlying business the email promotes stays exposed even after hiring an agency to run the send, with a maximum civil penalty reaching $53,088 per non-compliant email in 2026, an inflation-adjusted FTC figure this research could only corroborate through a secondary source, so confirm it against the FTC’s current guide before treating it as a locked number. Under TCPA, the FCC’s 2013 ruling in FCC 13-54 applies ordinary federal agency-law principles, meaning a business can be held vicariously liable for calls or texts a vendor makes on its behalf under actual authority, apparent authority, or ratification, even though it never personally placed the contact.

Read together, both doctrines point at the same uncomfortable conclusion: the agency running the campaign and the client whose business it promotes can both end up exposed, and neither statute lets either side simply point at the other. What determines who pays is the service agreement in place before the campaign runs, specifically who is named as sender or initiator of record, which party indemnifies the other, and what insurance and audit rights sit behind that answer.

The Fact Pattern This Guide Is Scoped To

This is not about an agency’s own new-business prospecting, and it is not about a business hiring a subcontractor to run outreach for its own internal portfolio. It is the fact pattern that sits between those two: a client hires a marketing agency, and the agency runs an outbound campaign, cold email, SMS, or both, on the client’s behalf, using the client’s brand and offer. That campaign then breaks CAN-SPAM or TCPA, and the question is whether the agency answers for it as the operator, the client answers for it as the underlying business, or both do.

Two guides already live on this site and cover adjacent ground without answering this specific question. One covers CAN-SPAM as it applies to an agency’s own prospecting emails. The other covers the federal TCPA framework generally. Neither one is written from the angle of an agency acting as a hired vendor running a client’s campaign, which is the scope of everything below.

TCPA’s Vicarious Liability Doctrine, and Why the Client Doesn’t Get to Say It Wasn’t Them

The FCC’s 2013 declaratory ruling, known as FCC 13-54, addressed exactly this kind of arrangement for calls and texts. It held that a company can be vicariously liable under TCPA for calls or texts a third-party vendor makes on its behalf, under ordinary federal common-law agency principles, even without personally placing the call itself. Three doctrines carry that liability across to the client: actual authority (the client explicitly told the agency what to send and to whom), apparent authority (the client’s own conduct made it reasonable for a recipient, or a court, to believe the agency was acting for it), and ratification (the client accepted the benefit of the campaign, new leads, booked meetings, after learning how it was run).

A typical agency engagement checks most of these boxes by default. The client approves the campaign strategy, supplies or approves the contact list, reviews the messaging, and then keeps the meetings the campaign books. That is close to a textbook description of actual authority and ratification both, which is exactly why “the agency sent it, not us” is a weaker defense than it sounds.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

CAN-SPAM’s Non-Delegable Rule, Read From the Agency’s Side of the Contract

CAN-SPAM runs the same non-delegable logic from the email side, and it is already established on this site: per sender.net, liability cannot be outsourced to an ESP, cold-email tool, or agency partner, and the sending business remains responsible regardless of who operates the send button. That rule was written to stop a client from hiring an agency specifically to create distance from a campaign it directed. It does not, on its own, say the agency escapes exposure either. CAN-SPAM’s framework can reach multiple parties who know or should know a message is non-compliant, which is the reason an agency that operates the send button is not automatically outside the statute’s reach just because the underlying business is the one the rule was primarily written to catch.

The practical read: CAN-SPAM was built to keep the client from hiding behind the agency, and TCPA’s vicarious liability doctrine was built to keep the client from hiding behind the vendor relationship generally. Both rules exist because regulators anticipated exactly this kind of hired-vendor arrangement and wrote the doctrine to prevent it from becoming an escape hatch for either side.

Why Duguid’s Capability Test Still Matters for Who Triggered the Rule

One more piece of settled law belongs in this picture. The Supreme Court’s 2021 ruling in Facebook v. Duguid held that an “automatic telephone dialing system” under TCPA must have the capacity to store or produce phone numbers using a random or sequential number generator, a technology-defined test that turns on the calling or texting system’s capability, not on who typed the message or which department approved it. For an agency-run campaign, that test decides whether the stricter TCPA consent requirements were triggered in the first place, a separate question from who is vicariously liable once they are. Both questions can matter on the same campaign: whether the system used counts as an ATDS, and, if the answer is yes, whether the client is on the hook for what its hired agency did with it.

What the Service Agreement Has to Allocate, Point by Point

Because neither statute cleanly hands the whole answer to one party, the contract between agency and client is where the real allocation happens. Four things belong in it explicitly, not left implied. First, who is named the CAN-SPAM sender or TCPA initiator of record for the campaign, a designation that shapes which party a regulator or a plaintiff’s attorney looks to first. Second, which direction indemnification runs, and for what: standard contract-negotiation guidance holds that a party should indemnify only for its own negligence, not accept sweeping or unlimited indemnification for the other side’s decisions, and that whoever controls legal defense and strategy on a claim materially changes that party’s actual cost exposure if one arrives.

Third, what errors-and-omissions insurance either party carries specifically for outreach-compliance claims, since indemnity obligations typically sit outside standard liability coverage, which can leave a party that agreed to broad indemnification exposed to costs no policy covers. Fourth, what audit rights the agency has over a client-supplied contact list, and what audit rights the client has over the agency’s consent-documentation practices, since a dispute about who caused a violation usually turns on which party can produce a record.

Building the Allocation In Before the Campaign Launches

  1. Name the sender or initiator of record for the specific campaign in the service agreement, not left to be inferred after a complaint arrives.
  2. Write indemnification to cover each party’s own negligence, not a blanket transfer of risk to whichever side has less leverage in the negotiation.
  3. Confirm whether either party’s existing liability insurance covers an outreach-compliance claim, since indemnity commitments often fall outside standard coverage.
  4. Build in an audit right: the agency’s standing to review how a client-supplied list was built, and the client’s standing to review the agency’s consent records.
  5. Document who approved what, and when, throughout the campaign, since actual authority and ratification are both proven with a record, not a recollection.

Where This Leaves an Agency Evaluating Its Own Vendors

None of the above is legal advice, and the doctrine summarized here is well-established but general. The specific language in a specific service agreement, read by a lawyer who can see the actual contract, is the qualified next step for any agency currently negotiating this exact allocation. What the doctrine does make clear is that “we hired a vendor” was never a liability shield on either side of this relationship, for the client hiring the agency or for the agency itself when it evaluates a vendor of its own.

Human + AI SDRs run every conversation over SMS on the VA Horizon Private CRM, with consent and the full exchange preserved as a timestamped transcript rather than a verbal claim, which is the kind of record this exact liability question keeps coming back to needing.

What this means for you

  • CAN-SPAM’s non-delegable liability rule and TCPA’s FCC 13-54 vicarious liability doctrine both point at hired-vendor arrangements directly, and neither one lets a client or an agency fully offload exposure onto the other.
  • TCPA vicarious liability under FCC 13-54 runs on actual authority, apparent authority, or ratification, three doctrines a typical agency engagement (approved strategy, supplied list, kept results) tends to satisfy by default.
  • CAN-SPAM’s maximum civil penalty is $53,088 per non-compliant email in 2026, an inflation-adjusted, secondary-sourced figure worth re-verifying against the FTC’s current guide before repeating it as fixed.
  • The service agreement, not the statute alone, is where sender-of-record designation, indemnification direction, E&O insurance, and audit rights get allocated between agency and client.

Sources

The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

If a client hires an agency to run its outreach, does the client stay liable if it breaks TCPA?
Often, yes. The FCC’s FCC 13-54 ruling holds a business can be vicariously liable for a vendor’s calls or texts under actual authority, apparent authority, or ratification, three standards a typical agency engagement, where the client approves strategy and keeps the resulting meetings, tends to satisfy.
Does hiring an agency shift CAN-SPAM liability away from the client?
No. CAN-SPAM liability cannot be outsourced to an ESP, cold-email tool, or agency partner, and the underlying sending business remains responsible. That does not automatically clear the agency either, since CAN-SPAM can reach a party that operated the send button and knew or should have known of a violation.
Does using an autodialer or automated texting tool change who is liable?
The Supreme Court’s Facebook v. Duguid ruling defines an automatic telephone dialing system by whether it can store or produce numbers using a random or sequential generator, a capability test that determines whether TCPA’s stricter consent rules were triggered at all, a separate question from who bears vicarious liability once they were.
What should an agency-client contract specify about outreach liability?
Four things: who is the CAN-SPAM sender or TCPA initiator of record, which direction indemnification runs and for what, what E&O insurance covers an outreach-compliance claim specifically, and what audit rights each party has over the other’s list-sourcing or consent-documentation practices.
Is this guide legal advice for a specific agency-client contract?
No. It summarizes well-established, general doctrine. A lawyer reviewing the actual contract language is the qualified next step for any agency or client negotiating this specific allocation.

A documented transcript beats a liability argument.

Book a 15-minute call and see how Human + AI SDRs keep every SMS conversation, and the consent behind it, on record in the VA Horizon Private CRM, priced per booked meeting with no retainer.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement