The Fact Pattern This Guide Is Scoped To
This is not about an agency’s own new-business prospecting, and it is not about a business hiring a subcontractor to run outreach for its own internal portfolio. It is the fact pattern that sits between those two: a client hires a marketing agency, and the agency runs an outbound campaign, cold email, SMS, or both, on the client’s behalf, using the client’s brand and offer. That campaign then breaks CAN-SPAM or TCPA, and the question is whether the agency answers for it as the operator, the client answers for it as the underlying business, or both do.
Two guides already live on this site and cover adjacent ground without answering this specific question. One covers CAN-SPAM as it applies to an agency’s own prospecting emails. The other covers the federal TCPA framework generally. Neither one is written from the angle of an agency acting as a hired vendor running a client’s campaign, which is the scope of everything below.
TCPA’s Vicarious Liability Doctrine, and Why the Client Doesn’t Get to Say It Wasn’t Them
The FCC’s 2013 declaratory ruling, known as FCC 13-54, addressed exactly this kind of arrangement for calls and texts. It held that a company can be vicariously liable under TCPA for calls or texts a third-party vendor makes on its behalf, under ordinary federal common-law agency principles, even without personally placing the call itself. Three doctrines carry that liability across to the client: actual authority (the client explicitly told the agency what to send and to whom), apparent authority (the client’s own conduct made it reasonable for a recipient, or a court, to believe the agency was acting for it), and ratification (the client accepted the benefit of the campaign, new leads, booked meetings, after learning how it was run).
A typical agency engagement checks most of these boxes by default. The client approves the campaign strategy, supplies or approves the contact list, reviews the messaging, and then keeps the meetings the campaign books. That is close to a textbook description of actual authority and ratification both, which is exactly why “the agency sent it, not us” is a weaker defense than it sounds.
CAN-SPAM’s Non-Delegable Rule, Read From the Agency’s Side of the Contract
CAN-SPAM runs the same non-delegable logic from the email side, and it is already established on this site: per sender.net, liability cannot be outsourced to an ESP, cold-email tool, or agency partner, and the sending business remains responsible regardless of who operates the send button. That rule was written to stop a client from hiring an agency specifically to create distance from a campaign it directed. It does not, on its own, say the agency escapes exposure either. CAN-SPAM’s framework can reach multiple parties who know or should know a message is non-compliant, which is the reason an agency that operates the send button is not automatically outside the statute’s reach just because the underlying business is the one the rule was primarily written to catch.
The practical read: CAN-SPAM was built to keep the client from hiding behind the agency, and TCPA’s vicarious liability doctrine was built to keep the client from hiding behind the vendor relationship generally. Both rules exist because regulators anticipated exactly this kind of hired-vendor arrangement and wrote the doctrine to prevent it from becoming an escape hatch for either side.
Why Duguid’s Capability Test Still Matters for Who Triggered the Rule
One more piece of settled law belongs in this picture. The Supreme Court’s 2021 ruling in Facebook v. Duguid held that an “automatic telephone dialing system” under TCPA must have the capacity to store or produce phone numbers using a random or sequential number generator, a technology-defined test that turns on the calling or texting system’s capability, not on who typed the message or which department approved it. For an agency-run campaign, that test decides whether the stricter TCPA consent requirements were triggered in the first place, a separate question from who is vicariously liable once they are. Both questions can matter on the same campaign: whether the system used counts as an ATDS, and, if the answer is yes, whether the client is on the hook for what its hired agency did with it.
What the Service Agreement Has to Allocate, Point by Point
Because neither statute cleanly hands the whole answer to one party, the contract between agency and client is where the real allocation happens. Four things belong in it explicitly, not left implied. First, who is named the CAN-SPAM sender or TCPA initiator of record for the campaign, a designation that shapes which party a regulator or a plaintiff’s attorney looks to first. Second, which direction indemnification runs, and for what: standard contract-negotiation guidance holds that a party should indemnify only for its own negligence, not accept sweeping or unlimited indemnification for the other side’s decisions, and that whoever controls legal defense and strategy on a claim materially changes that party’s actual cost exposure if one arrives.
Third, what errors-and-omissions insurance either party carries specifically for outreach-compliance claims, since indemnity obligations typically sit outside standard liability coverage, which can leave a party that agreed to broad indemnification exposed to costs no policy covers. Fourth, what audit rights the agency has over a client-supplied contact list, and what audit rights the client has over the agency’s consent-documentation practices, since a dispute about who caused a violation usually turns on which party can produce a record.
Building the Allocation In Before the Campaign Launches
- Name the sender or initiator of record for the specific campaign in the service agreement, not left to be inferred after a complaint arrives.
- Write indemnification to cover each party’s own negligence, not a blanket transfer of risk to whichever side has less leverage in the negotiation.
- Confirm whether either party’s existing liability insurance covers an outreach-compliance claim, since indemnity commitments often fall outside standard coverage.
- Build in an audit right: the agency’s standing to review how a client-supplied list was built, and the client’s standing to review the agency’s consent records.
- Document who approved what, and when, throughout the campaign, since actual authority and ratification are both proven with a record, not a recollection.
Where This Leaves an Agency Evaluating Its Own Vendors
None of the above is legal advice, and the doctrine summarized here is well-established but general. The specific language in a specific service agreement, read by a lawyer who can see the actual contract, is the qualified next step for any agency currently negotiating this exact allocation. What the doctrine does make clear is that “we hired a vendor” was never a liability shield on either side of this relationship, for the client hiring the agency or for the agency itself when it evaluates a vendor of its own.
Human + AI SDRs run every conversation over SMS on the VA Horizon Private CRM, with consent and the full exchange preserved as a timestamped transcript rather than a verbal claim, which is the kind of record this exact liability question keeps coming back to needing.
What this means for you
- CAN-SPAM’s non-delegable liability rule and TCPA’s FCC 13-54 vicarious liability doctrine both point at hired-vendor arrangements directly, and neither one lets a client or an agency fully offload exposure onto the other.
- TCPA vicarious liability under FCC 13-54 runs on actual authority, apparent authority, or ratification, three doctrines a typical agency engagement (approved strategy, supplied list, kept results) tends to satisfy by default.
- CAN-SPAM’s maximum civil penalty is $53,088 per non-compliant email in 2026, an inflation-adjusted, secondary-sourced figure worth re-verifying against the FTC’s current guide before repeating it as fixed.
- The service agreement, not the statute alone, is where sender-of-record designation, indemnification direction, E&O insurance, and audit rights get allocated between agency and client.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
- FCC, Declaratory Ruling and Order (FCC 13-54), TCPA vicarious liability
- Supreme Court of the United States, Facebook, Inc. v. Duguid (2021)
- sender.net, CAN-SPAM Act Compliance Guide
- Wikipedia, Indemnity
