Written by: Matt Beucler, CEO, Plura AI
Updated September 2026
Key Takeaways for Agency Leaders
- Agencies share TCPA risk with their clients, including statutory damages of $500-$1,500 per violation and potential eight-figure class-action exposure.2
- Consent, DNC suppression, and opt-out records must be tracked separately for each client and campaign to prevent cross-contamination of risk.
- Core 2026 requirements include prior express written consent naming the specific client, 31-day DNC scrubbing, 8 a.m.-9 p.m. local time windows, and honoring revocations within 10 business days.
- Lead generation consent needs to identify the specific client by legal name; broad “marketing partners” language creates significant litigation exposure.
- Agencies that operationalize these pillars per client reduce vicarious liability and class-action exposure across their portfolios.
Why Agencies Face Elevated TCPA Risk
Agencies that run outbound campaigns often sit in the middle of the TCPA risk chain. Under federal common-law agency principles in the FCC’s 2013 Declaratory Ruling (FCC 13-54), a seller can face vicarious liability for TCPA violations committed by third-party telemarketers acting on its behalf.2 That framework covers marketing agencies, contact centers, and lead-gen partners executing campaigns for brands.
Three theories typically appear in litigation: actual authority, apparent authority, and ratification. Ratification creates particular risk for agencies and brands. A court can find ratification when a party learns of potential violations and does not take corrective action, such as pausing campaigns, updating scripts, or changing vendors.
Consent and DNC obligations attach to the specific seller named in the consent record, so agencies must track them per client. An agency that sends texts for two different clients needs separate consent records for each. A consumer who consented to Client A’s messages has not consented to Client B’s outreach.
This principle is reinforced by 47 C.F.R. § 64.1200(d)(3), which states that when a party other than the seller records or maintains do-not-call requests, the seller remains liable for failures to honor those requests. In practice, the brand and the agency both stay in the frame, even when a third party manages lists.
The Core Requirements: Five Pillars of TCPA Compliance
Key Requirements: TCPA Compliance for Agencies
- Prior Express Written Consent (PEWC) for autodialed or prerecorded calls and texts, as defined in 47 C.F.R. § 64.1200(f)(9).
- Time restrictions: calls and texts only between 8 a.m. and 9 p.m. local time at the recipient’s location.
- DNC compliance: National Registry scrubbing at least every 31 days under 47 C.F.R. § 64.1200(c)(2)(i)(D).
- Caller ID and disclosure requirements: accurate caller ID plus agent name, company name, and contact information on every outbound contact.
- Opt-out and revocation handling: honor within 10 business days and maintain internal suppression lists per client for at least 5 years under 47 C.F.R. § 64.1200(d)(3) and (d)(6).
Each pillar needs enforcement at the campaign level for each client. A single global DNC scrub or consent list for the entire agency does not align with how regulators and courts assign responsibility.
New TCPA Developments Impacting 2026 Campaigns
Several recent FCC actions and court decisions affect how agencies structure outbound programs. Leadership teams should understand these shifts before planning 2026 campaigns.
The FCC’s one-to-one consent rule came in December 2023 and was later vacated by the Eleventh Circuit in January 2025 in Insurance Marketing Coalition v. FCC (No. 24-10277). The court found that the FCC exceeded its statutory authority. The underlying requirement that consent clearly identify the caller still appears in 47 C.F.R. § 64.1200(f)(9), and courts continue to reject broad “marketing partners” consent language.
The FCC’s revocation rules, effective April 11, 2025, describe how consumers can revoke consent by any reasonable method. Callers must honor revocations within 10 business days. A broader rule that would treat a single revocation as cutting off all communications from the same sender has been delayed to January 31, 2027.
The FCC’s February 8, 2024 Declaratory Ruling classifies AI-generated voices as “artificial” under the TCPA. AI voice calls now sit in the same consent bucket as prerecorded messages. Telemarketing AI calls to cell phones require prior express written consent.
In March 2026, the FCC released a Notice of Proposed Rulemaking on call center onshoring. This NPRM outlines potential future requirements but does not yet create binding obligations.5
On July 14, 2026, the Seventh Circuit decided Steidinger v. Blackstone Medical Services. The court held that text messages are not “calls” under Section 227(c)(5) of the TCPA, creating a circuit split with the Ninth Circuit. The decision does not change other TCPA text-message requirements, including consent under Section 227(b) and revocation handling.
Financial Exposure: Penalties for TCPA Violations
TCPA exposure scales quickly for high-volume operations. Statutory damages under 47 U.S.C. § 227(b)(3) are $500 per violation, with potential trebling to $1,500 for willful or knowing violations. Each call or text counts as a separate violation. A campaign of 10,000 records with bad consent can create $5 million to $15 million in potential exposure.3
TCPA claims carry a four-year statute of limitations under 28 U.S.C. § 1658. WebRecon’s January 2026 litigation statistics show that 77.6% of TCPA filings were putative class actions3, so most matters arrive at class scale. Agencies can appear alongside clients under vicarious liability theories.
Class action settlements have averaged $6.6 million3, and some individual enforcement actions have reached hundreds of millions of dollars. For agencies that dial or text at scale, a single systemic gap can become a balance-sheet event.
Collecting Prior Express Written Consent for Each Client
Strong consent flows give agencies and clients the best footing when campaigns are challenged. Consent must be clear, conspicuous, and specific to the seller. Under 47 C.F.R. § 64.1200(f)(9), prior express written consent is a written agreement that bears the signature of the person called and clearly authorizes a specific seller to deliver marketing messages using an autodialer or artificial or prerecorded voice. The agreement also states that consent is not a condition of purchase.
Lead form practices that support agency campaigns include:
- A clear, unchecked checkbox that requires affirmative consumer action.
- A disclosure that names the specific client by legal entity name instead of “our partners.”
- A statement that consent is not a condition of purchase.
- A link to the client’s privacy policy.
- Timestamped consent records that store IP address, source URL, and the exact disclosure text shown at the time of opt-in.
Compliant disclosure language for a lead form can read: “By clicking Submit, I agree to be contacted by [Client Legal Name] at the number I provided, including by autodialer or prerecorded message, for marketing purposes. Consent is not a condition of purchase.”
Non-compliant language reads: “By submitting this form, you agree to be contacted by our marketing partners.” Courts have repeatedly struck down such language because it does not clearly identify who will be calling.
Do Not Call List Compliance for Agency Campaigns
Agencies need DNC controls that match how they actually run campaigns. They must scrub against the National DNC Registry and maintain internal suppression lists for each client. The DNC scrub must use a registry version obtained no more than 31 days before any call under 47 C.F.R. § 64.1200(c)(2)(i)(D). Internal do-not-call requests must be honored within 10 business days and retained for 5 years under 47 C.F.R. § 64.1200(d)(3) and (d)(6).
DNC scrubbing needs to occur per client. A number on Client A’s suppression list may still be reachable for Client B if the consumer separately consented to Client B’s outreach. Mixing suppression lists across clients can create compliance gaps and also remove valid records, which reduces reachable volume.
Dialers should determine the recipient’s time zone based on actual geographic location, not area code. Consumers frequently keep numbers after moving. A 6 p.m. call from a Pacific-time office to an Eastern-time consumer at 9:05 p.m. in their local time falls outside the permitted window.
Multi-Client Attribution: Keeping Consent and DNC Separate
Multi-client operations introduce a specific operational risk: mixing consent and DNC data across brands. A consumer who opted out of Client A’s messages has not opted out of Client B’s messages. A consumer who consented to Client A’s outreach has not consented to Client B’s campaigns. Treating these records as interchangeable often drives agency-level TCPA exposure.
A practical multi-client attribution framework includes:
- Separate consent records for each client, tagged to the client’s legal entity name.
- Separate DNC suppression lists for each client, with documented scrub dates.
- Separate opt-out lists for each client, with timestamps and revocation method recorded.
- Audit trails for each client, exportable on demand for legal review or carrier requirements.
Use a CRM or compliance platform that tags consent and DNC status by client and campaign. Under 47 C.F.R. § 64.1200(d)(3), when a party other than the seller records or maintains do-not-call requests, the seller remains liable for failures to honor those requests. Technology partners can help manage the process, but they do not remove the underlying responsibility.
Once internal tracking is in place, the next major risk area is the source of leads. Lead generation consent often fails to name the specific client, which creates exposure before a campaign even starts.
Lead Generation Consent: Closing the “Marketing Partners” Gap
Lead-buying programs can quietly introduce TCPA risk into otherwise disciplined operations. Broad consent to “marketing partners” remains a litigation risk even after the one-to-one rule was vacated. A consumer who agreed to hear from a long list of “partners” can argue they never agreed to outreach from a specific caller by name. The vacating of the FCC one-to-one rule did not validate broad consent language; it left the prior standard in place.
When buying leads, agencies can require contractual representations that consent was collected naming the agency’s specific client. Before purchasing third-party leads, send vendors a written questionnaire. Request a sample consent record with timestamp and IP address, the exact consent form text consumers saw, confirmation of DNC scrubbing frequency, and a signed compliance attestation. Spot-check a sample of leads to confirm consumers remember opting in to the specific client by name.
Lead generation forms should avoid vague language like “our partners” or “third-party marketers”. Forms should list the exact legal name of the business that will contact the consumer, with the disclosure placed immediately next to the consent mechanism.
Contracts and Vendor Management for TCPA Controls
Vendor oversight is a core part of an agency’s TCPA risk posture. Generic “comply with all applicable laws” language has been rejected by courts as insufficient because it does not show that the brand exercised real oversight. Vendor contracts benefit from specific operational controls, audit rights, and clear allocation of liability.
A vendor compliance checklist for agency operations includes:
- Confirm that the vendor collects and stores full consent records (timestamp, IP address, source URL, exact disclosure text, affirmative action) and can produce them within 72 hours of a request.
- Require proof of National DNC Registry scrubs within 31 days before any campaign.
- Require indemnification that names TCPA and applicable state mini-TCPA statutes explicitly and covers statutory damages and defense costs from day one.
- Secure audit rights with a defined production deadline, typically 72 hours for consent records.
- Require errors and omissions or commercial general liability insurance with the agency named as an additional insured, with a minimum of $1 million per occurrence for smaller vendors and higher limits for high-volume partners.
- Run vendor names and key principals through PACER to check for prior TCPA litigation history before signing.
A compliance clause in a vendor contract is a promise, but an audit is proof. Run formal audits quarterly for high-volume vendors and annually for lower-volume ones, and document every audit in writing.
How Plura AI Helps Agencies Support Compliance
Plura AI is an FCC-licensed communications platform built for high-volume outbound operations. Its compliance engine functions as a core layer of the platform and enforces controls at the carrier level before each contact.

For agencies running multi-client campaigns, Plura’s platform includes:
- Real-time DNC scrubbing against federal and state registries before every dial, with immutable scrub logs per campaign.
- Timestamped, audit-ready consent logging that cannot be altered after capture.
- Automated quiet-hours enforcement through time-zone detection at the recipient’s location.
- Per-campaign compliance settings for multi-client attribution, so consent and suppression records stay separated by client.
- TCPA-litigator screening on every outbound contact.
- 100% U.S. infrastructure by architecture, which avoids offshore exposure under the FCC NPRM and state onshoring laws.
Plura’s AI Predictive Dialer enforces calling-window restrictions and DNC suppression at the carrier level on every outbound dial. Plura’s AI SMS platform applies the same consent and suppression logic to text campaigns, with 10DLC-registered numbers and per-campaign opt-out handling. Plura supports real-time TCPA-litigator and DNC screening on outbound contacts across client accounts.

1
Plura supports compliance for agencies by providing enforcement tools and audit-ready records. Customers remain responsible for their own regulatory obligations, consent collection practices, and the claims they make to their end users.
Watch the compliance engine in action across voice and SMS campaigns in a live demo.
Checklist: TCPA Compliance Priorities for Agencies
- Obtain prior express written consent for each client, naming that specific client’s legal entity.
- Scrub all numbers against the National DNC Registry at least every 31 days before any campaign.
- Honor internal suppression lists for each client within 10 business days of any opt-out or revocation.
- Call or text only between 8 a.m. and 9 p.m. local time at the recipient’s location.
- Provide clear opt-out instructions in every message and honor any reasonable revocation method.
- Track consent and DNC status separately for each client instead of using a single agency-wide list.
- Audit vendors and contracts quarterly for high-volume vendors and annually for lower-volume ones.
- Retain consent records, DNC scrub logs, and opt-out requests for at least 4 years, with 5 years as a stronger operational target.
- Verify that lead-generation consent names the specific client before purchasing any leads.
- Train every agent on TCPA basics and the agency’s specific per-client procedures.
Conclusion and Next Steps for Agency Teams
Agencies share TCPA liability with their clients, so consent and DNC records need to align with how campaigns are sold and executed. Records should be tracked for each client, and lead-generation consent should name the specific seller. Vendor contracts benefit from clear compliance language, audit rights, and indemnification that covers defense costs from the outset.
Practical next steps include reviewing current consent records to confirm that each names the correct client legal entity. Leadership teams can also audit DNC scrubbing processes to confirm per-client separation and evaluate whether the current dialer and SMS platforms enforce controls at the carrier level before each contact.
Compare Plura plans and rates to see how per-campaign compliance enforcement is structured for multi-client agency operations.
FAQ
What Is the One-to-One Consent Rule?
The FCC’s one-to-one consent rule, adopted in December 2023, would have required consent to name a single seller. The Eleventh Circuit vacated it in January 2025 in Insurance Marketing Coalition v. FCC, finding that the FCC exceeded its statutory authority. The requirement that consent clearly identify the caller remains in 47 C.F.R. § 64.1200(f)(9), and courts continue to treat broad “marketing partners” language as weak support for prior express written consent.
Can an Agency Use a Lead Generator’s Consent for Its Client?
An agency can rely on a lead generator’s consent when the consent form specifically names the client as the seller. Generic consent to “marketing partners” does not align with the requirement that consent clearly authorize a specific seller to deliver messages. Agencies can request the exact consent form text, confirm that the client’s legal name appears in the disclosure, and retain a copy of that consent record tied to each lead before automated outreach begins.
Do Agencies Need to Scrub DNC for Every Campaign?
Agencies need DNC scrubbing that matches each client’s campaigns. The National DNC Registry must be scrubbed at least every 31 days before any call under 47 C.F.R. § 64.1200(c)(2)(i)(D), and internal suppression lists must be maintained for each client. Each client’s campaigns should have their own DNC documentation, including scrub date, record count, and scrub provider.
What Are the Penalties for TCPA Violations?
As outlined in the penalties section above, statutory damages generally range from $500 to $1,500 per violation, and most TCPA matters arrive as putative class actions. Agencies can review the earlier “Financial Exposure” section for the full breakdown and example calculations.
How Should Agencies Handle Opt-Outs Across Multiple Clients?
Agencies should maintain separate suppression lists for each client and treat opt-outs at the client level. A consumer who opts out of Client A’s messages has not automatically opted out of Client B’s messages. When a consumer revokes consent for a specific client through any reasonable method, that revocation should apply across all campaigns for that client. Under FCC rules effective April 2025, revocations must be honored within 10 business days. Internal do-not-call requests must be retained for at least 5 years under 47 C.F.R. § 64.1200(d)(6), and opt-out requests from any channel should feed into the relevant client’s suppression list.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
5 This article contains forward-looking statements regarding industry trends, technology adoption, and future capabilities. These statements reflect current expectations and are subject to change. Plura AI undertakes no obligation to update forward-looking statements except as required.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.