A client hands you a CSV of 40,000 numbers. "Text everyone the launch offer." You load it, hit send, and three weeks later a demand letter shows up. It names the brand — and it names your agency. The client shrugs and points at you: "You sent it." You point back: "It was your list." Now you're both reading the same statute and hoping the other one blinks.

Full disclosure: I work for ReadySMS. We build SMS infrastructure a lot of agencies run their client sending through, so I've watched this exact standoff play out more than once. The uncomfortable answer is that under the TCPA, "you sent it" and "it was your list" can both be true at the same time — and the plaintiff's lawyer knows it.

The TCPA doesn't care whose CSV it was

The Telephone Consumer Protection Act creates a private right of action worth $500 per violation, trebled to $1,500 for willful or knowing violations. That's per text, not per campaign. A 40,000-message blast to numbers without valid consent isn't a $1,500 problem — it's an arithmetic problem with a lot of zeros.

Courts have consistently held that liability can attach to the party that physically initiated the message and to the party on whose behalf it was sent. That's the trap for agencies. You're the sender. Your client is the "on behalf of" party. Plaintiffs' firms routinely name both, because naming both maximizes the pool of insurance and assets they can reach.

So the real question isn't "who's liable" — it's often "both, until you've drawn a defensible line." Two things draw that line: the contract and the technical record of what actually happened.

What the client owns vs. what you own

Split responsibility along the thing each party actually controls. Here's the division that survives contact with a lawyer:

ResponsibilityWho owns itWhy
Obtaining and documenting consentClientThey own the customer relationship and the opt-in moment
Providing an accurate consent record on requestClientOnly they can attest to how a number got on the list
Honoring STOP / opt-outAgency (platform-enforced)You control the send system; you must not re-text an opt-out
Quiet-hours complianceAgency (platform-enforced)Timing is a sending decision, not a list decision
Litigator / DNC scrubbingShared, agency-executedYou run the scrub; the client decides whether to accept the cost
Message content (SHAFT, disclosures)SharedClient supplies intent; agency should catch violations

The pattern: the client owns provenance (where the number came from and whether there was consent), and the agency owns process (what the system does with those numbers once they're loaded). Both parties can breach independently. A client can hand you a list with zero consent. An agency can re-text someone who sent STOP last month. Different failures, same lawsuit.

If you take one thing from the table: **you cannot verify a client's consent for them, but you can control whether your system does the compliant thing on send.** Guard the second part relentlessly, because it's the part a plaintiff can prove or disprove from your logs.

The contract clauses that actually protect an agency

A handshake and a Slack message that says "we have consent, promise" is not a defense. You need language in the MSA or a compliance addendum. At minimum:

  1. Consent representation and warranty. The client represents that every number provided has prior express consent (and prior express written consent for marketing) valid under the TCPA, and that consent records will be produced within a defined window on request.
  2. Indemnification. The client indemnifies the agency for claims arising from the client's failure to obtain valid consent or from list defects. This is the clause that decides who ultimately pays after the dust settles.
  3. Right to scrub, and who eats the cost. State that the agency may run litigator/DNC scrubbing before send and that the client authorizes and pays for it — or explicitly declines in writing. A declined scrub in writing is worth its weight in gold later.
  4. List provenance disclosure. Require the client to tell you the source of each list. A purchased list from six months ago is a different risk than a list the client grew from web opt-ins — and it changes how often you should be re-scrubbing.

Indemnification doesn't make you immune. If the agency is negligent — re-texting opt-outs, ignoring quiet hours, blasting a purchased list you were told was purchased — a court can still hold you directly liable, and indemnity clauses have exceptions for the indemnified party's own misconduct. That's precisely why the technical guardrails matter as much as the paper.

There's a related clause most agencies forget entirely: what happens to the opt-in list when the client leaves. We wrote that up separately in the SMS offboarding clause post, and it belongs in the same addendum as everything above.

Guardrails your platform should enforce automatically

Contracts allocate blame after the fact. Platform enforcement prevents the violation in the first place — and produces the log that proves you weren't negligent. Here's what should be non-optional in your sending stack:

  • Automatic STOP / opt-out handling. When a contact replies STOP or UNSUBSCRIBE, the opt-out should propagate so that contact can't be messaged again across any campaign — not just the one they replied to. In ReadySMS this is automatic, which matters because the most common agency-caused violation isn't a bad list at all: it's re-texting someone who already opted out, across a different workflow, months later.
  • Quiet-hours enforcement. Sends outside permitted local hours (based on the recipient's area) get held. Quiet-hours violations are a favorite for plaintiff firms because they're trivially provable from a timestamp. If your platform holds the send, there's nothing to prove. More on why the smart quiet-hours window is tighter than the legal one is in this breakdown.
  • Litigator / DNC scrubbing. Screen known TCPA-litigator and DNC-complainer numbers before send. This is the standalone scrub at $0.005 per contact — on a 40,000-number list that's $200. Against a single $1,500-per-text exposure, the math isn't close. And DNC and litigator lists are not the same thing: a number can pass DNC and still sue you.
  • Consent / attestation capture. For bulk and API sends, the opt-in attestation gets recorded, building an audit trail that shows the agency asked and the client attested.

When a demand letter arrives, the difference between "we enforce STOP, quiet hours, and scrubbing at the platform level, here are the logs" and "uh, we sent what they gave us" is often the difference between a manageable client-indemnified claim and a joint liability nightmare.

Where the scrub cost decision gets uncomfortable

The awkward conversation is always the same: you tell the client scrubbing costs $0.005/contact, they say the list is "clean, we don't need it." Now what?

Two rules. First, get the refusal in writing — that's clause #3 above doing its job. Second, understand that "we grew this list ourselves" and "we bought this list six months ago" carry wildly different risk. A purchased or aged list needs re-scrubbing far more often; we laid out a source-based scrub schedule for exactly this reason. If a client refuses to scrub a purchased list, that's a moment to seriously consider whether you want your agency's name on that send at all.

Run the honest math for the client. A 40,000-contact scrub is $200. If even a handful of litigators are sitting on that list — and purchased lists are seeded with them precisely to generate suits — a single $1,500 claim wipes out 7,500 contacts' worth of scrubbing cost. The full lawsuit-vs-scrubbing comparison makes it hard to argue with.

The practical takeaway

Liability under the TCPA doesn't split cleanly by whose CSV it was — it splits by who controlled what, and both parties can breach at once. Your job as the agency is to own the process cleanly and push provenance responsibility onto the client with paper that holds up.

Concretely:

  • Put a consent warranty, indemnification, and a scrub-cost clause in every client agreement before you send a single text on their behalf.
  • Let the platform enforce STOP, quiet hours, and scrubbing automatically — so your logs prove you did the compliant thing regardless of what the client attested.
  • Treat a client's refusal to scrub a purchased list as a red flag, in writing, every time.

None of this makes anyone lawsuit-proof, and I won't pretend it does — compliance is ultimately the sender's responsibility, and that includes you. But an agency that draws the liability line with a real contract and automatic enforcement is in a completely different position from one relying on a client's "trust me."

If you want to see how the STOP handling, quiet-hours enforcement, and litigator scrubbing actually work in-app before you wire them into your client workflow, the litigator scrubbing explainer is a good next read — and you can test the whole stack on the 2,500 free credits without a card.