When an outsourced SDR vendor violates the TCPA, the company that hired them is usually liable too. The TCPA was enacted in 1991 to protect consumer privacy, and both federal law and 2026 state statutes like Pennsylvania’s SB 992 extend liability up the chain to the seller on whose behalf calls were made. Vendor indemnification clauses shift cost, not legal exposure.
TCPA vendor liability is the question most companies hiring or considering outsourced SDR vendors for B2B sales development skip during vendor selection and meet again in a demand letter. The Telephone Consumer Protection Act and the FCC’s rules reach the seller… the company whose product the calls promote… not just the third party that dialed. This article explains how vicarious liability works, where indemnity protections stop, what new state rules and AI voice-call regulations change, and how to audit vendor compliance and manage risk before outsourced telemarketing creates legal and financial exposure.
Top Questions, Answered
If my outsourced SDR agency breaks TCPA, am I liable? Usually, yes. The Telephone Consumer Protection Act covers telemarketing calls made “on behalf of” a seller, and sellers are routinely held liable for third-party telemarketers’ TCPA violations under vicarious liability principles. The Federal Communications Commission clarified this in 2013. Hiring a vendor outsources the dialing, not the exposure.
Does an indemnification clause protect me from TCPA claims? No. It shifts money after the fact, not TCPA liability. The seller can still be named, certified against in a class action, and forced to defend. Then you chase the telemarketer for reimbursement, subject to caps, exclusions, and solvency.
What is Pennsylvania SB 992 and does it apply to B2B calls? SB 992 modernizes Pennsylvania’s telemarketing law. It covers text messages, voicemails, and ringless voicemail, bans Sunday solicitation, and requires prior express written consent for any robocall… including calls to business and wireless lines. It extends liability to the company that hired the telemarketer, with penalties of $1,000 per violation, $3,000 when the recipient is 60 or older.
Can I be sued for calls a vendor made without my knowledge? Yes. Vicarious liability attaches when the third party acted with actual or apparent authority, or when the seller ratified the conduct by accepting its benefits. If your team took the meetings those calls produced, “we didn’t know” gets thin fast.
What TCPA documentation should I require from an SDR vendor? Consent records with a stated retrieval turnaround, provenance for every call list, DNC scrub logs, caller locations in writing, an insurance certificate that responds to TCPA claims, a named compliance owner, and audit rights.
Key Takeaways
- Vicarious liability is the default, not the exception. Courts, plaintiffs, and state attorneys general work up the chain to the seller, who has the deepest pockets.
- Pennsylvania SB 992 starts a 90-day clock once signed. Passed both chambers unanimously July 12, 2026. Penalties run $1,000 per violation, $3,000 where the recipient is 60 or older, plus a private right of action for consumers.
- Text messages and calls now diverge by circuit. On July 14, 2026, the Seventh Circuit held text messages are not “telephone calls” under the TCPA’s do-not-call provision. The Ninth Circuit holds the opposite.
- Enforcement is working the whole chain. The same day, a federal district court kept the 49-state attorneys general case against Avid Telecom moving.
- Indemnification transfers cost, never exposure. A capped indemnity against uncapped TCPA statutory damages is a rounding error.
Where Liability Attaches: The Scenario Grid
Who Is Legally Liable for Vicarious Liability When an Outsourced Vendor Makes an Unlawful Call?
Start with the statute. The TCPA’s do-not-call provision lets consumers sue over telemarketing calls made “by or on behalf of” the same seller. The TCPA is a strict liability statute, so liability is not determined by intent. Courts read that phrase to put the seller in the caption next to the telemarketer that dialed.
For robocall and autodialer violations, the Federal Communications Commission (FCC) clarified in 2013 that a seller may be held liable for TCPA violations by third-party telemarketers under vicarious liability principles: actual authority, apparent authority, and ratification. Reference: In re Dish Network, 28 FCC Rcd 6574 (2013). The FTC’s Telemarketing Sales Rule adds a second path… providing substantial assistance to a telemarketer you know is breaking the rules is itself a violation.
On the district court dockets where TCPA class actions live, plaintiffs name all parties… seller, telemarketer, dialer platform… and let discovery sort it out. Your vendor’s dialing logs, your contract, and your meeting acceptance emails become exhibits. This is the plumbing underneath B2B outbound sales, and most buyers never inspect it.
What Did Pennsylvania SB 992 Actually Change Under the Telephone Consumer Protection Act on July 12, 2026?
Pennsylvania’s Telemarketer Registration Act dates to 1996. SB 992 passed both chambers unanimously on July 12, 2026 and went to Governor Shapiro’s desk. Once signed, sellers and telemarketers get 90 days to comply.
Telephone solicitation now expressly includes text messages, voicemails, and ringless voicemail. Calls and texts are barred between 7:00 p.m. and 9:00 a.m. on weekdays, banned on Sundays, and restricted on legal holidays… keyed to the recipient’s location, not your dialer’s clock.
No one may initiate robocalls or prerecorded messages without prior express written consent, to any line: residential, wireless, or business. Caller ID spoofing is out, including neighbor-spoofing. So are AI-generated messages that mislead consumers.
The clause that matters here: liability reaches the company that hired the caller. When a third-party vendor initiates unlawful calls on a seller’s behalf in Pennsylvania, the seller can be held liable by statute… vicarious liability, codified. Violations also run through the state’s consumer protection law, which gives consumers a private right of action for actual damages or $100, whichever is greater. State courts will hear consumers’ claims alongside the federal TCPA docket.
The safe harbor rewards clean operators: communications backed by prior express written consent or an established business relationship within the past twelve months sit outside the definition of telephone solicitation. The protection is only as good as the consent records behind it.
Primary source: Pennsylvania SB 992.
Do the New Rules Apply to B2B Calls, or Only Consumers?
The B2B exemption is narrower than most sales teams assume, and it keeps narrowing.
Two plain-language definitions. Prior express written consent (PEWC) is a signed agreement (electronic counts) to receive telemarketing calls or text messages from a specific company at a specific number. Prior express consent, without the writing, is a lower bar. An established business relationship (EBR) covers existing customers and recent inquirers… in Pennsylvania, within the past twelve months… and substitutes for consent.
Under the FCC’s and FTC’s rules, the federal do-not-call registry generally exempts business landlines. But the TCPA treats every wireless number as residential, regardless of use. Your prospect’s cell phone is a consumer line even when the pitch is pure B2B. The federal baseline is in our cold calling laws guide.
Pennsylvania goes further: SB 992’s robocall consent rule names business lines explicitly, and the state’s own do-not-call list covers business numbers. A federal-only playbook run against a Pennsylvania call list is a stack of TCPA violations with a 90-day fuse.
What Did the Seventh Circuit’s Texts-Are-Not-Calls Ruling Change, and What Did It Not Change?
On July 14, 2026, the Seventh Circuit held in Steidinger v. Blackstone Medical Services, No. 25-2398, that text messages are not “telephone calls” under section 227(c)(5) of the Telephone Consumer Protection Act. Inside Illinois, Indiana, and Wisconsin, the TCPA class-action theory that consumers used against marketing texts lost its private right of action.
What it did not change is longer. District courts had split on the question for years, the Ninth Circuit held the opposite in Howard v. Republican National Committee in January 2026, and the Supreme Court is the likely referee. Autodialer and artificial-voice claims under section 227(b) still cover text messages everywhere. State legislation is unaffected… SB 992 pulls texts in by name.
The operator takeaway: do not rebuild a texting program on a circuit split. Outbound campaigns reach customers in all fifty states, and venue is not a compliance control.
Why Does an Indemnification Clause Fail Exactly When You Need It?
The math is straightforward. TCPA statutory damages run $500 per violation, up to $1,500 where the conduct is willful or knowing. A 10,000-call campaign against a dirty list is $5 million to $15 million in theoretical exposure. Now read the indemnification clause in a typical vendor contract: liability capped at fees paid.
A $12,000 cap against seven-figure TCPA class exposure is not protection. It is a coupon.
Indemnification fails on timing: defense costs land on the seller the day the complaint is filed, while reimbursement arrives after settlement, if ever. It fails on scope, because most clauses exclude TCPA violations traceable to your call lists, your script, or your instructions. It fails on solvency. And it does not displace vicarious liability… the seller is held liable either way.
The honest structure is insurance-backed. Ask whether the telemarketer carries coverage that responds to TCPA claims, because standard general liability policies routinely exclude telemarketing. Then ask for the certificate.
What Does the FCC’s Offshore Call Center Rulemaking Signal About Where This Goes Next?
In March 2026 the Federal Communications Commission adopted a Notice of Proposed Rulemaking on offshore call centers, published in the Federal Register on April 23, 2026. The FCC’s proposals: onshoring incentives, English proficiency standards, a 30 percent illustrative cap on offshore routing, and bans on call centers in foreign-adversary countries.
Be precise about scope. The NPRM targets customer service call centers at regulated telephone and broadband providers, not outbound telemarketing agencies. It is a signal, not a rule.
But signals price in early, and enforcement already works the whole chain. On July 14, 2026, the federal district court in Arizona ex rel. Mayes v. Michael D. Lansky, L.L.C. rejected Avid Telecom’s attempts to dismiss the robocall suit brought by 49 state attorneys general… all parties in the calling chain, one caption. Where a vendor’s callers sit, and who can produce records on demand, are becoming diligence questions with teeth. We laid out the operational side in US-based vs offshore SDRs.
Caller-location disclosure is moving from nice-to-know to contract term. Telemarketers who will not put it in writing are answering the question anyway.
How Do You Audit a Vendor’s Compliance Posture Before You Sign?
Vicarious liability makes the audit the seller’s to run. Start with the one-business-day test: ask the telemarketer to produce a consent record, with timestamp and source, for a number they recently dialed. A clean operation retrieves it in hours. A factory stalls, because the record lives with a data broker three contracts away.
Then work the paper trail. Where did the call list come from, and under what legal basis was the consumer information collected? Which dialer platform, configured by whom? Do regular audits and DNC scrubs run on a logged cadence? Who, by name, owns compliance? The execution side is covered in our guide to effective outbound sales calling.
Ask before you sign, in the same spirit as our guide to outsourcing lead generation. Telemarketers worth hiring answer without flinching. The rest disqualify themselves, which is cheaper than discovery.
The Leadium Third Party Vendors Liability Chain
We built a named framework for this because buyers keep inspecting one link and calling it diligence. The Leadium Vendor Liability Chain has five links, and vicarious liability attaches at whichever one is weakest.
1. Who dials. Employee, contractor, or offshore subcontractor? Every third party between you and the phone is an entity you did not vet. Get every dialing party named in the contract.
2. Whose list. A call list of unknown origin means unknown consent, unknown reassigned numbers, unknown litigators seeded in the rows. Demand source and legal basis in writing.
3. Whose consent record. Who holds it, in what format, retrievable how fast? If the answer is a shrug, the seller’s safe harbor does not exist.
4. Whose contract. Indemnification scope, audit rights, termination for compliance cause, disclosure of every subcontractor. The only link most buyers read… one of five.
5. Whose insurance. A TCPA-responsive policy with your company as additional insured separates an indemnity that pays from one that decorates the contract.
A chain fails at its weakest link. Most buyers inspect link four and skip the rest.
The 14-Point Vendor Compliance Checklist
Consent and data
- [ ] Consent records in a defined format with a one-business-day retrieval SLA
- [ ] Provenance documented for every call list, with legal basis for the consumer information
- [ ] Suppression list syncs between your CRM and the vendor’s platform on a stated cadence
- [ ] DNC scrubs run at least every 31 days, with logs you can request
- [ ] Reassigned-numbers screening included in list hygiene, not sold as an upsell
Calling operations
- [ ] Caller locations disclosed in writing, including third-party subcontractors
- [ ] Quiet-hours and Sunday logic keyed to the recipient’s location
- [ ] State-specific rules (Pennsylvania, Texas, Oregon, Florida) mapped before launch
- [ ] AI voice and prerecorded messages, if any, disclosed and consent-gated in writing
- [ ] Call recordings retained on a stated schedule you can audit
Contract and accountability
- [ ] Indemnification scope reviewed against realistic class exposure, not fees paid
- [ ] Audit rights covering consent records and scrub logs on notice
- [ ] Insurance certificate on file that responds to TCPA claims
- [ ] Termination for compliance cause, exercisable without penalty
Seven Red Flags in an SDR Vendor’s Compliance Story
“We handle compliance” with nothing in writing
If the program is real, it survives being written down. A telemarketer who waves the question off is telling you the program is the sales call.
They cannot produce a consent record inside one business day
The retrieval test is the cheapest diligence you will run. Fail it before contract, and you know what happens after a demand letter.
The dialer runs on the vendor’s time zone, not the recipient’s
Quiet hours, Sunday bans, and holiday rules key to where the prospect is. A platform set to the vendor’s clock is a violation generator with a monthly invoice.
Subcontracted or offshore callers are not named in the contract
You cannot audit a third party you did not know existed. If the org chart behind your outbound calls is a mystery, so is your liability.
No named compliance owner
“Our team stays on top of it” means nobody owns it. Ask for a name. Titles are free; accountability is not.
AI voice agents with no disclosure policy
Courts and regulators treat undisclosed AI voice as deception, and Pennsylvania wrote that into statute. A vendor running AI callers on your account without telling you is spending your risk budget.
Indemnification capped at fees paid
A $4,000-per-month cap against TCPA statutory damages of $500 to $1,500 per call is not indemnification. It evaporates on contact with a class action.
Frequently Asked Questions
Does an established business relationship exempt my calls? Under SB 992, communications backed by an EBR within the past twelve months fall outside telephone solicitation. Federal rules recognize EBR concepts too, but state windows differ. The exemption only works if the seller can document when the relationship started.
What counts as prior express written consent? A signed agreement identifying the specific company, disclosing that the person agrees to receive telemarketing calls or texts, listing the number, and not conditioned on purchase. Pre-checked boxes fail. Bundled consent that never names your company is the first thing a plaintiff’s lawyer screenshots.
Is one-to-one consent still required? No. The Eleventh Circuit vacated the FCC’s one-to-one consent rule in January 2025, and Pennsylvania stripped a similar provision from SB 992. Single-seller consent remains the defensible standard, because state legislation does not always follow the federal retreat.
Are B2B calls to cell phones covered by TCPA? Yes. The statute treats wireless numbers as residential regardless of use. A B2B pitch to a personal cell follows consumer rules, which is why cell identification and manual-dial workflows exist.
How long should consent and call records be kept? Five years is the federal floor for telemarketing records, and some states run longer. Retain consent for as long as you rely on it, plus the limitations period. Storage is cheap. Reconstructing consent later is not.
What should I do if I receive a TCPA demand letter about vendor calls? Preserve records, notify the telemarketer in writing under the contract’s notice clause, put your insurer on notice, and get counsel who has defended TCPA violations. Your response window shapes whether this stays a letter.
Does hiring a US-based agency eliminate TCPA exposure? No. Vicarious liability follows the calls, not the callers’ passports. What US-based operations change is auditability: one jurisdiction, one employer, no subcontract chain, records you can inspect. It shrinks the weak links. It does not repeal the statute.
Do AI voice calls require special disclosure? AI-generated voices count as artificial or prerecorded messages under FCC rules, so prior express written consent comes first. Pennsylvania adds a ban on AI content used to mislead consumers. If a vendor’s AI experiment initiates calls on your account without consent, the seller inherits the consent problem.
How is class action exposure calculated? TCPA statutory damages stack per violation: $500 to $1,500 per call or text, multiplied across the class. Courts have certified TCPA classes over routine outbound calling campaigns, and a modest list with a bad month produces eight-figure complaints. Prevention is the only cheap option.
What does a real compliance audit clause look like? Notice-based access to consent records, scrub logs, dialing records, and subcontractor lists, at least annually and after any TCPA complaint. Include a cure period, and termination for compliance cause if the cure fails. A telemarketer who resists regular audits is forecasting the results.
About the Author
Kevin Warner is Founder and CEO of Leadium, a boutique, 100% US-based B2B outbound sales development agency. 12+ years in outbound, 1,700+ clients served, and a deliberate cap of 30-35 active clients… boutique by choice. Kevin runs every discovery and closing call personally.
See How Leadium Would Build Your First 90 Days of Qualified Pipeline
Book a call with Kevin. You will get cost-per-meeting math against your ACV, a channel recommendation, and a ramp timeline… and we will walk your current vendor contract through the Vendor Liability Chain, link by link, so you know where it holds and where it does not.

.avif)
.png)

.avif)
.avif)
.avif)
.avif)
.avif)
.avif)
.avif)











.avif)
.avif)

.avif)

.avif)
.png)