Skip to main content
TPSCheck Blog
How Agencies Can Manage TPS and CTPS Compliance for Multiple Clients

How Agencies Can Manage TPS and CTPS Compliance for Multiple Clients

If your agency makes marketing calls on behalf of clients, you already know that TPS compliance is not optional. What you may not fully appreciate is how much more complex and risky that obligation becomes when you are managing compliance across five, ten, or fifty client accounts simultaneously.

A single business checking its own call list against the TPS has one set of numbers, one calling schedule, and one audit trail to maintain. An agency has all of that multiplied by however many clients it serves, with the added pressure that a compliance failure on any one account can expose both the agency and the client to ICO enforcement.

This article sets out the specific compliance challenges agencies face, what the ICO expects from organisations that make calls on behalf of others, and how to build workflows that scale without creating regulatory risk.

Why agencies face higher compliance risk

Marketing agencies, lead generation firms, and outsourced telemarketing operations occupy a uniquely exposed position under UK telecommunications regulations. The risks are structural, not incidental, and they stem from three factors.

Shared liability under PECR

The Privacy and Electronic Communications Regulations 2003 (PECR) do not limit responsibility to the organisation that physically dials the number. The ICO's published guidance on direct marketing using live calls is explicit: responsibility sits with the "sender," "caller," or "instigator" of the marketing message.

The ICO defines instigating as encouraging, incentivising, or asking someone else to send your direct marketing message. This means that when an agency makes calls on behalf of a client, both the agency and the client can be held responsible for any PECR breach, including calls to TPS-registered numbers.

The ICO has acted on this principle. In its April 2024 enforcement against Outsource Strategies Ltd and Dr Telemarketing Ltd, the regulator fined both companies a combined £340,000 for making 1.43 million calls to TPS-registered numbers. Outsource Strategies attempted to blame its contracted partners for TPS screening failures. The ICO rejected that defence and found the company's own internal suppression systems had still allowed over 141,000 calls to numbers flagged as "do not call."

The lesson is clear: outsourcing the calls does not outsource the liability. Both parties are on the hook.

For a full breakdown of recent ICO enforcement cases and how fines are calculated, see our article on TPS fines and ICO enforcement.

Multiplied attack surface

A single compliance gap in a business that runs its own campaigns affects one set of numbers. The same gap in an agency's process can affect every client simultaneously. If your TPS screening workflow has a flaw, for example a batch of numbers that was not re-checked within 28 days, that flaw may have propagated across dozens of client campaigns before anyone notices.

The ICO analyses complaint patterns to identify systemic issues. An agency generating complaints across multiple client brands, even at low volumes per brand, creates a pattern that regulators are equipped to detect.

The evidence burden is heavier

When a complaint reaches the ICO, the agency needs to produce evidence not just that it checked TPS, but that it checked the right numbers, for the right client, at the right time, and acted on the results. This is significantly more complex than a single business producing its own compliance records.

If client data has been commingled, if audit logs do not distinguish between campaigns, or if records have been overwritten, the agency may be unable to demonstrate compliance even if it was, in fact, compliant at the time.


Client-specific data separation

The first structural requirement for agency TPS compliance is strict separation of client data. This is not merely a best practice; it is an operational necessity driven by both regulatory and contractual obligations.

Why separation matters

Each client's call lists, TPS check results, suppression files, and consent records are that client's data. Mixing them together creates several problems:

  • Regulatory risk. If the ICO investigates a complaint related to Client A's campaign, you need to produce records specific to Client A. If those records are entangled with Client B's data, you either delay your response or risk disclosing another client's information.
  • Contractual exposure. Most agency-client contracts require that data is handled in isolation. Commingling data could breach your data processing agreements.
  • Operational errors. When suppression lists are shared or confused between clients, numbers that should be suppressed for one client may be incorrectly applied to another, or worse, not applied at all.

How to implement separation

The most reliable approach is to use separate API keys for each client account. TPSCheck's Growth plan and above supports multiple API keys, allowing you to assign a dedicated key to each client. Every check performed under that key is automatically tagged and isolated in your audit logs.

This means:

  • All TPS and CTPS results for Client A are retrievable under Client A's API key
  • Usage reporting is broken down per client without manual tracking
  • If a client relationship ends, their data footprint is cleanly identifiable for deletion or handover

For agencies managing a large number of client accounts, the Enterprise plan provides a reseller dashboard with full sub-account management, giving you centralised oversight without sacrificing data isolation.


Audit trails that work per client

The ICO's expectations around record keeping apply with particular force to agencies. When you make calls on behalf of others, you need to demonstrate compliance not just for your own organisation, but for each client relationship independently.

What the ICO expects

The ICO guidance on direct marketing using live calls states that organisations should maintain records of when numbers were checked, what results were received, and what action was taken based on those results. For agencies, this requirement extends across every client engagement.

TPSCheck's audit log feature records every check with:

  • The phone number checked
  • The TPS and CTPS result at the time of the check
  • A precise timestamp
  • The API key (and therefore the client) that performed the check
  • Line type, carrier, and location data returned

These records are stored securely, cannot be modified after creation, and can be exported as CSV or PDF at any time.

Responding to ICO enquiries

If the ICO contacts your agency about a complaint, you need to respond quickly with relevant evidence. The ability to filter audit logs by client (via API key), date range, and specific phone numbers means you can produce a targeted compliance report within minutes rather than days.

This matters because ICO investigations often move on timescales that do not accommodate manual data trawling. Having structured, per-client records ready to export is the difference between a straightforward response and a protracted investigation.

Retention periods

Different clients may have different retention requirements based on their own compliance policies or contractual terms. TPSCheck audit log retention scales with your plan:

Plan Retention Period
Pro 90 days
Growth 12 months
Business 24 months
Enterprise Custom

For most agency use cases, 12 to 24 months of retention is appropriate, as this covers the typical window within which the ICO may investigate a complaint. See our documentation for full details on audit log access and export.


Managing the 28-day re-check requirement

ICO guidance is clear: numbers must be screened against TPS and CTPS registers within 28 days before making a marketing call. For a single business with one campaign cycle, this is straightforward. For an agency juggling multiple clients with different calling schedules, it requires careful planning.

The complexity for agencies

Consider a typical scenario. Your agency manages outbound campaigns for eight clients. Three run weekly calling campaigns. Two run monthly campaigns. One runs quarterly bursts. Two have continuous drip campaigns.

Each of these clients has a different set of numbers, checked at different times, with different expiry dates on those checks. A number checked on 1 February for Client A is compliant until 1 March. The same number, if it also appears on Client C's list, may have been checked on 15 January and is already outside the 28-day window.

Building a re-check schedule

The practical solution is to align re-checking with each client's campaign cadence:

  • Weekly campaigns: Re-check the entire calling list weekly. The 28-day window is never at risk.
  • Monthly campaigns: Re-check 3 to 5 days before each campaign launch. This gives time to process results and update suppression lists.
  • Quarterly or ad-hoc campaigns: Schedule a full re-check as part of campaign preparation, regardless of when the last check was performed.

TPSCheck's batch checking feature allows you to submit up to 100 numbers per API request, making it practical to re-screen entire client lists efficiently. For agencies on the Business or Enterprise plans, rate limits of 600 requests per minute or higher mean that even large lists of tens of thousands of numbers can be processed in minutes.

Automating the process

Rather than relying on manual calendar reminders, integrate re-checking directly into your campaign management workflow through the TPSCheck API. A scheduled job that automatically re-screens each client's active numbers every 21 days (leaving a 7-day buffer before the 28-day deadline) eliminates the risk of human error.

For a detailed explanation of the 28-day rule and its implications, see our article on the 28-day TPS re-check rule explained.


White-label and client reporting

Agencies often need to demonstrate compliance to their clients as well as to regulators. This creates a reporting requirement that goes beyond internal record keeping.

Client-facing compliance reports

Your clients may require periodic evidence that TPS screening is being performed correctly on their behalf. This could be a contractual obligation, part of their own compliance programme, or simply a reasonable expectation of professional service.

TPSCheck's compliance reports can be exported as branded PDF or CSV files, filtered by the relevant client API key and date range. This gives you a ready-made deliverable for client compliance reviews without any manual compilation.

White-label options for larger agencies

For agencies that position TPS compliance as a core part of their service offering, or that want to resell compliance checking to their client base, TPSCheck's Enterprise plan includes white-label capabilities:

  • Custom API domain. Host the API on your own domain (e.g., api.youragency.com) so clients interact with your brand, not ours.
  • Branded reports. All exports carry your logo and branding.
  • Reseller dashboard. Manage sub-accounts, monitor usage, and control access for all clients from a single interface.
  • Branded documentation. Provide API documentation styled to your brand if clients integrate directly.

This transforms TPS compliance from a cost centre into a value-added service or even a revenue stream. You maintain the client relationship. We provide the infrastructure.


Building a compliant agency workflow

Bringing all of this together, here is a practical workflow for agencies managing TPS and CTPS compliance across multiple clients.

1. Onboard each client with a dedicated API key

When you take on a new client that involves outbound calling, create a separate API key for their account. This ensures all checks, results, and audit records are isolated from day one. Document the API key assignment in your client setup process.

2. Perform an initial full screen of the client's call list

Before any campaign activity begins, run the entire contact list through TPSCheck's batch API. Flag and suppress all TPS and CTPS-registered numbers. Record the date of this initial screen as the baseline for the 28-day re-check cycle.

3. Establish a re-check schedule tied to the campaign calendar

Map each client's calling frequency to a re-check cadence. For clients with continuous campaigns, automate a rolling re-check every 21 days. For clients with periodic campaigns, schedule re-checks as a mandatory pre-launch step.

4. Integrate TPS checking into your campaign launch process

Make TPS screening a gate in your campaign workflow, not a parallel task. No campaign should be approved for dialling until the compliance check is confirmed complete and the results are applied to the suppression list.

5. Maintain per-client suppression lists

In addition to TPS and CTPS results, maintain each client's own do-not-call list separately. Numbers where individuals have requested not to be called must be suppressed regardless of their TPS status. These internal suppression lists should never be shared between clients.

6. Export and archive compliance reports regularly

Generate and store compliance reports for each client at least monthly, or after each campaign. Do not rely solely on the platform retaining your data; keep your own copies as part of your agency's compliance documentation.

7. Include compliance obligations in client contracts

Your agreements with clients should clearly state:

  • That TPS and CTPS screening will be performed before all marketing calls
  • Which party is responsible for maintaining consent records
  • That both parties share liability under PECR
  • How compliance evidence will be provided and retained
  • What happens to data when the relationship ends

This protects both you and your clients. The ICO's guidance recommends having a contract in place between organisations setting out their respective responsibilities for PECR compliance.

8. Review and audit quarterly

Run a quarterly internal review of your compliance processes. Check that all clients have active re-check schedules, that audit logs are being maintained, and that no client's data has drifted outside its designated API key. Identify and close any gaps before they become regulatory issues.


Choosing the right plan for agency use

Not all TPSCheck plans are built for multi-client management. Here is how the plans map to typical agency needs:

Agency Size Recommended Plan Key Features
Small agency (2-3 clients) Pro (£79/month) 50,000 checks, audit logs (90-day retention), batch checking, compliance reports
Mid-size agency (5-10 clients) Growth (£149/month) 150,000 checks, multiple API keys, 28-day compliance tracking, 12-month audit retention
Large agency (10+ clients) Business (£199/month) 500,000 checks, compliance risk scoring, 24-month retention, phone support
Enterprise or reseller Enterprise (from £249/month) Custom volume, white-label API, sub-account management, dedicated account manager

The Growth plan is the starting point for most agencies, as it is the first tier that includes multiple API keys, which are essential for per-client data separation. Agencies with higher volumes or white-label requirements should consider Business or Enterprise.

View full plan details and sign up


Summary

Agencies that make marketing calls on behalf of clients operate under heightened compliance pressure. The ICO holds both the instigator and the caller responsible under PECR. Data must be kept separate. Audit trails must be maintained per client. Re-check schedules must account for different campaign cadences. And when the regulator comes asking questions, evidence must be produced quickly and cleanly.

None of this is unmanageable, but it does require deliberate process design rather than ad-hoc checking. The tools exist to automate the heavy lifting. What matters is building compliance into your agency's workflow from the start, not retrofitting it after a complaint.

With fines now reaching up to £17.5 million under the Data (Use and Access) Act 2025, the cost of getting this right is negligible compared to the cost of getting it wrong.

Start your free account or read the API documentation to see how TPSCheck fits into your agency's compliance workflow.


TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).