Why agencies face higher compliance risk
Marketing agencies, lead generation firms, and outsourced telemarketing operations occupy a uniquely exposed position under UK telecommunications regulations. The risks are structural, not incidental, and they stem from three factors.
Shared liability under PECR
The Privacy and Electronic Communications Regulations 2003 (PECR) do not limit responsibility to the organisation that physically dials the number. The ICO's published guidance on direct marketing using live calls is explicit: responsibility sits with the "sender," "caller," or "instigator" of the marketing message.
The ICO defines instigating as encouraging, incentivising, or asking someone else to send your direct marketing message. This means that when an agency makes calls on behalf of a client, both the agency and the client can be held responsible for any PECR breach, including calls to TPS-registered numbers.
The ICO has acted on this principle. In its April 2024 enforcement against Outsource Strategies Ltd and Dr Telemarketing Ltd, the regulator fined both companies a combined £340,000 for making 1.43 million calls to TPS-registered numbers. Outsource Strategies attempted to blame its contracted partners for TPS screening failures. The ICO rejected that defence and found the company's own internal suppression systems had still allowed over 141,000 calls to numbers flagged as "do not call."
The lesson is clear: outsourcing the calls does not outsource the liability. Both parties are on the hook.
For a full breakdown of recent ICO enforcement cases and how fines are calculated, see our article on TPS fines and ICO enforcement.
Multiplied attack surface
A single compliance gap in a business that runs its own campaigns affects one set of numbers. The same gap in an agency's process can affect every client simultaneously. If your TPS screening workflow has a flaw, for example a batch of numbers that was not re-checked within 28 days, that flaw may have propagated across dozens of client campaigns before anyone notices.
The ICO analyses complaint patterns to identify systemic issues. An agency generating complaints across multiple client brands, even at low volumes per brand, creates a pattern that regulators are equipped to detect.
The evidence burden is heavier
When a complaint reaches the ICO, the agency needs to produce evidence not just that it checked TPS, but that it checked the right numbers, for the right client, at the right time, and acted on the results. This is significantly more complex than a single business producing its own compliance records.
If client data has been commingled, if audit logs do not distinguish between campaigns, or if records have been overwritten, the agency may be unable to demonstrate compliance even if it was, in fact, compliant at the time.
Client-specific data separation
The first structural requirement for agency TPS compliance is strict separation of client data. This is not merely a best practice; it is an operational necessity driven by both regulatory and contractual obligations.
Why separation matters
Each client's call lists, TPS check results, suppression files, and consent records are that client's data. Mixing them together creates several problems:
- Regulatory risk. If the ICO investigates a complaint related to Client A's campaign, you need to produce records specific to Client A. If those records are entangled with Client B's data, you either delay your response or risk disclosing another client's information.
- Contractual exposure. Most agency-client contracts require that data is handled in isolation. Commingling data could breach your data processing agreements.
- Operational errors. When suppression lists are shared or confused between clients, numbers that should be suppressed for one client may be incorrectly applied to another, or worse, not applied at all.
How to implement separation
The most reliable approach is to use separate API keys for each client account. TPSCheck's Growth plan and above supports multiple API keys, allowing you to assign a dedicated key to each client. Every check performed under that key is automatically tagged and isolated in your audit logs.
This means:
- All TPS and CTPS results for Client A are retrievable under Client A's API key
- Usage reporting is broken down per client without manual tracking
- If a client relationship ends, their data footprint is cleanly identifiable for deletion or handover
For agencies managing a large number of client accounts, the Enterprise plan provides a reseller dashboard with full sub-account management, giving you centralised oversight without sacrificing data isolation.
Audit trails that work per client
The ICO's expectations around record keeping apply with particular force to agencies. When you make calls on behalf of others, you need to demonstrate compliance not just for your own organisation, but for each client relationship independently.
What the ICO expects
The ICO guidance on direct marketing using live calls states that organisations should maintain records of when numbers were checked, what results were received, and what action was taken based on those results. For agencies, this requirement extends across every client engagement.
TPSCheck's audit log feature records every check with:
- The phone number checked
- The TPS and CTPS result at the time of the check
- A precise timestamp
- The API key (and therefore the client) that performed the check
- Line type, carrier, and location data returned
These records are stored securely, cannot be modified after creation, and can be exported as CSV or PDF at any time.
Responding to ICO enquiries
If the ICO contacts your agency about a complaint, you need to respond quickly with relevant evidence. The ability to filter audit logs by client (via API key), date range, and specific phone numbers means you can produce a targeted compliance report within minutes rather than days.
This matters because ICO investigations often move on timescales that do not accommodate manual data trawling. Having structured, per-client records ready to export is the difference between a straightforward response and a protracted investigation.
Retention periods
Different clients may have different retention requirements based on their own compliance policies or contractual terms. TPSCheck audit log retention scales with your plan:
| Plan | Retention Period |
|---|---|
| Pro | 90 days |
| Growth | 12 months |
| Business | 24 months |
| Enterprise | Custom |
For most agency use cases, 12 to 24 months of retention is appropriate, as this covers the typical window within which the ICO may investigate a complaint. See our documentation for full details on audit log access and export.
Managing the 28-day re-check requirement
ICO guidance is clear: numbers must be screened against TPS and CTPS registers within 28 days before making a marketing call. For a single business with one campaign cycle, this is straightforward. For an agency juggling multiple clients with different calling schedules, it requires careful planning.
The complexity for agencies
Consider a typical scenario. Your agency manages outbound campaigns for eight clients. Three run weekly calling campaigns. Two run monthly campaigns. One runs quarterly bursts. Two have continuous drip campaigns.
Each of these clients has a different set of numbers, checked at different times, with different expiry dates on those checks. A number checked on 1 February for Client A is compliant until 1 March. The same number, if it also appears on Client C's list, may have been checked on 15 January and is already outside the 28-day window.
Building a re-check schedule
The practical solution is to align re-checking with each client's campaign cadence:
- Weekly campaigns: Re-check the entire calling list weekly. The 28-day window is never at risk.
- Monthly campaigns: Re-check 3 to 5 days before each campaign launch. This gives time to process results and update suppression lists.
- Quarterly or ad-hoc campaigns: Schedule a full re-check as part of campaign preparation, regardless of when the last check was performed.
TPSCheck's batch checking feature allows you to submit up to 100 numbers per API request, making it practical to re-screen entire client lists efficiently. For agencies on the Business or Enterprise plans, rate limits of 600 requests per minute or higher mean that even large lists of tens of thousands of numbers can be processed in minutes.
Automating the process
Rather than relying on manual calendar reminders, integrate re-checking directly into your campaign management workflow through the TPSCheck API. A scheduled job that automatically re-screens each client's active numbers every 21 days (leaving a 7-day buffer before the 28-day deadline) eliminates the risk of human error.
For a detailed explanation of the 28-day rule and its implications, see our article on the 28-day TPS re-check rule explained.
White-label and client reporting
Agencies often need to demonstrate compliance to their clients as well as to regulators. This creates a reporting requirement that goes beyond internal record keeping.
Client-facing compliance reports
Your clients may require periodic evidence that TPS screening is being performed correctly on their behalf. This could be a contractual obligation, part of their own compliance programme, or simply a reasonable expectation of professional service.
TPSCheck's compliance reports can be exported as branded PDF or CSV files, filtered by the relevant client API key and date range. This gives you a ready-made deliverable for client compliance reviews without any manual compilation.
White-label options for larger agencies
For agencies that position TPS compliance as a core part of their service offering, or that want to resell compliance checking to their client base, TPSCheck's Enterprise plan includes white-label capabilities:
- Custom API domain. Host the API on your own domain (e.g., api.youragency.com) so clients interact with your brand, not ours.
- Branded reports. All exports carry your logo and branding.
- Reseller dashboard. Manage sub-accounts, monitor usage, and control access for all clients from a single interface.
- Branded documentation. Provide API documentation styled to your brand if clients integrate directly.
This transforms TPS compliance from a cost centre into a value-added service or even a revenue stream. You maintain the client relationship. We provide the infrastructure.
Building a compliant agency workflow
Bringing all of this together, here is a practical workflow for agencies managing TPS and CTPS compliance across multiple clients.
1. Onboard each client with a dedicated API key
When you take on a new client that involves outbound calling, create a separate API key for their account. This ensures all checks, results, and audit records are isolated from day one. Document the API key assignment in your client setup process.
2. Perform an initial full screen of the client's call list
Before any campaign activity begins, run the entire contact list through TPSCheck's batch API. Flag and suppress all TPS and CTPS-registered numbers. Record the date of this initial screen as the baseline for the 28-day re-check cycle.
3. Establish a re-check schedule tied to the campaign calendar
Map each client's calling frequency to a re-check cadence. For clients with continuous campaigns, automate a rolling re-check every 21 days. For clients with periodic campaigns, schedule re-checks as a mandatory pre-launch step.
4. Integrate TPS checking into your campaign launch process
Make TPS screening a gate in your campaign workflow, not a parallel task. No campaign should be approved for dialling until the compliance check is confirmed complete and the results are applied to the suppression list.
5. Maintain per-client suppression lists
In addition to TPS and CTPS results, maintain each client's own do-not-call list separately. Numbers where individuals have requested not to be called must be suppressed regardless of their TPS status. These internal suppression lists should never be shared between clients.
6. Export and archive compliance reports regularly
Generate and store compliance reports for each client at least monthly, or after each campaign. Do not rely solely on the platform retaining your data; keep your own copies as part of your agency's compliance documentation.
7. Include compliance obligations in client contracts
Your agreements with clients should clearly state:
- That TPS and CTPS screening will be performed before all marketing calls
- Which party is responsible for maintaining consent records
- That both parties share liability under PECR
- How compliance evidence will be provided and retained
- What happens to data when the relationship ends
This protects both you and your clients. The ICO's guidance recommends having a contract in place between organisations setting out their respective responsibilities for PECR compliance.
8. Review and audit quarterly
Run a quarterly internal review of your compliance processes. Check that all clients have active re-check schedules, that audit logs are being maintained, and that no client's data has drifted outside its designated API key. Identify and close any gaps before they become regulatory issues.
Choosing the right plan for agency use
Not all TPSCheck plans are built for multi-client management. Here is how the plans map to typical agency needs:
| Agency Size | Recommended Plan | Key Features |
|---|---|---|
| Small agency (2-3 clients) | Pro (£79/month) | 50,000 checks, audit logs (90-day retention), batch checking, compliance reports |
| Mid-size agency (5-10 clients) | Growth (£149/month) | 150,000 checks, multiple API keys, 28-day compliance tracking, 12-month audit retention |
| Large agency (10+ clients) | Business (£199/month) | 500,000 checks, compliance risk scoring, 24-month retention, phone support |
| Enterprise or reseller | Enterprise (from £249/month) | Custom volume, white-label API, sub-account management, dedicated account manager |
The Growth plan is the starting point for most agencies, as it is the first tier that includes multiple API keys, which are essential for per-client data separation. Agencies with higher volumes or white-label requirements should consider Business or Enterprise.
View full plan details and sign up
Summary
Agencies that make marketing calls on behalf of clients operate under heightened compliance pressure. The ICO holds both the instigator and the caller responsible under PECR. Data must be kept separate. Audit trails must be maintained per client. Re-check schedules must account for different campaign cadences. And when the regulator comes asking questions, evidence must be produced quickly and cleanly.
None of this is unmanageable, but it does require deliberate process design rather than ad-hoc checking. The tools exist to automate the heavy lifting. What matters is building compliance into your agency's workflow from the start, not retrofitting it after a complaint.
With fines now reaching up to £17.5 million under the Data (Use and Access) Act 2025, the cost of getting this right is negligible compared to the cost of getting it wrong.
Start your free account or read the API documentation to see how TPSCheck fits into your agency's compliance workflow.
TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).