DataMembershipFree phone app
Guide

GDPR for Call Centres: What Outbound Teams Need to Know

Outbound call centres handle a lot of personal data. UK GDPR sets how you hold and use it; PECR sets the rules for the calls themselves. Here are the essentials for your floor.

Have a lawful basis

For bought marketing data you will usually rely on consent or legitimate interests. Know which, and make sure the data supports it — the consent record on each DataMembership row helps.

Tell people where you got their details

If someone asks, say which company supplied their details and give them your privacy information. Script it so every agent can answer.

Handle objections immediately

When someone says "don't call me", stop. Add them to your suppression list and upload it to your data account so they are removed from every future delivery.

Keep only what you need

Set a retention period for call lists, delete old data and keep records of consent and objections.

Screen and display

Screen against TPS/CTPS, show a caller ID, and keep abandoned calls within Ofcom limits.

Questions

Who is responsible — us or our client?

Often both. The company whose products are marketed and the call centre making the calls can each be held responsible, so agree processes in writing.

This guide is general information, not legal advice. For the full rules see the Information Commissioner's Office (ico.org.uk). Last updated October 2026.