Why call centres face higher compliance risk
Call centres are disproportionately represented in ICO enforcement actions for TPS violations. The reasons are structural, not necessarily about intent.
Volume multiplies exposure
A small business making 50 marketing calls a week has limited exposure. A call centre making 5,000 calls a day across multiple campaigns has 100 times the opportunity for a TPS-registered number to slip through. At volume, even a 1% failure rate means dozens of potentially unlawful calls every day.
Multiple clients mean multiple risk profiles
Each client brings their own data, their own consent basis, and their own suppression requirements. Managing these separately whilst maintaining consistent compliance processes is operationally complex. The ICO does not care which client provided the data. If your agents dial the number, your call centre bears the regulatory risk.
Staff turnover creates knowledge gaps
Call centres typically have higher staff turnover than most industries. Every new agent is a compliance risk until they are trained. And compliance training is often the first thing to be shortened when campaign deadlines are tight.
Delayed complaints obscure the trail
The ICO received 44,404 nuisance call complaints in 2024 alone. Complaints can arrive weeks or months after the call was made. By that point, the campaign may have ended, the data may have been archived, and the agent who made the call may have left. Without proper records, you cannot reconstruct what happened or demonstrate that you followed the correct process.
The "instigator" problem
Under PECR, both the caller and the instigator of a marketing call bear responsibility for compliance. If your call centre makes calls on behalf of a client, both you and the client can be held liable. The ICO has explicitly stated that outsourcing marketing calls does not transfer compliance responsibility away from the instigator. This cuts both ways: your clients cannot blame you, and you cannot blame your clients.
The regulatory context
Before getting into the checklist, it is worth grounding the discussion in what the law actually requires.
Regulation 21 of PECR prohibits unsolicited direct marketing calls to individuals registered with the TPS, unless you have their specific prior consent. The same applies to CTPS for corporate numbers.
The ICO recommends re-screening calling lists against TPS and CTPS at least every 28 days. This is guidance rather than statute, but it is the standard against which the ICO assesses your processes. For a detailed analysis of the 28-day rule, see our article on the 28-day TPS re-check rule explained.
Maximum fines under the new regime have increased to £17.5 million or 4% of annual global turnover since the Data (Use and Access) Act 2025 enforcement provisions came into force in February 2026. For the full enforcement picture, including recent cases, see our article on TPS fines and ICO enforcement.
For call centres specifically, recent enforcement is instructive. In April 2024, Outsource Strategies Ltd, a Cardiff-based telemarketing operation, was fined £240,000 for making over 1.3 million calls to TPS-registered numbers. The ICO found that 141,914 of those calls were to numbers flagged as "do not call" on the company's own internal suppression systems. In other words, their processes existed on paper but failed in practice.
That distinction matters. The ICO does not just ask whether you have compliance procedures. It asks whether you follow them.
Pre-campaign compliance checklist
Every outbound campaign should pass through these checks before a single call is made. This is not bureaucracy. It is the minimum standard the ICO expects.
Data source verification
- [ ] Confirm the origin of the calling list (purchased, client-provided, or internally generated)
- [ ] Verify that the data provider has documented consent or a lawful basis for sharing the data
- [ ] Check that consent statements specifically name the organisation on whose behalf calls will be made
- [ ] Confirm the data is not older than 28 days since its last TPS/CTPS screening
- [ ] Reject any list where the data source cannot be verified or consent evidence is inadequate
TPS and CTPS screening
- [ ] Screen the entire calling list against both TPS and CTPS registers before the campaign launches
- [ ] Remove or flag all TPS/CTPS-registered numbers unless specific, documented consent exists
- [ ] Record the date, time, and results of the screening for every number on the list
- [ ] Confirm that no number on the list was last screened more than 28 days ago
- [ ] For ongoing campaigns, schedule re-screening at 25-day intervals to provide a buffer before the 28-day deadline
Suppression list management
- [ ] Apply the client's own suppression list (do-not-call requests made directly to the client)
- [ ] Apply your call centre's internal suppression list (numbers that have requested removal from any campaign)
- [ ] Cross-reference against any industry or sector-specific suppression files
- [ ] Confirm that suppression lists have been updated within the last 24 hours
Consent documentation
- [ ] For any TPS-registered number you intend to call, verify that specific prior consent exists
- [ ] Confirm consent names the calling organisation explicitly
- [ ] Confirm consent covers telephone marketing specifically (not just "contact" or "communication")
- [ ] Verify that consent has not expired or been withdrawn
- [ ] Store consent evidence in an accessible, auditable format
Campaign configuration
- [ ] Verify that the correct CLI (Calling Line Identification) is presented on all outbound calls
- [ ] Confirm the CLI connects to a working number if called back
- [ ] Brief all agents on the campaign's compliance requirements, including what to do if a recipient asks to be removed
- [ ] Test the dialler system to confirm it is pulling from the screened, suppressed list and not the raw data
Managing multiple client lists
This is where call centre compliance gets genuinely difficult. You may be running campaigns for five, ten, or twenty different clients simultaneously. Each one has different data, different consent bases, and different suppression requirements.
Keep client data segregated
Never mix calling lists between clients. A number suppressed for Client A might be perfectly valid for Client B, or it might not. Cross-contamination of data between clients creates compliance chaos and makes it impossible to produce clean audit trails.
Maintain client-specific suppression lists
Each client's do-not-call requests must be tracked separately. When someone tells your agent "take me off your list," that instruction applies to the client whose campaign generated the call, not necessarily to every client you work for. However, if someone asks not to receive calls from your call centre specifically, that suppression should apply universally.
Use separate API keys per client
If you are using an API for TPS checking, use separate credentials for each client account. This produces segregated audit logs automatically, which makes reporting straightforward and avoids any data protection issues around co-mingling records. TPSCheck's Growth plan and above supports multiple API keys for exactly this purpose.
Document the compliance chain
For each client, maintain a record of:
- Who provided the data and when
- What consent basis was claimed
- When the data was last TPS/CTPS screened
- Which suppression lists were applied
- Who authorised the campaign to proceed
If a complaint arrives six months later, this documentation is what allows you to reconstruct what happened.
Record-keeping and audit logs
The ICO does not accept verbal assurances. When it investigates, it asks for evidence. Specifically, it wants to see timestamped records showing that you checked each number against the TPS/CTPS registers before calling, and what the result was.
What your records must include
For every number you call in a marketing campaign, you should be able to produce:
| Record | Purpose |
|---|---|
| Phone number checked | Identifies the specific number verified |
| TPS/CTPS result at time of check | Proves the number was not registered, or that consent existed |
| Date and time of check | Proves the check was performed within the 28-day window |
| Who or what performed the check | Identifies the responsible person or system |
| Campaign and client reference | Links the check to a specific campaign for traceability |
Retention periods matter
The ICO can investigate complaints that are months old. If your records have been deleted by the time an investigation begins, you cannot demonstrate compliance even if you were compliant at the time. The AFK Letters case is instructive here: the company claimed it deleted customer data after three months, which meant it could not produce consent evidence for the ICO. It was fined £90,000.
Retain audit logs for at least 12 months. For higher-risk operations, 24 months is more appropriate. TPSCheck's audit log feature retains records for up to 24 months depending on plan, with full export capability in CSV and PDF formats. See our documentation for details on how audit data is structured.
Automate wherever possible
Manual record-keeping breaks down at call centre volumes. An agent making 80 calls a day cannot be expected to maintain a compliance spreadsheet alongside their primary role. Compliance logging must be built into the workflow, not bolted on as an afterthought.
API-based TPS checking produces audit logs automatically. Every check is timestamped and recorded without any manual intervention. This is fundamentally more reliable than asking staff to maintain records by hand, and it produces exactly the kind of evidence the ICO expects.
Handling complaints and building evidence
When a complaint reaches the ICO, the investigation process follows a predictable pattern. Understanding this pattern allows you to prepare your response before it is needed.
How complaints escalate
- A consumer reports an unwanted call to the ICO or the TPS directly, usually through an online form
- Complaints accumulate against a specific telephone number or company. The ICO analyses complaint data for patterns.
- The ICO opens an assessment. It may request information from your call centre about your calling activity and compliance processes.
- If the assessment indicates potential breaches, the ICO may launch a formal investigation. This involves detailed data requests and can take several months.
- If the investigation finds breaches, the ICO can issue enforcement notices and monetary penalties. All enforcement actions are published publicly.
The important point for call centres: there is often a significant lag between the call being made and the complaint arriving. You need records that survive that gap.
What the ICO will ask for
Based on published enforcement cases, when the ICO investigates a call centre, it typically requests:
- Call records showing which numbers were dialled, when, and by which agent
- TPS screening evidence demonstrating that numbers were checked before calling
- Consent records if you called any TPS-registered numbers on the basis of consent
- Suppression list evidence showing what do-not-call lists were applied
- Compliance policies and procedures including staff training records
- Data source documentation showing where the calling list originated
How to respond effectively
If you receive an information request from the ICO:
- [ ] Respond within the stated deadline. Late or non-responsive behaviour is treated as an aggravating factor.
- [ ] Provide complete audit logs for the relevant time period and campaign
- [ ] Include your TPS screening records with timestamps
- [ ] Provide copies of your compliance policies and training documentation
- [ ] Show the suppression lists that were applied and when they were last updated
- [ ] If you hold consent for any TPS-registered numbers that were called, provide the evidence
- [ ] Co-operate fully. The ICO considers cooperation when determining penalty amounts.
Proactive complaint management
Do not wait for the ICO to contact you. Monitor complaints internally:
- [ ] Record every do-not-call request received by agents, including the date, the number, the campaign, and the client
- [ ] Investigate every complaint to determine whether the call should have been made
- [ ] Add complainant numbers to suppression lists immediately
- [ ] If you identify a process failure, fix it and document the corrective action
- [ ] Report compliance incidents to the relevant client with full details
Compliance risk scoring: going beyond basic TPS checks
For high-volume call centres, a simple pass/fail TPS check is sometimes not enough context. A number may not be TPS-registered, but it might be invalid, associated with spam complaints, or not checked recently enough to be reliable.
Compliance risk scoring analyses multiple factors to produce an overall risk assessment for each number, scored from 0 to 100. The factors include:
- TPS and CTPS registration status
- Number of days since the last check
- Number validity and reachability
- Community spam reports and complaint history
- Line type (mobile vs landline, personal vs business)
This allows call centres to prioritise their lists more intelligently. Numbers with low risk scores can proceed to agents. Numbers with elevated scores can be routed to a manual review queue. Numbers with critical risk can be automatically suppressed.
For call centres managing large volumes across multiple campaigns, this kind of automated triage significantly reduces complaint risk without requiring manual review of every number. TPSCheck includes compliance risk scoring on Business and Enterprise plans.
The printable checklist
Use this as a reference for every outbound campaign. Print it, pin it to the wall, and work through it before any dialling begins.
Before the campaign
- [ ] Data source verified and documented
- [ ] Consent basis confirmed and evidence stored
- [ ] Full calling list screened against TPS and CTPS
- [ ] All TPS/CTPS-registered numbers removed (unless specific consent held)
- [ ] Client suppression list applied
- [ ] Internal suppression list applied
- [ ] Screening results logged with timestamps
- [ ] No number on the list last checked more than 28 days ago
- [ ] Correct CLI configured and tested
- [ ] All agents briefed on compliance requirements
- [ ] Complaint handling procedure confirmed with agents
During the campaign
- [ ] All do-not-call requests recorded and actioned immediately
- [ ] Suppression lists updated in real time
- [ ] Compliance logs generating automatically with each check
- [ ] Any new numbers added to the campaign screened before dialling
- [ ] Re-screening scheduled at 25-day intervals for ongoing campaigns
- [ ] Complaints investigated and documented within 24 hours
After the campaign
- [ ] Full audit trail exported and archived
- [ ] Compliance report generated for the client
- [ ] Any complaints reviewed and root causes addressed
- [ ] Suppression list updates confirmed as permanent
- [ ] Lessons learned documented for future campaigns
- [ ] Audit logs retained for minimum 12 months (24 months recommended)
Ongoing operations
- [ ] Staff compliance training delivered to all new starters
- [ ] Refresher training conducted quarterly
- [ ] Compliance procedures reviewed and updated annually
- [ ] Client data segregation verified regularly
- [ ] Suppression list integrity audited monthly
- [ ] ICO enforcement actions monitored for sector-relevant developments
Making compliance operational
The checklist above covers what you need to do. The practical question is how to do it at scale without it becoming a full-time administrative burden.
For call centres making thousands of calls daily, manual TPS checking is not viable. Copying numbers into a web form one at a time does not scale, and spreadsheet-based tracking breaks down under volume.
The operational model that works is API-based checking integrated directly into your dialler or CRM workflow. Numbers are screened automatically before they reach an agent. Results are logged without manual intervention. Re-checking is triggered on schedule. Audit trails are generated as a byproduct of normal operations, not as a separate compliance exercise.
TPSCheck is built for this kind of integration. The batch checking API processes up to 100 numbers per request, the audit log system maintains timestamped records of every check, and plans scale from 10,000 to 500,000+ checks per month. For call centres that need the full compliance toolkit, including risk scoring, 28-day tracking, and 24-month audit retention, the Business plan at £199 per month covers 500,000 checks with a 99.9% uptime SLA.
View all plans and features or read the API documentation to see how it fits your workflow.
Summary
TPS compliance for call centres is not a one-off task. It is an ongoing operational discipline that requires proper processes, reliable tooling, and consistent execution across every campaign and every client.
The ICO has issued more than £2.59 million in fines for nuisance calls since April 2023, and the new maximum penalty of £17.5 million means the stakes have never been higher. For call centres, where volumes amplify every risk, systematic compliance is the only viable approach.
The checklist in this article covers the essentials: verify your data, screen your lists, manage your suppressions, keep your records, and handle complaints properly. Do these consistently and you have a defensible compliance position. Skip any of them and you are exposed.
Start a free TPSCheck account to test the API with 50 checks. No credit card required.
TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).