Skip to main content
TPSCheck Blog
How Often Should You Re-Check TPS? The 28-Day Rule Explained

How Often Should You Re-Check TPS? The 28-Day Rule Explained

If you make marketing calls in the UK, you have probably heard that you need to re-check phone numbers against the TPS register every 28 days. It is one of the most frequently repeated rules in telemarketing compliance.

But here is the thing most people get wrong: the 28-day rule is not a statutory requirement. PECR does not mandate a specific re-checking interval. The 28-day figure comes from a combination of how the TPS register operates and the ICO's published guidance on best practice.

Getting this distinction right matters. It affects how you build your compliance processes, how you defend your approach if the ICO comes asking questions, and whether you are doing more or less than you actually need to.

This article explains exactly where the 28-day figure comes from, what the law actually requires, and how to put a practical re-checking process in place.

What the law actually says

The legal obligation to screen against the TPS sits in Regulation 21 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). The regulation states that a person shall not make unsolicited direct marketing calls to a number listed on the TPS register unless the called subscriber has previously notified the caller that they consent to such calls.

That is the legal requirement: do not call TPS-registered numbers without consent. Full stop.

What Regulation 21 does not do is specify how frequently you must check the register. It does not say "every 28 days." It does not say "every week" or "every month." It simply says you must not call someone who is registered.

So where does the 28-day figure come from?


Where the 28-day figure originates

The 28-day period relates to two things, and they are often confused.

1. The TPS registration activation period

When someone registers their number with the TPS, it takes up to 28 days for that registration to become active on the register. This is an operational characteristic of how the TPS system works, not a compliance obligation imposed on callers.

2. Regulation 21's statutory defence

Regulation 21 includes a specific provision that protects callers from liability in this scenario. It states:

"A person shall not be held to have contravened paragraph (1)(b) where the number allocated to the called line has been listed on the register for less than 28 days preceding that on which the call is made."

In plain English: if someone registered with the TPS fewer than 28 days ago and you call them, you have not broken the law. This is a statutory defence built into PECR itself, acknowledging the delay between registration and activation.

3. ICO guidance on checking frequency

The ICO's published guidance on direct marketing using live calls states:

"It can take 28 days for a TPS or CTPS registration to become active. This means that if they did the check more than 28 days ago, then you may inadvertently call numbers where the registration has become active."

This is the origin of the "re-check every 28 days" practice. The ICO is making a logical recommendation: because registrations take up to 28 days to appear, a check older than 28 days could miss numbers that have since become active. If you call those numbers, you lose the statutory defence provided by Regulation 21.

The ICO also advises that when obtaining call lists from third parties who claim to have already screened them, you should "make sure that this happened recently" because of the 28-day activation window.

This is guidance, not legislation. But it is guidance from the regulator that enforces PECR, which makes it the closest thing to a requirement that exists.


Why the distinction matters

You might wonder whether this is splitting hairs. If the ICO recommends 28 days, is it not effectively a requirement?

In practice, the distinction matters for three reasons.

Proportionality in enforcement

If the ICO investigates your organisation for calling TPS-registered numbers, one of the first things it will assess is whether you had reasonable processes in place. Demonstrating that you re-check within 28 days aligns with the ICO's own guidance, which puts you in a strong position. But the ICO assesses compliance holistically. A business that re-checks every 30 days with robust processes is in a very different position from one that never re-checks at all.

Risk-based approach

Understanding that 28 days is guidance rather than a hard legal deadline allows you to take a risk-based approach. Some businesses choose to re-check more frequently, especially during active campaigns where calling volumes are high and the cost of a complaint is significant. Others with low calling volumes may find that 28-day cycles are more than sufficient.

Defence against misinformation

Many TPS checking providers and compliance consultants state flatly that the 28-day re-check is a legal requirement. It is not. Knowing the actual legal position means you can make informed decisions rather than reacting to inaccurate claims. It also means you understand that compliance is about more than ticking a box every 28 days.


Does the 28-day rule apply to CTPS?

Yes. The same logic applies to the Corporate Telephone Preference Service (CTPS), which covers business numbers. CTPS registrations also take up to 28 days to become active, and the ICO's guidance on screening frequency applies equally.

If your marketing calls target businesses as well as individuals, you should re-check against both registers on the same cycle.

For a detailed explanation of the differences between TPS and CTPS, see our product guide.


What about existing customer relationships?

A common question is whether you need to screen numbers against TPS if the person is an existing customer or has given consent.

The answer depends on the type of consent you hold.

Specific prior consent: If a subscriber has specifically notified you that they consent to receiving your marketing calls, you may call them even if they are TPS-registered. This consent must be specific to your organisation and to marketing calls. A general "agree to be contacted" tick box is unlikely to be sufficient.

Existing customer relationship: Having a commercial relationship with someone does not automatically override their TPS registration. Unlike the "soft opt-in" that exists for email marketing under PECR Regulation 22, there is no equivalent exemption for live marketing calls. If someone is registered on the TPS and has not given you specific consent to call, you must not call them for marketing purposes.

The safest approach is to screen all numbers, regardless of whether you believe you hold consent. This protects you if your consent records turn out to be inadequate, and it costs very little compared to the risk of a complaint.


What happens if you check less frequently than 28 days?

If your most recent TPS check is older than 28 days and you make marketing calls based on it, you face several risks.

Loss of the statutory defence

As discussed above, Regulation 21 provides a defence where a number has been listed on the TPS for fewer than 28 days. If you last checked 45 days ago and a number was registered 30 days ago, that registration has been active for longer than 28 days. You cannot rely on the statutory defence, and calling that number is a PECR breach.

Increased complaint risk

People who register with the TPS typically do so because they are already frustrated by marketing calls. The sooner their registration takes effect, the sooner they expect the calls to stop. A person who registered three weeks ago and is still receiving calls is likely to complain to the ICO.

Regulatory consequences

Under the Data (Use and Access) Act 2025, which came into force in February 2026, maximum fines for PECR breaches have increased to £17.5 million or 4% of annual global turnover. Recent ICO enforcement actions demonstrate that the regulator takes TPS violations seriously:

  • Poxell Ltd was fined £150,000 for making over 2.6 million calls to TPS-registered numbers.
  • Skean Homes Ltd was fined for making 614,342 unsolicited marketing calls to TPS-registered subscribers.
  • Pinnacle Life Limited received an enforcement notice and monetary penalty for instigating nearly 48,000 unsolicited calls to TPS-registered individuals.

These fines were issued under the old £500,000 cap. Under the new regime, penalties for the same conduct could be significantly higher. For a full analysis of ICO enforcement trends, see our article on TPS fines and enforcement.

Reputational damage

Beyond fines, the ICO publishes details of all enforcement actions on its website. Being publicly named as a business that called TPS-registered numbers erodes trust with customers and prospects alike.


Practical implementation: building a re-check process

Knowing the theory is one thing. Putting it into practice is another. Here is a straightforward approach to implementing 28-day re-checking.

Step 1: Record when each number was last checked

Every phone number in your calling list needs a timestamp showing when it was last screened against the TPS and CTPS registers. Without this, you cannot determine which numbers are due for re-checking.

Step 2: Set a re-check deadline

Apply a 28-day window from the date of the last check. Any number where the check is older than 28 days should not be called until it has been re-screened.

A prudent approach is to set your internal deadline at 25 days rather than 28. This provides a buffer for weekends, public holidays, or technical delays, ensuring you never accidentally exceed the 28-day window.

Step 3: Prioritise active campaign lists

Not every number in your database needs re-checking at the same frequency. Focus on lists that are actively being used in outbound campaigns. Dormant lists can be re-checked when they are reactivated.

Step 4: Re-check in bulk before campaigns launch

Before any outbound calling campaign begins, screen the entire list against TPS and CTPS, regardless of when individual numbers were last checked. This ensures your data is as fresh as possible at the point of use.

Step 5: Maintain an audit trail

Log every TPS check with a timestamp, the result, and the source. If the ICO asks you to demonstrate your compliance processes, these records are your evidence. A verbal assurance that "we check regularly" is not sufficient.

For details on how to integrate these steps with your existing systems, see our API documentation.


How to automate re-checking

Manual re-checking works at small scale, but it breaks down quickly as your contact database grows. Spreadsheets get out of date. Calendar reminders get ignored. Staff leave and take institutional knowledge with them.

Automation eliminates these risks.

API-driven re-checking

The most reliable approach is to integrate TPS checking directly into your calling workflow via API. With a programmatic approach, you can:

  • Automatically flag numbers where the last check is approaching 28 days
  • Trigger batch re-checks on a schedule without manual intervention
  • Receive immediate notification if a previously clear number becomes TPS-registered
  • Generate audit logs automatically for every check

TPSCheck provides a REST API that supports both single-number and batch checking, making it straightforward to build automated re-checking into your existing systems.

TPSCheck's 28-day compliance tracking

For teams that want automation without building custom integrations, TPSCheck's Growth, Business, and Enterprise plans include a built-in 28-day compliance tracking dashboard. Here is how it works:

  1. Register your numbers. Add phone numbers to the monitoring system through the dashboard or bulk upload.
  2. Automatic tracking. The system records when each number was last checked and calculates the compliance deadline.
  3. Proactive re-checking. Numbers are automatically re-checked on Day 25, providing a three-day safety buffer before the 28-day deadline.
  4. Status change alerts. If a number's TPS or CTPS status changes, you receive an immediate notification by email or webhook.
  5. Compliance dashboard. View all monitored numbers, their last check date, and a countdown to the next required re-check.

This approach means your team can focus on calling rather than compliance administration. The system handles the scheduling, and you have a complete audit trail if the ICO ever requests evidence of your screening processes.


Choosing the right plan for re-checking

The volume and frequency of your re-checking determines which TPSCheck plan is most cost-effective.

Scenario Recommended plan Why
Small list, occasional campaigns Starter (10,000 checks/month, £29/month) Sufficient for initial checks and periodic re-screening
Regular campaigns, growing database Pro (50,000 checks/month, £79/month) Includes audit logs and compliance reports
Continuous calling, compliance tracking needed Growth (150,000 checks/month, £149/month) Includes 28-day compliance tracking dashboard
High volume, full automation Business (500,000 checks/month, £199/month) Adds compliance risk scoring and 24-month audit retention

All plans include TPS and CTPS checking, phone intelligence data, and API access. Pay-as-you-go credit packs are also available from £4 for 1,000 checks if you need flexibility without a subscription.

View all plans and features on our pricing page.


Summary: what you need to remember

  1. PECR requires you to screen against TPS before making marketing calls. This is a legal obligation.
  2. PECR does not specify a re-checking frequency. The legislation does not mention 28 days as a screening interval.
  3. The 28-day figure comes from how the TPS register operates. Registrations take up to 28 days to become active.
  4. Regulation 21 provides a statutory defence for calls made to numbers listed for fewer than 28 days. After that, you are exposed.
  5. The ICO recommends re-checking within 28 days as best practice, to avoid calling numbers where registrations have become active since your last check.
  6. Following ICO guidance is the practical standard. While not legally binding, it represents the regulator's expectation and is the benchmark against which your processes will be assessed.
  7. Automation removes the risk of human error. Manual tracking fails at scale. API-driven re-checking ensures nothing falls through the gaps.

If you are not currently re-checking your calling lists within 28 days, now is the time to start. And if you are doing it manually, there is a better way.

Start your free TPSCheck account -- 50 checks per month, no credit card required. Or explore our API documentation to see how re-checking integrates with your existing systems.