This is not legal advice. It is a plain-English summary of published regulation. Your obligations depend on what you sell, who you call and where your data came from. Where the position is genuinely unsettled, this page says so rather than choosing the tidy answer. Check anything that matters against the regulator's own words, all of which are linked, and take proper advice before relying on it.
Last checked against the sources: 17 August 2026
What PECR requires for marketing calls
For a live marketing call to an individual, PECR does not require consent. It requires that you don't call anyone registered with the TPS, and don't call anyone who has told you they don't want calls from you. Automated recorded-message calls are a different regime and do require prior consent.
This is the single most misunderstood point in UK outbound. PECR regulation 21 prohibits unsolicited direct marketing calls to a subscriber who has registered with the Telephone Preference Service, or who has previously notified you that they object. It does not impose a general consent requirement on live calls.
Regulation 19 is stricter and covers automated calling systems — a recorded message played to whoever answers. Those need the subscriber's prior consent, which in practice means an opt-in that specifically covers automated calls. A consent that covers being called does not automatically cover being played a recording.
Two further categories carry their own consent requirements added after the original regulations: calls marketing claims management services and calls marketing pension schemes. If you are in either sector, the live-call position above does not apply to you.
PECR sits on top of UK GDPR rather than replacing it. Satisfying regulation 21 tells you the call is permitted; it says nothing about whether you are allowed to hold and use the data, which is the separate question covered in section 06.
TPS and CTPS: who must screen, and how often
Anyone making unsolicited live marketing calls must screen against the TPS for individuals and the CTPS for corporate subscribers. Registrations take effect 28 days after they are made, which is why screening every 28 days became the norm — but the obligation is not to call a registered number, not to run a screen on a schedule.
The TPS is the register of individuals who have opted out of unsolicited sales and marketing calls. It includes sole traders and, in most cases, partnerships, since those are treated as individual subscribers. The CTPS is the equivalent for corporate subscribers — limited companies, LLPs, public bodies.
Screening is a paid service. Businesses licence access to the register through the TPS in order to check their lists against it. Current licence terms and pricing are on the TPS site.
The 28-day figure is the delay between someone registering and the registration taking effect. Screening a list every 28 days means no number can be registered and callable at the same time. Screening once and then working the list for three months does not, however regularly you screened before that.
Does a customer's own consent override their TPS registration?
The common industry position is yes — that where someone has specifically consented to calls from you, you may call them despite a TPS registration, because the call is no longer “unsolicited”. The ICO's guidance supports this in principle for genuinely specific, recent, informed consent.
Where it gets contested is what counts as specific enough, and how long it lasts. A tick-box on a form eighteen months ago naming a category of business rather than you is a weaker position than most lists assume, and the ICO has taken enforcement action against organisations relying on exactly that. If you are calling TPS-registered numbers on the strength of third-party consent, that is the highest-risk thing on this page.
Dialspace does: hold your suppression lists and Do Not Call register, block a flagged number across every campaign regardless of who imports it, and record when each screen was run.
It does not: hold a TPS licence for you or screen against the TPS register on your behalf. That licence is yours, and no software can hold it for you.
Ofcom on abandoned and silent calls
Ofcom's policy sets an abandoned call rate of no more than 3% of live calls, measured per campaign over any 24-hour period. Where a call is abandoned, an information message must play within two seconds of the greeting ending, and that number must not be called again by the same campaign for 72 hours unless a person is available to take the call.
An abandoned call, in Ofcom's terms, is one where a person answers but no agent is available to speak to them within two seconds of their greeting finishing. A silent call is the subset where nothing at all is played. Both arise from the same cause: dialling more numbers than there are agents to handle the answers.
The information message has requirements of its own. It must identify the company on whose behalf the call was made, state that the call was for marketing purposes, and give a number the person can call to opt out — one that is free or charged at a basic rate. It must not contain marketing content. A message that uses the opportunity to pitch is itself a breach.
Answering machine detection deserves particular care. Where AMD wrongly classifies a live person as an answering machine, that is an abandoned call and counts towards your rate. Ofcom's policy addresses AMD false positives directly and they are not a defence.
Ofcom enforces this under the persistent misuse provisions of the Communications Act 2003, which is a different power from the ICO's. The 3% figure is a policy threshold rather than a statutory one — Ofcom describes it as the level at which it will normally consider intervening, not a permission to abandon 3% of calls as a target.
Dialspace does: pace dialling against available agents, count abandoned calls per campaign per 24 hours so the figure is visible before it becomes a problem, and hold a number back for 72 hours after an abandoned call.
It does not: guarantee you stay under 3%. That depends on how you configure pacing and how many agents you actually have on the floor, both of which are yours to decide.
CLI: the number you present
You must present a Calling Line Identification on outbound marketing calls, it must be a valid dialable number, and it must be capable of receiving return calls. It must not be a premium rate number.
The purpose is that somebody who missed your call can ring back and reach you. A presented number that rings out, is unallocated, or connects to a dead line defeats it, and Ofcom treats presenting an invalid CLI as a form of misuse.
This has a direct bearing on local presence. Presenting a local number so that a recipient sees a familiar dialling code is permitted — what is not permitted is presenting a number that isn't yours, isn't valid, or can't take a call back. If you use local presence, every number in the pool needs to be one you control and one that is answered.
Dialspace does: present numbers from a pool you own, route return calls on any of them back to your floor, and monitor whether networks have started flagging one.
It does not: make presenting a number lawful in itself. If you present a number that cannot receive a return call, the tool has not solved your problem.
Call recording and what you must disclose
You must inform people that calls are recorded, but no law requires a beep or a specific announcement. The requirement comes from UK GDPR transparency — telling people what you do with their data — not from a rule about recordings. An announcement at the start of the call is the simplest way to satisfy it, not the only lawful one.
The widespread belief that a recorded announcement is legally mandatory usually traces back to the Lawful Business Practice Regulations 2000, which concern interception of communications and require reasonable efforts to inform users that interception may occur. That is a different thing from a business recording its own calls, and the regulations do not prescribe a beep.
In practice, telling the person clearly at the start of the call is the safest and simplest route, and it is what most floors do. What matters is that the person knows, that you can evidence they were told, and that your privacy notice explains what happens to the recording and for how long you keep it.
Is announcing at the start of the call sufficient on its own?
For most marketing calls, telling the person at the start is generally accepted as meeting the transparency obligation. But an announcement alone doesn't give you a lawful basis for the recording, doesn't set a retention period, and doesn't handle a request to delete it later.
Sector rules can also override the general position entirely. Regulated firms have their own recording obligations that may require recording calls you would otherwise not record, and keeping them for periods set by the regulator rather than by you. If you are FCA-regulated, the general position on this page is not the one that governs you.
Dialspace does: record each side of the call on its own channel, let an agent pause recording so card details never enter the audio, apply the retention period you set, and delete a recording on request with a log of who did it.
It does not: write your privacy notice or decide your lawful basis. Those are yours, and the tool cannot infer them.
Consent, legitimate interests and bought leads
For live marketing calls you generally need a lawful basis under UK GDPR to process the data — commonly legitimate interests — and separately you must satisfy PECR by screening against the TPS. Consent is not usually required for the call itself, but it is required for automated calls, and third-party consent only helps you if it named you or your type of organisation specifically enough.
A bought lead arrives with an implicit claim attached: that the person agreed to hear from businesses like yours. Whether that claim holds is the whole question, and it is your responsibility rather than the seller's. The ICO expects buyers to carry out due diligence on where consent came from and what exactly the person was shown — not to take a supplier's assurance at face value.
There is also an obligation people routinely miss. When you obtain personal data from a source other than the individual, you must give them a privacy notice — normally within a month, or at the first time you contact them, whichever is earlier. A floor buying leads and ringing them without ever sending that notice is not compliant regardless of how good the consent was.
Can legitimate interests cover calling a bought lead?
Sometimes, and it is genuinely arguable in both directions. Legitimate interests is available as a basis for direct marketing, and the ICO acknowledges this directly. It requires a balancing test: your interest against the person's rights and their reasonable expectations.
The difficulty with bought data is that reasonable expectation is exactly what is in doubt. Someone who filled in a comparison form may reasonably expect a call from a business in that market; someone whose details were passed through four intermediaries almost certainly does not expect a call from the fourth. The further the lead has travelled from the point of collection, the weaker the argument becomes — and there is no bright line telling you where it fails.
Anyone offering you a confident yes or no on this without seeing the collection notice and the chain of custody is guessing.
Dialspace does: keep the consent evidence and source against each lead, so if anyone asks why a call was allowed you can show where the data came from and what the person was told.
It does not: assess whether that consent is adequate. Only you can judge the collection notice, and a record of a bad consent is still a bad consent.
What happens when someone complains
It depends what they complain about. The ICO handles PECR breaches — unwanted marketing calls, calling TPS-registered numbers, automated calls without consent. Ofcom handles persistent misuse of the network, which is where abandoned and silent calls sit. They are separate regulators with separate powers, and one complaint can reach both.
A member of the public reporting a nuisance call to the ICO is the most common route. The ICO aggregates complaints, and a pattern against one organisation is what typically triggers investigation rather than any single report. Its published enforcement register is worth reading: the cases show what actually gets organisations fined, which is usually volume of complaints combined with weak consent evidence.
Ofcom's route is different. It investigates persistent misuse under the Communications Act, and its concern is the pattern of calling behaviour rather than the marketing itself — abandoned rates, silent calls, invalid CLI.
What helps in both cases is the same and it is unglamorous: a record of where each lead came from, what the person was told, when the number was last screened, who called and what was said. An organisation that can produce that is in a different position from one that can only assert it was careful.