Cold calling and the law

How to build a UK cold calling list you are allowed to call

The companion question to whether cold calling is legal. That page covers the call. This one covers the list — where the numbers may legitimately come from, what the ICO expects you to have checked before you dial, and the duties that continue for as long as you keep the file. Every quotation below was read on the ICO’s own guidance or on legislation.gov.uk on 28 August 2026.

This is not legal advice

This page quotes primary sources and says where one is silent. It cannot tell you whether your own list is lawful — that turns on where your data came from, what those people were told, and what you intend to do with it. Take your own advice before you scale.

Two separate questions, and people answer only one

A calling list has to clear two different regimes at once, and they ask different things:

  • PECR asks about the number. Is it on the TPS or CTPS register? Has this person told you to stop? That is a screening question, and it is covered on the legality page.
  • Data protection law asks about the data. Where did you get it, were the people told, and what is your lawful basis for holding it? That is what this page is about.

A list can pass the first test completely and still be unlawful under the second. Screening a bought file against the TPS does not answer the question of whether you were entitled to have the file.

Publicly available sources: allowed, with conditions

The ICO addresses this directly under the heading “Can we use publicly available personal information for direct marketing purposes?”. It first sets out what it means by the term:

“The term ‘publicly available’ can refer to information sourced from various places, including: the open version of the electoral register; Companies House; websites and social media; and press articles or ‘rich’ lists.”

And then the answer, which is a qualified yes:

“Data protection law and PECR don’t necessarily prevent you from doing this but there may be restrictions. For example, you must tell people that you have their information and what you want to do with it, as well as ensuring what you want to do is fair and lawful.”

The sentence that most list-building falls foul of is the one after it:

“You must consider whether your direct marketing activities will be unexpected to the people whose information you are collecting from public sources. For instance, because someone’s social media page has not been made private or they are seeking a large audience for their social media post doesn’t mean that you are free to use their personal information for direct marketing purposes. They won’t expect you to do this.”

Read that test honestly against your own source. A restaurant that publishes a bookings number on its own website expects trade calls on that number; that is what the number is for. A named individual’s personal profile scraped from a social network does not carry the same expectation, and the ICO says so in terms. The distinction is not the difficulty of getting the data — both are one click — it is what the person would reasonably expect.

Source read 28 August 2026: ICO — collect information and generate leads.

What we found when we counted a real dataset

We built a list of UK hospitality venues from public sources and counted which contact channels those businesses actually publish. Base: 30,852 UK venues with a website — restaurants, pubs, cafés, fast food, hotels, guest houses, bars, bakeries and similar — counted 28 August 2026.

  • 72.5% have a publicly discoverable phone number (22,378)
  • 42.6% have a publicly discoverable email address (13,155)
  • 32.8% have a phone number and no email at all (10,105)

Two things follow. First, for roughly a third of these venues no email address is published in either place we looked — which is the honest case for calling rather than a slogan about it. Second, the number they published is a business line they publish in order to be rung. That is a materially better starting point, on the ICO’s expectation test, than a personal detail obtained from somewhere the person did not choose to be found. The full method, the two separate sources and the limitations are set out on the contactability data page; we would rather be argued with than quoted loosely.

Buying a list: the nine questions the ICO expects you to have asked

If you buy or rent data, the ICO is explicit that the compliance risk does not transfer with the invoice:

“However, it is important to remember that you are responsible for ensuring compliance with data protection law and PECR. It is not enough to simply accept a third party’s assurances that the information they are supplying to you is compliant. This means that you must undertake proportionate checks and due diligence before you get the information.”

It then lists what to establish. Paraphrased for length, but the substance is the ICO’s:

  • Who compiled it — the seller, or somebody else?
  • Where it came from — from people directly, or from other sources, and is it fair that those sources were used?
  • What people were told when their information was collected.
  • When it was compiled — the collection date and the age of the file.
  • What type of information it is, including whether any is special category data.
  • How it was collected — the context and the method.
  • What consent records exist, if it is sold as consented data: what people agreed to, what they were told, whether you were named, and when and how they consented.
  • What evidence of suppression screening there is — in the ICO’s words, “can it be demonstrated that the TPS has been checked against and how recently?”
  • How the seller handles people’s rights — does it pass objections on?

And the conclusion, which is the useful one to hold on to when a broker is confident and vague at the same time:

“A reputable third party should be able to demonstrate to you that the information it is supplying is reliable. You should not use the information if it cannot do this, or if you aren’t satisfied with its explanations.”

Note the phrase “were you named”. Consent collected for “selected third parties” is not consent for you, and a seller who cannot produce the wording cannot show that it is.

Appending phone numbers to existing contacts: the ICO is unusually blunt

Buying additional contact details to bolt onto records you already hold — data matching or appending — is treated far more sceptically than most people expect:

“If people have consented to you having their additional contact details for direct marketing, then it is likely that you can match these with what you already hold. If people have not agreed, then it is likely to be unfair in most cases to obtain such details for direct marketing. This is the case, even if you explain in your privacy information that you might seek out further information about people from third parties. This is because it removes people’s choice about what channels you can contact them on for direct marketing.”

“Even if you explain in your privacy information” is the part worth reading twice. A disclosure in a privacy policy does not rescue this. The ICO adds that you cannot assume someone wants to be reached on a channel they never gave you, and that “even if they have forgotten, they still won’t reasonably expect you to market them using details they never gave you or agreed to you having”.

Your lawful basis: what legitimate interests actually requires

Consent is not the only route. The ICO’s guidance on planning direct marketing:

“If your direct marketing activity doesn’t need consent under PECR, then you might be able to rely on the legitimate interests as your data protection reason (‘lawful basis’). For example, if you can show the way you use people’s information: is proportionate; has a minimal privacy impact; and is not a surprise to people or they are not likely to object to what you are doing.”

It is a three-part test — a legitimate interests assessment. In the ICO’s own framing: a purpose test (do you have a legitimate interest, for example growing your business), a necessity test (is using the data in this way necessary, or could you achieve the purpose another way), and a balancing test weighing your interest objectively against the interests and rights of the people affected, including “the potential nuisance factor of unwanted messages”.

Two practical consequences. The assessment is a document you should be able to produce, not a state of mind. And the ICO says that where you rely on legitimate interests, “you should give people a clear option to opt out of your direct marketing when you initially collect their details”.

Source read 28 August 2026: ICO — plan direct marketing.

The moment someone says no: suppress, do not delete

This is counter-intuitive and it is the single most common operational mistake. The ICO:

“If someone no longer wants you to use their information for direct marketing purposes, you should put their details onto a suppression or ‘do not contact’ list, instead of deleting them. Doing this means you can check against your list so you don’t use their information for direct marketing in future by mistake.”

Delete the record and the number simply returns on the next import, and you call them again. The objection itself is absolute:

“People have a legal right to object to you using their information for direct marketing purposes. If someone objects, you must stop using their personal information for direct marketing. There are no reasons that you can use to refuse their objection.”

The ICO also notes there is no required form of words — “People can object verbally, as well as in writing, and this might be directed to any part of your organisation” — so a refusal spoken on a call is an objection, and needs to be captured on the call. And once someone has objected, “you can’t contact them at a later date to ask if they’ve changed their mind”.

Source read 28 August 2026: ICO — respect people’s preferences.

Keeping the list accurate, and not keeping it forever

Accuracy is a legal duty, and the ICO spells out what has to be recorded accurately: the contact details, the source of that information, which methods of marketing people consented to, any objections, opt-outs or withdrawals, and the suppression list itself. A list whose provenance was never recorded cannot satisfy that, and cannot answer the buying questions above either.

On screening freshness it is direct: “you must use the most recent version of the TPS to check phone numbers before making live marketing calls”. That sits alongside regulation 21(3) of PECR, under which a number listed for less than 28 days before the call does not put you in breach — so a screen older than 28 days leaves everything registered since it unprotected.

On retention, there is no fixed period: “Data protection law doesn’t have specific timescales for how long you need to keep people’s information for direct marketing”, but you must be able to justify why keeping it is necessary, and delete or anonymise it when it is not — “unless you need to keep a small amount for another purpose, such as a suppression list”. The suppression list is the thing you keep after everything else goes.

Who is responsible when someone else does the calling

Outsourcing does not move the duty. The ICO on working with others:

“Responsibility for complying with PECR is with the ‘sender’, ‘caller’ or ‘instigator’ of the direct marketing message. You are likely to be instigating if you encourage, incentivise or ask someone else to send your direct marketing message. This means that PECR may still apply to you, even if you don’t send the message yourself or you don’t hold the contact details that your messages are sent to.”

Where another organisation checks your list against the TPS or dials on your instructions, the ICO’s example treats them as acting on your instructions — the decisions, and the exposure, remain yours. That is worth knowing before signing with an agency on the understanding that compliance is “handled”.

One to watch: the register’s own wording is being amended

Regulation 26 of PECR — the provision that creates the register the TPS and CTPS maintain — carries an outstanding amendment on legislation.gov.uk, read 28 August 2026: words in regulation 26(1)–(5) are to be substituted by S.I. 2026/386. The register requirement is not being removed, and we are not going to speculate on the effect. It is recorded here so that anyone building a process on this page checks the source again rather than assuming it is frozen. The ICO’s telephone marketing guidance separately carries a notice that it is under review because of the Data (Use and Access) Act.

Source: PECR 2003, regulation 26.

The build sequence, in order

  • Choose a source you can defend on expectation, not just on availability. Published business contact points beat scraped personal details.
  • Record provenance on every row as you collect it — where it came from and when. Retrofitting this is close to impossible.
  • If you buy, run the nine checks above before payment, and walk away from a seller who cannot answer them.
  • Write the legitimate interests assessment down — purpose, necessity, balance — before the first call, not after a complaint.
  • Screen against the TPS and the CTPS, and against your own suppression list, which is a separate duty.
  • Re-screen at least every 28 days, and always before a campaign.
  • Capture objections on the call itself and suppress rather than delete.
  • Review and delete what you no longer need, keeping the suppression list.
  • Present your caller ID and say who is calling — the duties on the call are on the legality page.

Where this touches FoxEra

To be plain about the boundary: FoxEra does not screen your list against the TPS or CTPS for you, and does not warrant that leads you find or import are lawful to call. That is your responsibility, and we would rather say it than let it be assumed.

What the product does do is on the record-keeping side of the list above. Every call is transcribed word for word and the outcome is stored against the contact, so an objection said out loud on a call exists in writing afterwards, and the provenance and outcome of a contact are in one place rather than in someone’s memory. That is described in the outbound calling CRM. If you are still working out which category of tool you need, the comparison of AI calling, power diallers and answering services covers it, and what a connected minute costs covers the money.

Frequently asked questions

Can you use publicly available information to build a cold calling list?

ICO guidance says data protection law and PECR do not necessarily prevent it, but there may be restrictions: you must tell people you have their information and what you intend to do with it, and what you do must be fair and lawful. You must also consider whether the marketing will be unexpected — a page not being private does not make the information free to use.

What should you check before buying a marketing list?

The ICO says accepting the seller’s assurances is not enough. Establish who compiled the data, where it came from, what people were told, when it was compiled, what type it is, how it was collected, what consent records exist, what evidence of TPS screening there is and how recent, and how the seller handles objections.

Do you need consent to call a business from a list?

Not necessarily. PECR does not require consent for live marketing calls to numbers that are not registered and have not objected. You still need a lawful basis under data protection law for the personal data, which for direct marketing is often legitimate interests — subject to the ICO’s purpose, necessity and balancing test.

Can you append phone numbers to contacts you already hold?

The ICO says that where people have not agreed, obtaining additional contact details for direct marketing “is likely to be unfair in most cases”, and that saying so in your privacy information does not cure it, because it removes people’s choice of channel.

Should you delete someone who asks not to be called?

No — suppress them. ICO guidance says to put their details on a suppression or do-not-contact list instead of deleting, so you can check against it and avoid contacting them again by mistake.

How often should a calling list be re-screened?

The ICO says to use the most recent version of the TPS before making live marketing calls. Regulation 21(3) of PECR gives no protection once a number has been registered for 28 days or more, so a screen older than that leaves recent registrations uncovered.