Home/Compliance
Compliance is the product
In this industry the difference between a good supplier and a liability is the paper trail. Here is ours, in enough detail that your compliance officer can judge it.
The framework we work inside
Which rules apply, and where
Four things govern what we do. The UK GDPR and the Data Protection Act 2018 cover how we handle personal data. The Privacy and Electronic Communications Regulations 2003 (PECR) cover the marketing channels themselves — and PECR is stricter than the GDPR on live calls, automated calls, email and SMS. Ofcom's rules on persistent misuse cover how a dialler may behave. And the CAP Code covers the claims made in the marketing that follows.
We are a data controller for the survey we run, and usually a processor for the campaign work we do on your behalf. Which hat we are wearing changes who is responsible for what, so it is set out explicitly in the contract rather than assumed.
Lawful basis and consent
Survey respondents are told at the start of the call who is calling and why. The marketing permission is taken at the end, once they know what they have shared, and the agent reads the statement in full. That statement names the channels — telephone, email, SMS, post — and describes the categories of company that may contact them. Consent is recorded against the record with the date, time, agent and campaign, and the audio is retained.
Consent obtained this way is specific and evidenced, which is what the ICO looks for. A tick box on a competition entry from four years ago is not, which is why we do not buy that kind of data in.
Screening before dialling
Consumer numbers are screened against the Telephone Preference Service and business numbers against the CTPS before they reach the dialler, and re-screened on a rolling cycle for long-running campaigns. Postal selections are screened against the Mailing Preference Service. Client suppression files are applied on top. Screening dates are recorded per record and appear in the monthly compliance log.
Dialler conduct
We hold the abandoned-call rate below the 3% threshold in Ofcom's persistent misuse guidance, measured per campaign per day. Calls are left to ring for at least 15 seconds before clearing. Calling line identification is presented on every outbound marketing call, and the number presented is answered by a person during office hours — not a recorded message.
Vulnerable people
Agents are briefed to end the call politely and suppress the record at any sign that the person does not understand the conversation, is distressed, or is being pressed into it by someone else. This applies particularly to the over-50s propositions such as funeral plans. A suppressed record is not sold, not re-dialled, and not passed to a client.
Individual rights
Requests to access, correct, erase or object to processing are handled within one calendar month. An objection to marketing is actioned immediately on the call and propagated across every campaign within 24 hours. Where a request concerns data we processed for a client, we pass it on and support their response.
Security and location
Personal data is held on systems inside the United Kingdom. Access is role-based and logged, transfers to clients are encrypted with credentials sent by a separate channel, and staff are trained on data protection at induction and annually after that. Personal data breaches are assessed immediately and, where the threshold is met, reported to the ICO within 72 hours and to affected clients without undue delay.
Where regulated products are involved
We are not authorised by the Financial Conduct Authority and we do not advise on financial products. Insurance and funeral plan leads are supplied only to FCA-authorised firms or their appointed representatives, and we verify the firm on the FCA register before the first delivery. Our scripts introduce the client's proposition without recommending it.
Documents we will send you
- Data processing agreement (UK GDPR Article 28 terms)
- Our ICO registration certificate
- The consent statement as read to respondents
- The full campaign script, before it goes live
- Employers' and public liability insurance certificates
- A sample record with provenance fields populated
- A named recording, on request, for any record you query
Who to contact
- Data protection
- dpo@uk-lifestyle.co.uk
- Complaints
- compliance@uk-lifestyle.co.uk
- Audit requests
- compliance@uk-lifestyle.co.uk
Audit
What an audit of us looks like
Clients audit us, and we would think less of the ones who did not. You are welcome to do any of the following, at reasonable notice.
- Listen to recordings behind a random sample of delivered leads
- Review the live script and the consent statement as read
- Inspect screening dates and suppression records for your campaign
- Sit with the floor during a briefing or a calling session
- Trace any single record end to end, from source to delivery
- Review our breach log, complaints log and training records
- Verify that opt-outs you have reported were actioned within 24 hours
- Ask for a written response to your own compliance questionnaire
If something goes wrong
Complaints
If you have received a call from us that you did not want, we would rather hear about it than not. Email compliance@uk-lifestyle.co.uk with the date and rough time of the call and we will find the recording, tell you where your details came from, and suppress them.
We acknowledge complaints within two working days and aim to resolve them within ten. If you are not satisfied with our response you have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. Complaining to us first is not a condition of complaining to them.
To stop marketing calls generally, register free with the Telephone Preference Service at tpsonline.org.uk. We screen against it before every campaign.
Send us your compliance questionnaire
Most prospective clients have one. We will complete it properly and return it with the supporting documents attached.