





A debt collection agency agreement is the written contract that gives an agency legal authority to chase your debts on your behalf, and it must lock down four things: scope of what the agency can and cannot do, commission and fee mechanics, UK GDPR data-processing terms under Article 28, and compliance with FCA rules on fair treatment. Without those four clause families in writing, you have no enforceable control over how your name gets used to collect money.
TL;DR:
- A clear agency agreement must specify the scope of authority, including permitted recovery actions and restrictions on legal or subcontracting activities.
- Commission rates should be tiered based on how long the debt is overdue, with full documentation required to justify lower rates for newer accounts.
- Contracts must address data processing in accordance with UK GDPR, including sub-processor rules, breach notification timelines, and end-of-contract data deletion.
- The agreement should include FCA compliance obligations, such as exercising forbearance with vulnerable customers and reporting on customer vulnerabilities.
- Regular performance reviews, audit rights, and termination procedures with written data return or deletion are critical to manage ongoing risk and data security.
A debt collection agency agreement is a contract that appoints a third party to recover money on your behalf while you retain ownership of the debt. That distinction matters more than most businesses realise. When you appoint an agency, the debt stays yours: the agency acts as your representative, contacts debtors in your name (or its own, disclosed), and hands back whatever it recovers, minus commission. When you sell or assign a debt, ownership transfers permanently to the buyer, who then collects for itself and keeps everything.
Mixing the two up in a contract creates real problems. If your paperwork reads like a sale, but you intended an agency appointment, you can lose the right to withdraw the account, negotiate directly with the debtor, or take it to court yourself later. Get the structure wrong and you may also find you have unintentionally transferred customer data outside your control, which raises separate GDPR headaches.
A written agreement matters for reasons beyond clarity of intent:
Practical triggers for putting an agency agreement in place: any unpaid invoice past several weeks where internal reminders have failed, any account where the debtor has stopped responding, or any portfolio large enough that ad hoc phone calls to a collector no longer scale. StepChange notes that earlier placement generally improves recovery odds and avoids the messier escalation route of sale or court action, so the contract should exist before you need it, not after a dispute forces the issue.
Every agreement, whatever its length, should cover the same clause families. Treat this as a checklist to run through before signing anything, not a wish list.
Pro Tip: Ask for a sample compliance breach report before you sign. If the agency cannot produce one, or the format looks thin, that tells you more about how they will actually behave under pressure than anything in their sales pitch.
Beyond those four pillars, insist on a clause defining what counts as a “successful recovery” for commission purposes; partial payments, disputed settlements, and debtor bankruptcy can each be treated differently, and vague wording here is where disputes usually start. A well-drafted agency agreement template will also separate “recovered” from “collected but not yet remitted,” since timing differences between when the agency receives money and when it pays you can matter for cash flow on larger portfolios.
Article 28(3) of the UK GDPR sets out the minimum terms that must appear in any contract where a processor handles personal data on a controller’s instructions, and debt collection almost always falls into this category. The ICO’s own guidance lists what has to be specified in writing, and skipping any of it is a compliance gap, not a drafting shortcut.
The contract must state:
A statistic worth sitting with: many businesses assume a signed non-disclosure agreement covers their GDPR obligations. It does not. The ICO’s guidance sets out eight specific mandatory terms under Article 28(3), and an NDA typically covers none of them properly. If the agency mishandles data and your contract only has a confidentiality clause, you may find yourself jointly and severally liable for a breach you thought you had outsourced.
Beyond the core terms, the agreement needs to address sub-processors directly: can the agency use a third-party dialler service, a tracing bureau, or an outsourced call centre, and if so, under what conditions? Any sub-processor should be subject to the same data protection terms, and you should retain the right to object to a specific sub-processor on reasonable grounds.
Practical points that matter as much as the legal boilerplate:
A GDPR-focused review of your agency’s obligations before signing is worth the hour it takes. Most disputes over data handling trace back to a contract that never specified sub-processor rules or deletion timelines in the first place.
The Financial Conduct Authority’s Consumer Credit sourcebook, known as CONC, applies to debt collection activity, and it applies to your agency even though you are the one who signed the original credit agreement or supply contract. CONC 7 covers arrears, default, and recovery, including repossessions, and the FCA’s own handbook is explicit that firms must ensure their agents and any third parties acting for them comply with these rules, not just the firm itself.
That obligation does not disappear just because you outsourced the phone calls. If your agency breaches CONC while collecting on your behalf, the regulatory and reputational exposure can land on you as much as on them, which is why the contract has to build in enforceable safeguards rather than relying on the agency’s own compliance culture.
What this means practically for your agreement:
Pro Tip: Build a quarterly compliance check into the contract rather than a one-off audit at signing. Agencies that were compliant a year ago are not automatically compliant now, especially after the Consumer Duty raised the bar on what “fair treatment” actually requires in practice.
The Consumer Duty adds a further layer: agencies now need to evidence that customers are achieving good outcomes, not just that a process was technically followed. A contract that only references CONC without mentioning Consumer Duty obligations is already a step behind where the regulatory expectation sits. If you want a fuller grounding in what “compliant” actually looks like before you vet an agency, Debtrecoveryhub’s guide to FCA debt collection rules sets out the checklist in more depth, and a dedicated guide on vulnerable customer handling is worth reading before you finalise any reporting clause.
Commission rates are rarely fixed, whatever an agency’s rate card suggests. The single biggest lever is account age: a 30-day overdue invoice with full documentation is cheap to collect and commands a lower rate, while a two-year-old account with patchy paperwork is expensive to chase and priced accordingly. Volume is the second lever. An agency handling 200 accounts a month for you will usually offer a better blended rate than one handling five.
Before agreeing final rates, it is worth comparing what a typical UK commission structure looks like across different account ages, so you know whether a quoted rate is reasonable or opportunistic.
None of this needs to be reinvented from scratch. Below is a short set of clause structures, written generically so you can adapt the specifics (names, thresholds, jurisdiction) to your own agreement. These are illustrative starting points, not a substitute for a lawyer reviewing your final draft, particularly on a high-value or complex portfolio.
Appointment and authority clause:
“The Client appoints the Agency to act as its agent for the purpose of recovering the debts listed in Schedule 1 (‘the Debts’). The Agency’s authority is limited to: issuing demand correspondence, making telephone contact, negotiating payment plans within the parameters set out in Schedule 2, and reporting recovery status to the Client. The Agency shall not initiate legal proceedings, agree to write off any part of a Debt exceeding [X]% of principal, or subcontract performance of this Agreement to a third party, without the Client’s prior written consent.”
Article 28(3) data-processing clause:
“For the purposes of UK GDPR, the Client is the Controller and the Agency is the Processor. The subject matter of processing is debt recovery activity in respect of the Debts; the duration is the term of this Agreement plus [X] days for wind-down. The nature and purpose of processing is limited to recovery-related contact and reporting. The categories of data subject are debtors named in Schedule 1, and the categories of personal data are name, contact details, and payment history. The Agency shall process personal data only on the Client’s documented instructions, maintain confidentiality, implement appropriate technical and organisational security measures, and shall not engage a sub-processor without the Client’s prior written authorisation.”
Commission structure clause:
No commission is payable on sums subsequently repaid, reversed, or successfully disputed by the debtor, and any commission already paid on such sums shall be refunded to the Client within [X] days."
Audit and termination clause:
“The Client, or an appointed representative, may audit the Agency’s records relating to the processing of personal data and performance of this Agreement on [X] days’ written notice. Either party may terminate this Agreement on [X] days’ written notice; the Client may terminate immediately in the event of the Agency’s material breach of CONC obligations or UK GDPR requirements.”
The table below sets out what each clause family should specify, so you can check a draft agreement against it line by line.
| Clause family | Must specify | Common gap |
|---|---|---|
| Appointment and scope | Permitted actions, prohibited actions, settlement authority limit | No cap on write-off authority |
| Data processing (Article 28) | Subject matter, duration, data types, sub-processor rules | Sub-processors not addressed at all |
| Commission | Rate bands by age, basis (gross or net), clawback terms | Flat rate regardless of account age |
| Audit rights | Frequency, scope, who can conduct it | Right exists on paper but no mechanism to exercise it |
| Termination | Notice period, immediate-termination triggers, data return | Vague “reasonable notice” with no fixed period |
How you exit an agency agreement matters almost as much as how you enter it. A contract that goes quiet on termination leaves you exposed exactly when things are already going wrong, whether that is a performance failure, a compliance breach, or simply the end of a fixed term.
Set a standard notice period (30 to 90 days is typical for a debt recovery relationship) for termination without cause, but build in immediate-termination triggers for serious breaches: a CONC violation, a data breach caused by the agency’s negligence, or repeated failure to meet reporting obligations. If the agency is actively pursuing a court claim or has an existing repayment plan in negotiation when the relationship ends, the contract should require it to hand over full case files and preserve the status of any ongoing action, so a replacement agency (or you, directly) can pick it up without losing ground.
On data, the requirement is straightforward under Article 28(3)(g): the agency must delete or return all personal data at the end of the contract, and you should ask for this in writing, not verbally confirmed.
Skipping this stage is where most of the real risk in an agency relationship actually sits, since a poorly closed contract can leave data scattered across systems you no longer have visibility over.
Every clause covered so far assumes you already know which agency you are contracting with. That is often the harder problem. Debtrecoveryhub’s platform matches your case to vetted agencies based on debt type, amount, age, and location, rather than leaving you to cold-call providers and hope one turns out to be a good fit.
The intake process asks for the details that actually affect fee negotiation and placement outcomes: how old the debt is, whether you have full documentation, the debtor’s location, and whether the case involves consumer debt, a commercial invoice, or something more specialist like a cross-border claim. That detail matters because, as covered in the commercial terms section above, account age and documentation quality are the two biggest drivers of the commission rate you will actually be offered. Turning up to a negotiation with a vague description of “an old unpaid invoice” puts you at a disadvantage before the conversation even starts.
If you are preparing to approach an agency, gather your invoices, any signed contracts or terms of business, a full correspondence history with the debtor, and a note of any prior payment or dispute activity. That is the same documentation an agency will want to see in the placement file, and having it ready before you submit a case through the platform speeds up matching and improves the quality of the quotes you receive. For businesses chasing unpaid commercial invoices specifically, Debtrecoveryhub’s unpaid invoice recovery service is a natural starting point for that intake.
Data protection covers personal data, but a debt collection agency agreement usually needs a separate confidentiality clause too, one that protects information that is not personal data at all. Think commercial terms, account structures, internal escalation policies, and any proprietary scoring or prioritisation methods you share with the agency to help it work your portfolio effectively.
A standard confidentiality clause should cover both directions. You are sharing sensitive commercial information with the agency, and the agency may in turn be sharing its own methods or systems with you during onboarding. The clause should specify what counts as confidential information, how long the obligation survives after termination (typically two to five years, sometimes indefinitely for genuinely sensitive material), and what the exceptions are: information already public, information independently developed, or disclosure required by law or regulator.
Where agreements often fall short is in failing to address subcontracted staff and freelance agents. If the agency uses external callers or a satellite office, your confidentiality obligations need to bind those third parties too, not just the agency’s core employees. Without that extension, information can leak through a route the contract never anticipated.
It is also worth stating explicitly that confidentiality obligations survive termination of the agreement. An agency that stops working for you should not be free to use your account insights, pricing structures, or debtor lists for any other purpose the moment the contract ends.
Every agency agreement should specify what happens when the parties disagree, because disputes over commission calculations, disputed recoveries, or alleged compliance breaches are common enough that leaving the process undefined just guarantees a messier fight later.
A tiered approach works well in practice. Start with a defined escalation path: disputes first go to named representatives on each side for informal resolution within a set period, commonly 14 to 28 days. If that fails, many agreements then require mediation before either party can proceed to formal proceedings, since mediation is faster and considerably cheaper than litigation for most commercial disagreements of this size.

Arbitration is worth considering for higher-value portfolios or where confidentiality of the dispute itself matters, since arbitration proceedings are private in a way court proceedings are not. It does add cost, though, so for smaller relationships a straightforward jurisdiction clause pointing to the courts of England and Wales (or Scotland, if that is where your business is based) is often sufficient and considerably cheaper to invoke if things do go wrong.
Whichever route you choose, state it explicitly. A contract silent on dispute resolution defaults to litigation in whatever jurisdiction a claimant chooses to bring proceedings, which is rarely the outcome either party would have picked deliberately.
The contract should set explicit rules on how the agency contacts debtors, not leave it to the agency’s internal policy, because how debtors are contacted is one of the areas regulators scrutinise most closely under CONC.
Specify which channels are permitted: letters, email, SMS, and telephone calls are standard, but you may want to exclude certain channels for particular account types (no calls to a workplace number, for instance, or no SMS for accounts involving disclosed vulnerability). Set a maximum contact frequency too. A common standard limits calls to a set number per week and prohibits contact outside reasonable hours, generally 8am to 9pm on weekdays with tighter restrictions at weekends.
The contract should also require the agency to log every contact attempt, successful or not, so you have a complete record if a debtor later complains about being contacted excessively. This record-keeping requirement doubles as your evidence base if a regulator or ombudsman ever asks how the account was handled.
Finally, address what happens once a debtor formally requests no further contact, or asks that all communication go through a solicitor or debt adviser. The contract should require the agency to honour that instruction immediately and document compliance, since continuing contact after such a request is one of the more common sources of formal complaints against collection agencies.
A debt collection agency should carry professional indemnity insurance covering errors, omissions, and negligence in the course of its work, and your contract should require evidence of current cover before the relationship begins, not just a promise that cover exists.
Ask for a minimum indemnity limit appropriate to the size of the portfolio you are placing; an agency handling a handful of small accounts needs less cover than one managing a multi-million-pound corporate debt book. Public liability insurance matters too if agency staff ever visit premises as part of tracing or negotiation work, and cyber liability cover is increasingly relevant given how much personal data the agency will be processing on your behalf.
Build a requirement into the contract that the agency notifies you if its insurance lapses, is cancelled, or is materially changed during the term, and that it provides a renewed certificate of insurance annually without you having to chase for it. An agency reluctant to share proof of cover, or one whose policy limits look thin relative to the value of debt you are placing, is telling you something about how seriously it takes its own risk exposure.
FCA rules and CONC get most of the attention, but a debt collection agency agreement needs to address other legislation too, depending on the type of debt involved. The Consumer Credit Act 1974 still governs certain regulated credit agreements, and if any of your debts arose under a regulated credit agreement, the agency needs to understand and comply with the notice and default requirements that Act imposes, separately from CONC.
Where debts involve consumers, the Consumer Protection from Unfair Trading Regulations 2008 prohibits misleading or aggressive collection practices, and a contract silent on this leaves you dependent entirely on the agency’s own internal training. The Administration of Justice Act 1970 also makes it a criminal offence to harass a debtor with demands designed to cause alarm or distress, which is a useful backstop clause to reference explicitly if you want the agency’s obligations to be unambiguous.
For business-to-business debt, the Late Payment of Commercial Debts (Interest) Act 1998 may entitle you to statutory interest and compensation on top of the principal owed, and the contract should specify whether the agency is instructed to pursue this additional recovery or stick to principal only. Getting this wrong in the contract can mean leaving genuine additional recovery on the table simply because nobody specified it should be pursued.
The pattern I notice most often isn’t a missing clause. Its scope creep in the appointment clause itself, wording so loose that an agency ends up with implied authority to do things nobody actually intended, like agreeing settlements at a discount the client never sanctioned. The second recurring blind spot is treating Article 28 as a box to tick rather than a live obligation. Businesses sign it once and never revisit it, even when the agency changes its sub-processors or IT systems eighteen months later.
Weak audit rights are the third failure, and the most avoidable. A right to audit that nobody ever exercises is not a control, it is decoration.
Treat the contract as something you review, not something you file. Set a calendar reminder for a six-monthly check against performance and compliance reporting. For anything above a modest portfolio value, or anything involving vulnerable customers at scale, get a solicitor to review the final draft before signing. The cost is small next to the exposure a bad contract creates.
— Jack
There are platforms that match your case to debt collection agencies based on your debt’s type, amount, age, and location, with the detail that shapes fair commercial terms gathered upfront.
That matters because, as this guide has set out, the strength of your agreement depends heavily on the quality of information you bring to the negotiation table. A vague brief gets a vague quote. A detailed intake, covering documentation, account age, and debtor location, gives you a stronger starting position for commission bands, reporting obligations, and every other clause covered above.
If you are chasing unpaid commercial invoices right now, start with Debtrecoveryhub’s Business Debt Recovery service, submit your case details, and get matched with agencies suited to the specific profile of what you are owed, rather than negotiating from a position of uncertainty.
Before finalising any agreement, go to the primary sources rather than relying solely on secondary guides, however thorough:
Yes. Selling a debt transfers legal ownership to the buyer, but the underlying obligation to pay does not disappear, it simply now sits with the new owner. This differs from an agency appointment, where the original creditor still owns the debt and the agency collects on their behalf.
You cannot make a genuine debt disappear by refusing contact, but you have the right to request that communication happens through a specific channel, such as in writing only, or through a solicitor or debt adviser. A properly drafted agency agreement should require the collecting agency to honour such requests immediately.
Avoid making promises about payment amounts or dates you are not certain you can keep, and avoid confirming details about the debt (its exact amount, whether it is definitely yours) without checking the agency’s paperwork first. If a debt is disputed, say so clearly and ask for evidence rather than agreeing to anything on the call.
CONC does not mandate an exact number of days, but the FCA’s rules require firms to give customers reasonable time to negotiate a repayment plan, and 30 days is a commonly used benchmark that many agency agreements build in as a contractual standard.
Under Article 28(3)(g) of the UK GDPR, the agency must delete or return all personal data at the end of the contract, and a well-drafted agreement will require written certification of that deletion rather than a verbal assurance.
Category :
Share :