




GDPR applies to debt collection in the UK. Full stop. Whether you are a creditor chasing an overdue invoice or a collection agency instructed to recover on someone else’s behalf, the UK GDPR and Data Protection Act 2018 govern every step: how you hold debtor data, who you share it with, how long you keep it, and how you respond when a debtor asks what you know about them.
The three lawful bases most commonly used in debt collection are performance of a contract (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), and compliance with a legal obligation (Article 6(1)©). Before you do anything else, identify which one applies to your specific processing activity and record it.
If you are dealing with an urgent incident right now, take these steps first:
GDPR applies to every stage of debt collection in the UK, and the lawful basis, DPA, and retention policy must be documented before data is shared with any collection agency.
| Point | Details |
|---|---|
| Lawful basis is mandatory | Document contract performance, legitimate interest, or legal obligation before any processing begins. |
| DPA before data sharing | A written Data Processing Agreement must be in place before passing debtor data to any collection agency. |
| Data subject rights apply | Respond to SARs within one month; erasure can be refused only on specific documented grounds. |
| Retention needs justification | No single UK period applies; align with limitation periods and document every retention decision. |
| Debtrecoveryhub | Matches creditors with vetted, GDPR-aware collection agencies based on debt type, amount, and location. |
Under the EU GDPR (Regulation 2016/679), a controller decides the purposes and means of processing personal data. A processor processes data only on the controller’s documented instructions. Getting this allocation wrong is one of the most common and costly mistakes in outsourced collections.
Typical allocation in practice:
Three scenarios that illustrate this:
Pro Tip: Before instructing any collection agency, confirm in writing whether the relationship is controller-processor or joint-controller. The answer determines who is liable for a SAR, who must respond to erasure requests, and who carries the regulatory risk if something goes wrong.
Practical guidance from Thomson Reuters confirms that contacting a corporate director at a private home address requires careful contextual balancing: the legal basis and proportionality of the contact must be assessed before any letter is sent.
The answer depends on the stage of the debt and the nature of the processing. Most debt collection activities will rely on one of three bases under Article 6 of the EU GDPR.
The three bases and when each fits:
Running a legitimate interests assessment (LIA) — the three-part test:
What a lawful-basis record should include:
When consent is not appropriate: Consent is rarely the right basis for debt collection. A debtor cannot freely give consent when there is a power imbalance or a financial obligation already in place. Relying on consent also means the debtor can withdraw it at any time, which would halt processing entirely. Consent may occasionally be appropriate for sending marketing communications about debt management products, but not for the recovery activity itself.
Pro Tip: Document your LIA as a standalone record, not just a line in a privacy notice. If the ICO investigates, a well-reasoned LIA is your primary evidence that the processing was proportionate.
You can share debtor personal data with a collection agency, but three things must be in place before you do: a lawful basis for the transfer, a written Data Processing Agreement, and appropriate technical and organisational measures (TOMs).
Required DPA clauses — a checklist:
When is a DPIA required?
A Data Protection Impact Assessment is mandatory before processing that is likely to result in high risk to individuals. In debt collection, a DPIA is required when:
Sample DPA clause headings (generic labels):
| Clause heading | Purpose |
|---|---|
| Processing instructions | Limits agency to documented purposes only |
| Security and TOMs | Sets minimum technical standards |
| Sub-processor approval | Requires written consent before onward sharing |
| International transfers | Mandates SCCs or UK IDTA for non-UK/EEA transfers |
| Breach notification | Sets timeline for agency to notify creditor |
| Deletion and return | Specifies what happens to data on contract end |
| Audit and inspection | Gives creditor right to verify compliance |
Data subject rights still apply in full. A debtor can submit a Subject Access Request, ask for their data to be erased, object to processing, or request restriction. None of these rights are automatically suspended because a debt is owed. However, some rights have lawful limits that are directly relevant to debt recovery.
Handling a Subject Access Request (SAR):
Erasure requests under Article 17:
A debtor can request erasure, but the right is not absolute. You may refuse where processing is necessary for:
The CJEU’s ruling in the SCHUFA case reinforced that private retention of insolvency and discharge data beyond national register periods requires strict necessity and proportionality. If a credit reference agency holds discharge data longer than the public register, it must demonstrate a compelling justification.
Where erasure is refused, document the refusal with the specific legal ground, the date, and who made the decision. Provide the debtor with information about their right to complain to the ICO.
Pro Tip: When a debtor objects to processing under Article 21, you must stop processing unless you can demonstrate compelling legitimate grounds that override their interests. In practice, an active court judgment is often the clearest compelling ground. Document this assessment every time.
Retention must be limited to what is necessary for the purpose. There is no single statutory retention period for debt data in the UK; you must justify each period with a lawful basis and a documented business need.
Typical retention triggers and suggested ranges:
| Trigger | Suggested retention range | Notes |
|---|---|---|
| Active recovery (debt unpaid, no judgment) | Duration of recovery plus 6 years | Aligns with Limitation Act 1980 for contract claims |
| County Court Judgment (CCJ) obtained | 6 years from date of judgment | Statutory enforcement window |
| Statutory accounting records | 6 years from financial year end | Companies Act requirement |
| Debt fully repaid | 6 years from final payment | Limitation period for any dispute |
| Insolvency / discharge | Until national register deletion, then reassess | SCHUFA principle: private retention beyond register period requires strict justification |
The SCHUFA judgment is the clearest statement of this principle at EU level: retaining discharge data after the public register has removed it is presumptively disproportionate unless a specific, documented necessity can be shown.
Suppression lists and pseudonymisation after erasure:
A January 2026 ruling by the Brussels Market Court recognised that a minimal pseudonymised suppression list can be lawful where complete deletion would risk repeated wrongful contact. The logic: if you delete all records of a debtor who has complained about wrongful contact, you have no mechanism to prevent the same error recurring. A hashed identifier on a “do not contact” list, with no recoverable personal data, can satisfy both the erasure request and the duty to prevent further harm.
Pro Tip: If you maintain a suppression list after an erasure request, document the decision in writing: the legal ground (Art. 17(3)(b) or legitimate interest), the data elements retained, the security measures applied, and the review date. Keep this record separate from the main processing register.
The core rule is simple: identify yourself, explain your purpose, use proportionate contact frequency, and never disclose debt details to anyone who is not the debtor or their authorised representative.
Dos and don’ts by channel:
Lawful first-contact script (telephone):
“Good morning, this is [name] calling from [organisation]. I’m trying to reach [debtor’s full name]. Could you confirm whether I have the right number? I’m not able to discuss the reason for my call with anyone other than [debtor’s full name].”

If a third party answers and asks what the call is about, the response must be: “I’m not able to share that information. Please ask [debtor’s name] to call us on [number].”
FCA CONC obligations: Under CONC 7.3, firms must treat customers in or approaching arrears with forbearance and due consideration. Where a debtor proposes a repayment plan, active pursuit must be suspended while the proposal is assessed. This obligation sits alongside GDPR: continuing to process data for aggressive collection purposes while a repayment plan is under discussion may breach both regimes simultaneously.
For guidance on ethical debt collection practices that satisfy both GDPR and FCA requirements, the operational controls are closely linked.
Immediate steps when data is mishandled:
The NCSC’s breach response guidance covers the technical steps to contain and investigate a breach, including isolating affected systems and preserving forensic evidence. For incidents involving suspected fraud or identity manipulation, specialist support from a digital fraud investigation service may be needed alongside the regulatory response.
Complaint flow for individuals:
Complaint and investigation timeline:
| Stage | Typical timeframe |
|---|---|
| Internal complaint response | 30 days (extendable) |
| ICO acknowledgement | Within 2 weeks |
| ICO assessment and triage | 3–6 months |
| ICO investigation (formal) | 6–18 months depending on complexity |
| Civil claim (County Court) | 6 months depending on complexity |
Getting to a defensible baseline for GDPR compliance in debt collection does not require a complete overhaul. It requires the right controls in the right order.
Compliance checklist (ordered by priority):
Pro Tip: Set a calendar trigger to review your DPIA and ROPA whenever you introduce a new contact channel, change your agency partner, or acquire a new debt portfolio. A DPIA that was accurate 18 months ago may be materially wrong today.
For the full picture on pre-action obligations before enforcement, the pre-action protocol for debt sets out what creditors must do before issuing proceedings.
UK creditors dealing with EU-based debtors, or instructing agencies with EU operations, face an additional layer of compliance. Since Brexit, the UK operates its own data protection regime under the UK GDPR, and transfers of personal data between the UK and the EU (and vice versa) require a specific legal mechanism.
The current position:
The European Commission granted the UK an adequacy decision in June 2021, meaning personal data can flow freely from the EU to the UK without additional safeguards. That decision is subject to periodic review. UK creditors sending data to EU-based processors (including collection agencies) benefit from the same adequacy finding in the opposite direction under UK domestic rules.
Where transfers become more complex:
For UK businesses pursuing debts across borders, the international debt recovery guide covers jurisdictional considerations in more detail.
Practical step: Before instructing any agency, ask for a copy of their sub-processor list and confirm the transfer mechanism for each sub-processor location. This is a standard DPA audit right and should be exercised before the contract is signed, not after a breach occurs.
The compliance failures that generate ICO complaints and civil claims in debt collection are rarely about the law itself. Most organisations understand, at least in outline, that GDPR applies. The failures are operational.
The three mistakes that come up repeatedly are: a DPA that was drafted once and never reviewed, a retention policy that exists on paper but is not enforced in the CRM, and staff who have completed a tick-box training module but cannot answer a debtor’s SAR correctly under time pressure.
Poor DPA drafting is the most consequential. A DPA that omits sub-processor controls, lacks an audit right, or fails to specify deletion timelines gives the creditor no contractual remedy when the agency mishandles data. By the time the breach occurs, the creditor is exposed alongside the agency with no contractual protection.
Retention policy failures are subtler. The policy says “delete after six years” but nobody has configured the CRM to enforce it, and accounts from 2015 are still sitting in the system. That is a live GDPR breach, not a theoretical one. The fix is not a better policy document; it is a deletion workflow that runs automatically.
Training is the third gap. GDPR training in collections needs to be scenario-based: what do you say when a debtor asks you to stop calling? What do you do when you realise you have the wrong address? What is the 72-hour rule and who do you call? Generic e-learning does not answer these questions in a way that sticks.
The organisations that handle this well treat GDPR compliance as an operational discipline, not a legal exercise. They audit their DPAs annually, run deletion reports quarterly, and test their SAR process with a mock request once a year. That is not a large investment of time. It is the difference between a manageable ICO enquiry and a formal investigation.
Knowing the rules is one thing. Finding a collection agency that actually follows them is another. Many creditors discover their agency’s GDPR controls only after a complaint lands on their desk.
Debtrecoveryhub matches creditors with vetted collection agencies based on debt type, amount, age, and location. Every agency in the network is assessed for its data protection controls before referrals are made, which means you are not starting from scratch when you need to check a DPA or confirm an agency’s sub-processor list.
The platform’s intake process captures the details needed to match your case to an agency with the right jurisdictional experience, including cross-border cases where UK GDPR and EU GDPR both apply. You get a shortlist of agencies that fit your specific situation, not a generic directory.
To get matched with a GDPR-aware collection agency, submit your case details and receive a tailored recommendation. For a quick quote, the debt recovery quote form takes under two minutes to complete.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
GDPR requires every organisation involved in debt collection to have a documented lawful basis for processing debtor personal data, to issue privacy notices, to honour data subject rights (including SARs and erasure requests), and to have a written Data Processing Agreement in place before sharing data with a collection agency.
Yes. The UK retained the EU GDPR framework through the Data Protection Act 2018 and the UK GDPR, which applies in full to all UK controllers and processors, including those engaged in debt collection.
Under the Limitation Act 1980, most contract debts become statute-barred after six years from the date the cause of action accrued. This does not erase the debt but removes the creditor’s right to enforce it through the courts.
A debtor can object to processing or request erasure, but neither right is absolute. Where a creditor has a legitimate interest or a legal obligation (such as an active court judgment), processing can continue despite an objection, provided the creditor documents its compelling grounds.
Raise the complaint first with the organisation’s DPO or data protection contact. If unresolved, escalate to the Information Commissioner’s Office (ICO) at ico.org.uk. Civil compensation claims can be brought under Article 82 GDPR or Section 168 of the Data Protection Act 2018.
Category :
Share :