Skip to main content

Debt Recovery Hub

GDPR and debt collection: what UK creditors and collectors must do

GDPR applies to debt collection in the UK. Full stop. Whether you are a creditor chasing an overdue invoice or a collection agency instructed to recover on someone else’s behalf, the UK GDPR and Data Protection Act 2018 govern every step: how you hold debtor data, who you share it with, how long you keep it, and how you respond when a debtor asks what you know about them.

The three lawful bases most commonly used in debt collection are performance of a contract (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), and compliance with a legal obligation (Article 6(1)©). Before you do anything else, identify which one applies to your specific processing activity and record it.

If you are dealing with an urgent incident right now, take these steps first:

  • Stop the processing activity that may be unlawful.
  • Identify and document the lawful basis (or absence of one).
  • If personal data has been sent to the wrong person or accessed without authority, treat it as a potential personal data breach and assess whether ICO notification is required within 72 hours.
  • If a debtor has contacted you to object to processing or request erasure, log the request with a timestamp and begin the 30-day response clock.
  • If a third party has been told about a debt without the debtor’s knowledge, preserve all records and seek legal advice immediately.

Key takeaways

GDPR applies to every stage of debt collection in the UK, and the lawful basis, DPA, and retention policy must be documented before data is shared with any collection agency.

Point Details
Lawful basis is mandatory Document contract performance, legitimate interest, or legal obligation before any processing begins.
DPA before data sharing A written Data Processing Agreement must be in place before passing debtor data to any collection agency.
Data subject rights apply Respond to SARs within one month; erasure can be refused only on specific documented grounds.
Retention needs justification No single UK period applies; align with limitation periods and document every retention decision.
Debtrecoveryhub Matches creditors with vetted, GDPR-aware collection agencies based on debt type, amount, and location.

Table of Contents

Who is the controller and who is the processor when debts are passed to a collection agency?

Under the EU GDPR (Regulation 2016/679), a controller decides the purposes and means of processing personal data. A processor processes data only on the controller’s documented instructions. Getting this allocation wrong is one of the most common and costly mistakes in outsourced collections.

Typical allocation in practice:

  • The original creditor is almost always the controller. It decided to extend credit, holds the original contract, and determines why the debt is being pursued.
  • The collection agency is usually a processor when it acts purely on the creditor’s instructions: sending letters, making calls, and reporting back.
  • The agency becomes a joint controller or independent controller for its own processing activities, such as maintaining its own internal credit risk records, running automated scoring, or reporting to a credit reference agency.

Three scenarios that illustrate this:

  1. Creditor instructs agency to send payment reminders only. The agency is a processor. The creditor must provide a written Data Processing Agreement (DPA) before any data is shared.
  2. Creditor assigns the debt outright. The agency acquires the debt and becomes the controller for all subsequent processing. It must issue its own privacy notice to the debtor.
  3. Agency uses its own automated scoring system to prioritise cases. Even if acting as processor for contact purposes, the agency is an independent controller for that scoring activity and must have its own lawful basis.

Pro Tip: Before instructing any collection agency, confirm in writing whether the relationship is controller-processor or joint-controller. The answer determines who is liable for a SAR, who must respond to erasure requests, and who carries the regulatory risk if something goes wrong.

Practical guidance from Thomson Reuters confirms that contacting a corporate director at a private home address requires careful contextual balancing: the legal basis and proportionality of the contact must be assessed before any letter is sent.


Which lawful basis applies to processing debtor personal data?

The answer depends on the stage of the debt and the nature of the processing. Most debt collection activities will rely on one of three bases under Article 6 of the EU GDPR.

The three bases and when each fits:

  1. Performance of a contract (Art. 6(1)(b)): Applies when processing is necessary to perform the original credit agreement or to take pre-contractual steps. Useful for the initial stages of recovery where the debtor is a party to the contract.
  2. Legitimate interests (Art. 6(1)(f)): The most frequently used basis for ongoing collection activity, tracing, and sharing data with an agency. Requires a three-part balancing test.
  3. Compliance with a legal obligation (Art. 6(1)©): Applies where processing is required by law, such as anti-money-laundering checks, statutory accounting records, or court-ordered disclosure.

Running a legitimate interests assessment (LIA) — the three-part test:

  1. Purpose test: Is the interest legitimate? Recovering a genuine debt is a recognised legitimate interest.
  2. Necessity test: Is the processing necessary for that purpose? Could you achieve the same result with less data or less intrusive means?
  3. Balancing test: Do the debtor’s interests or fundamental rights override your legitimate interest? Consider vulnerability, the sensitivity of the data, and whether the debtor would reasonably expect this processing.

What a lawful-basis record should include:

  • The specific processing activity described in plain terms.
  • The basis selected and why.
  • For legitimate interests: a summary of the LIA outcome, including any mitigations applied.
  • The date the assessment was made and who approved it.
  • A review trigger (e.g. when the processing purpose changes).

When consent is not appropriate: Consent is rarely the right basis for debt collection. A debtor cannot freely give consent when there is a power imbalance or a financial obligation already in place. Relying on consent also means the debtor can withdraw it at any time, which would halt processing entirely. Consent may occasionally be appropriate for sending marketing communications about debt management products, but not for the recovery activity itself.

Pro Tip: Document your LIA as a standalone record, not just a line in a privacy notice. If the ICO investigates, a well-reasoned LIA is your primary evidence that the processing was proportionate.


Passing data to a debt collection agency: contracts, DPIAs and safeguards

You can share debtor personal data with a collection agency, but three things must be in place before you do: a lawful basis for the transfer, a written Data Processing Agreement, and appropriate technical and organisational measures (TOMs).

Required DPA clauses — a checklist:

  • Scope and subject matter of the processing.
  • Duration, nature, and purpose of the processing.
  • Type of personal data and categories of data subjects.
  • Sub-processing restrictions (agency must seek written permission before engaging sub-processors).
  • Security obligations and minimum technical standards (ISO 27001 certification is increasingly expected for compliant debt collection operations).
  • International transfer safeguards (Standard Contractual Clauses or UK IDTA where applicable).
  • Deletion or return of data on termination.
  • Audit rights for the controller.
  • Breach notification obligations (agency must notify creditor without undue delay).

When is a DPIA required?

A Data Protection Impact Assessment is mandatory before processing that is likely to result in high risk to individuals. In debt collection, a DPIA is required when:

  • Automated profiling or scoring is used to prioritise cases or make decisions about debtors.
  • Large-scale processing of personal data is involved (e.g. a portfolio of thousands of accounts).
  • New contact channels or technologies are introduced (e.g. AI-driven outreach).
  • Sensitive categories of data are processed (e.g. health information relevant to vulnerability).
  • Data is shared across borders, particularly outside the UK or EU.

Sample DPA clause headings (generic labels):

Clause heading Purpose
Processing instructions Limits agency to documented purposes only
Security and TOMs Sets minimum technical standards
Sub-processor approval Requires written consent before onward sharing
International transfers Mandates SCCs or UK IDTA for non-UK/EEA transfers
Breach notification Sets timeline for agency to notify creditor
Deletion and return Specifies what happens to data on contract end
Audit and inspection Gives creditor right to verify compliance

How do data subject rights work in a debt-collection context?

Data subject rights still apply in full. A debtor can submit a Subject Access Request, ask for their data to be erased, object to processing, or request restriction. None of these rights are automatically suspended because a debt is owed. However, some rights have lawful limits that are directly relevant to debt recovery.

Handling a Subject Access Request (SAR):

  1. Receive and log the request with a timestamp.
  2. Verify the identity of the requester.
  3. Identify all personal data held across every system (CRM, call recordings, letters, emails, notes).
  4. Redact third-party data that would identify another individual.
  5. Respond within a statutory timeframe aligned with GDPR requirements; extensions may apply for complex requests with proper notification to the requester.
  6. If refusing any element, document the specific exemption relied upon (e.g. legal professional privilege, prevention of crime).

Erasure requests under Article 17:

A debtor can request erasure, but the right is not absolute. You may refuse where processing is necessary for:

  • Compliance with a legal obligation (e.g. statutory accounting records under the Companies Act).
  • The establishment, exercise, or defence of legal claims.
  • A task carried out in the public interest.

The CJEU’s ruling in the SCHUFA case reinforced that private retention of insolvency and discharge data beyond national register periods requires strict necessity and proportionality. If a credit reference agency holds discharge data longer than the public register, it must demonstrate a compelling justification.

Where erasure is refused, document the refusal with the specific legal ground, the date, and who made the decision. Provide the debtor with information about their right to complain to the ICO.

Pro Tip: When a debtor objects to processing under Article 21, you must stop processing unless you can demonstrate compelling legitimate grounds that override their interests. In practice, an active court judgment is often the clearest compelling ground. Document this assessment every time.


Retention must be limited to what is necessary for the purpose. There is no single statutory retention period for debt data in the UK; you must justify each period with a lawful basis and a documented business need.

Typical retention triggers and suggested ranges:

Trigger Suggested retention range Notes
Active recovery (debt unpaid, no judgment) Duration of recovery plus 6 years Aligns with Limitation Act 1980 for contract claims
County Court Judgment (CCJ) obtained 6 years from date of judgment Statutory enforcement window
Statutory accounting records 6 years from financial year end Companies Act requirement
Debt fully repaid 6 years from final payment Limitation period for any dispute
Insolvency / discharge Until national register deletion, then reassess SCHUFA principle: private retention beyond register period requires strict justification

The SCHUFA judgment is the clearest statement of this principle at EU level: retaining discharge data after the public register has removed it is presumptively disproportionate unless a specific, documented necessity can be shown.

Suppression lists and pseudonymisation after erasure:

A January 2026 ruling by the Brussels Market Court recognised that a minimal pseudonymised suppression list can be lawful where complete deletion would risk repeated wrongful contact. The logic: if you delete all records of a debtor who has complained about wrongful contact, you have no mechanism to prevent the same error recurring. A hashed identifier on a “do not contact” list, with no recoverable personal data, can satisfy both the erasure request and the duty to prevent further harm.

Pro Tip: If you maintain a suppression list after an erasure request, document the decision in writing: the legal ground (Art. 17(3)(b) or legitimate interest), the data elements retained, the security measures applied, and the review date. Keep this record separate from the main processing register.


Contacting debtors lawfully: what you can and cannot do

The core rule is simple: identify yourself, explain your purpose, use proportionate contact frequency, and never disclose debt details to anyone who is not the debtor or their authorised representative.

Dos and don’ts by channel:

  • Telephone: Do identify the organisation and the purpose of the call at the outset. Do not call at unreasonable hours or with excessive frequency. Do not leave detailed voicemails that could be heard by third parties.
  • SMS: Do keep messages brief and non-disclosing (e.g. “Please call [number] regarding your account”). Do not include the creditor’s name, debt amount, or account reference in a text message.
  • Email: Do use a subject line that does not disclose the nature of the debt. Do not send detailed account information to an email address that may be shared or monitored by others.
  • Home visits: Do give advance notice where possible. Do not discuss the debt with anyone other than the debtor. Do not visit a workplace unless the debtor has specifically agreed to this.
  • Social media: Do not contact debtors via social media platforms. Do not send connection requests or messages that could expose the debt to the debtor’s network.

Lawful first-contact script (telephone):

“Good morning, this is [name] calling from [organisation]. I’m trying to reach [debtor’s full name]. Could you confirm whether I have the right number? I’m not able to discuss the reason for my call with anyone other than [debtor’s full name].”

Hand holding phone handset during call in office

If a third party answers and asks what the call is about, the response must be: “I’m not able to share that information. Please ask [debtor’s name] to call us on [number].”

FCA CONC obligations: Under CONC 7.3, firms must treat customers in or approaching arrears with forbearance and due consideration. Where a debtor proposes a repayment plan, active pursuit must be suspended while the proposal is assessed. This obligation sits alongside GDPR: continuing to process data for aggressive collection purposes while a repayment plan is under discussion may breach both regimes simultaneously.

For guidance on ethical debt collection practices that satisfy both GDPR and FCA requirements, the operational controls are closely linked.


What to do if data is mishandled: complaints, breaches and remedies

Immediate steps when data is mishandled:

  1. Document what happened: who was affected, what data was involved, when it occurred, and how it was discovered.
  2. Preserve all evidence (emails, call logs, system records).
  3. Assess whether the incident meets the threshold for a personal data breach under Article 33: is there a risk to the rights and freedoms of individuals?
  4. If yes, notify the ICO within 72 hours of becoming aware. Late notification must be accompanied by reasons for the delay.
  5. If the breach is likely to result in high risk to individuals, notify the affected data subjects directly without undue delay.

The NCSC’s breach response guidance covers the technical steps to contain and investigate a breach, including isolating affected systems and preserving forensic evidence. For incidents involving suspected fraud or identity manipulation, specialist support from a digital fraud investigation service may be needed alongside the regulatory response.

Complaint flow for individuals:

  1. Raise a complaint directly with the organisation’s Data Protection Officer (DPO) or data protection contact.
  2. If unresolved within 30 days, escalate to the ICO (ico.org.uk). The ICO can investigate, issue enforcement notices, and impose fines.
  3. Pursue a civil claim for compensation under Article 82 GDPR / Section 168 Data Protection Act 2018 if material or non-material damage has been suffered.

Complaint and investigation timeline:

Stage Typical timeframe
Internal complaint response 30 days (extendable)
ICO acknowledgement Within 2 weeks
ICO assessment and triage 3–6 months
ICO investigation (formal) 6–18 months depending on complexity
Civil claim (County Court) 6 months depending on complexity

Practical compliance checklist for creditors and collectors

Getting to a defensible baseline for GDPR compliance in debt collection does not require a complete overhaul. It requires the right controls in the right order.

Compliance checklist (ordered by priority):

  1. Lawful basis documented — Record the specific basis for each processing activity in your Record of Processing Activities (ROPA). Owner: creditor/DPO.
  2. ROPA maintained — A current, accurate ROPA covering all debt-related processing. Owner: creditor and agency (each maintains their own). Urgent.
  3. DPA in place — A written Data Processing Agreement with every collection agency before data is shared. Owner: creditor. Urgent.
  4. DPIA completed — For automated profiling, large-scale processing, or new contact technologies. Owner: creditor/DPO.
  5. TOMs documented — Technical and organisational measures recorded and reviewed annually. ISO 27001 certification provides strong evidence of compliance for debt collection operations.
  6. Retention policy — A written schedule with triggers, periods, and deletion procedures. Owner: creditor and agency.
  7. Privacy notices — Accurate, accessible notices issued to debtors at the point of first contact. Owner: controller.
  8. Staff training — All staff handling debtor data trained on GDPR basics, contact rules, and SAR handling. Review annually.
  9. Breach response procedure — A documented procedure with named roles, 72-hour notification trigger, and ICO contact details. Owner: DPO/compliance lead.
  10. SAR handling procedure — A logged, timed process for receiving, verifying, and responding to subject access requests within one month.

Pro Tip: Set a calendar trigger to review your DPIA and ROPA whenever you introduce a new contact channel, change your agency partner, or acquire a new debt portfolio. A DPIA that was accurate 18 months ago may be materially wrong today.

For the full picture on pre-action obligations before enforcement, the pre-action protocol for debt sets out what creditors must do before issuing proceedings.


International data transfers in debt collection: what UK creditors need to know

UK creditors dealing with EU-based debtors, or instructing agencies with EU operations, face an additional layer of compliance. Since Brexit, the UK operates its own data protection regime under the UK GDPR, and transfers of personal data between the UK and the EU (and vice versa) require a specific legal mechanism.

The current position:

The European Commission granted the UK an adequacy decision in June 2021, meaning personal data can flow freely from the EU to the UK without additional safeguards. That decision is subject to periodic review. UK creditors sending data to EU-based processors (including collection agencies) benefit from the same adequacy finding in the opposite direction under UK domestic rules.

Where transfers become more complex:

  • UK to non-EEA countries: If a collection agency uses sub-processors or data centres outside the UK/EEA (common with cloud-based CRM systems), the creditor must ensure the DPA includes the UK International Data Transfer Agreement (IDTA) or the Addendum to EU Standard Contractual Clauses.
  • EU debtors, UK creditor, non-EEA agency: If a UK creditor instructs an agency based in, say, the United States or India to contact EU debtors, both the UK GDPR and the EU GDPR may apply simultaneously. The agency must have appropriate transfer mechanisms in place under both regimes.
  • Credit reference data: Sharing debtor data with credit reference agencies that operate across borders requires specific transfer safeguards and, in light of the SCHUFA ruling, careful attention to retention periods in each jurisdiction.

For UK businesses pursuing debts across borders, the international debt recovery guide covers jurisdictional considerations in more detail.

Practical step: Before instructing any agency, ask for a copy of their sub-processor list and confirm the transfer mechanism for each sub-processor location. This is a standard DPA audit right and should be exercised before the contract is signed, not after a breach occurs.


Where most organisations actually slip up

The compliance failures that generate ICO complaints and civil claims in debt collection are rarely about the law itself. Most organisations understand, at least in outline, that GDPR applies. The failures are operational.

The three mistakes that come up repeatedly are: a DPA that was drafted once and never reviewed, a retention policy that exists on paper but is not enforced in the CRM, and staff who have completed a tick-box training module but cannot answer a debtor’s SAR correctly under time pressure.

Poor DPA drafting is the most consequential. A DPA that omits sub-processor controls, lacks an audit right, or fails to specify deletion timelines gives the creditor no contractual remedy when the agency mishandles data. By the time the breach occurs, the creditor is exposed alongside the agency with no contractual protection.

Retention policy failures are subtler. The policy says “delete after six years” but nobody has configured the CRM to enforce it, and accounts from 2015 are still sitting in the system. That is a live GDPR breach, not a theoretical one. The fix is not a better policy document; it is a deletion workflow that runs automatically.

Training is the third gap. GDPR training in collections needs to be scenario-based: what do you say when a debtor asks you to stop calling? What do you do when you realise you have the wrong address? What is the 72-hour rule and who do you call? Generic e-learning does not answer these questions in a way that sticks.

The organisations that handle this well treat GDPR compliance as an operational discipline, not a legal exercise. They audit their DPAs annually, run deletion reports quarterly, and test their SAR process with a mock request once a year. That is not a large investment of time. It is the difference between a manageable ICO enquiry and a formal investigation.


Finding a GDPR-aware collection partner

Knowing the rules is one thing. Finding a collection agency that actually follows them is another. Many creditors discover their agency’s GDPR controls only after a complaint lands on their desk.

Debtrecoveryhub

Debtrecoveryhub matches creditors with vetted collection agencies based on debt type, amount, age, and location. Every agency in the network is assessed for its data protection controls before referrals are made, which means you are not starting from scratch when you need to check a DPA or confirm an agency’s sub-processor list.

The platform’s intake process captures the details needed to match your case to an agency with the right jurisdictional experience, including cross-border cases where UK GDPR and EU GDPR both apply. You get a shortlist of agencies that fit your specific situation, not a generic directory.

To get matched with a GDPR-aware collection agency, submit your case details and receive a tailored recommendation. For a quick quote, the debt recovery quote form takes under two minutes to complete.


Sources


This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

How does GDPR affect debt collection?

GDPR requires every organisation involved in debt collection to have a documented lawful basis for processing debtor personal data, to issue privacy notices, to honour data subject rights (including SARs and erasure requests), and to have a written Data Processing Agreement in place before sharing data with a collection agency.

Does GDPR still apply in the United Kingdom?

Yes. The UK retained the EU GDPR framework through the Data Protection Act 2018 and the UK GDPR, which applies in full to all UK controllers and processors, including those engaged in debt collection.

How long before a debt becomes uncollectible in the UK?

Under the Limitation Act 1980, most contract debts become statute-barred after six years from the date the cause of action accrued. This does not erase the debt but removes the creditor’s right to enforce it through the courts.

Can a debtor use GDPR to stop debt collection?

A debtor can object to processing or request erasure, but neither right is absolute. Where a creditor has a legitimate interest or a legal obligation (such as an active court judgment), processing can continue despite an objection, provided the creditor documents its compelling grounds.

Where do you complain about GDPR misuse in debt collection?

Raise the complaint first with the organisation’s DPO or data protection contact. If unresolved, escalate to the Information Commissioner’s Office (ICO) at ico.org.uk. Civil compensation claims can be brought under Article 82 GDPR or Section 168 of the Data Protection Act 2018.