Yes, marketing calls are still allowed under PECR, but the rules are tight. You must screen every number against the TPS and CTPS, never send an automated or recorded message without specific opt-in consent, and treat claims management and pension calls as effectively banned unless the recipient has already opted in. The immediate action for any business running a campaign: pause your call lists, run them against the current suppression registers, and check your CLI and consent records before you dial another number.
TL;DR:
- Screening call lists against updated TPS and CTPS registers before every campaign is essential, as the 28-day rule can easily be overlooked and lead to breaches.
- Automated marketing calls require verified, explicit consent that must be recorded with timestamps and clear wording to comply with stricter PECR rules.
- High-risk sectors like claims management and pensions must obtain explicit opt-in consent before any outbound call, making cold calling nearly impossible without prior consent.
- Maintaining comprehensive, timestamped records of screening, consent, and call logs in an auditable system is mandatory, especially when using third-party services or automation tools.
- Enquiries or breaches by the ICO typically focus on evidence of proper screening, consent, and suppression, with repeated violations and vulnerable recipients increasing enforcement risk.
Table of Contents
- What PECR requires for live marketing calls
- Automated calls and consent: why recorded messages need explicit permission
- TPS and CTPS screening, the 28-day rule and list hygiene
- High-risk sectors: claims management and pensions
- Practical compliance checklist for lawful marketing calls
- How PECR and UK GDPR fit together
- What happens after an ICO complaint or breach
- Why automation is becoming the practical answer to PECR compliance
- Get your telephone marketing checked before your next campaign
- Where to check the official rules
- Sources
What PECR requires for live marketing calls
The Privacy and Electronic Communications Regulations 2003 (PECR) still govern every unsolicited marketing call made in the UK, and regulation 21 is the core provision. It bans calling any number listed on the Telephone Preference Service (TPS) or Corporate Telephone Preference Service (CTPS), unless the subscriber has specifically told you it's fine to call, or the number was registered fewer than 28 days before your call.
That 28-day gap catches out a surprising number of callers who assume a fresh list is automatically clean. It rarely is.
During any live call, you must:
- Identify your organisation clearly at the start of the conversation
- Display your number so Calling Line Identification (CLI) works, never suppress it
- Give a contact address or Freephone number if the person asks for one
The ICO's telephone marketing guidance is explicit that having an existing customer relationship doesn't automatically make a call "solicited." If someone bought a service from you last year but never asked to hear about a new product, that call is still unsolicited marketing under PECR, and the same suppression rules apply.
Automated calls and consent: why recorded messages need explicit permission
Automated marketing calls sit under a stricter regime than live calls. Regulation 19 requires specific, explicit consent before you play a recorded or autodialled message to anyone, and general marketing consent gathered for live calls or email doesn't cover it.
An automated call must:
- Only go to a number that has specifically agreed to receive automated marketing messages
- State the caller's name clearly within the message
- Include a contact address or Freephone number the recipient can use to respond
Consent for automated calls needs to be recorded with a timestamp, the exact wording the person agreed to, and how it was captured, whether that's a web form, a signed contract clause, or a verified verbal opt-in on a prior call. Vague box-ticking ("we may contact you about offers") won't hold up if the ICO asks you to evidence it.
TPS and CTPS screening, the 28-day rule and list hygiene
Screening isn't a one-off task. Numbers get added to the TPS and CTPS registers constantly, so a list checked in January is stale by March. Re-screen before every campaign wave, not just when you first acquire a list.
The 28-day rule works both ways: you're not in breach if you call a number within 28 days of it joining the register, but that window closes fast, and relying on it as a strategy rather than a genuine oversight is exactly the kind of pattern that draws ICO attention.
Build compliance into your systems rather than your memory:
- Integrate TPS/CTPS checks directly into your CRM or dialler so suppressed numbers can't be loaded onto a call list
- Keep an internal do-not-call list for anyone who's objected directly to you, separate from the national registers
- Store time-stamped screening snapshots for every campaign, not just a note saying "list was checked"
- Retain call logs, consent records and screening evidence for at least as long as your data retention policy specifies, ideally longer given how ICO investigations can look back over past campaigns
High-risk sectors: claims management and pensions
Two sectors face a much stricter regime than general marketing. The ICO's guidance on live direct marketing calls confirms that claims management services generally need prior, explicit consent before any call, and pension scheme marketing carries narrow exceptions that usually require the caller to be a trustee, scheme manager, or an FCA-authorised firm meeting specific criteria.
In practice, this makes unsolicited cold calling in these sectors nearly unworkable unless you've built a proper opt-in pipeline. If your business touches claims handling or pensions in any way:
- Build explicit opt-in capture into every acquisition channel before calls start
- Keep separate, more detailed consent records than you would for general marketing
- Escalate any grey-area case (mixed products, introducer relationships, third-party lead sources) to legal or compliance before dialling
Practical compliance checklist for lawful marketing calls
Running a defensible campaign comes down to sequence. Skip a step and you've created a gap the ICO will find.
- Acquire or refresh your call list from a legitimate, documented source
- Screen every number against TPS and CTPS before it goes anywhere near a dialler
- Apply your internal suppression list on top of the national registers
- Capture and log consent evidence where automated calls or high-risk sectors require it
- Configure CLI display and finalise call scripts so agents identify the organisation correctly
- Offer an opt-out during every call and record it immediately, not at the end of the shift
Pro Tip: Run your suppression check as close to dial time as possible, not days in advance. A number that was clean on Monday can register with the TPS by Thursday, and campaigns often run longer than compliance teams expect.
Keep consent logs, screening snapshots, and call recordings together in one auditable system rather than scattered across spreadsheets and voicemail systems. If you outsource calling to a third party, your contract needs explicit compliance clauses and clear liability allocation, because the ICO can still hold you responsible for a supplier's mistakes. Test your process quarterly: pull a sample of recent calls and check the paper trail exists for each one.
How PECR and UK GDPR fit together
PECR and UK GDPR ask different questions. PECR is about the channel, specifically whether you're allowed to make this call to this number, while UK GDPR is about your lawful basis for processing someone's personal data at all. You can technically rely on legitimate interests under UK GDPR for some marketing activity, but PECR's consent requirement for automated calls and its TPS/CTPS restrictions still apply regardless.
In practice, collecting clear, well-documented consent upfront usually simplifies both problems at once, since it satisfies PECR's channel rule and gives you a clean UK GDPR lawful basis with less ambiguity to defend later. If you're using any profiling or automated dialling logic to prioritise who gets called, consider whether a Data Protection Impact Assessment is warranted before you scale it.
What happens after an ICO complaint or breach
The ICO's investigations focus on process: can you show you screened against TPS/CTPS, evidence any consent you relied on, and demonstrate this wasn't a repeat issue. Weak or missing records turn a single complaint into a much bigger problem.
Factors that push a case toward enforcement include repeated breaches, high call volumes, vulnerable recipients, and an absence of any suppression process at all.
If a complaint lands:
- Suspend the campaign or list in question immediately
- Preserve every record you have, screening snapshots, consent logs, call scripts, supplier contracts
- Notify the ICO where your obligations require it, and cooperate fully rather than going quiet
- Get external legal advice early if the complaint touches automated calls, claims management, or pensions, where the stricter rules mean penalties tend to be harsher
Guidance in this area keeps shifting, and monitoring ICO updates as the Data (Use and Access) Act 2025 beds in is worth building into your compliance calendar rather than treating as an annual task.
Why automation is becoming the practical answer to PECR compliance
Most breaches trace back to process failure, not bad intent: a stale list, a missed re-screen, a consent record nobody can find. That's an operations' problem, and it's exactly the kind of problem automated systems handle better than a spreadsheet and good intentions.
An automation layer that checks TPS/CTPS before every dial, enforces CLI display, and logs consent with a timestamp removes the human error that triggers most enforcement action, as seen in Call Time's software features designed for managing outbound calling campaigns. Some providers build this kind of compliance-first infrastructure into their outbound calling automation, pairing screening and audit trails with the operational side of running campaigns at scale.
— Ravi
Get your telephone marketing checked before your next campaign
There are service providers offering an alternative to building this checklist by hand: TPS and CTPS screening, consent capture, CLI enforcement, and audit trails run automatically instead of relying on someone remembering to re-check a list before every campaign wave.

The managed service maps directly onto the checklist above. Every number gets screened before it reaches a dialler, every consent record is timestamped and searchable, and call logs sit in one place instead of scattered across spreadsheets and supplier systems. That matters most when an ICO enquiry lands and you need evidence fast, not a scramble through old files.
For businesses handling payment details on calls, the same infrastructure can extend to PCI-compliant call payment workflows, and teams evaluating any automation supplier should work through a proper vendor procurement checklist before signing with any provider.

If your current process depends on a spreadsheet and good memory, book a compliance review with Gmdautomation and see what a managed, audit-ready setup looks like for your call volumes.
Where to check the official rules
- What are PECR? | ICO, the ICO's plain-English overview of the regulations
- Regulation 21, PECR 2003, the full statutory text on legislation.gov.uk
Sources
- Telephone marketing | ICO
- The Privacy and Electronic Communications (EC Directive) Regulations 2003 — regulation 21
