GDPR cold calling: an operational guide for human and AI calls

Privacy and security controls for GDPR-compliant voice calls
Privacy and security controls for GDPR-compliant voice calls

Cold calling is legal in some GDPR-covered situations, but teams must satisfy both data-processing rules and the destination country's telemarketing rules. This operational guide turns those requirements into seven eligibility gates for human, automated, and AI voice calls.

Cold calling is legal in some GDPR-covered situations. The answer depends on more than GDPR, however. You need a lawful basis to use personal data and permission to use the calling channel under the recipient's national telemarketing rules. AI voice calls introduce another issue because automated-call consent rules can be stricter than rules for a human caller.

The practical task is to turn those requirements into a decision that your dialer can enforce before every call.

This guide provides general operational information, not legal advice. Have qualified counsel approve the rules for every destination and campaign type you use.

Can you cold call under GDPR?

Yes, in some cases. GDPR does not contain a blanket ban on cold calls. It governs the collection, storage, selection, and use of personal data involved in the campaign. A separate layer of ePrivacy or national telemarketing law determines whether you may place the call.

For each number, you therefore need two valid answers:

  1. May we process this person's data for direct marketing? Under GDPR, the likely lawful bases are consent or legitimate interests.
  2. May we contact this number in this way? The answer depends on the destination country's rules, the subscriber type, do-not-call registrations, the subject of the call, and whether a human or an automated system speaks.

Passing one test does not satisfy the other. A legitimate interests assessment cannot override a national do-not-call register. Valid consent to process data may also be too vague to authorize prerecorded or automated marketing calls.

This distinction matters for teams building outbound voice AI. Dasha can place and operate outbound conversations through a managed voice runtime, APIs, and webhooks. Your application still needs to decide who is eligible, provide the right disclosures, and stop future calls when someone objects.

GDPR and telemarketing law do different jobs

The GDPR text supplies the data-processing rules. Article 6 lists six lawful bases. Article 14 controls the privacy information due when contact data came from another source. Article 21 gives people an absolute right to object when their personal data is used for direct marketing.

The EU's ePrivacy Directive supplies the channel framework. Article 13 requires prior consent for automated calling and communication systems without human intervention. For other unsolicited direct marketing calls, each member state chooses an opt-in or opt-out regime in its national law.

That produces three consequences that generic GDPR checklists often miss:

  • There is no single EU-wide yes or no for live cold calls.
  • B2B outreach is not exempt from GDPR when a record identifies an employee, founder, or sole trader.
  • Permission for a human sales representative does not automatically cover an AI agent, prerecorded message, or automated voicemail.

Run the rules for the recipient's country. The location of your company or voice platform does not replace that destination analysis.

The seven gates before a cold call

A defensible campaign treats compliance as an eligibility pipeline, not a clause in a vendor contract.

GateQuestionEvidence to retain
1. ScopeDoes the record identify a natural person, and does GDPR or UK GDPR apply?Data category, source, country, and subscriber type
2. Call typeIs the speaker a person, an interactive AI agent, or a prerecorded message?Campaign mode and approved classification
3. Channel permissionDoes national law allow this call to this subscriber?Country ruleset version, register-screen result, and any consent record
4. Lawful basisWhy is the processing necessary and fair?Consent record or legitimate interests assessment ID
5. TransparencyHas the person received the required privacy information on time?Notice version, delivery channel, and timestamp
6. ObjectionHas this person or number opted out anywhere in the organization?Central suppression result and preference history
7. Data controlsAre recording, transcript, retention, access, and transfers configured for this purpose?Policy version, retention date, and access controls
Seven compliance gates before an outbound GDPR cold call

If any required value is missing, hold the call. Do not let an agent infer eligibility from a job title, a public profile, or a note that says the lead is “GDPR compliant.”

When legitimate interests can support B2B cold calling

GDPR Recital 47 says that processing for direct marketing may be a legitimate interest. The word “may” matters. It is an available basis, not blanket approval for prospecting.

A legitimate interests assessment (LIA) should answer three questions:

  1. Purpose: What specific commercial interest does the campaign pursue?
  2. Necessity: Is using this person's number reasonably necessary, or could you achieve the purpose with less intrusive data or a different channel?
  3. Balance: Would the person reasonably expect this use, and do their rights, interests, or likely harm outweigh yours?

Role relevance helps the balance test. A targeted call to a procurement lead about a service within that person's remit is easier to justify than dialing every employee at the company. It is still only one factor. Data source, number type, frequency, vulnerability, call content, and the ease of objecting also matter.

Use consent where local law requires it or where the legitimate interests balance is weak. Valid consent must be freely given, specific, informed, unambiguous, and demonstrable. A phone number on a company website is not consent. A list vendor's assurance is not proof that the person consented to calls from your named organization.

B2B does not mean “outside GDPR”

GDPR protects natural persons. A generic switchboard number with no link to a person may fall outside its definition of personal data. A named work direct dial, a founder's mobile number, or a CRM record tying a person to a company normally identifies a natural person.

Business context can change the person's reasonable expectations and the balancing test. It does not remove their rights. If that person objects to direct marketing, Article 21 requires you to stop using their personal data for that purpose. You cannot continue by claiming an overriding business reason.

The UK example: UK GDPR plus PECR

The United Kingdom makes the two-layer model concrete. UK GDPR covers personal data. The Privacy and Electronic Communications Regulations (PECR) govern the call.

For most live marketing calls, the ICO's live-call rules allow calls without prior consent when all of these conditions are met:

  • the recipient has not previously objected to your calls;
  • the number is absent from the Telephone Preference Service (TPS) and, for corporate subscribers, the Corporate Telephone Preference Service (CTPS), unless the subscriber specifically agreed to your calls;
  • you display a valid caller number;
  • you identify the organization calling; and
  • you provide contact details or a Freephone number if asked.

Claims-management marketing calls require consent. Pension marketing calls have a separate, narrow exception. Financial Conduct Authority rules can add further restrictions.

For B2B campaigns, screen both TPS and CTPS. Sole traders and some partnerships are “individual subscribers,” while companies and limited liability partnerships are usually “corporate subscribers.” The ICO's B2B marketing guidance also confirms that UK GDPR still applies when the campaign processes an identifiable business contact's data.

Public and purchased numbers still require screening. The caller remains responsible even if a data supplier says it checked the list. Because a TPS or CTPS registration takes effect after 28 days, a check older than that can miss a newly effective registration. Screen close to call time and against your own suppression list as well.

Article 14 makes the first call a deadline

Many outbound teams obtain names and numbers from public sites, enrichment services, event lists, or data brokers. In those cases, GDPR Article 14 generally requires the controller to provide privacy information within one month and, when the data is used to communicate, no later than the first communication.

That means a privacy email sent only after the first cold call can be late. Design the opening and the available full notice together. The first layer should make the caller's identity, purpose, data source or source category, lawful basis, and right to object clear. Give the recipient an accessible route to the complete notice through a channel the campaign is permitted to use.

A short opening for a consented AI voice campaign might be:

Hi, this is Ava, an AI assistant calling for Acme about your request for a logistics demo. Acme uses your contact details for this follow-up. You can ask me to stop now, and I can provide Acme's full privacy notice.

The wording must match the real data source, purpose, lawful basis, and caller. A disclosure cannot repair an ineligible call.

AI voice calls need a stricter decision path

An interactive AI call can sound live while still operating without a human speaker. That distinction matters because European automated-call rules can require prior consent.

For EU and EEA campaigns, classify the system under the recipient country's implementation of the ePrivacy Directive before dialing. For UK campaigns, PECR clearly requires consent for automated marketing calls that play recorded messages. Current UK guidance describes that category around recorded-message systems, so an interactive generative voice agent needs a jurisdiction-specific legal classification rather than an assumption that human live-call rules apply.

There is also a separate transparency duty. Since 2 August 2026, Article 50 of the EU AI Act requires systems intended to interact directly with people to be designed so the person is informed that they are interacting with AI, unless that fact is obvious to a reasonably informed, observant, and circumspect person in context. For an outbound sales call, disclose AI use clearly at the start.

The conservative production rule is simple: do not route EU or UK marketing leads to an AI voice agent under a ruleset written for human callers. Use a consented campaign path until the applicable automated-call classification and national requirements are approved.

Recording is another processing purpose

Call permission does not by itself authorize recording, transcription, sentiment extraction, or model evaluation. For each use, define the purpose and lawful basis, deliver the required notice, minimize access, and set a retention period. Local interception and communications laws may impose additional requirements.

If recording is unnecessary, disable it. If a transcript is enough, do not retain audio by default. Avoid placing sensitive details in prompts or call metadata merely because the platform can accept them.

How to enforce the rules in a Dasha call workflow

Compliance controls work best in your backend, where CRM data, consent evidence, national registers, and suppression records can be evaluated together. Dasha handles the real-time conversation and call lifecycle. It does not create a lawful basis or certify a list.

A production flow looks like this:

  1. Create one eligibility record. Store the destination country, subscriber type, call mode, source, lawful-basis record, notice version, register-screen time, and suppression result. Pass a stable decision ID to the call, rather than copying the full compliance file into voice metadata.
  2. Reject before connection. Use a pre-call service to fail closed when consent is missing, a register check is stale, or the number appears on any suppression list. Dasha's webhook lifecycle supports call metadata and a start webhook that can accept or reject a call.
  3. Make the opening deterministic. Identify the calling organization, marketing purpose, and AI agent before the variable sales dialogue begins. Keep the required disclosure outside prompt branches that the model might skip.
  4. Treat an objection as an event. Give the agent a tool that writes the person and number to a central suppression service during the conversation. Confirm the request once, end the marketing path, and block retries across campaigns and vendors.
  5. Reconcile every outcome. Completed and failed call webhooks should update the CRM with the decision ID, notice delivered, objection status, call disposition, and retention date. Dasha can return call results through webhooks and exposes call history for operational review.
  6. Limit retained conversation data. Configure recordings deliberately, restrict transcript access, and expire call artifacts according to the documented purpose.

Deleting an objector from the active lead table is insufficient. Keep the minimum suppression record needed to prevent re-importing and calling the same person again. The ICO explicitly recommends a do-not-call or suppression list for this reason.

A pre-launch checklist for GDPR cold calling

Before enabling a campaign, require an owner to sign off on each item:

  • Document GDPR or UK GDPR territorial scope.
  • Encode destination-country rules by call type and subscriber type.
  • Give human, AI, prerecorded, and voicemail paths separate eligibility rules.
  • Require consent evidence or an approved LIA for every selected contact.
  • Record the data source and Article 14 notice timing.
  • Screen national do-not-call registers and the organization's suppression list close to call time.
  • Identify the organization, purpose, and AI use in the opening where applicable.
  • Update a central suppression service immediately when someone objects.
  • Approve controls for recording, transcription, analytics, retention, access, and transfers.
  • Require vendors to accept only eligible records and return disposition and opt-out events.

This model scales because the legal decision remains deterministic even when the conversation is generated in real time. If you are building compliant outbound voice workflows, evaluate Dasha's voice AI backend with your eligibility service, disclosure script, suppression tool, and retention policy as part of the first production test.

Related Posts

We use cookies for functional and analytical purposes. Please refer to our Privacy Policy for details.