The rules we work to
Outbound contact and offshore data handling are both regulated, and the exposure is shared. We would rather show you how we handle it than leave you to assume.
- Registers screened
- DNCR, TPS, CTPS
- Data residency
- Your systems
- Access model
- Named, least-privilege
- Last reviewed
- August 2026
Calling and contacting in Australia
Three separate regimes apply, and they catch people out in different ways.
Do Not Call Register
Administered by ACMA under the Do Not Call Register Act 2006.
- Business numbers cannot be registered, so B2B voice calling is generally permitted
- Consumer lists washed before a campaign runs, and re-washed on schedule
- Washing inside the prescribed window is the defence — stale checks are not
Telemarketing Industry Standard
The 2017 Industry Standard applies to telemarketing calls to Australian numbers generally — not only to numbers on the register.
- Permitted hours on weekdays and Saturdays; no Sunday or public holiday calls without express consent
- Caller's name, the business name and the purpose, stated up front
- Calling line identification enabled
- Calls terminated immediately on request
Spam Act 2003
Governs commercial email and SMS — and unlike the Do Not Call rules, it does apply to business-to-business messages.
- Consent established and recorded before sending
- Sender clearly identified in every message
- A working unsubscribe that is actually honoured
Sending personal information offshore
This is the part most providers in our category say nothing about, and it is the part your compliance people will ask about first.
Under Australian Privacy Principle 8, an Australian entity that discloses personal information to an overseas recipient generally has to take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles — and in many circumstances remains accountable for what happens to it. Outsourcing the work does not outsource the duty.
So we build the engagement to make that duty dischargeable rather than leaving you to hope.
- Work inside your systems. Your CRM, your helpdesk, your drive — so records stay in your control rather than being copied offshore
- Least-privilege access. People get the permissions the role needs and nothing more, granted individually and revoked on exit
- Named individuals. You know who is on your account; access is not pooled or shared between staff
- Written terms. Confidentiality and data-handling obligations in the engagement, plus whatever your business requires on top
- Controlled workspace. Delivery happens from a managed office environment, not from unmanaged personal devices
- Clean exit. Access revoked, working copies destroyed, documentation handed over
Ask us for the detail
If you have a supplier security questionnaire or a data processing agreement, send it through and we will work to it.
Calling and contacting in the UK
Governed by PECR and enforced by the ICO, with Ofcom's persistent-misuse powers sitting alongside and UK GDPR covering the personal data of business contacts.
TPS and CTPS — both, always
- Corporate subscribers — limited companies, LLPs, Scottish partnerships, public bodies — register on the CTPS
- Sole traders and most partnerships in England, Wales and Northern Ireland count as individual subscribers and register on the TPS, with the same protection as consumers
- You cannot tell which from a phone number, so both are screened. “It's B2B” is not an exemption
- Registrations take time to activate, so screening repeats on a schedule
On every call
- The organisation identified by name
- CLI presented, never withheld, with a valid contact number
- Our own suppression list screened, and objections honoured immediately
- Automated and recorded-message calls only with specific prior consent, business or not
- Bought lists diligence-checked before use
How this shows up day to day
Scripts reviewed
Every campaign script is checked against the identification and disclosure requirements before the first dial, not after a complaint.
Dialling windows enforced
Shift patterns are built around permitted calling hours in the destination market, including public holidays.
Access controlled
Individual accounts, least privilege, revoked on exit. No shared logins, no data on personal devices.
People trained
Compliance is part of onboarding for every caller, and part of the quality review — not a laminated poster.
Compliance questions
Is this legal advice?
No. This page describes how we operate and summarises the obligations we work to. Your own duties — under the Privacy Act if you are an Australian entity, or UK GDPR and PECR if you are a UK one — are yours to take advice on.
Can we audit how you handle our data?
Ask and we will walk you through it: who has access, at what level, on what devices, and how it is revoked. Send us your supplier security questionnaire and we will complete it.
Where is our data physically handled?
Our delivery team is in Karachi. Wherever possible the work happens inside your own systems rather than data being copied out of them — which keeps your records in your control and makes access easy to revoke.
About the information on this page
Last reviewed August 2026. This page describes our operating practice and summarises regulatory obligations in plain language. It is not legal advice, it is not exhaustive, and the rules change. Your own obligations as the business instructing the contact are yours to take advice on. For the authoritative position see ACMA and the Do Not Call Register, the OAIC, the ICO and Ofcom.
Send us your security questionnaire.
If your procurement process needs to see how we handle data before you can even have a conversation, start there. We would rather answer it early.
Prefer to talk now? Call (02) 9156 1078 or message us on WhatsApp.