- Read time:
- Published:
- Group:
- GDPR/Data Protection and Information Security
As part of our best practice framework and GDPR compliance, we have processes in place to avoid any negative impact on call recipients including:
- TPS/CTPS screening as standard, in addition to our own ‘Do not call’ list.
- Mechanisms that allow individuals to easily exercise their “Individual Rights” under GDPR including their ‘right to object’, their ‘right to be forgotten’, their ‘right to rectification’ and/ or submit a Data Subject Access Request.
- Clear privacy, data protection and information security policies that explain how we use and protect the data we process.
- Robust quality assurance and data management processes.
- Technologies that protect the individual’s data such as call obfuscation to protect sensitive payment details, encrypted call recordings, data transfer via secure FTP.
- Systems that manage how many times a number is called.
- Strict policies and in-depth training for all staff on data protection and GDPR.
- Easy access to call histories and number look-ups so callers know and can explain exactly where the data they are calling came from.
- Rigorous training and ongoing coaching around calling ‘best practice’ such as:
- Callers should state who they are and why they are calling at the start of a call.
- If the prospect is not interested, their wishes must always be respected.
- Listen and understand – do not ‘hard’ sell. Callers should listen to the prospect and provide relevant information, tailored to their interests and pain points.