Skip to content
BCC Telemarketing
ServicesSectorsHow we workAboutCareersInsights
Book a call
ServicesSectorsHow we workAboutCareersInsightsBook a call
01933 443322info@bcctelemarketing.co.ukLinkedIn
Home/Legal

Data Processing Agreement

On this page

    How this agreement works. This Data Processing Agreement ("DPA") forms part of the services agreement, statement of work or terms of business (the "Agreement") between BCC and the client named in it. It applies whenever BCC processes personal data on the client's behalf. If there is a conflict between this DPA and the Agreement on data protection, this DPA wins. A signed copy is available on request from info@bcctelemarketing.co.uk.

    1. Parties and definitions

    "BCC" means Business & Consumer Choices Telemarketing Limited, company number 08909427, 5 Orion Park, Orion Way, Kettering, NN15 6PP, and, where relevant, its group companies. "Client" means the customer named in the Agreement.

    "Data Protection Law" means all laws that apply to the processing, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), the EU GDPR where it applies, South Africa's Protection of Personal Information Act 2013 (POPIA) and applicable US federal and state laws, each as amended. "Controller", "processor", "personal data", "personal data breach", "data subject" and "processing" have the meanings given in the UK GDPR. Under POPIA, the Client is the "responsible party" and BCC is the "operator".

    2. Roles

    For the services, the Client is the controller and BCC is the processor. The Client is responsible for making sure it has a lawful basis for the processing and for any instructions it gives, including that any data it supplies may lawfully be used for the campaign (for example that it has been screened or consented as the law requires, unless the Agreement says BCC will do this).

    3. Processing only on instructions

    BCC will process personal data only on the Client's documented instructions, which are set out in the Agreement, this DPA, campaign briefs and any written instructions the Client gives later. This includes instructions about transfers outside the UK. If BCC thinks an instruction breaks Data Protection Law, it will tell the Client promptly. If the law requires BCC to process personal data other than on instructions, BCC will tell the Client first unless the law prevents it.

    4. Confidentiality

    BCC will make sure that everyone authorised to process the personal data is bound by a duty of confidentiality and has received appropriate data protection training.

    5. Security

    BCC will put in place appropriate technical and organisational measures to protect the personal data, taking account of the risk, including those set out in Annex 2. BCC may update these measures as long as the overall level of protection is not reduced.

    6. Sub-processors

    The Client gives BCC general authorisation to use the sub-processors listed in Annex 3. BCC will tell the Client at least 14 days before adding or replacing a sub-processor, so the Client can object on reasonable data protection grounds. If the Client objects and the parties cannot agree a solution, the Client may end the affected services. BCC will put a written contract in place with each sub-processor that gives the same level of protection as this DPA and remains responsible to the Client for the sub-processor's performance.

    7. International transfers

    BCC may process personal data in the UK and South Africa, where it has operations, and in the locations of its sub-processors. Where personal data is transferred from the UK (or the EEA) to a country without adequacy status, BCC will make sure the transfer is covered by an appropriate safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or the EU Standard Contractual Clauses, supported by a transfer risk assessment. The Client authorises transfers to BCC's Durban centres for the purpose of providing the services.

    8. Helping the Client

    Taking into account the nature of the processing and the information available to it, BCC will:

    • promptly pass on any request it receives from a data subject about the Client's data (and not respond itself unless authorised), and help the Client respond to data subject requests;
    • record and pass on any request not to receive marketing calls without delay, and keep the number suppressed for the Client's campaigns;
    • help the Client with its obligations on security, breach notification, data protection impact assessments and consultation with regulators.

    9. Personal data breaches

    BCC will notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Client's personal data. The notice will include, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. BCC will take reasonable steps to contain the breach and will co-operate with the Client's investigation. BCC will not notify regulators or data subjects about a breach of the Client's data without the Client's agreement, unless the law requires it.

    10. Return and deletion

    When the services end, or earlier at the Client's written request, BCC will return or securely delete the Client's personal data (including call recordings) within 30 days, as the Client chooses, unless the law requires BCC to keep it. BCC will confirm deletion in writing on request.

    11. Audits and information

    BCC will make available the information reasonably needed to show that it meets this DPA and will allow audits by the Client or an independent auditor it appoints, on at least 30 days' written notice, during business hours, no more than once a year (unless a breach or regulator requires otherwise), and subject to reasonable confidentiality. Each party bears its own costs.

    12. Liability, term and law

    The limitations of liability in the Agreement apply to this DPA, except where the law does not allow them to. This DPA lasts for as long as BCC processes personal data for the Client. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, unless the Agreement says otherwise.

    Annex 1: Details of the processing

    Subject matter Provision of outsourced telemarketing, customer service, lead generation, event and subscription campaigns, data services and AI voice agent services under the Agreement.
    Duration The term of the Agreement plus the return or deletion period in section 10.
    Nature and purpose Making and receiving calls, emails and chats on the Client's behalf; recording calls; updating records; taking orders, bookings, registrations and payments; data cleansing and research; reporting to the Client.
    Types of personal data Names, job titles, organisation, contact details (phone, email, postal address), account or membership numbers, order, subscription and booking history, call notes and recordings, marketing preferences, and any other data specified in the campaign brief. 
    Special category data None, unless agreed in writing in the campaign brief.
    Data subjects The Client's customers, prospects, members, subscribers, event attendees and exhibitors, and their staff.
    Locations United Kingdom, South Africa, and the locations of the sub-processors in Annex 3.

    Annex 2: Security measures

    • Role-based access to systems and data, with unique logins and multi-factor authentication for remote access.
    • Encryption of data in transit and, where supported, at rest.
    • Secure contact centre premises with controlled entry, clear-desk rules and no personal phones or recording devices on the calling floor.
    • Call recordings stored securely with restricted access and set retention periods.
    • Payment card data kept out of recordings and handled in line with PCI DSS where payments are taken.
    • Staff vetting, confidentiality agreements and data protection training at induction and at least yearly.
    • Anti-malware, patching, firewalls and backups.
    • An incident and breach response procedure.

    Questions about this page?

    Our data protection team is happy to help.

    info@bcctelemarketing.co.uk
    BCC Telemarketing

    Got a campaign in mind?

    info@bcctelemarketing.co.uk01933 443322

    Our centres

    Kettering, UK (Head office)

    5 Orion Park, Orion Way, Kettering, NN15 6PP

    Lighthouse Quarter, Durban

    14 Chartwell Drive, Umhlanga, 4320, South Africa

    Manhattan House, Durban

    Platinum Towers, Equinox Road, Umhlanga, Durban, 4320, South Africa

    Explore

    • Services
    • Sectors
    • How we work
    • About
    • Careers
    • Insights
    • Contact

    Your data

    • Received a call
    • Your data rights
    • Complaints
    • Trust & compliance
    LinkedInInstagramTikTok
    Accreditations & memberships
    Privacy PolicyData Processing AgreementModern Slavery StatementAccessibility Statement

    © 2026 Business & Consumer Choices Telemarketing Limited. Registered in England and Wales, company number 08909427. Registered office: 5 Orion Park, Orion Way, Kettering, NN15 6PP. VAT number GB245405716. ICO registration ZA665710.

    Cookies

    We use cookies to see how our site is used and to improve it. Is that OK? Cookie policy

    Your cart is empty

    Continue shopping

    Search

    No products found.