Guides

Help desk software and data protection law in the United Kingdom

What applies when a UK organisation puts customer data into a help desk: the UK GDPR processor contract, transfers and the UK–US data bridge, the Data (Use and Access) Act 2025, monitoring agents, FCA and Ofcom complaint deadlines, and call recording. With links to the official texts.

By the help-desk.reviews teamPublished 19 September 2026Updated 19 September 2026Prices and figures verified 18 September 2026
General information, not legal advice. Several Data (Use and Access) Act changes took effect in 2026. We link to official sources and state what we verified as of September 2026. Check your own obligations with a qualified solicitor or your data protection officer.

The short version

  • Sign the processor contract first. UK GDPR requires a written contract before the vendor touches real customer data.
  • An EU data centre is still abroad. For UK GDPR it is a restricted transfer.
  • Run data protection complaints through the help desk. Since 19 June 2026 you must acknowledge them within 30 days.
  • Tell agents how they are monitored. Dashboards, QA scoring and recordings fall under the ICO's monitoring guidance.
  • Regulated firms have hard deadlines. FCA: eight weeks, or 15 business days for payments. Telecoms: six weeks to ADR.
  • Announce call recording. The law requires reasonable efforts to tell every caller.

What must the contract with a help desk vendor say?

A help desk vendor that stores tickets for you is a processor: it handles personal data on your instructions. The ICO's guidance on contracts is plain: whenever a controller uses a processor, there must be a written contract. It must include terms on sub-processors, the other companies the vendor passes your data to, such as hosting or AI model providers.

Most vendors call this contract a data processing agreement (DPA). Sign it before you import real tickets, including during a free trial.

Is an EU-hosted help desk a transfer?

Yes. The ICO's guide to international transfers calls sending personal data to a separate organisation outside the UK a restricted transfer. A tenant hosted in Frankfurt or Dublin is outside the UK, so it needs a UK transfer mechanism. Where no UK adequacy regulations apply, the ICO's tools are the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses, plus a risk assessment that UK law now calls a "data protection test". Check that the vendor's DPA includes the UK Addendum, not only the EU clauses.

For US vendors there is the UK–US data bridge, in force since 12 October 2023. You can send data without further safeguards to US organisations certified to the UK Extension to the EU–US Data Privacy Framework. Signing up to the UK Extension is a separate choice from the EU certification, so check the vendor's entry on the official list yourself.

The bridge rests on the EU–US framework, which is under appeal. As of September 2026 the appeal to the EU Court of Justice was still pending, with no hearing date found. That is why a DPA with fallback clauses matters.

If your group also has EU companies, their data can come to a UK tenant more easily. The EU renewed its adequacy decisions for the UK on 19 December 2025, and they last until 27 December 2031.

What did the Data (Use and Access) Act 2025 change for support teams?

The ICO's summary of the DUAA says the changes were phased in between June 2025 and June 2026. Four of them touch a help desk directly.

  • A complaints process. Under section 103, fully in force since 19 June 2026, you must help people complain about how you use their data, for example with an electronic form. You must acknowledge each complaint within 30 days and respond without undue delay.
  • The subject access clock can pause. Under section 76, in force since 5 February 2026, you still have one month, extendable by two more for complex requests. The time between asking the requester for more information and receiving it does not count. Your SLA timers need a pause state.
  • Searches must be reasonable and proportionate. Section 78 limits what you must find to a reasonable and proportionate search. Tickets, chats and call recordings about the requester remain in scope, so you still need a per-person search and export.
  • New cookie exceptions. Schedule 12, in force since 5 February 2026, adds exceptions to the PECR consent rule, including storage strictly necessary for a service the user asked for and some statistical uses. A chat widget's marketing or cross-site tracking cookies fit none of them.

The ICO finalised its cookie guidance on 29 April 2026. "Strictly necessary" applies only where the service could not technically work without the storage. For the statistical exception you must offer a simple, free way to object. The guidance does not mention chat widgets, so load the widget without non-essential cookies until the visitor opens it or consents.

Can you monitor agents with dashboards and QA scores?

Yes, within limits. The ICO's guidance on monitoring workers says you must tell workers the nature, extent and reasons for monitoring, identify a lawful basis, and carry out a data protection impact assessment (DPIA) before monitoring that is likely to be high risk. Agent performance dashboards, call and screen recording, activity tracking and AI quality scoring all fall within it. The ICO flags the guidance as under review after the DUAA.

How should regulated firms set up SLAs?

If you are regulated by the FCA, DISP 1.6 sets complaint deadlines. You must acknowledge a complaint promptly in writing. By the end of eight weeks you must send a final response, or explain in writing why you cannot and tell the customer about the Financial Ombudsman. For payment services and e-money complaints the deadline is 15 business days.

Telecoms providers have a shorter clock. Ofcom cut the point at which customers can take an unresolved complaint to alternative dispute resolution (ADR) from eight weeks to six, for complaints raised on or after 8 April 2026, according to CMS.

In practice, tag complaints as a separate type, run SLA targets in business days, and trigger the deadlock letter automatically before the deadline. Our guide to SLA basics explains how help desk SLA timers work.

Do you have to announce call recording?

The Investigatory Powers (Interception by Businesses etc.) Regulations 2018 let a business record calls on its own system for purposes such as establishing facts, regulatory compliance and checking staff standards. One condition is that you make all reasonable efforts to tell everyone using the system that calls may be recorded. Hence the familiar announcement, plus a notice to staff. UK GDPR applies on top.

What to check in a help desk before you buy

  1. The DPA. Signed before you import real tickets, with a full sub-processor list.
  2. Transfer terms. The UK Addendum or IDTA in the DPA, and for US vendors an active UK Extension certification that you have checked yourself.
  3. Hosting and support access. Where data is stored and where support staff sit. See our help desks with EU data hosting.
  4. A complaints route. A form, a tag and a 30-day acknowledgement timer for data protection complaints.
  5. Pausable SLA timers. For subject access requests, and business-day targets for FCA or Ofcom deadlines.
  6. Per-person search, export and deletion. Tickets, attachments and recordings, plus configurable retention periods.
  7. Monitoring settings. Which agent reports exist and who sees them. Run the DPIA before go-live.
  8. Call recording controls. An announcement on every call and a way to pause recording.
  9. Exit terms. Export format and notice period. Our migration checklist covers the rest.

Frequently asked questions

Is a help desk hosted in the EU a restricted transfer under UK GDPR?

Yes. The ICO treats any transfer to a separate organisation outside the UK as restricted, including to an EU data centre. The contract needs the UK Addendum or the IDTA.

Can I use a US help desk under the UK–US data bridge?

Only if the vendor is an active participant in the EU–US Data Privacy Framework and has also signed up to the UK Extension. Because the framework was under appeal as of September 2026, keep fallback clauses in the DPA.

What does the DUAA complaints rule mean for a support team?

Since 19 June 2026 you must make it easy to complain about how you use personal data, acknowledge each complaint within 30 days and respond without undue delay. A form, a tag and an SLA timer handle this.

Do I need consent to record support calls in the UK?

The 2018 interception regulations allow a business to record calls for purposes such as establishing facts and checking staff standards, on condition that it makes all reasonable efforts to tell everyone that calls may be recorded. UK GDPR also applies to the recordings.

Keep reading

This page was researched and drafted with AI assistance from the sources listed on it. We have not run hands-on tests of these products. Method: How we review