Data Protection and Marketing Compliance

Last updated: [29 July 2026

Propria.io takes data protection seriously. This page explains which laws apply to our work, how we handle personal information when we carry out outreach and marketing, and where your responsibilities sit as a client.

For details of how we handle your own personal information, please read our Privacy Policy.

Which Laws Apply to Us

Two separate sets of rules govern the work we do.

UK GDPR and the Data Protection Act 2018. Since the UK left the EU, the law that applies to us is the UK General Data Protection Regulation, read together with the Data Protection Act 2018. It governs how personal information is collected, stored, used and shared, and it gives individuals rights over that information. It is regulated by the Information Commissioner's Office.

PECR. The Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended, govern electronic marketing specifically, including email, SMS, telephone calls and the use of cookies. PECR sits on top of UK GDPR rather than replacing it, so both apply to any campaign we run.

EU GDPR. Where a campaign targets or monitors people in the European Economic Area, EU GDPR applies in addition to the UK rules. We assess this at the point we scope a campaign, and we tell clients when it is relevant to them.

Our Role: Controller and Processor

Data protection law treats these two roles differently, and it matters which one applies.

  1. Where we act as controller. We decide how personal information is used. This covers our own marketing, our own prospect research, our website, and our client records. Our Privacy Policy sets out what we do in this role.

  2. Where we act as processor. We handle personal information on your instructions, using data you control. This covers campaigns run on your lists, your CRM, your website enquiry data and similar work.

Where we act as processor, UK GDPR Article 28 requires a written data processing agreement between us. We include these terms in our client documentation, and you can request a copy at any time from privacy@propria.io

How We Handle Outreach Data

We gather business contact information from publicly available sources. Doing so lawfully requires more than the information being public, so we take the following steps.

Lawful basis. For business-to-business outreach, we rely on legitimate interests. We record a Legitimate Interest Assessment (LIA) for each campaign, weighing our interest in offering a relevant service against the reasonable expectations and rights of the people we contact. Where we cannot satisfy ourselves that the balance is right, we do not run the campaign.

Relevance and targeting. Before a campaign begins we review the client's product or service and define who it is genuinely relevant to. Narrow, relevant targeting is not a legal requirement in itself, but it is central to whether a legitimate interests basis holds up, so we treat it as part of the assessment rather than as marketing language.

Telling people we hold their data. Where we collect personal information from public sources rather than from the individual, UK GDPR Article 14 requires us to tell that person within one month, or at the point we first contact them, whichever comes first. Our outreach identifies who we are, explains where we obtained their details, and links to our privacy information.

Retention. Prospect data is reviewed regularly and deleted when it is no longer relevant to a live or planned campaign, or when the individual objects.

Objections and opt-outs. Every message we send includes a clear way to opt out. We act on objections promptly and suppress the contact so that they are not contacted again through a later campaign.

Electronic Marketing Under PECR

PECR draws a distinction that is often overlooked, and it determines whether consent is required before we send a marketing email or text.

Corporate subscribers. Limited companies, limited liability partnerships, Scottish partnerships, government bodies and other public authorities are corporate subscribers. The consent rule in PECR regulation 22 does not apply to them, so a marketing email may be sent to a corporate subscriber without prior consent. We must still identify ourselves, provide a valid contact address, and stop on request.

Individual subscribers. Individuals, sole traders and unincorporated partnerships outside Scotland are individual subscribers. Consent is required before sending them marketing email or SMS, unless the soft opt-in applies, meaning we obtained their details in the course of a sale or negotiations for a sale, the marketing relates to similar products or services, and they were given an easy way to opt out both at the point of collection and in every message.

This distinction is why we do not describe our outreach as automatically compliant simply because it is business-to-business. A great many businesses are sole traders or partnerships, and those contacts are treated as individual subscribers. We screen for this when building a campaign list.

UK GDPR still applies either way. Even where PECR permits a message without consent, the named individual behind a business email address is still identifiable, so we need a lawful basis, we must be transparent, and the person retains their rights. Being a corporate subscriber removes the consent requirement under PECR. It does not remove our obligations under UK GDPR.

Telephone and cookies. Where a campaign involves marketing calls, we screen against the Telephone Preference Service and the Corporate Telephone Preference Service. Cookies and similar technologies are set only in accordance with the consent requirements of PECR Regulation 6.

How We Keep Compliance Current

  1. We take external data protection advice and act on it, rather than relying only on internal judgement.

  2. We have a named compliance contact responsible for data protection questions and requests. We have not appointed a statutory Data Protection Officer, as we do not meet the criteria that require one.

  3. We keep written records of our processing activities, our Legitimate Interest Assessments and our supplier arrangements.

  4. We review this page and our supporting policies as the law and ICO guidance develop.

We do not claim to be perfect or permanently compliant, because no organisation honestly can. What we do commit to is documented decisions, prompt handling of requests and objections, and quick correction when needed.

Security

We have security measures in place to protect personal information from loss, misuse, unauthorised access, alteration, or disclosure.

Access to personal information is restricted to employees, agents, contractors and other third parties who have a genuine business need for it. They are bound by a duty of confidentiality and may only process personal information on our instructions.

We have procedures for dealing with any suspected personal data breach. Where the law requires it, we will report a breach to the ICO within 72 hours of becoming aware of it, and we will inform affected individuals without undue delay where the breach is likely to pose a high risk to their rights.

Your Responsibilities as a Client

Compliance is shared. Where we run campaigns for you, the following sit with you.

  1. Your own lawful basis. Where you supply a list or a CRM export, you are responsible for having collected that data lawfully and for being able to demonstrate it.

  2. Accuracy of your data. You are responsible for the accuracy and currency of any data you provide to us.

  3. Your sector rules. You must comply with any regulatory framework specific to your industry or the countries you operate in, and tell us if something changes that affects a campaign. We cannot monitor every regulatory regime in every market on your behalf, which is why this needs to come from you.

  4. Passing on requests. If someone contacts you to object, opt out or exercise a data protection right in connection with a campaign we run, tell us promptly so that we can act on it within the statutory time limits.

If anything on this page is unclear, or you want to see the documentation behind a particular campaign, ask us.

Contact

Data protection questions, requests and complaints should be sent to privacy@propria.io.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, although we would ask that you come to us first so that we have the chance to put things right.