What is GDPR Compliance and Why Contact Centers Should be GDPR Compliant

Harry Fozzard Published on September 10, 2021

Summary

Open Access BPO recently completed a comprehensive GDPR audit to certify that we comply with the General Data Protection Regulation laws. Read this to learn why we comply with GDPR and how it fits into our framework for service delivery excellence. This GDPR Certification compliments our PCI DSS Level 1 certification.

Contact Center Compliance – Untangling Acronyms

Call centers must respect myriad rules and regulations designed to protect consumer privacy and prevent unwanted intrusion into their lives. Companies dialing the US market consider some or all of the following regulations:.

  • Telemarketing Consumer Protection Act (TCPA)
  • National Do Not Call Registry (the DNC List)
  • Health Insurance Portability and Accountability Act (HIPAA)
  • Fair Debt Collection Practices Act (FDCPA)
  • Payment Card Industry Data Security Standard (PCI DSS)
  • Consent for Call Recording (law vary by state)
  • California Consumer Privacy Act (CCPA)
  • General Data Protection Regulation (GDPR)

Each has its unique mandates and applications. A call center that doesn’t do outbound telemarketing needn’t consider TCPA. Centers engaged in B2B sales might not need to respect the DNC list. Companies that are not engaged in collections or gathering medical information are not obliged to comply with HIPAA or the Fair Debt Practices Act, respectively.

Compliance extends to a range of formal measures enacted at the organizational level for departments like Operations, Information Technology, Human Resources, and Training. These measures obtain when everyone, from the executive suite to the frontline agent, understands and promotes these standards with a complete understanding of their import and application.

We could say that compliance is part of the service companies outsource to service providers like Open Access BPO. Our clients patronize us because we handle data security and data privacy duties. Further, compliant organizations demonstrate the kind of commitment to privacy and industry self-policing that mark quality organizations. These call centers and BPOs rise to the level of representing the brands that engage them.

What is GPDR?

Against this backdrop of various compliance mandates, the General Data Protection Regulation laws arrived in 2018 with great fanfare. Commonly called GDPR, the European Union (EU) enacted this legislation, and it requires businesses to protect EU citizens’ personal data and privacy.

Since it’s impossible to ascertain a person’s citizenship using standard call center or business process outsourcing tools, any global business must comply with GDPR.
GDPR enacts a sweeping set of rules about personal data, starting with consent. According to the GDPR site, “Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”

Building on that accumulated data, there are extensive rules about data privacy. Data protection falls into two categories: data protection and data privacy. For GDPR, data protection is keeping data safe from unauthorized access. On the other hand, data privacy guarantees that users retain the right to make their own decisions about who can process their data and what they can do with it.

For any organization planning a GDPR compliance initiative, you can find everything on the GDPR.eu site, including a compliance checklist and templates to get you started.

GDPR for Contact Centers & Business Process Outsourcers

Call centers will need to wrap their arms around the organizational behaviors that treat personal data differently now that GDPR has set a benchmark for privacy legislation. In essence, we need to start thinking about personal data from the perspective of the person.

Data protection becomes a priority. People get assigned to the job of promoting the tenets of data security and data privacy. This team monitors collected, stored, and processed data. Transparency dictates that we report data breaches to affected parties in a timely fashion.

Call recording isn’t a default setting anymore. Call recording falls under the consent umbrella of specific, informed, and unambiguous. A set of official rules governs the reasons for call recording, so “This call may be monitored or recorded for quality assurance purposes” may be on the way out. To record a call, you need a reason that benefits the caller, and she must agree to the recording.

Third parties secure the data and keep it accessible to its owner. Call centers and BPOs that store data are responsible for its security and access. Companies that outsource to call centers and BPOs are likewise accountable for that data. Data must be safe, and the data owner must have access to move or remove their registered data. Moreover, any data owner can invoke the GDPR right to be forgotten and have their data removed.

The Future of Privacy for Contact Centers & Business Process Outsourcers

The penalties for GDPR non-compliance can be steep. In late 2019, ZDNet reported that the German Federal Commissioner for Data Protection and Freedom of Information slapped mobile services provider 1&1 Telecommunications with a 9.55m ($10.65m) fine.

The reason? 1&1 Telecommunications did not effectively protect its customers’ personal data. Anyone calling 1&1’s call centers could access customer information with a name and date of birth.

Leaving aside the financial and legal penalties for non-compliance, more significant considerations should drive BPOs into the arms of GDPR’s intent.

As consumers increasingly understand and question how third parties manage their dataโ€”pushing back on the surveillance economyโ€”businesses must embrace responsible customer-centric behavior concerning data.

This imperative parallels the drive for customer experience excellence. As users grow to expect more competent, seamless support that keeps getting better, more proactive, and more anticipatory, their sensitivity to data use matures. They understand that data permits these strides in customer support efficacy. One manifestation of data use that has hopefully reached its twilight: uninvited, stalker ads are waning. Government intervention is one reason; another is that people don’t like it.

Businesses who champion the customer ultimately win, not because legislation mandates these consumer protections, but because they make winners of all stakeholdersโ€”consumers, BPOs, and client organizations.

These organizations, cognizant of the human rights to privacy and data ownership, deliver an experience that anticipates customer needs for assistance and their need for data custodians that they can trust.

Read More

Avatar photo
Harry Fozzard works with the marketing team at Open Access BPO, one of the world's leading high-touch multi-lingual service providers. He's been working at the intersection of marketing and offshore outsourcing since 2002. He's dived throughout SE Asia and Australasia
Join us on facebook
Open Access BPO 14 hours ago
Today marks International Day of Awesomeness, a reminder to embrace the extraordinary.

One of Open Access BPO's core values, "Make Awesome Happen," guides us in our commitment to excellence.

We strive to create an awesome work environment for our team, build awesome partnerships that drive success, and ultimately, deliver awesome solutions that positively impact our clients' customers.

#WeSpeakYourLanguage
#AwesomeOABPO #OABPOholidays
#InternationalDayOfAwesomeness
Open Access BPO 17 hours ago
๐—ข๐—ฝ๐—ฒ๐—ป ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—•๐—ฃ๐—ข ๐— ๐—ฎ๐—ป๐—ถ๐—น๐—ฎ'๐˜€ ๐—ฆ๐˜‚๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€๐—ณ๐˜‚๐—น ๐—•๐—น๐—ผ๐—ผ๐—ฑ ๐——๐—ผ๐—ป๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐——๐—ฟ๐—ถ๐˜ƒ๐—ฒ

Open Access BPO Manila's annual blood donation drive last March 5 was a success, with more than 30 employees taking part in this life-saving initiative.

Held two weeks after the Davao team hosted their leg of the program, OABPO Manila's Clinical Services team partnered with the Philippine Red Cross.
Employee blood donations totaled nearly 14,000 CCs, expected to help over 90 patients.

Open Access BPO makes it a point to give back to the community this annual bloodletting event and several outreach programs.

#WeSpeakYourLanguage
#OneForHealth #OABPOCares
Open Access BPO 3 days ago
๐—ข๐—ฝ๐—ฒ๐—ป ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—•๐—ฃ๐—ข'๐ฌ ๐‚๐จ๐ฆ๐ฆ๐ข๐ญ๐ฆ๐ž๐ง๐ญ ๐ญ๐จ ๐—š๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ ๐—˜๐—พ๐˜‚๐—ถ๐˜๐˜† ๐จ๐ง ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ช๐—ผ๐—บ๐—ฒ๐—ป'๐˜€ ๐——๐—ฎ๐˜†

On International Women's Day, Open Access BPO acknowledges the significant contributions of women leaders and innovators globally.

This year's theme, #AccelerateAction, reminds us that we must urgently dismantle barriers to gender equality.

Open Access BPO is dedicated to cultivating an environment that empowers women at all career stages.

We support established leaders, high-potential employees advancing within the organization, and emerging talent exploring their professional capabilities.
Our global offices are structured to ensure safe and inclusive spaces, fostering professional development and innovation.

We're committed to building a #diverse and equitable workplace where women are empowered to realize their full potential.
Open Access BPO actively supports initiatives that drive systemic change and contribute to a more equitable future.

#WeSpeakYourLanguage
#OABPOonIWD2025 #IWD2025
#InternationalWomensDay
Open Access BPO 3 days ago
Customer loyalty hinges on consistently exceeding expectations. Proactive adaptation of your #CallCenter's #CustomerService strategy is crucial to this success.

Here's how often you should refine your approach: https://buff.ly/inDm6r3

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
Outsource your #CustomerSupport needs only to a trusted #CustomerExperience firm: https://buff.ly/ijHXFrU

#WeSpeakYourLanguage
#CX #outsourcing
Open Access BPO 5 days ago
๐—ข๐—ฝ๐—ฒ๐—ป ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—•๐—ฃ๐—ข ๐˜€๐˜‚๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€๐—ณ๐˜‚๐—น๐—น๐˜† ๐—ต๐—ผ๐˜€๐˜๐—ฒ๐—ฑ ๐—ฎ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜๐—ฒ๐—ฑ ๐—ผ๐—ฝ๐—ฒ๐—ป ๐—ต๐—ผ๐˜‚๐˜€๐—ฒ ๐—ผ๐—ป ๐— ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐Ÿญ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ, ๐—ฎ๐˜ ๐—ถ๐˜๐˜€ ๐— ๐—ฎ๐—ธ๐—ฎ๐˜๐—ถ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ฒ, ๐—ณ๐—ผ๐—ฐ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ผ๐—ป ๐—ฐ๐˜‚๐˜€๐˜๐—ผ๐—บ๐—ฒ๐—ฟ ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฎ๐—ด๐—ฒ๐—ป๐˜ ๐—ฟ๐—ผ๐—น๐—ฒ๐˜€ ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ฒ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฎ๐—ป๐˜†'๐˜€ ๐—ณ๐—น๐—ฎ๐—ด๐˜€๐—ต๐—ถ๐—ฝ ๐—ณ๐—ถ๐—ป๐˜๐—ฒ๐—ฐ๐—ต ๐—ฝ๐—ฟ๐—ผ๐—ด๐—ฟ๐—ฎ๐—บ.

The ๐‚๐’๐‘ ๐„๐ฑ๐ฉ๐ซ๐ž๐ฌ๐ฌ ๐‡๐ข๐ซ๐ข๐ง๐  ๐„๐ฏ๐ž๐ง๐ญ streamlined recruitment, attracting a diverse pool of qualified candidates. Attendees participated in structured assessments, with many progressing to client interviews and nearing onboarding.

To enhance the candidate experience, Open Access BPO offered show-up incentives, complimentary meals, sign-on bonuses, and referral bonuses for current employees. A raffle with travel and shopping vouchers further contributed to the event's engagement.

This initiative underscores Open Access BPO's commitment to securing top-tier talent for its clients and will inform future hiring strategies.

#WeSpeakYourLanguage
#OABPOcareers
Open Access BPO 5 days ago
Customer satisfaction surveys are goldmines, but only if you use them right.

Don't let your data gather dust! Get practical steps to turn survey results into actionable improvements by visiting: https://buff.ly/Ljjfw9X

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
Ready to elevate your #CustomerExperience?

Connect with our #CX experts today and let us help you implement these strategies: https://buff.ly/30QwHuQ

#WeSpeakYourLanguage
#CustomerSatisfaction #CSat
#CustomerSuccess #CallCenter