What Happens When You Collect Customer Phone Numbers?
Taking a customer’s phone number turns a one-off transaction into a record. The business now holds that record, with the obligations that come with holding it. The record does not stay accurate on its own. Nor does the reason for holding it last forever.
Which? asked its own members whether an old mobile number had been updated everywhere. Of those who had changed a number in the past decade, only half had told every account that mattered. That is what they said themselves (Which?, 2024). That was a survey of more than 15,000 Which? panel members, not a count of the UK public.
The number a business wrote down is not necessarily the number the customer still has. What follows works through what the ICO’s own guidance says about a record like that.
Key Takeaways
- A phone number taken for one job becomes a record the business holds, with accuracy and retention questions attached (ICO, 2026).
- The ICO draws the marketing line at what a message contains, not at whether a business holds a number (ICO, 2026).
- In 2025, email and post sent to the wrong recipient outnumbered ransomware among ICO reports by more than five to one, calculated from the regulator’s own dataset (ICO, 2026).
- Of Which? panel members who had changed a mobile number in the past decade, only half had updated it everywhere (Which?, 2024).
- Several of the ICO’s own pages carry a notice that the guidance is under review, following the Data (Use and Access) Act.
- Several routes tell a customer their order is ready without the business holding a phone number at all.
What actually happens to a phone number after you take it?
A phone number stops being something a customer said out loud. It becomes a record sitting in whatever system it landed in. The ICO’s own guidance puts the underlying test plainly: “You must only collect what you actually need, and shouldn’t ask for or keep anything ‘just in case’.” (ICO, 2026)
That test applies wherever the number ends up. A single number often lands in more than one place. It can be written on an order pad or typed into a booking system. It might be keyed into a till, too. It might also be saved on a staff member’s own phone.
That phone might then be used to text a customer from a personal number. What running updates through WhatsApp involves covers what that particular route asks a business to hold onto. A number can also sit in an exported spreadsheet. Or it can pass to whichever platform sends the message.
None of these holders talk to each other. A number on a paper pad does not update when a phone-based entry changes. A spreadsheet export does not know the till record was corrected afterwards either. Each copy ages at its own pace. Nobody fixes that drift, unless somebody goes back and corrects it by hand.
The principle behind the ICO’s test is data minimisation. Personal data has to stay relevant and limited to what a business needs it for. It is not simply for what might be useful later. A number typed in for one order stops being necessary. That happens once the order has gone out.
What do the ICO’s own pages say, and which of them are under review?
The guidance is public, plain, and currently being revised. The regulator says so on the pages themselves. Five of the ICO pages cited in this article carry a standing notice. It reads: “Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.”
The two principles a business runs into first sit on those pages. On data minimisation, the ICO’s guidance says: “You must not collect personal data on the off-chance that it might be useful in the future.”
On storage limitation, the ICO’s guidance says: “You must not keep personal data for longer than you need it.” (ICO, 2026)
What the current review changes is not this article’s to explain. Only the ICO’s own words on each page are reported here. That happens only where a page states something directly. A hand check covered every ICO page cited in this article. It ran on 29 August 2026 and found the following. Every row was checked again on 4 September 2026.
| ICO page cited in this article | Carries the “under review” notice | Date shown on the page |
|---|---|---|
| Getting started with data protection | Yes | None shown |
| Data minimisation | Yes | None shown |
| Storage limitation | Yes | None shown |
| Accuracy | Yes | None shown |
| Right to erasure | Yes | None shown |
| Identify direct marketing | No | Latest update 20 August 2025 |
| A guide to subject access | No | Updated 16 July 2026 |
| What is the right of access? | No | Updated 8 December 2025 |
| Personal data breaches: a guide | No | Note dated 20 August 2025 |
| Guide to the data protection fee | No | None shown |
| Data security incident trends | No | Latest updates list, top entry 11 March 2025 |
| Data security incident trends, incident types | No | None shown |
Where a page states what changed, in its own words, that description gets reported. Nothing more is added. The breach guidance’s own changelog attributes a timing change to the Act. It moved the reporting timescale for breach reports under PECR. The change moved it from 24 hours to 72 hours after becoming aware of a breach. That change is dated 20 August 2025 (ICO, 2026).
The subject access page’s own changelog names a date. Its 16 July 2026 update is attributed to changes under the Act. It also says the update aligns with other guidance. That guidance covers the regulator’s right of access. That guidance was updated separately (ICO, 2026).
A text saying your order is ready is not a marketing message
The line the ICO draws sits in what a message says. It is not about whether a business holds a number to send it to. Its guidance states this directly. “Data protection law and PECR don’t stop you from telling your customers important information that they need to know as part of their relationship with you.” (ICO, 2026)
PECR defines direct marketing as “the communication (by whatever means) of advertising or marketing material which is directed to particular individuals”.
The ICO’s guidance gives an update like an order-ready text a different name. “This type of communication is often referred to as a ‘service message’. It covers messages that aren’t promotional but are for administrative or customer services purposes”.
One example the ICO gives is a message that will “remind people how to contact you in case of a problem”.
The distinction that matters is what happens once a promotional line gets added. The ICO’s guidance covers both directions.
“If your service message has elements that are direct marketing, even if that is not the main purpose of your message, then it will count as direct marketing.”
The ICO adds one more line. “if your service message contains general branding or logos, this doesn’t count as direct marketing.”
A text reading “Table 4, your food is ready” sits inside the service-message test. The same text with a line offering money off attached moves toward direct marketing instead. That is on the ICO’s own reading of its rules.
What does the ICO’s own breach data actually show?
The ICO’s own published breach dataset supplies the figures here, calculated directly by the author. In 2025, 3,194 of the 13,457 incidents reported fell into the two categories the ICO names for an incorrect recipient: email, and post or fax. That is more than five times the 617 reported as ransomware that year (ICO, 2026). The ICO warns its own dataset is not definitive: “it contains only the data security incidents that were discovered and then reported to the ICO.” (same source)
Two things about that dataset are worth understanding before the figures mean anything.
Rows are not incidents
The ICO’s file holds 206,140 rows, but only 77,222 distinct reported incidents (ICO, 2026). One incident can appear on several rows. That happens if more than one data type or data subject type is involved. Counting rows instead of incidents overstates the breach count. The factor is about 2.67.
The ICO’s own dataset notes explain why some reports “hold multiple characteristics for some of the categories of data and as such appear on multiple rows”.
Every figure in this article is a count of distinct incidents. Each is calculated directly from the file, never from rows.
What the ICO does not have a category for
The ICO’s own published list of incident types includes several categories. One covers post and fax sent to the wrong recipient. It defines this as cases “where a fax or piece of post containing personal data is sent to the wrong fax number or postal address.” (ICO, 2026)
That published list carries no category naming text messages at all.
The table below lists the ICO’s categories separately rather than pooling them. Only the first two are named for an incorrect recipient. A failure to use bcc reaches the people it was addressed to, so it is not counted in the comparison above. None of these categories covers SMS, and this article makes no claim about where a misdirected text would sit.
| Incident type, 2025 | Incidents | Share of 2025 total |
|---|---|---|
| Data emailed to incorrect recipient | 2,459 | 18.3% |
| Data posted or faxed to incorrect recipient | 735 | 5.5% |
| Failure to use bcc | 434 | 3.2% |
| Data of wrong data subject shown in client portal | 228 | 1.7% |
| Phishing | 1,526 | 11.3% |
| Ransomware | 617 | 4.6% |
Calculated by the author from the ICO’s own incident dataset, 13,457 total reported incidents in 2025. Categories and incident types, in the ICO’s own words, are “allocated by the ICO and are assigned as a best fit.” (ICO, retrieved 2026-08-29)
The number you wrote down last year may not be theirs now
A stored number decays quietly, and nothing in most systems flags it. Which? surveyed 15,220 members of its own online panel between 19th and 31st July 2024. It found that “one in 10 (11%) said they had changed their mobile number within the past decade” (Which?, 2024).
Of that group, “only half (50%) said they had updated their number with all relevant accounts and organisations” (Which?, 2024). That is half of the number-changers, a subgroup of roughly 1,700 out of the 15,220 surveyed. It is not half of the UK public. Among its members, Which? reports that “Seven per cent had experienced problems caused by the deactivation or reallocation of a landline and/or mobile phone number” (same source).
Two clocks run here and they are easy to confuse. The first is how long a number can sit unused before the provider cuts it off. Which? contacted 16 UK mobile providers. Among the 12 that responded, “‘low usage’ deactivation policies varied enormously, ranging from three months (Lebara and 1p Mobile) to nine months (Voxi)” (Which?, 2024). A call, a text, some data or a top-up inside that window was generally enough to stay connected.
The second clock starts after that one, and the same report puts numbers on it (same source). “Giffgaff shared that it holds on to deactivated numbers for a year before reallocating them to another customer, while Three waits at least 18 months.”
So a number stops reaching its owner well before it belongs to anybody else.
The ICO’s own accuracy principle assumes exactly this kind of drift. Its guidance puts it this way.
“In some cases it is reasonable to rely on the individual to tell you when their personal data has changed, such as when they change address or other contact details.”
Whether that record needs active checking depends on the use.
“This depends on what you use the information for. If you use the information for a purpose that relies on it remaining current, you should keep it up to date.”
A group taken down in one sitting ages the same way, only faster. Collecting numbers from a tour or event group covers a case like it. A number picked up abroad, or for a single trip, works the same way. It is simply less likely to still work months later.
A messaging platform sees the same decay from the other side, but less clearly than it might. Twilio has one delivery code for a number that “is unknown and may no longer exist” (Twilio, 2026). It has another for a handset “unavailable on the carrier network” (Twilio, 2026). The two do not cleanly separate. Twilio lists “The device is powered off or has insufficient signal” among the possible causes of the first code as well (same source).
So a bounced message rarely settles whether a number is dead or a phone was simply off. It settles nothing at all unless somebody reads the delivery receipts.
Holding it has a running cost, and not only the obvious one
The cost of holding a number is not the text message itself. It is the standing obligations that come with the record (what a text actually costs to send covers the message cost). Holding personal data means answering for it if someone asks what is held. It also means reporting it if it goes wrong.
A customer can ask what a business holds on them. The ICO’s guidance describes this right of access as giving “people the right to obtain a copy of their personal information from you, as well as other supplementary information.”
A business receiving that request has, in the ICO’s words, to “respond without undue delay, and within one month of receipt of the request.” (ICO, 2026)
The ICO adds a caveat.
“You may extend the time limit by up to a further two months where necessary, if the request is complex or you receive a number of requests from the person.”
That extension is covered on the same guidance page as the one-month rule above.
A customer can also ask for a number to be deleted. The ICO’s own guidance on the right to erasure is direct: “The right is not absolute and only applies in certain circumstances.” (ICO, 2026)
If a number is exposed by accident, the clock starts immediately.
The ICO’s guidance says a business “must report a notifiable breach to the ICO without undue delay, but not later than 72 hours after becoming aware of it.” (ICO, 2026)
It adds: “If a risk is likely, you must notify the ICO; if a risk is unlikely, you don’t have to report it.”
The regulator’s own dataset notes state this plainly: “Organisations are required to report breaches within 72 hours of discovery under Article 33 of the GDPR.” (ICO, 2026)
The ICO also charges a data protection fee, and not every organisation has to pay it. Its guidance states that “there are three different tiers of fee and controllers are expected to pay between £52 and £3,763.” (ICO, 2026)
It adds: “the fee for tier 1 is £52.”
“Not all controllers must pay a fee. Many can rely on an exemption.”
| Data protection fee | What the ICO’s guide states |
|---|---|
| Full range across all tiers | £52 to £3,763 |
| Tier 1 | £52 |
(ICO, retrieved 2026-08-29). The ICO publishes a self-assessment tool on the same page. It is for working out which tier, if any, applies to a specific business.
What can you tell a customer without holding their number at all?
Several routes reach a customer without the business keeping anything about them afterwards. Calling a name across a counter works without collecting so much as a first name. So does showing an order number on a screen, or handing over a physical pager.
The ways a venue can tell a customer their order is ready sets out the full comparison. The table below narrows it to one question. What does each route leave the business holding afterwards?
| Route | What the business ends up holding |
|---|---|
| Calling a name | Nothing |
| A screen showing an order number | Nothing |
| A pager handed over and returned | Nothing, once the pager is back |
| A QR code scanned by the customer | Depends on the platform; some ask for nothing at all |
A scanned QR code is one version of that last row. How QR codes work at a service counter covers the mechanics. Upd8All is one implementation of it. The customer receives updates by scanning a code. Nothing needs installing first, since the code opens the updates in a browser.
No phone numbers or email addresses are exchanged between the business and the customer. Pairing happens by scanning a QR code. There are no accounts and no sign-up, for either side. What it will not do is carry more than a short message. Channels are one-way, capped at 40 characters. The customer still needs a smartphone with a camera. A working connection is needed too, to read the update. What data Upd8All itself collects sets out the rest.
What you ask for is what you end up holding
Every field on an order pad or a booking form is a small decision. It is a decision about what gets kept. Some of those decisions matter for a week and then quietly stop mattering. Others turn into a record nobody remembers agreeing to keep.
The habit worth building is not a policy document. It is walking through a business’s own collection points, one field at a time. That means the pad by the till, the booking form, the loyalty sheet.
Ask a plain question of each one. Once the order is collected, the appointment confirmed, or the trip is over, does anything get done with that field? A name used to call an order is doing a job. A number nobody has looked at since the day it was written down is not.
Fields that fail that question are not automatically a problem. They are simply the ones worth checking first. They are also the ones nobody would notice going missing.
Frequently Asked Questions
What kind of data breach actually gets reported to the ICO most often?
Not the kind most people picture. Of the 13,457 incidents reported in 2025, 10,304 were classed non-cyber rather than as an attack, which is about 77 per cent. That figure is calculated by the author from the regulator’s own published dataset (ICO, 2026). The ICO assigns those categories itself, as a best fit.
Is a text saying an order is ready a marketing message?
Not automatically. The ICO’s guidance draws the line at what a message contains. It does not draw it at whether the message arrived by text. An update that simply confirms an order is ready sits inside a category. The regulator calls that category a service message. Attaching a promotional offer to the same text changes that. It can turn the text into direct marketing instead (ICO, 2026).
How long can a business keep a customer’s phone number?
The ICO sets no fixed number of days or months for keeping a customer’s details. Its storage limitation guidance is plain on this. Organisations should not keep personal data for longer than needed. It adds one more point. They should be able to justify how long they keep it (ICO, 2026).
What happens if a text goes to the wrong number?
It depends on the platform, and the answer is murkier than it looks. A failed message may come back as Twilio’s code 30005, described as a destination that “is unknown and may no longer exist” (Twilio, 2026). The same code covers a handset powered off or short of signal (same source). So a bounce is not proof the number has gone. Separately, the ICO’s published list of incident types carries no category naming text messages (ICO, 2026).
Does a customer have the right to have their number deleted?
Sometimes, and it depends on the specific request rather than a blanket rule. The ICO publishes detailed erasure guidance covering several separate grounds. It treats each request as its own question to work through (ICO, 2026). A business handling a request weighs its own facts against that guidance. It does not assume the answer either way.
Does a small business have to pay the ICO anything to hold customer contact details?
Not every controller pays. The ICO publishes a self-assessment tool alongside its fee guidance (ICO, 2026). A business can use it to check whether liability applies. That check runs on turnover, staff numbers and processing activity. That check comes before assuming a bill is due. Some categories carry no charge at all.
Sources
- ICO, Getting started with data protection, retrieved 2026-08-29, https://ico.org.uk/for-organisations/advice-for-small-organisations/getting-started-with-gdpr/getting-started-with-data-protection/
- ICO, Data minimisation, retrieved 2026-08-29, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/data-minimisation/
- ICO, Storage limitation, retrieved 2026-08-29, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/
- ICO, Accuracy, retrieved 2026-08-29, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/accuracy/
- ICO, Identify direct marketing, retrieved 2026-08-29, https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/identify-direct-marketing/
- ICO, A guide to subject access, retrieved 2026-08-29, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/
- ICO, Right of access: What is the right of access?, retrieved 2026-09-04, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/what-is-the-right-of-access/
- ICO, Right to erasure, retrieved 2026-08-29, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/
- ICO, Personal data breaches: a guide, retrieved 2026-08-29, https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
- ICO, Guide to the data protection fee, retrieved 2026-08-29, https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/
- ICO, Data security incident trends, retrieved 2026-08-29, https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/
- ICO, Data security incident trends, glossary of terms: incident types, retrieved 2026-08-29, https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/glossary-of-terms/incident-types/
- Which?, Recycled phone numbers leaving mobile phone users exposed to hacking, nuisance calls or being cut off, Which? warns, retrieved 2026-08-29, https://www.which.co.uk/policy-and-insight/article/recycled-phone-numbers-leaving-mobile-phone-users-exposed-to-hacking-nuisance-calls-or-being-cut-off-which-warns-aafml1k0f5nN
- Which?, Phone number recycling investigation, retrieved 2026-08-29, https://www.which.co.uk/news/article/phone-number-recycling-investigation-a9rlC8c0RCVu