Method

Is your telemarketing GDPR-safe? A checklist for consent and do-not-call rules

What to check before the first call: consent, do-not-call registers, opt-out and records. A practical GDPR checklist for telemarketing in the Nordics.

5 October 2026Wolf Intelligence
Läs inlägget på svenska →

A call that breaks the rules costs more than a call that never happens. It can mean complaints, a damaged brand and a team that loses momentum while someone sorts out the mess. The good news: staying on the right side of the line is mostly process, not law school.

This is a practical checklist for sales and marketing managers. It is not legal advice, and the rules differ between Sweden, Norway and Finland, so confirm the details for your case.

Know why you are allowed to call

Every call needs a legal basis for using the person’s data. In practice there are two you will meet most often:

  • Consent. The person actively said yes to being contacted, about something specific. Pre-ticked boxes and vague small print do not make strong consent.
  • Legitimate interest. Sometimes usable, especially in business-to-business calls, but it needs a real balancing of your interest against the person’s rights. It is also the basis that is easiest to get wrong.

Consent is the cleaner foundation, and it is the reason we build Wolf Leads on opt-in. A person who asked to be contacted is a better call and a safer call.

What to check before every campaign

  1. Where did the data come from? You should be able to say exactly how and when each person entered the list. “We bought it” is not an answer.
  2. What did the person agree to? Consent for one purpose does not stretch to every offer you can think of. Match the call to what they said yes to.
  3. Have you checked the do-not-call registers? In Sweden, consumers can block telemarketing through the NIX register, and you are expected to screen against it. Norway and Finland have their own mechanisms. Screen close to the time of calling, since people register all the time.
  4. Does the caller say who they are? Name, company and the reason for the call, in the first seconds.
  5. Is opting out one sentence? If someone says “don’t call me again”, that must be logged and respected, every time. The right to object to direct marketing is a strong one.
  6. Can you prove it later? Keep the source, the date, the wording of the consent and the opt-out history. If a regulator or a customer asks, you want an answer in minutes, not weeks.

Where teams usually slip

The risk rarely sits in the first call. It sits in the process around it.

  • Lists that are reused months later without re-screening.
  • Opt-outs written on a note or in one person’s head instead of in the system.
  • Several tools holding different versions of the same contact.
  • Leads from a third party with no record of what was actually agreed.

Most of these are system problems. A CRM that stores the consent source, flags blocked numbers and syncs opt-outs to your dialer removes whole categories of mistakes. That is one reason we build the system around the leads, not just the leads.

Compliance is also a sales advantage

When the person on the line expects the call, the call is shorter, friendlier and more likely to end in a meeting. Doing it by the book is not a brake on results. It is part of how a good hunt works.


Want leads with documented opt-in and a calling process you can stand behind? Tell us what you need.

Want help with leads, systems or a new Nordic market? Tell us what you need and we'll get back to you.

Plan the next hunt →