Telecoms providers get green light to share data in fraud fight

Telecos have been given new guidance to make it easier share customer and network data to identify telephone-enabled fraud.

Fraud now accounts for 45 per cent of reported crime in the UK, according to government figures, with telecoms networks routinely exploited to distribute scam calls and text messages.

Comms Council UK (CCUK) has published the guidance following work with the Home Office and Ofcom and input from the Information Commissioner’s Office (ICO).

It addresses uncertainty among communications providers over when information about suspected fraudsters can legally be shared with other operators, law enforcement agencies, banks and fraud prevention organisations.

CCUK says that uncertainty has made some providers reluctant to exchange intelligence even where doing so could help prevent scams.

The guidance sets out what information can be shared, the circumstances in which sharing is lawful and the legal frameworks providers can rely on. These include UK GDPR, the Data Protection Act 2018 and the Data Use and Access Act 2025.

It also includes a checklist and processes to help operators and their legal, compliance and data protection teams assess when information can be exchanged.

Telecoms networks routinely exploited to distribute scam calls

Networks exploited by fraudsters

Fraud operations can involve multiple networks, communications providers and financial institutions, making it difficult for any individual operator to see the complete chain.

CCUK says more effective sharing of network intelligence could allow suspicious activity to be stopped earlier.

The guidance includes examples where information exchanged between organisations has already resulted in enforcement action.

In one case, analysis of data from several telecoms companies identified an “SMS blaster” sending fraudulent messages on a large scale. The investigation resulted in an arrest, conviction and sentence.

In another case, telecoms data was passed to financial institutions to identify businesses potentially being targeted by fraudsters. Banks were then able to investigate and introduce additional fraud monitoring and controls.

ICO: data protection is not a barrier

ICO head of investigations Andy Curry said operators should not regard data protection legislation as preventing legitimate anti-fraud cooperation.

Data protection law is not a barrier to sharing information to prevent fraud. In fact, it provides a clear and lawful framework for doing so responsibly,” he said.

Telecoms providers of all sizes should have the confidence to share data lawfully with industry partners, law enforcement and fraud prevention organisations to protect their customers.”

Curry added that organisations acting in good faith and taking “reasonable and proportionate steps” to share information responsibly could expect the ICO’s support.

CCUK chair Tracey Wright said uncertainty over data protection had previously inhibited cooperation between providers.

For too long, telecoms providers haven’t had the confidence to appropriately share information to disrupt fraud,” she said.

This guidance, developed with Ofcom, the Home Office and the ICO, changes that.”

Ofcom strategy and delivery director Amy Jordan said cooperation between communications providers, regulators, law enforcement and anti-fraud organisations was increasingly important.

Effective data sharing between communications providers and other organisations, including anti-fraud bodies, regulators and law enforcement agencies, is an important step in helping protect customers against criminals,” she said.

Fraud Minister Lord Hanson said the guidance would help deliver commitments contained in the Government’s Telecommunications Fraud Charter.

Only by working in close collaboration between industry, government and law enforcement will we make it harder for fraudsters to operate and better protect the public,” he said.

The guidance forms part of commitments under the Government’s Fraud Strategy 2026–2029 and Telecommunications Fraud Charter and is available to communications providers across the UK.

Phone numbers, IP addresses and call recordings

Data already shared through existing anti-fraud schemes can include telephone numbers linked to fraudulent activity, call records used to identify potential victims, domains used for fraud and phishing, keywords and phrases used in malicious SMS and Calling Line Identification (CLI) data associated with mass-marketing fraud.

The guidance also identifies personal data that may be relevant to fraud investigations, including names, dates of birth, addresses, phone numbers, email and IP addresses, online usernames, financial account and transaction information, facial images and call recordings or transcripts.

CCUK says personal data can be shared for fraud prevention where doing so is necessary and proportionate, with providers expected to share only the minimum amount of information required.

Because individual fraud cases vary, CCUK says there is no definitive list of information that can always be exchanged. Instead, the guidance points providers towards the relevant legislation and resources for determining what can lawfully be shared in a particular situation.

It also includes checklists and process flows intended to help operators and their legal, compliance and data protection teams assess common data-sharing scenarios.