Skip to content

The Why, What and How of GDPR for Telcos

· Callr

The Why, What and How of GDPR for Telcos

Data protection is often treated as a burden. Even when the benefit to people is obvious, asking businesses to comply with one more set of rules can feel like friction. But the internet only stays a safe place to communicate when there are clear, enforceable rules behind it. The point of the General Data Protection Regulation (GDPR) is not only to protect individuals and curb abuse — it sets a single, workable framework for how personal data is collected and handled across Europe. When that framework works, everyone gains: people get real control over their data, and businesses operate in a more predictable environment with more trust from their customers.

The challenge of data privacy online

For years, the absence of strong, consistent data-protection rules had real costs — for individuals and for society. Telecom operators sit at the center of this, because they carry millions of sensitive conversations, messages, and call records. Without clear protections, people effectively lost control of their data: they couldn’t tell who held it, what was stored, which data points were accessed, or why. When something went wrong, recourse was difficult or impossible.

That gap let a wide range of intrusive but effective practices flourish — unclear wording, needlessly long terms and conditions, and controversial clauses buried in the fine print. GDPR makes many of these practices unlawful.

Why individuals need a firm framework

The societal stakes are higher than they first appear. Weak data rules erode privacy over time and concentrate influence in the hands of whoever holds the largest datasets. A reliable data-protection framework is, in plain terms, part of the infrastructure of a healthy democracy. The right to privacy is foundational: without it, freedom of expression and the ability to make free, informed decisions are all weakened.

Why businesses benefit too

Insufficient data rules hurt businesses as much as consumers. The biggest problem with the pre-GDPR landscape was fragmentation. Even within the EU, telecom and internet obligations differed from country to country, and that patchwork made full compliance genuinely hard. The more authorities a company had to deal with, the harder it became to be proactive about data practices.

The old penalties made things worse. When fines are trivial next to the revenue at stake, they invite the “how much would it cost us to just pay the fine?” calculation — a sign that the legal system has failed to do its job.

Cutting through the local regulatory jungle

The flaws in the old framework are clear, but enforcement is the real test. A law has to be simple and clear enough to apply. When it isn’t, the outcome looks much the same regardless of the policy on paper:

  • Insufficient or unenforced laws — countries where protections are weak, absent, or simply not applied.
  • Permissive laws with little effect — rules so lax that their practical impact is close to zero.
  • Strong laws, weak enforcement — countries with serious regulations on the books, but limited follow-through, so businesses incorporated elsewhere could do largely as they pleased.

European telecom rules were a good example of how complicated this got. Requirements around shortcodes and phone numbers, SMS signaling and message priority (marketing versus notification), voicemail recordings, and contact-list management could differ significantly from one country to the next.

The territoriality problem

The biggest change GDPR introduced is extra-territorial applicability. Before it, the territorial scope of data law was ambiguous, and the core uncertainty was simple: which law applies?

  • The law of the business’s country?
  • The law of the customer’s country, if different?
  • Or the law of wherever the data was “processed”?

For telcos this was a major risk, because many countries can be involved in a single data flow. Consider a call center:

  • located in Tunisia,
  • calling customers in France, Italy, and Spain,
  • on behalf of a company based in Portugal,
  • using a German software vendor to process the call data.

Which law should that call center follow? GDPR makes the answer unambiguous: only the customer’s location matters. Whether the company is European or not, and whether the processing happens inside or outside the EU, any organization processing the personal data of people in the EU must comply with GDPR.

The three pillars of GDPR

GDPR exists to give Europe a modern data-protection framework, fit for current and future needs. The previous EU directive on data protection dated back to 1995, so an update was overdue.

The underlying principles carry over from that earlier directive, but the policies around them changed substantially. The most important changes fall into three groups: privacy by design, data ownership and control, and consent and penalties.

I. Privacy by design

The idea of privacy by design — building data protection into a product or service from the start, rather than bolting it on afterward — has been around for decades. In practice it means a system should collect only the data it actually needs (data minimization) and limit access to that data to the smallest number of people and services required to process it.

Its inclusion in GDPR matters as much for what it signals as for what it mandates. In a world where every system followed this principle, much data-protection regulation would be unnecessary. A law won’t change how companies think overnight, but it establishes the expectation.

II. Data ownership and control

GDPR gives people a new set of rights over how online services collect and process their data. These rights require real engineering work: businesses that handle customer data must offer a way for people to access, correct, and delete it. Large companies often had such interfaces already; smaller ones may need help from a provider to comply.

Data portability

Data portability means people can move their data easily from one service to another. Under GDPR, a person must be able to obtain the data they provided in a “commonly used and machine-readable format.”

This makes switching providers easier and lets people keep their own backups. It is a demanding requirement for telecom operators, who must adopt common standards so customers can move data between providers. In France, number portability has been the norm for telecom operators since 2007. Telcos, which collect, store, and analyze large volumes of customer data, have had to rethink significant parts of their processes — and in some cases find new revenue streams in the process.

Right of access

The right of access is a major step toward transparency. People can ask a data controller whether their personal data is being collected, where, and for what purpose.

Right to be forgotten

Already implemented in some countries before GDPR, this right lets a person:

  • erase their personal data,
  • stop further dissemination of that data,
  • and, in some cases, require third parties to halt processing of it.

III. Greater responsibilities and bigger fines

Consent rules were rewritten to reflect reality. Consent must now be given in an intelligible, easily accessible form, using clear and plain language — and it must be as easy to withdraw as it is to give. Together, these rules give people more control and make deliberately opaque terms and conditions unlawful.

Penalties tied to revenue

Penalties for non-compliance are much larger in both size and scope. For the most serious violations — such as ignoring privacy-by-design principles or failing to obtain consent — organizations can be fined up to €20 million or 4% of annual global turnover, whichever is higher, under a tiered system. New violations are also recognized, including failing to notify the authorities and affected individuals of a breach, or failing to carry out a proper impact assessment.

Data protection officers

Organizations that process data at large scale, or that handle sensitive data (such as medical or judicial records), must appoint a Data Protection Officer (DPO). The DPO is the main point of contact with data-protection authorities. They must be free of any duties that could create a conflict of interest, have the resources and skills to do the job, and report directly to the highest level of management. Breaches must now be logged internally and reported to the relevant authority.

What GDPR means for businesses

GDPR affects every organization that collects and processes personal data. Online services and social platforms are heavily impacted, but so is any company holding large customer files — telecom operators and marketing firms included. Below we look at the impact on telecom businesses, then point to broader ways to approach compliance.

GDPR for telcos

Telecom companies are meaningfully affected. Any business that moves information for warehousing, reporting, or marketing must be ready to delete or anonymize those datasets. Controllers processing data at large scale must appoint a DPO. Data portability obliges operators to provide customer data in a standard format.

It can sound like a lot — but there’s an upside. The framework is unified across Europe: complying with one set of rules is far simpler than tracking dozens of national regimes.

Companies that already handle European customer data should work through a few essentials:

  • Ask new customers for explicit consent to collect and use their data.
  • Review existing customers’ data, and remove anything that’s no longer needed.
  • Train staff so compliance is continuous, not a one-off project.

Compliance as an advantage

Yes, getting compliant takes work in the short term. But that work is also an opportunity to adopt better data practices and run a cleaner, more efficient operation. Businesses that take privacy seriously and build trustworthy mechanisms earn the confidence and loyalty of their customers and prospects — which ultimately supports growth. Most would have needed to tidy up their data practices regardless. And as connected devices multiply and data volumes keep climbing, data minimization only becomes more important for keeping networks efficient.

A note on the limits of GDPR

No law is flawless, and GDPR is no exception. The rights it grants people are welcome, but the framework was designed around two assumptions:

  1. that personal data of EU citizens sits in a small number of centralized locations, and
  2. that identifiable organizations are responsible for implementing the standards.

Decentralized, immutable systems sit in tension with both assumptions: their data is distributed across many nodes worldwide, and records generally cannot be altered once written. How regulation adapts to those architectures remains an open question.

How Callr fits in

Callr runs its own EU telecom infrastructure, with EU data residency by default — so the voice, SMS, and call-data flows you build through our REST API and webhooks stay on European footing from the start. That makes the data-minimization and locality questions above easier to answer. If you want the specifics on how Callr handles personal data, see our GDPR page, or get in touch to talk through your use case.

Book a demoGet started for free