Handling Client Data: The Rules That Apply to Every Campaign
The data on your screen doesn’t belong to Invarium. It belongs to the person it describes, and our client is answerable for it to their own regulator.
That’s the whole reason these rules exist, and it’s why they don’t bend for a difficult caller, a busy queue, or a colleague who needs a favour. This article covers the rules that apply on every campaign, regardless of client.
Where the data actually comes from
You’re working with information a client has entrusted to us under contract. Every one of those contracts contains data protection obligations, and several carry penalties if we breach them.
Practically: when you open a record, you’re touching data that a client’s regulator can ask questions about. When something goes wrong, they ask the client, and the client asks us.
The seven rules
1. Access only what the call requires. Having access to a system is not permission to browse it. Looking up a relative, a neighbour, a colleague, or a public figure out of curiosity is a breach even if you tell nobody and change nothing. Systems record who opened which record and when, and access reviews check exactly this.
2. Capture only what the script asks for. Every extra detail you write into a notes field is data we then have to secure, justify holding, and eventually delete. If the script doesn’t ask, don’t record it. “It seemed relevant” is not a lawful basis.
3. Verify identity every single time. Follow the campaign’s verification steps in full before disclosing anything. The pressure cases are the dangerous ones — the caller who is angry, in a rush, or says they’ve already verified with someone else. That pressure is often deliberate. Failing verification and being wrong costs you a minute; passing someone who shouldn’t have passed costs considerably more.
4. Keep the data in the system. No screenshots. No photos of your monitor. No copying details into WhatsApp, personal email, Notes, a spreadsheet on the desktop, or a notebook. No USB drives. The moment information leaves the platform, we cannot protect it, cannot prove what happened to it, and cannot delete it on request.
5. Don’t discuss customers outside the floor. Not by name, not by “you won’t believe this call.” A story told on a kombi is a disclosure, and call content is confidential without exception.
6. Lock your screen whenever you step away. Windows key + L. Two seconds. An unlocked machine on an open floor is an open filing cabinet, and anything done under your login is attributed to you.
7. Never share your login. Not with a colleague covering your break, not with a team leader in a hurry. Shared credentials destroy the audit trail, and if something goes wrong under your account you have no way to show it wasn’t you.
Recordings are data too
Call recordings contain everything the customer said, including anything they volunteered that wasn’t asked for. They’re subject to the same rules as any other record.
You can’t request, download, forward or replay a recording outside the approved process. If a recording is needed for QA, a dispute, or a complaint, it goes through your team leader.
Some campaigns require you to state that the call is recorded. Where the script says it, say it — that wording usually exists because a regulator requires it.
What changes between campaigns
The seven rules above are the floor. Individual campaigns add requirements on top, depending on where the client and their customers sit:
- South African clients — POPIA
- European clients or customers — GDPR
- US healthcare work — HIPAA
- Bermuda clients — PIPA
You don’t need to know the detail of each. Your campaign brief tells you what applies to your work. What matters is understanding why a rule that seems stricter than the campaign next door exists — it’s usually a regulator’s requirement rather than a local preference, and it isn’t negotiable.
If you move between campaigns, don’t carry habits across. What’s acceptable on one may be a breach on another.
Retention: we don’t keep things forever
Data is held for a defined period and then deleted. That’s a legal requirement, not housekeeping.
Which is why local copies are such a problem. A file saved to your desktop, or details in a personal notebook, sits outside every retention schedule we have. When the client instructs deletion, we can honestly say the record is gone from the system — and be wrong, because a copy exists somewhere nobody knows about.
Keep it in the system, and retention takes care of itself.
When a customer asks about their data
Customers have rights over their information, including the right to ask what’s held and to have it corrected. Requests like this are legitimate, and they carry deadlines.
Don’t try to handle it yourself and don’t guess. Note the request, tell the customer it’s been passed on, and escalate to your team leader immediately. The clock starts when the request is made, not when it reaches the right desk.
If something goes wrong
Report it immediately — phone IT and log a ticket. Sending information to the wrong recipient, disclosing to someone who failed verification, or discovering records visible to people who shouldn’t see them all count, and all start a 24-hour statutory clock.
You will not be disciplined for reporting a mistake quickly. Concealing one is a different matter.
Read next: The Cyber and Data Protection Act in Plain English, and Reporting a Security Incident.
Watch: Data protection under POPIA — a short overview of the South African rules, relevant if you’re on an SA campaign and a useful illustration of how client-side regulation shapes what we do.

