This guidance has been produced by the Comms Council UK, the Home Office, Ofcom and with input from the Information Commissioner’s Office (ICO). It is aimed at telecommunications providers of all sizes operating in the United Kingdom and is designed to give organisations confidence in sharing data for fraud prevention purposes, explaining what is lawful, what frameworks exist to support it, and how to get started. It reflects the shared commitments set out in the government’s Fraud Strategy 2026–2029 and the Telecommunications Fraud Charter (November 2025), both of which recognise multi-sector data sharing as central to detecting and disrupting fraud at scale.
This guidance is the result of a series of workshops led by CCUK and hosted by the Home Office, bringing together a wide range of organisations from government, regulators, law enforcement, industry and trade bodies, to improve cross‑sector data‑sharing on telecoms fraud.
Fraud causes serious harm to individuals, businesses and the wider economy. Telecoms providers are at the centre of the challenge, and tackling it effectively requires collaboration – including sharing relevant data with industry partners, law enforcement and fraud prevention organisations. The legal framework, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA) and the Data Use and Access Act 2025 (DUAA) provide a strong foundation for organisations to refer to, so that data can be shared confidently. However, communications providers have not always been clear nor confident as to how they can lawfully share data of suspected fraudsters on their networks.
As part of the work undertaken for this guidance, we collected real-world examples of data sharing and their impact – outlined in Appendices 4 and 5 – demonstrating what effective cross-sector collaboration makes possible in practice.
This guidance is built on three principles:
1. Sharing data appropriately helps disrupt fraud faster, reduce losses, protects customers, and helps to prevent bad actors move undetected between providers;
2. Good practice and network management builds trust with industry partners, carriers and law enforcement – and the market credibility that comes with that; and,
3. Improved regulatory confidence, and a demonstrable record of responsible governance that reduces the likelihood of increased regulatory scrutiny.
● Fraud prevention is usually a lawful reason to share information.
● Share the minimum necessary.
● Keep a brief record of your decision.
● Use established schemes wherever possible.
● If unsure, seek advice – but don’t assume data protection law prevents sharing.