In a properly drafted outsourced lead generation contract you are the data controller and the agency is the processor, so the personal data is yours to direct. Getting it back in a usable form is a separate question, answered by the exit clause rather than by the law. Article 28(3)(g) of the UK GDPR is the only part that happens on its own.
The question gets a vague answer in most procurement calls because "the data" is four different things sharing one word. There is the list: names, companies, work email addresses. Then the engagement record, meaning who opened, who replied, what they wrote back, and where every contact sits in a sequence. Underneath both sits the system they live in. Underneath that sits the sending infrastructure, which is the domains, the mailboxes and the LinkedIn accounts the outreach actually goes out from.
Four assets, four different clauses, and I have read plenty of contracts that handled the first one properly and left the other three unmentioned. The list is the part everybody argues about and the cheapest of the four to replace. Eighteen months of reply data is the part nobody raises and the part you'll miss.
Who owns the leads when you outsource lead generation?
Nobody, in the sense the word usually carries. The UK GDPR text on legislation.gov.uk does not use the word owner anywhere in its definitions. It allocates two roles instead. Article 4(7) defines a controller as the body which "determines the purposes and means of the processing of personal data". Article 4(8) defines a processor as one "which processes personal data on behalf of the controller". Duties hang off those roles, and there is no property right in the middle for either side to claim.
So drop the ownership word. It doesn't get you anywhere. Ask two better questions instead. Who decides what happens to the data while the campaign runs, and what are you contractually entitled to receive when it stops? The first is settled by the facts of how the work is done. The second is settled by whatever your commercial lawyer put in clause 11, which in the contracts I've read is usually one sentence long.
Treat the four assets separately when you read a draft, because agencies do:
- The target list. Cheap to rebuild. Any decent data vendor will sell you the same firmographic slice again for a few hundred pounds.
- The engagement record. Expensive to rebuild, because it can't be rebuilt. Opens, clicks, replies, objection text, no-show reasons and sequence position are the record of your market answering you, and a new agency starting cold will spend six months relearning it.
- The system of record. Determines whether the first two are a live database or a CSV attachment.
- The sending infrastructure. Domains, warmed mailboxes and LinkedIn accounts. Warming a fresh domain takes weeks, so losing this on day one of a transition costs you the pipeline gap, not the setup fee.
Is the agency the data controller or the processor?
Most agency contracts say processor. On the facts of how a lot of outbound is actually run, that's optimistic.
The ICO publishes a decision list for working this out in its guidance on how to determine whether you are a controller or processor. It asks which organisation decides to collect the personal data in the first place, the lawful basis for doing so, what types of personal data to collect, which individuals to collect data about, whether to disclose the data and to whom, what to tell individuals about the processing, and how long to retain it. Make any of those calls and the ICO says you are likely a controller.
Now look at what an outsourced SDR team does on a normal Tuesday. It picks the sectors. It picks the job titles. It builds the list from its own data subscriptions. It writes what goes in the first touch, which is the privacy-relevant part of what individuals get told. Those are controller decisions on the ICO's own list, and calling the arrangement a processing agreement in clause 2 doesn't change them.
The ICO's own worked example on that page is close enough to be uncomfortable. A bank briefs a market research company with a budget and an objective, and leaves it to decide sample sizes, interview method and which customers to approach. The ICO's conclusion is that the research company is a joint controller with the bank, even though the bank commissioned the work and set the purpose. Swap the research company for an SDR agency and the brief for an ICP document and you have the standard lead generation engagement.
The law is blunt about what happens when the label and the facts disagree. Article 28(10) says that if a processor infringes the Regulation "by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing". The ICO puts the same point in plainer words in its guidance on what a processor contract must contain: a processor that acts outside the controller's instructions in a way that decides purpose and means "will be considered to be a controller in respect of that processing and will have the same liability as a controller".
An agency that builds lists is doing nothing wrong by building them. The problem is narrower than that: the paperwork describes an arrangement that differs from the one actually running, and the paperwork is what gets read out if anyone ever complains.
The second half of this bites harder, and it bites you rather than the agency. The ICO's direct marketing guidance, updated on 28 April 2026, covers collecting information and generating leads, and on buying or renting data it is unambiguous: "it is not enough to simply accept a third party's assurances that the information they are supplying to you is compliant." You are told to run proportionate due diligence first, and the ICO lists what to ask for. Who compiled the information. Where it came from. What privacy information people were given. When it was compiled. What records of consent exist. Whether it has been checked against suppression lists, and how recently. How the seller handles objections.
Ask an agency those seven questions in writing during procurement. The answers, or the absence of them, will tell you more about the quality of the operation than the case studies will.
What should the data clauses in a lead generation contract say?
This is the table I use when reading a draft. The redline column is written so you can paste it straight to a lawyer or back to the agency.
| Clause | What a good version says | What a bad version says | What to ask for in redline |
|---|---|---|---|
| Controller and processor roles | Names the client as controller and the agency as processor for campaign execution, and states separately where the agency acts as a joint controller for list building, with the shared duties written out. | "The Supplier acts as a data processor." One line, no carve-out for the list building the agency actually does. | Set out the roles activity by activity. If the agency sources the list, say who is controller for that step and who provides the privacy information. |
| The exported list at exit | All contact records processed for the client are returned in a structured machine readable format within a named number of working days of termination, at no extra charge. | "Data will be made available on request." No format, no deadline, no price. | Name the format (CSV or a documented API export), the window in working days, and that the fee is nil. Add a field map so the export is readable without the agency's tool. |
| Sequence and reply data | Defines campaign data to include send, open, click, reply and bounce events, full reply bodies, sequence position, disposition codes and note fields, and includes all of it in the exit export. | Silent. "Contact data" is returned and the engagement history stays in the agency's tool. | Define "Campaign Data" explicitly in the definitions clause and reference that definition in the exit clause. This is the line that decides what a transition costs you. |
| Call recordings and transcripts | Recordings and transcripts of calls made on the client's behalf are client data, returned or deleted at the client's choice, with the retention period stated. | "Recordings are retained by the Supplier for training and quality purposes." Indefinitely, and not yours. | Recordings of identifiable people are personal data under Article 4(1), so treat them like everything else. Ask for the retention period in months and the deletion certificate. |
| The CRM instance itself | The instance is licensed in the client's name, the client is named as billing owner or is granted a super admin seat, and the instance survives termination. | Work is done in the agency's own tenant. On termination you lose the interface and get a file. | Ask whose name is on the subscription and who holds the super admin seat. If the answer is the agency, ask what happens to the tenant on day one after notice. |
| Notice period and data return window | The return window runs from the last day of service, not from the notice date, and access to the system continues until the export is verified as complete. | Access is cut on the day notice is served, and the export lands whenever it lands. | Tie access to verified receipt of the export. Add a short remedy if the export is incomplete, so the last invoice is the thing that clears when the data does. |
| Sub-processors | A named list of sub-processors with a change notification period and a right to object, matching Article 28(2), plus flow-down of the same obligations under Article 28(4). | "The Supplier may appoint sub-processors." General consent, no list, no notice. | Ask for the current list by name and country, notice of changes with time to object, and confirmation that the agency stays liable for its sub-processors' compliance. |
The sub-processor row is the one nobody can negotiate away, because Article 28(2) requires prior specific or general written authorisation before a processor engages another processor, and requires the processor to tell you about intended changes and give you the chance to object. Article 28(9) settles the form: the contract has to be in writing, electronic form included. Everything else in that table is commercial, and commercial is where these deals go wrong.
What happens to your data when the contract ends?
Article 28(3)(g) of the UK GDPR requires the contract to say that, at the controller's choice, the processor deletes or returns all the personal data it has been processing, and deletes existing copies unless domestic law requires storage. The ICO's contract guidance sets out that same list of Article 28(3) minimum terms and calls end-of-contract provisions one of the eight that must be present.
That sounds like the problem is solved. It isn't, for four reasons.
First, the choice is yours to make, which means somebody has to make it, in writing, before the relationship gets cold. Deletion is the default nobody chose and everybody regrets.
Second, Article 28(3)(g) says nothing about format or timescale. A processor that emails you a 40,000 row export with column headers like cf_17 has complied with the Regulation and left you with a fortnight of reconciliation work. Name the format in the contract.
Third, it only covers personal data. Your sequence copy, your objection library, your dashboards, your call scoring rubric and your ICP research are not personal data, so nothing in the UK GDPR obliges anyone to hand them over. Those live or die on an intellectual property clause, and the default in most agency templates is that they belong to the agency.
Fourth, backups. The ICO is realistic here and says that where data in backups or archives cannot be deleted immediately, it may be acceptable for it to be "put immediately beyond use" and deleted on the processor's next destruction cycle, provided the retention period is appropriate and safeguards are in place. Ask what that cycle is in weeks. A sensible supplier answers straight away.
The LinkedIn hole nobody redlines
If any part of the campaign runs on LinkedIn, part of your engagement record is sitting somewhere that no exit clause can reach.
The LinkedIn User Agreement, effective 3 November 2025, says at section 2.2 that you will not share or transfer your account or any part of it, and that you will keep your password a secret. Section 8.2 lists among the things a member agrees not to do: "use or attempt to use another's account (such as sharing log-in credentials or copying cookies)".
Read that against how outsourced social selling is often run. If the agency works from its own reps' accounts, the connections and the message threads belong to accounts you have no claim on, and there's no export clause in the world that transfers them to you. If the agency works from your team's accounts by holding their credentials, that arrangement sits against LinkedIn's own terms, and a restricted account in the middle of a campaign is a bad week for everyone.
Decide which of those you are doing before the contract is signed, and write down what happens to the connections at exit. There's no tidy answer to this one, and any agency that offers you a tidy answer hasn't read the terms.
Do you need your own CRM to run an outsourced campaign?
No, but you need to know which of four arrangements you're buying, because they end very differently.
- The agency's tenant. Everything runs in a tool the agency owns and pays for. Cheapest to start, worst to leave. You get a file.
- A seat in the agency's tenant. You can log in and look. You still get a file, and the login stops on the last day.
- Your existing CRM, agency given user access. Best continuity, and the reason to prefer it is that the record never moves. The friction is that agency activity clutters a system your sales team already relies on, so agree the object model up front.
- A dedicated instance in your name. The agency builds and runs it, the licence and the billing sit with you, and on the last day you change the passwords rather than requesting an export.
The fourth is what the ORRJO Platform is: a CRM that belongs to the campaign and stays with the client. That's a commercial preference. Nothing in the law requires it, option three is just as defensible, and some in-house revenue operations teams will always prefer to keep everything in the system they already run.
Whichever you pick, four questions settle it: whose name is on the subscription, who holds the billing relationship, who holds the super admin seat, and what's still working on the morning after access is revoked.
Five questions to ask before you sign
Copy these into an email to the agency. The quality of the reply is the diligence.
- Are you acting as our processor, our joint controller, or both, and for which activities specifically? If you build the target list, which of us is the controller for that step and which of us provides the privacy information to the people on it?
- At the end of the contract, what exactly do we receive, in what file format, within how many working days of the last day of service, and at what cost? Please include reply bodies, sequence position and disposition codes in your answer.
- Whose name is on the CRM and sequencing subscriptions, and who holds the super admin seat? What still works on the morning after we give notice?
- For any data you supply to us, can you answer the ICO's due diligence list: who compiled it, where it came from, what people were told, when it was compiled, what consent records exist, when it was last screened against suppression lists, and how you pass on objections?
- Who are your sub-processors today, in which countries, and what notice do we get before that list changes?
An agency that answers all five in one reply has done this before. An agency that needs a call to explain question two is telling you something about question two.
How ORRJO handles it
The client is the controller. The campaign runs in a CRM instance that belongs to the client, so at the end of an engagement there is nothing to export and no window to negotiate, because the client already holds the admin seat. Contact records, reply bodies, sequence state and meeting notes stay in that instance. Sub-processors are named on request rather than after a request.
None of that is charity. It shortens procurement, and it means renewal gets decided on whether the meetings were any good rather than on who's holding the database. ORRJO's Lead Generation starts at £4,495 a month, and the data terms are identical at every level above that.
What nobody publishes about this
I looked for a figure on how many UK B2B lead generation contracts carry an end-of-contract return clause that would satisfy Article 28(3)(g), and how often data is actually returned when a client leaves. No primary source publishes it. The ICO publishes the rule and publishes its enforcement actions. It doesn't publish compliance rates by sector, and no trade body I could find surveys agency contract terms.
So there's no benchmark to hide behind here, and any article that gives you a percentage on this has made it up. The only reliable evidence available to you is the draft in front of you, so read the clause and worry about the case study later. If you are earlier in the process than that, the agency selection guide covers the commercial diligence, how to choose a lead generation agency covers the shortlist, and the guide to outsourcing lead generation covers the operating model the contract has to describe.
None of this costs anything to fix while both sides still want the deal. Once the relationship has soured, the only thing you're holding is an invoice you haven't paid yet, and that is a thin trade for eighteen months of reply data.
Want the data terms checked before you sign, or your current contract read? Book a call and we'll go through the clauses with you, whether or not you end up working with us.