Compliance
What consent do I need to capture for financial advice leads under GDPR?
Last reviewed 22 April 2026 · Reviewed by Jake McQuillan
Quick answer
What consent do I need to capture for financial advice leads under GDPR?
You need specific, granular, freely-given consent for: (1) being contacted by phone/SMS, (2) email marketing, (3) processing sensitive data (health, financial). Store consent timestamp, IP, user-agent and exact text shown. Unlimited retention requires separate basis.
Want us to do this for your firm?
Get a compliant lead-gen plan tailored to your niche and compliance setup.
Required consents
- Marketing calls/SMS: explicit, separate checkbox. Check TPS/CTPS.
- Marketing email: explicit, separate checkbox (soft opt-in narrow in regulated advice).
- Data processing: lawful basis (contract, legitimate interest, consent).
- Special category data (health for protection, ethnicity): explicit consent.
What to store
- Consent text shown (verbatim).
- Timestamp (ISO-8601).
- IP address.
- User-agent.
- Landing-page URL.
- Version of terms/privacy policy.
Retention
- Prospect (no client relationship): 12 to 24 months typical.
- Client: for life of relationship + 6 to 7 years after (FCA retention rules).
- Declined-advice: 6 years.
Watch out
- Pre-ticked consent boxes are not valid.
- Bundled consent is not valid.
- Use of third-party lead lists is almost always non-compliant.
Was this useful?
Related questions
Can I run paid ads for pensions in the UK?
Yes, but with strict conditions. All pension ads are financial promotions and must be approved by an authorised approver. Defined benefit transfer marketing is…
How does Consumer Duty fair value apply to marketing?
Fair value means marketing must not disguise total cost, must be aligned to target market, and must deliver real outcomes meaning "free" offers and opaque fees…
What FCA rules apply to financial adviser advertising?
Financial promotions must be fair, clear and not misleading (FCA COBS 4 and the Financial Promotions Regime). All regulated activity adverts must be approved b…
How does Consumer Duty affect my marketing?
Consumer Duty requires every stage of the customer journey — including marketing — to deliver good outcomes. Your ads and landing pages must be clearly underst…
How do I verify my Google or Meta ad account for UK financial services?
Google requires financial services verification via the FCA register (FRN). Meta requires authorisation via their Financial Products and Services policy. Both…