Direct Debit Compliance in the UK: A Practical Guide

22.05.2026

9 mins

Table of contents

Last updated: 19th May

 

If your business collects payments by Direct Debit, compliance is the foundation that keeps your collections running smoothly, your customers protected and your business on the right side of the rules.

The good news? Once you understand what’s required – and why – it becomes far easier to stay compliant. This guide breaks down the UK’s Direct Debit collection rules in plain English, giving you clear answers from people who know what they’re talking about.

 

What you’ll learn in this guide:

  • What governs Direct Debit in the UK – the regulatory bodies and rules you need to know
  • The six core Bacs Scheme Rules – incl. mandates, advance notice and the DD Guarantee
  • How UK GDPR applies to Direct Debit collection – and what you’re expected to have in place
  • The day-to-day operational obligations that keep your collections compliant
  • Answers to the most commonly asked compliance questions

 

 

What governs Direct Debit in the UK?

Direct Debit in the UK operates within a clear regulatory framework, overseen by three key bodies:

 

  • Bacs (Bankers’ Automated Clearing Services) – part of Pay.UK – sets and maintains the official Direct Debit Scheme Rules. The current version is 5.7, released in June 2024. Every organisation collecting Direct Debits must comply with these rules.
  • The Payment Systems Regulator (PSR) oversees payment systems in the UK, promoting competition, innovation and the interests of consumers. (psr.org.uk)

 

As a business collecting Direct Debits, you’ll primarily need to comply with the Bacs Scheme Rules – alongside UK GDPR and wider consumer protection legislation.

 

 

The Bacs Direct Debit Scheme rules: what you need to know

The Bacs Scheme Rules are split into two types: mandatory rules (which you must follow) and best practice guidance (strongly recommended). They cover six core areas:

 

1. Customer authorisation — the mandate

Before any Direct Debit can be collected, your customer must give their explicit consent. They do this by completing a Direct Debit Instruction (DDI) – commonly known as a mandate. This can be a paper form, an online sign-up or a telephone authorisation processed via Bacs-approved procedures.

The mandate must clearly set out what the customer is authorising: the amount (or how it will vary), the collection date, the frequency and your details as the collecting organisation. Verbal consent alone is not valid.

Mandates must be stored securely and cancelled promptly if a customer requests it. Once cancelled, you must stop collections immediately.

Follow our beginners’ guide to Direct Debit mandates.

 

2. Advance notice

You must give customers advance notice before taking any Direct Debit – and again whenever the amount, date or frequency changes. The standard minimum is 10 working days, though you can agree to a shorter notice period with your customers (subject to your sponsor bank’s approval).

This gives customers the chance to check their account, query anything unexpected and maintain trust in the arrangement. Skipping it – or changing a Direct Debit without notice – is one of the most common compliance failures.

 

3. The Direct Debit Guarantee

Every Direct Debit in the UK is backed by the Direct Debit Guarantee – one of the most consumer-friendly protections in the payments industry. It means:

  • If a Direct Debit is taken in error, the customer is entitled to a full and immediate refund from their bank.
  • If you change the amount, date or frequency without the required notice, the customer can claim a refund.
  • Customers can cancel a Direct Debit at any time by contacting their bank.

As a collecting organisation, you must display the Guarantee on all relevant communications. If a refund claim (known as an indemnity claim) is raised against you, it will be managed through the Bacs Payment Services Website (PSW).

 

4. Service User Number (SUN)

To collect Direct Debits through the Bacs system, your organisation needs a Service User Number – a unique identifier issued by a sponsoring bank. Larger businesses typically apply for their own SUN directly; smaller businesses often use a bureau or Facilities Management (FM) provider, which allows them to collect under the provider’s SUN.

 

No SUN? We handle your collections on your behalf through our sponsor bank.

5. AUDDIS – electronic mandate management

Most UK Direct Debits today are processed through AUDDIS (Automated Direct Debit Instruction Service), which replaces paper mandates with electronic instructions submitted directly to Bacs.

To use AUDDIS, you need robust data processing systems, secure storage and approval from your bank or provider before going live.

 

6. Record keeping and audit trails

You’re required to maintain full audit trails of mandates, advance notices, amendments, cancellations and any customer communications. These records are essential for resolving disputes, responding to indemnity claims and demonstrating compliance if you’re audited.

 

 

Direct Debit and GDPR: your data obligations

The UK’s Direct Debit regulations mean handling personal and financial data – so UK GDPR applies. Here’s what that means in practice:

 

Lawful basis for processing

You need a lawful basis for processing customer data. For Direct Debit, this is typically contractual necessity – the data is required to fulfil the payment agreement. Make sure your privacy policy reflects this clearly.

 

Data minimisation

Only collect what you genuinely need. Bank account details, sort codes, names and contact information are standard. Avoid collecting additional data unless it’s directly relevant to the payment arrangement.

 

Secure storage

Customer banking data must be stored securely – encrypted, access-controlled and protected against breach. If you’re using a third-party payment provider, make sure they meet the same standards.

At London & Zurich, we use AWS infrastructure, multi-factor authentication (MFA) and 24/7 monitoring to keep your payment data securely protected.

 

Data sharing and processors

If you share customer data with third parties (for example, your payment bureau), you’ll need a Data Processing Agreement in place that defines responsibilities, security standards and compliance obligations.

 

Retention and deletion

Don’t hold data longer than necessary. Define and document your retention periods – and ensure data is securely deleted when it’s no longer needed.

 

Breach response

Have a documented data breach response plan. Depending on the nature of a breach, you may be required to notify the ICO within 72 hours and inform affected customers.

 

 

Operational compliance: the day-to-day obligations

Beyond the scheme rules and GDPR, there are a number of operational practices that keep your Direct Debit operation running compliantly:

  • Use Bacs-approved software or a Bacs-approved bureau for all submissions.
  • Submit payment files accurately and on time – errors or late submissions can disrupt collections and damage customer relationships.
  • Validate customer bank account details before setting up new mandates. From 2024, updated Bacs rules require verification of not just sort code and account number, but also account name – so robust validation is more important than ever.
  • Have clear internal procedures for handling failed payments, indemnity claims and customer disputes – and make sure your team knows them.
  • Notify your sponsoring bank immediately if your business structure changes or you move banks. Uninterrupted collections depend on it.

 

 

Direct Debit compliance in the UK: your questions answered

 

Can a Direct Debit be taken without the customer’s permission?

No. Direct Debit regulations in the UK state every Direct Debit requires explicit customer authorisation via a signed mandate (DDI). Collecting without a valid mandate is a serious breach of the Bacs Scheme Rules.

 

Can a company increase a Direct Debit amount without notice?

No – any change to the amount, date or frequency of a Direct Debit must be communicated to the customer in advance, with at least 10 working days’ notice under standard Bacs rules (unless a shorter period has been agreed). Changing an amount without notice is a direct violation of the Direct Debit Guarantee and entitles the customer to a full refund.

 

What happens if a company fails to collect a Direct Debit?

If a Direct Debit fails, the payment is returned to you via a return code that explains the reason. You’ll need to follow up with the customer directly. Depending on your terms, you may be able to re-present the collection, though rules apply. Consistent failures can also trigger a review by your sponsoring bank.

 

Do I need to be FCA regulated to collect Direct Debits?

As per the Direct Debit regulations for the UK, most businesses collecting Direct Debits for their own goods or services don’t need FCA authorisation – particularly if they work through an authorised bureau. However, if you’re acting as a payment service provider in any way (for example, holding client money or initiating payments on behalf of others), FCA authorisation may apply.

 

How does GDPR apply to Direct Debit collection?

UK GDPR applies to all processing of personal data – including bank account details and payment histories. You need a lawful basis for processing, a clear privacy policy, secure data storage, defined retention periods and a data breach response plan. If you use a payment bureau, a Data Processing Agreement must be in place. London & Zurich manages this as standard.

 

Let us handle it

Compliance is one of those areas where getting it right matters enormously – and where having the right partner makes all the difference.

At London & Zurich, compliance is built into everything we do. We stay ahead of every Bacs rule update, handle your regulatory obligations as standard, and give you the peace of mind that everything is running exactly as it should. Expect to have real conversations with real members of our team, who care about your business staying compliant.

Ready to make compliance one less thing to worry about?

 

 

Sources & further reading

  1. Pay.UK – Bacs Direct Debit Scheme Rules v5.7 (June 2024); AUDDIS (Automated Direct Debit Instruction Service) guidance
  2. Financial Conduct Authority (FCA) – Payment Services Regulation overview
  3. Payment Systems Regulator (PSR) – Direct Debit oversight
  4. ICO (Information Commissioner’s Office) – UK GDPR guidance for organisations; Lawful basis for processing personal data; Personal data breaches: reporting obligations
  5. A Beginner’s Guide to Direct Debit Mandates
  6. A Guide to Direct Debit Service User Numbers (SUN)