The ICO fines HelloFresh

The ICO has fined food delivery company HelloFresh a whopping £140,000 for breaches of data protection regulations. In this case the Privacy and Electronic Communications Regulations (PECR).

The ICO found HelloFresh guilty of not making customers fully aware of what they were opting into. The ICO stated that this was a clear ‘breach of trust’. They added, “We will take clear and decisive action where we find the law has not been followed.” 

Read More

Data protection in the direct marketing data broking sector – and the GDPR

Organisations using marketing services of data brokers – take note! Are you compliant with data protection law, including the GDPR?

Data Protection Law; GDPR

At a glance and data protection law

  • Data broking for direct marketing purposes involves collecting data. The data may be about individuals from a variety of sources. It is then combined and sold or rented to other organisations but must be compliant with data protection law, which includes the GDPR.
  • If you use, or intend to use, the marketing services of data brokers, there are elements to be remembered. Firstly, you are responsible for ensuring that your processing of personal data is compliant with data protection law.
  • Before you use data broking services you must undertake appropriate due diligence. You must satisfy yourself that the personal data being offered to you complies with data protection law.
  • You must be transparent and tell people what you want to do with their data. This includes where you intend to use data broking services to obtain additional data about your customers. This includes profiling them.
  • You must ensure that you have a legal basis before you seek data from a data broking service.

The detail

What is data broking for direct marketing purposes?

Many different types of organisations use the marketing services of data brokers.

Data broking for direct marketing purposes involves collecting data about individuals from a variety of sources. The services provided by data brokers for direct marketing purposes include:

  • selling lists of contact details;
  • selling copies of the open electoral register;
  • profiling and data enrichment (eg adding data to the profile you already hold on people);
  • data matching (eg providing phone numbers for people who you only hold address details for);
  • data cleansing and tracing, for example, removing deceased records from your database and tracking down new contact details for people;
  • screening services, for example, screening the telephone numbers you hold against the Telephone Preference Service; and
  • audience segmenting or other profiling. For example, identifying target sub-groups within an audience for tailored messaging to comply with data protection law.

Subsequently, whilst the data brokers have responsibility for ensuring their processing of personal data is compliant with the data protection law, it isn’t that simple. Their clients that use their data broking services also have responsibilities under the GDPR and DPA 2018. You must comply with data protection law.

Therefore, if you are using data from a data broker then you must remember that you are responsible for ensuring that your processing of personal data is compliant with data protection law. This includes:

  • undertaking appropriate due diligence;
  • telling people what you want to do; and
  • having a valid lawful basis for the processing the data

What due diligence might be appropriate?

Before you use data broking services you must undertake appropriate due diligence. Is the data compliant with data protection laws? In particular, the GDPR, DPA 2018 and if applicable, the Privacy and Electronic Communications Regulations (PECR).

Simply accepting a data broker’s assurances that the data they are supplying is compliant is not good enough. You must be able to demonstrate your compliance with the GDPR and be accountable.

The individuals involved have the right to know that you have their data, and why. For example, for direct marketing purposes. However, this needs to be specific.

Due diligence

  • Who compiled the data? Was it the data broker you are buying it from, or was it someone else?
  • Where was the data obtained from – did it come from the individuals directly or has it come from other sources?
  • What privacy information was used when the data was collected? What were individuals told their data would be used for?
  • When was the personal data compiled? What date was it collected and how old is the data?
  • How was the personal data collected? What was the context and method of the collection?
  • Records of the consent (if it is ‘consented’ data). What did individuals consent to? What were they told, were you named, when and how did they consent?
  • Evidence that the data has been checked against opt-out lists. If claimed, can it be demonstrated that the TPS or CTPS has been screened against? How recently?
  • How does the data broker deal with individuals’ rights? Will they pass on objections?
  • Is this consent relevant?

A reputable data broker should be able to demonstrate to you that the data is reliable. Therefore, their data complies with data protection law.

What do we need to tell people?

You must be transparent about your processing of personal data. It is a legal requirement that you provide people with appropriate privacy information about what you intend to do with their data. You need to make your privacy information easy to understand and use plain language. Furthermore, keep your privacy notice short and to the point!

Notwithstanding, of your intentions to use data broking services to obtain additional data about your customers and/or to profile them you must be are of the laws. You must be clear and transparent and tell them before you do this. It is unlikely that your customers will expect you to be seeking data from other organisations about them. Many will object to this. The GDPR gives them the right to object.

However, simply stating what you intend to do with an individual’s personal data in your privacy information doesn’t automatically mean that you will be compliant. Therefore, you must also make sure that your obtaining of the personal data and any intended use is fair and lawful. Your privacy notice will detail this.

Therefore, if you buy or rent lists of individuals’ contact details to use for direct marketing, be aware. You must provide those on the list with your privacy information within one month of obtaining their data.

Do we need a valid lawful basis?

Yes, you must have an appropriate lawful basis under the GDPR for processing personal data. This means that if you intend to seek personal data from a data broking service, you must be able to demonstrate what your lawful basis for processing is before you obtain the data.

There are six lawful bases for processing. Undeniably, your choice of lawful basis will depend on the purpose you intend to process the personal data.

Therefore, if you intend to use contact details obtained from data brokers for electronic direct marketing you must be aware of the law. The PECR demands that you have consent and this is to the GDPR standard.

If you need help in making an informed decision and complying with data protection law, please feel free to call us on 03333 22 1011 or send an email to [email protected].

Company Director receives a 4-year ban following PECR breach

Howard Freeman – 14thFebruary 2019

The ICO (Information Commissioner’s Office) has banned a businessman from starting or managing a business for four years following his breach of the PECR (Privacy and Electronic Communications Regulations).

The director at Lad Media, Keith Hancock, was said to have “played a central role” in sending spam messages to thousands of people with SMS (text messages) containing marketing materials, many of whom had previously withdrawn their consent to receive such messages.

The ICO said that the lead generation and data brokerage business sent nearly 400,000 messages in total. More than a hundred people complained, citing distress and harassment to the industry text message reporting service.

Violations of the PECR

The PECR covers several areas, including electronic marketing, cookies and the security of public electronic communication services. It also prohibits organisations from sending electronic communications without first gaining recipients’ consent.

The amendment to the PECR in December of 2018 granted the ICO the power to fine businesses up to £500,000, directly to directors. Sadly, however, the amendment came along after the investigation into Lad Media had started, so it couldn’t be applied.

Nonetheless, the punishment has proven costly. Not only was Hancock banned from senior management roles. Lad Media also received a fine of £20,000, which it refused to pay, ultimately leading to a winding-up order.

Commenting on the incident, David Brooks, Chief Investigator for the Insolvency Service, said: “There is clear guidance on the internet about what communications you can send to people when it comes to marketing. So, there is no excuse for not knowing what your responsibilities are.

“Keith Hancock clearly failed to ensure Lad Media carried out sufficient checks on who was being sent direct marketing, even if it was done by a third party. Thanks to the joint work with the ICO, we have secured a ban appropriate for the seriousness of the offence.”

Does your business meet the requirements of the PECR?

This incident is a clear reminder that organisations must pay attention to the PECR. Admittedly, it has been somewhat ignored in the past 12 months as the GDPR (General Data Protection Regulation) has taken the focus away from PECR. Many businesses worry about violating the GDPR. However, violations of privacy laws can be just as damaging to your business.

Those looking to assess their compliance status should conduct a PECR audit, a service we can provide. Please get in touch for further information. You can call us on 03333 22 1011.

The team can help you address the key areas of PECR compliance and we can provide you with recommendations for improvement. We can confirm key areas where you already comply with PECR standards. Don’t get caught out with a PECR breach, call us today.