Google Consent Mode v2

Google Consent Mode v2

Google Consent Mode is a tool developed by Google which allows websites to adjust the behaviour of Google tags according to the user’s data privacy preferences. Version 2 works similarly to version 1, but with the addition of two new parameters, ad_user_data and ad_personalization, to allow more granular control over how users’ data is collected.

Read More

The ICO fines HelloFresh

The ICO has fined food delivery company HelloFresh a whopping £140,000 for breaches of data protection regulations. In this case the Privacy and Electronic Communications Regulations (PECR).

The ICO found HelloFresh guilty of not making customers fully aware of what they were opting into. The ICO stated that this was a clear ‘breach of trust’. They added, “We will take clear and decisive action where we find the law has not been followed.” 

Read More

Data protection in the direct marketing data broking sector – and the GDPR

Organisations using marketing services of data brokers – take note! Are you compliant with data protection law, including the GDPR?

Data Protection Law; GDPR

At a glance and data protection law

  • Data broking for direct marketing purposes involves collecting data. The data may be about individuals from a variety of sources. It is then combined and sold or rented to other organisations but must be compliant with data protection law, which includes the GDPR.
  • If you use, or intend to use, the marketing services of data brokers, there are elements to be remembered. Firstly, you are responsible for ensuring that your processing of personal data is compliant with data protection law.
  • Before you use data broking services you must undertake appropriate due diligence. You must satisfy yourself that the personal data being offered to you complies with data protection law.
  • You must be transparent and tell people what you want to do with their data. This includes where you intend to use data broking services to obtain additional data about your customers. This includes profiling them.
  • You must ensure that you have a legal basis before you seek data from a data broking service.

The detail

What is data broking for direct marketing purposes?

Many different types of organisations use the marketing services of data brokers.

Data broking for direct marketing purposes involves collecting data about individuals from a variety of sources. The services provided by data brokers for direct marketing purposes include:

  • selling lists of contact details;
  • selling copies of the open electoral register;
  • profiling and data enrichment (eg adding data to the profile you already hold on people);
  • data matching (eg providing phone numbers for people who you only hold address details for);
  • data cleansing and tracing, for example, removing deceased records from your database and tracking down new contact details for people;
  • screening services, for example, screening the telephone numbers you hold against the Telephone Preference Service; and
  • audience segmenting or other profiling. For example, identifying target sub-groups within an audience for tailored messaging to comply with data protection law.

Subsequently, whilst the data brokers have responsibility for ensuring their processing of personal data is compliant with the data protection law, it isn’t that simple. Their clients that use their data broking services also have responsibilities under the GDPR and DPA 2018. You must comply with data protection law.

Therefore, if you are using data from a data broker then you must remember that you are responsible for ensuring that your processing of personal data is compliant with data protection law. This includes:

  • undertaking appropriate due diligence;
  • telling people what you want to do; and
  • having a valid lawful basis for the processing the data

What due diligence might be appropriate?

Before you use data broking services you must undertake appropriate due diligence. Is the data compliant with data protection laws? In particular, the GDPR, DPA 2018 and if applicable, the Privacy and Electronic Communications Regulations (PECR).

Simply accepting a data broker’s assurances that the data they are supplying is compliant is not good enough. You must be able to demonstrate your compliance with the GDPR and be accountable.

The individuals involved have the right to know that you have their data, and why. For example, for direct marketing purposes. However, this needs to be specific.

Due diligence

  • Who compiled the data? Was it the data broker you are buying it from, or was it someone else?
  • Where was the data obtained from – did it come from the individuals directly or has it come from other sources?
  • What privacy information was used when the data was collected? What were individuals told their data would be used for?
  • When was the personal data compiled? What date was it collected and how old is the data?
  • How was the personal data collected? What was the context and method of the collection?
  • Records of the consent (if it is ‘consented’ data). What did individuals consent to? What were they told, were you named, when and how did they consent?
  • Evidence that the data has been checked against opt-out lists. If claimed, can it be demonstrated that the TPS or CTPS has been screened against? How recently?
  • How does the data broker deal with individuals’ rights? Will they pass on objections?
  • Is this consent relevant?

A reputable data broker should be able to demonstrate to you that the data is reliable. Therefore, their data complies with data protection law.

What do we need to tell people?

You must be transparent about your processing of personal data. It is a legal requirement that you provide people with appropriate privacy information about what you intend to do with their data. You need to make your privacy information easy to understand and use plain language. Furthermore, keep your privacy notice short and to the point!

Notwithstanding, of your intentions to use data broking services to obtain additional data about your customers and/or to profile them you must be are of the laws. You must be clear and transparent and tell them before you do this. It is unlikely that your customers will expect you to be seeking data from other organisations about them. Many will object to this. The GDPR gives them the right to object.

However, simply stating what you intend to do with an individual’s personal data in your privacy information doesn’t automatically mean that you will be compliant. Therefore, you must also make sure that your obtaining of the personal data and any intended use is fair and lawful. Your privacy notice will detail this.

Therefore, if you buy or rent lists of individuals’ contact details to use for direct marketing, be aware. You must provide those on the list with your privacy information within one month of obtaining their data.

Do we need a valid lawful basis?

Yes, you must have an appropriate lawful basis under the GDPR for processing personal data. This means that if you intend to seek personal data from a data broking service, you must be able to demonstrate what your lawful basis for processing is before you obtain the data.

There are six lawful bases for processing. Undeniably, your choice of lawful basis will depend on the purpose you intend to process the personal data.

Therefore, if you intend to use contact details obtained from data brokers for electronic direct marketing you must be aware of the law. The PECR demands that you have consent and this is to the GDPR standard.

If you need help in making an informed decision and complying with data protection law, please feel free to call us on 03333 22 1011 or send an email to [email protected].