The ICO fines HelloFresh

The ICO has fined food delivery company HelloFresh a whopping £140,000 for breaches of data protection regulations. In this case the Privacy and Electronic Communications Regulations (PECR).

The ICO found HelloFresh guilty of not making customers fully aware of what they were opting into. The ICO stated that this was a clear ‘breach of trust’. They added, “We will take clear and decisive action where we find the law has not been followed.” 

HelloFresh sent 1 million spam texts in just seven months and 79 million spam emails in the same period. That is some effort!

HelloFresh find £140,000

Poor practice and unfair statements

The marketing messages sent by HelloFresh were based on an opt-in statement which did not make any reference to the sending of marketing via text. Whilst there was a reference to marketing via email, this was hidden in an age confirmation statement. This was likely to unfairly incentivise customers to agree.

The clear breach of trust was also clear when customers cancelled their subscription. Former customer data was to be used for marketing purposes up to 24 months after subscriptions were cancelled. Therefore, no legal basis for processing existed and there was assumed consent. Both are in clear breach of the regulations.

The investigation by the ICO began in March 2022. This followed complaints made directly to the regulator, as well as to the 7726 spam message reporting service. The company also continued to contact former clients. This was even after they had requested this to stop. Again, a clear breach as STOP means STOP!

The Investigation

Andy Curry was the lead investigator at the ICO. Here is what he had to say:

“This marked a clear breach of trust of the public by HelloFresh. Customers did not know exactly what they’d be opting into, nor was it clear how to opt out. From there, they were hit with a barrage of marketing texts they didn’t want or expect. In some cases, even when they told HelloFresh to stop, the deluge continued.

“In issuing this fine, we are showing that we will take clear and decisive action where we find the law has not been followed. We will always protect the right of customers to choose how their data is used.

“The investigation that led to this fine began following complaints filed by the public, both to the ICO and to the 7726 service. If you receive nuisance calls, texts or emails, you must report it straight away.”

Is your communication strategy legal? Business leaders are keen to drive revenues. That is understandable, but at what cost? Is privacy and compliance on your board meeting agenda? Marketing may well deliver the results you desire. But, is it legal? As directors, it is therefore your responsibility to challenge your marketing team.

A very small fine and a missed opportunity

HelloFresh has global revenues of £6.8 billion. A fine should be between 2% and 4% depending on severity, under the GDPR. The PECR demands less. If this had been a GDPR fine the amount could have been over £1million. Therefore, has the ICO missed an opportunity to send a message here?

The message to business leaders is to challenge your marketeers and carry out independent audits. These may reveal poor practice and illegal behaviour. Whilst audits aren’t the cheapest, they don’t cost £140,000!

If you are not sure, call us on 03333 22 1011 or contact us and we will audit your marketing activities and potentially save you time, money and embarrassment.