News: 1621412888

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK data watchdog fines 'pandemic partner' biz £8k: It sent 84,000 marketing emails to people who'd given info for track and trace

(2021/05/19)


The UK's data watchdog has fined a company £8,000 for sending 84,000 direct marketing emails without consent to people who had provided their personal data for contact tracing purposes.

The Reg readership will have no problem in calculating this in their heads but for anyone feeling a bit slow today, that's just over 9.5 pence charged by the Information Commissioner's Office (ICO) for each email that reached its target.

The ICO hit Tested.me Ltd (TML) of St Albans with the penalty under section 55A of the Data Protection Act 1998, for a serious contravention of the Privacy and Electronic Communications Regulations (PECR) 2003. The maximum fine under the legislation is £500,000.

[1]

[2]

[3]

Incorporated in June 2020 according to Companies House (reg: 12699464), TML provides digital "track-and-trace" services to other businesses, issuing individuals with a QR code that they then scan on arrival at a business premises, thereby providing their contact-tracing details. It markets itself as a "your digital partner in the pandemic"

The business came to its attention of the ICO in November last year when a member of the public complained of an email sent by TML concerning a digital health passport. The mail thanked the individual for scanning into a business using TML's QR code and promoted a related app. The person who received the email said they had not provided consent to be sent it.

"The commissioner asked this complainant to provide further details of any complaint that they had made to TML directly. This correspondence revealed that the individual would have signed up to marketing communications on the online 'Visitor Registration Form' into which they entered their track-and-trace details."

[4]

The consent wording was: "Tick here if you agree for this venue, its alliance and tested.me to send you marketing materials in future. To comply with Government Guidance during the COVID-19 pandemic, we are collecting your name and contact details. We will store these for 21 days only before deleting them in line with GDPR regulations. Your details will not be shared with any other company or organisation."

There was no link to a privacy notice and no further information was provided, the ICO said. "The only indication an individual had as to who operated the page was a small 'tested.me' logo at the bottom of it."

Consent obtained on this basis was inadequate, said the ICO and it sent a bunch of questions to the company in November last year.

[5]

TML had sent four different emails to customers, and having scanned the contents of those the ICO decided two did not contravene PECR.

Consent was not freely given: ICO

The company claimed it had faced technical difficulties because some that opted out of receiving marketing comms had then filled out the Visitor Registration Form for a second time and ticked the marketing consent box. And TML added that it had misunderstood requests from people to no longer receive marketing comms as requests to delete personal data.

Consent provided by individuals who had filled in the Visitor Registration Form was invalid because "inadequate information was provided about the identity of TML and the venue in question's 'alliance'. Beyond a small texted.m logo at the bottom of the Visitor Registration Form, no information was provided about who TML is and what activities it engages in. It is also unclear which specific entities are part of a venue's alliance," the ICO ruled.

The watchdog said consent was not informed as the Visitor Registration Form contained no link to TML's privacy notice; consent was not freely given or specific as it was insufficiently granular; and the Visitor Registration Form made only references to marketing materials rather than permitting individuals to consent to marketing comms.

The ICO said it did not believe TML deliberately intended to break PECR rules but should have been aware of its responsibilities and should have taken reasonable steps to avoid the contravention.

"Taking into account all of the above, the Commissioner has decided that a penalty in the sum of £8,000 is reasonable and proportionate given the particular facts of the case and the underlying objective in imposing the penalty," the ICO concluded. ®

Get our [6]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKThukaFsC-BZIfg1dcIdAAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKThukaFsC-BZIfg1dcIdAAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKThukaFsC-BZIfg1dcIdAAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKThukaFsC-BZIfg1dcIdAAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKThukaFsC-BZIfg1dcIdAAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://whitepapers.theregister.com/

A hefty fine

Dwarf

At least such a hefty fine will act as a strong deterrent to others not to flout the rules

I wonder if they still have the marketing database and where they will use it next ?

Re: A hefty fine

Archivist

Did I miss the sarcasm flag?

Re: A hefty fine

Anonymous Coward

the real sarcasm flag is no flag. And in this case, you missed the "Fail".

...

Or... did I miss your sarcasm about missing sarcasm flag?

but sarcasm aside, what's the real message about the 8K fine? One message I gather is: business is a'booming, brother!

just, only, a paltry, the pitiful sum of ...

Flak

There is a word or phrase missing in the headline - pick one of the above or add a similar one of your own choice.

UK data watchdog fines 'pandemic partner' biz $%&*!!!! £8k

Incorporated in June 2020

Anonymous Coward

It appears ICO operates now a stunningly effective '2-strike policy': a gentle pat that's worth 8K, but maybe, just maybe, gets paid, and a large slap, which folds the company (which promptly re-unfolds itself in no time), in which case, no money at all, as no real tools to effectively extract this money. I wonder if they they learnt from the Middle East context (re. Israeli 'roof tapping')?

p.s. I'd love to see a simple chart: ICO total yearly - expenses, on one side, v. ICO total yearly - fines RECEIVED.

"it had faced technical difficulties"

Pascal Monett

It would appear that it faced no difficulty in hoovering up email addresses and then deciding to "inform" said people of a "special opportunity".

Don't come crying that you don't know how to handle someone who registers twice and only consents once. You should have a procedure on how to handle that, it's nothing technical.

I think the ICO was rather lenient on this matter. It seems obvious to me that TML's intent was to get consent using a purposefully vague definition of marketing "materials", which consent it could then use as it pleased to "accidentally" email 80K+ people.

You don't accidentally email tens of thousands of people based on a misunderstanding.

This was the plan, and it will happen again.

So, who still thinks that the NHS sharing patient data with 3rd parties is a good thing ? Outside of NHS management, obviously.

Re: "it had faced technical difficulties"

Primus Secundus Tertius

"So, who still thinks that the NHS sharing patient data with 3rd parties is a good thing ? "

Answer: the Treasury.

The Treasury will sell any public data, but everything about themselves remains secret. Time that policy was reversed.

ICO ffs

Terry 6

The ICO ought to be able to recognise a disingenuous, cynical abuse of members of the public's information. They're not children.

They ought to be aware that people signing in to a venue do not routinely ask to be sent marketing information and so realise that any marketing consent that is incidental to or included with the purpose of a specific consent is a breach unless there is clear evidence otherwise, e.g. a separate agreement with words to the effect "I also wish this organisation to send me their marketing".

It's not unreasonable. Some restaurants, for example, will ask you to sign up for "Information and special offers". It's up front, it's clear and it's specific -- rather than a general agreement that they can send you any kind of crap from any source they choose to be involved with.

Attack of the Tuxissa Virus

What started out as a prank posting to comp.os.linux.advocacy yesterday has
turned into one of the most significant viruses in computing history.
The creator of the virus, who goes by the moniker "Anonymous Longhair",
modified the Melissa virus to install Linux on infected machines.

"It's a work of art," one Linux advocate told Humorix after he looked
through the Tuxissa virus source code. "This virus goes well beyond the
feeble troublemaking of Melissa. It actually configures a UMSDOS partition
on the user's hard drive and then downloads and installs a stripped-down
version of Slackware Linux."

The email message that the virus is attached to has the subject "Important
Message About Windows Security". The text of the body says, "I want to let
you know about some security problems I've uncovered in Windows 95/98/NT,
Office 95/97, and Outlook. It's critically important that you protect your
system against these attacks. Visit these sites for more information..."
The rest of the message contains 42 links to sites about Linux and free
software.

Details on how the virus started are a bit sketchy. The "Anonymous
Longhair" who created it only posted it to Usenet as an early April Fool's
gag, demonstrating how easy it would be to mount a "Linux revolution".