News: 1621518312

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK data regulator fines American Express 0.14p per email after opted-out folk spammed 50 million times

(2021/05/20)


American Express has been fined 0.009 per cent of its annual profits by the Information Commissioner's Office (ICO) after spamming people who opted out of its marketing emails with 50 million unwanted messages.

The £90,000 fine was announced today after the British data regulator ruled the US bank had broken the law.

"This is a clear example of a company getting it wrong and now facing the reputational consequences of that error," said ICO head of investigations Andy Curry, recognising the fine was effectively small change for Amex.

[1]

[2]

[3]

"Between 1 June 2018 and 21 May 2019, 4,098,841 of those emails were marketing emails, designed to encourage customers to make purchases on their cards which would benefit Amex financially. It was a deliberate action for financial gain by the organisation. Amex also did not review its marketing model following customer complaints," said the ICO in a statement.

Customers were encouraged to spend £500 on their American Express credit cards in return for a £50 benefit, under the title "award-winning offers just for you".

The bank ignored complaints and when those customers went to the ICO, bankers claimed the spam was "a requirement of its Credit Agreements with customers". This was untrue – and the customers bombarded with spam had already opted out of marketing emails.

[4]UK data watchdog fines 'pandemic partner' biz £8k: It sent 84,000 marketing emails to people who'd given info for track and trace

[5]Oops, says Manchester City Council after thousands of number plates exposed in parking ticket spreadsheet

[6]UK watchdog would cease to enforce data protection law if Supreme Court sided with Google, its lawyer tells judges

[7]Scottish National Party members found among list of names signed up to rival Alba Party after website whoopsie

Justifying the spamming of its own customers, Amex claimed the spam was internally classified as a service message instead of marketing. Service messages are meant to be used for information about the service – for example, notifications of scheduled downtime or changes in interest rates. Instead Amex sent them unwanted inbox filler advertising new products and services.

The bank told its customers: "We feel that Card Members would be at a disadvantage if they were not aware of these campaigns and promotional periods."

[8]

The ICO found that Amex had broken the Privacy and Electronic Communications Regulations 2003, the law on sending marketing emails. The ICO's monetary penalty notice, which stated that Amex acted negligently rather than deliberately, said: "AMEX, as the transmitter or instigator of the direct marketing, is required to ensure that it is acting in compliance with the requirements of Regulation 22 of PECR, and to ensure that valid consent to send those messages had been acquired."

In Amex's case, 49 per cent of its customers had not opted in to receive marketing emails or had explicitly opted out – yet many of these collectively received the millions of messages sent by the bank anyway.

We have attempted to contact American Express for comment and will update this article if we hear back. In Q4 FY2020 alone Amex [9]made $1.4bn in profit .

[10]

The maximum fine for a breach of PECR is £500,000, though the regulator indicated it would impose a £90k penalty in a preliminary notice back in February, to which Amex did not object.

The £90k fine is discounted to £72k if paid by 16 June. This means the regulatory cost to Amex of doing business by sending 50 million unlawful marketing emails would be about 0.14p per message. Yesterday the ICO [11]priced unlawful emails at 9.5p when it fined a coronavirus track-and-trace company for identical lawbreaking . ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKaHmeOHljglPhsQYip3JwAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKaHmeOHljglPhsQYip3JwAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKaHmeOHljglPhsQYip3JwAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/05/19/ico_tested_me_fine/

[5] https://www.theregister.com/2021/05/13/manchester_numberplate_blunder_open_data/

[6] https://www.theregister.com/2021/04/30/lloyd_v_google_ico_intervention/

[7] https://www.theregister.com/2021/03/29/alba_party_website_error/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKaHmeOHljglPhsQYip3JwAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.businesswire.com/news/home/20210126005200/en/American-Express-Reports-Fourth-Quarter-Revenue-of-9.4-Billion-and-Earnings-Per-Share-Of-1.76

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKaHmeOHljglPhsQYip3JwAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2021/05/19/ico_tested_me_fine/

[12] https://whitepapers.theregister.com/

Ah, Amex.

Anonymous Coward

We used to use them for Merchant Services, back in the day before we had any other options. When we finally dropped them for Stripe and closed our account, we continued to get emails telling us our merchant statement was ready. I called them several times about this but they were unable to find any record of an open account - no account number was on the email - so had no way of stopping the emails and suggested we "just ignore them". They eventually stopped after a couple of years.

Relative costs and effective action

Mike 137

0.14p per message for general breaches. 9.5p for breaches involving GDPR category 9 (sensitive) data.

In both cases derisory, and for the perpetrators just a minor cost of doing business. Until either penalties actually hurt or (preferably) enforcement actually stops abuses, nobody is going to take any notice of the law at all. And even such enforcement as the one reported only applies where large numbers of people are affected. Individuals bringing single complaints to the regulator stand practically no chance of being taken seriously, let alone gaining redress.

Despite relatively adequate legislation, the entire data protection regime is in practice pretty much non-functional. If gauged by either its power to prevent abuses or to redress specific instances of wrongs, it's so far failed spectacularly. However it appears so far to be largely satisfactory to the EU, as we're well on the road to an adequacy decision (based on the law itself, despite almost universal non-compliance with it and pretty toothless enforcement).

Re: Relative costs and effective action

My-Handle

I implemented an SMS service in a website a little while ago (mainly for diagnostics to my phone), at a cost of 2.4p per message or similar. 0.14p per message is barely a rounding error, even for relatively poorly financed companies.

Disgusted Of Tunbridge Wells

The annual profit is irrelevant.

What matters is what was the return on these emails. Hopefully the £90k fine more than wiped that out.

spam spam spam and eggs spam and beans spam spam !

fredesmite2

I get 50+ spam a day in my gmail .. nothing will stop them,.

But I do know, that an Alan at home, co-working with his under-ground
cluster of gnomes, does a hell-of-a-lot more good for free software
than an Alan in a US-prison as yet another victim of "justice".

- David Weinehall discussing the DMCA/SSSCA on linux-kernel