Halfords slapped on wrist for breaching email marketing laws
- Reference: 1662629226
- News link: https://www.theregister.co.uk/2022/09/08/halfords_ico_email_breach_pecr_fine/
- Source link:
According to the Information Commissioner’s Office, it fined the business £30,000 for dispatching 498,179 messages to folk that hadn’t provided consent - equating to a £0.06 penalty per each email.
The decision relates to a direct marketing mailer that Halfords sent electronically on July 28, 2020 concerning a ‘Fix Your Bike’ government voucher scheme. This gave recipients up to £50 toward the cost of repairing a cycle in any approved retailer in the UK.
[1]
Unsurprisingly, Halfords' marketing email urged the individuals to book a free bike assessment and redeem their voucher in store, meaning this was marketing designed to generate income for the company. As such, the advertising of the service meant Halfords couldn’t rely on ‘legitimate interest’ to send the mail, which the ICO said it had done.
[2]UK Info Commissioner slams use of WhatsApp by health officials during pandemic
[3]Halfords suffers a puncture in the customer details department
[4]Cookie consent crumbles under fresh UK data law proposals
[5]Clearview AI fined millions in the UK: No 'lawful reason' to collect Brits' images
Under electronic marketing rules, legitimate interest cannot be used as a genuine alternative to consent - yet a soft opt-in does allow marketeers to dispatch emails to customers whose details were taken when they bought something or negotiated a service.
The ICO said that in the case of Halfords, customers that received the marketing material had previously ticked the box about not being contacted again.
[6]
[7]
The email didn’t include an unsubscribe link, the ICO said.
Andy Curry, head of investigations at the ICO, said in a statement: “It is against the law to send marketing emails or texts to people without their permission. Not only this, it is a violation of their privacy rights as well as being frustrating and downright annoying.
[8]
“Halfords are a household name and we expect companies like them to know and act better. This incident does not reflect well on the internal advice or processes and therefore a fine was warranted in this case. This also sends a message to similar organisations to review their electronic marketing operations, and that we will take necessary action if they break the law.”
The ICO said Halfords broke Privacy and Electronic Communications Regulations 2003 (PECR), adding it should have been aware of the rules and taken steps to prevent the contraventions. The breach, however, was considered to be negligent rather than deliberate, hence the size of the fine was considered proportionate.
If Halfords agrees to pays the fine before October 4, it’ll get a 20 percent discount meaning it has to cough £24,000. ®
Get our [9]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yxm9OQXtlgD7TZvklq-@wAAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2022/07/12/uk_department_of_health_and/
[3] https://www.theregister.com/2022/06/23/halfords_data_leak_vulnerability/
[4] https://www.theregister.com/2022/06/17/cookies_crumble_in_uk_data/
[5] https://www.theregister.com/2022/05/23/clearview_ai_ico_fine/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yxm9OQXtlgD7TZvklq-@wAAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yxm9OQXtlgD7TZvklq-@wAAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yxm9OQXtlgD7TZvklq-@wAAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://whitepapers.theregister.com/
A minor cost of doing business, quite so. Sixpence per message compares very favourably with Going Postal.
" The breach, however, was considered to be negligent rather than deliberate, hence the size of the fine was considered proportionate. "
I'm sure the last time Halfrauds were mentioned on El Reg, it was to do with any old clown being able to increment the order number through one of their websites and getting a total stranger's personal data? It was either an article or a commentard had spoke of it.
The fact that the above story has been spoken about (I think they were contacted over it and did nothing), and now this, I'd have thought that being negligent was every bit as bad as being deliberate. The fine should've been bigger, as otherwise they just won't learn.
Wikipedia says revenue was £1.1 billion in 2018, a £30k fine is a minor cost of doing business for them...