Marketing biz sent 107 million spam emails... to just 437k people
- Reference: 1681735513
- News link: https://www.theregister.co.uk/2023/04/17/ico_spam_email_fine/
- Source link:
London-based Join The Triboo Limited (JTT) dispatched the spams to some 437,324 people between August 2019 and August 2020, meaning the lucky recipients would have found an average of 244 of these messages in their inbox, the Information Commissioner’s Office told us.
“It’s an issue many of us face - opening up our email inboxes and it being filled with emails we did not ask for or consent to,” said Andy Curry, ICO head of investigations. “This shouldn’t be considered a fact of life.”
[1]
As Reg readers know, sending direct marketing to unsuspecting individuals is a law-breaking move, as outlined in the UK’s [2]Privacy and Electronic Regulations 2003 , the legislation used to penalize JTT.
[3]
[4]
The company’s actions came to light during an ICO investigation into Leads Work Limited, which was itself fined for contravening PECR by sending unsolicited direct marketing messages. LWL told the regulator it purchased data from a numbers of sources, including JTT.
The ICO found that in addition to direct marketing, JTT also acts as an agency by hosting electronic marketing for third parties to its own distribution lists. And JTT does lead generation and publishes several "editorial" websites that write about job-related topics in which users could subscribe.
[5]
The ICO found JTT did not have valid consent to send the 107 million direct marketing messages.
[6]Criminal records office yanks web portal offline amid 'cyber security incident'
[7]NHS Highland 'reprimanded' by data watchdog for BCC blunder with HIV patients
[8]Another RAC staffer nabbed for storing, sharing car crash data
[9]Five British companies fined for making half a million nuisance calls
Not one complaint about the emails was received by the ICO but it was not surprised by this as the emails were hosted and JTT’s role would not necessarily have been apparent to those receiving the emails.
Curry at the ICO said: “We provide advice and support to legitimate companies that want to comply with the law… that is however, not what was happening in this case. The company did not properly seek permission from the people it chose to bombard with spam emails. The company used job seeking websites as a key component in its unlawful campaign.
“In taking this action, we say to the public that we will continue to be on your side and protect you, and we say to any other organization operating outside of the law that we will pursue every case like this brought to us to the fullest extent.” ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZD1tIFQyQOBiBHG38qhsWwAAAZY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.legislation.gov.uk/uksi/2003/2426/contents/made
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD1tIFQyQOBiBHG38qhsWwAAAZY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZD1tIFQyQOBiBHG38qhsWwAAAZY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD1tIFQyQOBiBHG38qhsWwAAAZY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/04/06/acro_security_incident/
[7] https://www.theregister.com/2023/03/31/nhs_highland_reprimanded_by_data/
[8] https://www.theregister.com/2023/02/03/roadside_recovery/
[9] https://www.theregister.com/2022/12/08/ico_fines_marketing/
[10] https://whitepapers.theregister.com/
What a joke
Change the fine to £1 per spam email and watch the spammers move to an entirely new line of business. The fines levied are so low that the industry treats them as the cost of doing business. Also about time that company directors are held directly liable for the illegal actions of the companies under their control.
Re: What a joke
Who cares what the number is. They aren't going to collect the money.
Make sure the amount of the fine is actually paid, then we can discuss if it is high enough.
Re: What a joke
It's often the case that these kinds of companies are merely shells. In these cases a fine is usually enough to prompt the directors to declare the company bankrupt. In such cases it's long been my belief that the directors should be prosecuted.
Yes I know the whole point of a limited company is that it limits the liability of the directors, however I don't think this should be the case where fines are levied. Were it the case that directors became personally liable for such fines upon voluntary liquidation of the company I think a lot of these quite obviously deliberate breaches of the rules would stop overnight.
As long as spam is cheap and the expense of dealing with it falls on the recipient this sort of thing will continue.
The solution here is to require the spammer to pay a reasonable amount, say several £ to the recipient for their trouble in dealing with it. I've used the threat of that to stop a snail-mailer who simply couldn't grasp that having their mail to a former tenant returned as "No longer at this address" meant that they were misaddressing it.
We should regard spam - snail mail, email or phone - as pollution and apply the "Polluter pays" principle where payment is the economic cost of dealing with it, not a small fine.
All they need is a pair of Transient Interest Tracking Systems, I'm sure it would cost less than a £1 per spam email (as Big Boomer said above) penalty. I think the penalty should be progressive, £1 for 1-10000, £10 for 10001-1000000, and £100 for 1000001-N
Under the new Information Commissioner the ICO seems to have become somewhat more interested in spontaneous investigation, but the emphasis is still almost entirely on PECR and data breaches. There's never been (and still isn't) any clear indication of significant attention to infringements of the rights and freedoms of data subjects outside these two areas. That's a pity as it reduces the GDPR to data law, whereas in reality it was intended to be human rights law in relation to data. Unfortunately, current govt. proposals for the new UK legislation will support that reduced interpretation to the hilt.
Seriously?
...a £130,000 [] fine...
That is a £0.0012 fine per spam mail. What a joke.
What about 130.000 days in jail for the combined employees of the firm? Evenly distributed according to the effective size of the pay check.