News: 1705058835

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Data regulator fines HelloFresh £140K for sending 80M+ spams

(2024/01/12)


Food delivery company HelloFresh is nursing a £140,000 ($178k) fine by Britain’s data privacy watchdog after a probe found it had dispatched upwards of a staggering 79 million spam email and one million texts in just seven months.

The meal-kit company provides weekly packages of premeasured ingredients with recipes so customers can prepare their own meals rather than winging it at the grocery store.

The Information Commissioner’s Office says the company claimed messages were based on an opt-in statement, yet this statement did not include any reference to the sending of marketing messages via text. There was a nod to email marketing, however, this was included in an age confirmation statement that was “likely to unfairly incentivize customers to agree”.

[1]

As such, the emails and texts did not fit requirements that they be “specific” and “informed”: not mentioning SMS, being “unclear and bundled with others aspects,” the watchdog said.

[2]

[3]

In addition, customers weren’t give ample information that their data would be used for marketing messages for up to two years after they’d cancelled their HelloFresh subscription, the regulator added.

The investigation discovered that between August 23, 2021 and February 23, 2022, HelloFresh hit send on 80,993,013 messages, including 79,779,279 emails and 1,113,734 texts to subscribers. These were sent in contravention of Regulation 22 of the Private Electronic Communications Regulations.

[4]Manchester's finest drowning in paperwork as Freedom of Information requests pile up

[5]Britain's Ministry of Defence fined £350K over Afghan interpreter BCC email blunder

[6]Regulator says stranger entered hospital, treated a patient, took a document ... then vanished

[7]UK data watchdog fines three text spammers for flouting electronic marketing rules

[8]Brit data watchdog fines sleazy sales ops £250K for 'bombarding' folk with calls

The ICO says it was made aware of the spams issue after receiving complaints from recipients on its reporting service. It also found that even after people had asked HelloFresh to cease and desist, the spams continued.

“This marked a clear breach of trust of the public by HelloFresh,” said Andy Curry, ICO head of investigations. “Customers weren’t told exactly what they were opting into, nor was it clear how to opt out. From there, they were hit with a barrage of marketing texts they neither want nor expect, and in some cases, even when they told HelloFresh to stop, the deluge continued.”

[9]

“In issuing this fine, we are showing that we will take clear and decisive action where we find the law had not been followed. We will always protect the right of customers to choose how their data is used.”

The company was served with a £140,000 fine for breaking PECR, taking the number of fines handed to spammers to £2.44 million since April last year. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaFwNzoFZTNmWSs9I6JynQAAABY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaFwNzoFZTNmWSs9I6JynQAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaFwNzoFZTNmWSs9I6JynQAAABY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2023/12/20/greater_manchester_police_foi/

[5] https://www.theregister.com/2023/12/13/mod_bcc_email_fine/

[6] https://www.theregister.com/2023/12/01/nhs_health_board_ticked_off/

[7] https://www.theregister.com/2023/11/03/ico_text_spam_fines/

[8] https://www.theregister.com/2023/06/09/ico_cold_call_fines/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaFwNzoFZTNmWSs9I6JynQAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/



£140,000?

wolfetone

That's £0.00175 per message.

Where is the deterrent?

Re: £140,000?

Anonymous Coward

Roughly half a day's operating costs for the entire company, be assured they'll notice.

Re: £140,000?

wolfetone

Based on their own website, on the minimum amount of 2 people having 3 "recipes" a week - it's 4,002 orders. And that's just based on the "first box" offer which is less than the norm I think.

So again, that's feck all.

Re: £140,000?

Ochib

Profit afer tax for 2021 was 256.30m euros.

Re: £140,000?

Anonymous Coward

Where is the deterrent?

Deterrent? 8^D !!!!!!!!!!

Hmm ....

Me thinks that you - just - don't - get - it .

Unless you are fresh out of secondary school, you surely know that this has been going on, in the same manner with the same results, for eons.

There is no deterrent, there has never been such a thing.

Not with spammers, not with clearly avoidable data leaks , security breaches and other such accidents .

It is nothing but a very light slap on the wrist albeit soundly applied exclusively for the benefit of the gullible public sitting in the [1]peanut gallery .

This so that the usual culprits take due notice and strive to be more careful next time.

And don't get caught out.

More than anything, because it is very bad for business.

For both the culprits, the regulators and those controlling the regulators

.

[1] https://en.wikipedia.org/wiki/Peanut_gallery

Ochib

Should be at least £0.01 per spam

It is companies like these that make me ashamed to admit I studied Marketing

Flak

However... I have never worked in B2C marketing because it never sat right with me.

Can we see some proper fines please? £140k for 80M messages is a business expense, not a fine.

Re: It is companies like these that make me ashamed to admit I studied Marketing

My-Handle

There's a saying that I'm not quite remembering properly - it's something like

"When the punishment for breaking the law is a fine, it's no longer a law but a transaction"

or

"When the punishment for breaking the law is a fine, it becomes two laws - one for the rich and another for the poor"

Can anyone remember the actual saying?

devin3782

The fines should be at least a percentage of global turnover and it should be a tangible integer and not less than 5%

Lurko

If you fine* people on the basis of turnover, then it harms low margin businesses far more than high margin. So the Apples and Googles of this world would suffer proportionately less than retailers or manufacturers. In this case, on most recent 2022 accounts, HelloFresh were making a significant operating loss of £15m, after interest and tax that rose to £21.9m net loss. I'd hazard a guess that 2023 hasn't been a lot better, if you're losing £15-20m a year you're already pretty short of cash, and even turning the fine into £1m doesn't make the slap more painful. As HF had turnover around £500m, your minimum 5% turnover fine would be just short of £25m. Since HF total assets exceed total liabilities (there's a shareholder's deficit of £62m to balance the books), there's no cash to pay that sort of money, bankruptcy would be the likely outcome, along with redundancy for 2,000 staff. That would be a poor outcome for the regulator and employees.

I'd guess that (even with the 20% prompt payment discount), writing a cheque for £112k is going to sting, and the company will be mindful that if there's a repeat it'll be a much bigger penalty. The role of a regulator is to inform businesses of their obligations, guide and help them into compliance, and to use penalties and prosecutions as a last resort. In this case, if the ICO are happy that HF have learned their lesson and won't repeat the behaviour, then that's the outcome they want.

* Technically it's not a fine, it's a Civil Monetary Penalty, and if the company feel the regulator's being heavy handed they can challenge it through the courts. That persuades regulators to use CMPs prudently.

HelloFresh + spam

xyz

There's a joke in there someplace surely.

Re: HelloFresh + spam

Peter Gathercole

Hmm.

Fresh Spam. Surely an oxymoron.

Data regulator

elsergiovolador

Looks like Data regulator has become as spammer.

Instead of preventing spam, they are looking for their cut.

Surely they should be investigated.

Re: Data regulator

Lurko

Civil monetary penalties go the the Exchequer, not the regulator.

Whilst it's tempting to say the the costs of regulation should be recovered from the non-compliant, that would create an incentive for regulators to go round fining people rather than working to try and help businesses into compliance.

79,779,279 emails and 1,113,734 texts

heyrick

And a £140,000 fine taken as "look, we're standing up to them".

No, you're not.

Try £1 per infraction (double for those who asked for it to stop), then we'll talk about having done something.

Re: 79,779,279 emails and 1,113,734 texts

Anonymous Coward

The maximum the ICO can issue by way of CMP is £500k, under the Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010. So they could have set a higher penalty, but not by much in the grand scheme of things, and since this wasn't the worst of possible offences by a long chalk, it might be seen as reasonable given their scope for action. If you want the ICO to fine people more, then you'd need the politicians to increase the maximum penalties, and offer instruction to the ICO that penalties in general need to be higher. Arguably the low limit on penalties is intentional by government to avoid imposing high costs on the sort of big businesses that can do them favours.

Just because HF sent 80m emails, doesn't mean that all the recipients had a problem with that, many people are happy to receive emails from companies they do business with. In terms of the number of complaints, there were 8,729 valid complaints about HF marketing, so the penalty is about £13.50 per complaint.

And just for reference, the investigation started because HelloFresh cropped up many thousands of times on the 7726 spam text reporting service. I'm surprised the article didn't mention that.

Hmmm - is it just a coincidence...

Martin Gregorie

That this article seems to have a tie-in with this week's BOFH scheme?

Pascal is not a high-level language.
-- Steven Feiner