Spam crusade lands charity in hot water with data watchdog
- Reference: 1709631009
- News link: https://www.theregister.co.uk/2024/03/05/penny_appeal_ico_investigation/
- Source link:
The Information Commissioner's Office (ICO) has ordered Penny Appeal, which sends aid to more than 30 crisis-hit countries worldwide, to cease and desist.
The charity was found to have dispatched more than 460,000 unsolicited texts during a ten-day period to 52,000 people that had not consented to receive the messages or had "clearly opted out," the ICO said.
[1]
Following receipt of the texts, the ICO and Mobile UK's Spam Reporting Services received 354 complaints. Among them individuals reported saying their opt-out replies were ignored and others described the messages as "intrusive" and often received late at night.
[2]
[3]
During the course of its official probe, the ICO says it found Penny Appeal had constructed a new database and users' requests to opt out were not recorded, with messages transmitted to "anyone that had interacted" with the charity inside the past five years.
The watchdog has been engaged with Penny Appeal since 2020, addressing prior complaints about a similar campaign in the past. The charity had previously "committed to improving compliance with direct marketing law" yet the latest batch of complaints show it was "still sending illegal marketing texts," the ICO said.
[4]
Penny Appeal has 30 days to stop sending marketing comms for which it doesn't have valid consent, something the data regulator wants to remind all charities of.
[5]To BCC or not to BCC – that is the question data watchdog wants answered
[6]Cops visit school of 'wrong person's child,' mix up victims and suspects in epic data fail
[7]Insider steals 79,000 email addresses at work to promote own business
[8]Home improvement marketers dial up trouble from regulator
Andy Curry, head of investigations at the ICO, said in a statement: "Penny Appeal inundated people with text messages, with no regard for their consent or their right to opt out. This is unacceptable and we will act decisively to protect the public from unsolicited marketing texts."
"We also appreciate that small charities may need a helping hand when it comes to understanding the law. However, this is not an excuse for breaking it. All organisations sending direct marketing messages are responsible for ensuring they have valid consent to contact every recipient."
Charities falling under the glare of the ICO is not unheard of. In 2018, a counseling charity attracted the watchdog's ire after leaving [9]confidential files in a former office building . And [10]11 charities were fined in 2017 over dealings with people's personal data, including Cancer Research UK and Oxfam.
Mostly, however, it is still commercial organizations that are falling afoul of the regulator. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zeb7XH@9QQDde10zCjxXfwAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zeb7XH@9QQDde10zCjxXfwAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zeb7XH@9QQDde10zCjxXfwAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zeb7XH@9QQDde10zCjxXfwAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/12/15/to_bcc_or_not_bcc/
[6] https://www.theregister.com/2024/03/01/west_midlands_police_data_protection/
[7] https://www.theregister.com/2024/02/20/insider_steals_79000_email_addresses/
[8] https://www.theregister.com/2024/01/17/ico_cold_call_fines/
[9] https://www.theregister.com/2018/02/15/cgl_tameside_council_data_breach_filing_cabinet/
[10] https://www.theregister.com/2017/04/05/ico_fines_eleven_big_charities_over_dirty_data_dealings_chasing_funds/
[11] https://whitepapers.theregister.com/
I am sure there are many worthwhile charities out there, but since the government brought in special taxation rules for charities, it's become the organisation of choice for scammers and professional beggars who line their own pockets while supported "a good cause".
Some years ago, the company I worked for was being relentlessly spammed by a "charity" and I went as far as phoning their managing director and asking them to stop emailing us. Her response was that according to her marketing people we must have at some point given consent so it was perfectly OK for them to email us. And although their emails contain a unsubscribe link, there's no legal obligation for them to actually unsubscribe people. And so they carried on regularly spamming us.
I wrote a carefully worded letter telling them that they were explicitly not authorised to access to our email server and that I would collect evidence of any further accesses with a view to prosecuting them under section 1 of the computer misuse act (unauthorised access to a computer). I printed out the act, highlighted the relevant passage and suggested they consult a solicitor. The spam stopped and we never heard from them again.
Imagine donating to a charity
and seeing that donation ending up paying a fine ....
STOP
"Penny Appeal has 30 days to stop sending marketing comms for which it doesn't have valid consent"
What? No, stop sending marketing comms UNTIL you've checked consent has been given. It's not like they're first time "accidental" offenders.
Bloody chuggers (Charity muggers).