Marketing and the Law – Considerations for Data Protection
14th February 2024
Combining the need for adherence to data protection laws with marketing activities can be difficult, especially when digital marketing is concerned. New technologies make it easier than ever to target consumers based on their online activities, but just because you are lawfully permitted to process personal data does not automatically mean you can use this data for marketing purposes.
Recently, the recipe box giant HelloFresh was fined £140,000 by the ICO for sending spam emails and texts to its customers. Following a series of complaints to ICO and OFCOM’s spam text message reporting service 7726, the ICO investigated and found that HelloFresh was in breach of Regulation 22 of PECR.
HelloFresh sent a whopping 79 million spam emails and 1 million spam texts over a seven-month period without obtaining explicit consent from their customers and prospects. The opt-in statement that HelloFresh was relying on for proof of consent was unclear and did not refer to the sending of texts, and customers were not adequately informed that their data would be kept and used for marketing purposes for 2 years after they cancelled their subscription. Some individuals (Data Subjects) continued to receive marketing texts even after they had opted out.
| “Customers weren’t told exactly what they’d be opting into, nor was it clear how to opt out. From there, they were hit with a barrage of marketing texts they didn’t want or expect, and in some cases, even when they told HelloFresh to stop, the deluge continued.”
Andy Curry, Head of Investigations at the Information Commissioner’s Office |
What UK law says about marketing and data protection
The Privacy and Electronic Communications (EC Directive) Regulations 2003, referred to as PECR in the UK, and the ePrivacy Directive in Europe, is the legislation which stipulates what organisations must do when engaging in unsolicited digital marketing activities. Different rules apply to postal marketing and between B2B and B2C electronic marketing, but when targeting consumers via an electronic medium, in a nutshell, this law says organisations must:
- Establish a lawful basis for processing data for marketing purposes, i.e. consent, and
- They must obtain explicit consent from an individual to send them marketing materials
There is a little-known exemption in PECR which allows Controllers to offer opt-out consent when the relationship is first created, but this can only be used in certain specific situations and usually consent is only valid if it is opted in. It can be by way of an empty check box or button which customers check or slide if they are happy to receive emails, text messages or other forms of communication for marketing. If a customer places an enquiry or requests a callback about a particular product or service, this can be done without considering PECR.
What is ‘unsolicited’ communication?
An “unsolicited” message refers to any communication that hasn’t been explicitly requested. Even if a customer chooses to receive an online newsletter, it might seem like they’ve asked for it, but it’s still considered unsolicited marketing. This is because the individual receiving the message can’t decide exactly what content they receive or how often they receive it. Be aware we are not just talking emails here, asking social media followers to resend your message to their contacts would be considered ‘unsolicited marketing’.
What is explicit consent?
One cannot assume that because an individual has made a purchase or interacted with an organisation, it is okay to send them marketing materials. This is something they must usually opt into, and the organisation must provide proof of this consent. Written consent is ideal, but having a customer check a box agreeing to receive marketing materials or taking the consent verbally is acceptable. An organisation must obtain consent for every form of marketing communication, from emails and texts to calls and targeted online ads. Agreeing to one form of marketing communication doesn’t mean all forms are okay – if someone has agreed to email marketing, an organisation can’t then send them marketing text messages, even if they have previously provided their phone number.
Marketing and cookies
When the GDPR was introduced, the rules surrounding consent within PECR were aligned, and you will recall that suddenly every website started asking for cookie consent. OK, I accept, many sites still do not have compliant cookie banners, but they are in breach of the PECR legislation. Whilst cookies do not contain overt personal data they often contain some form of ID, other information or IP address which can help identify a visitor. Some cookies are essential for a website to function properly and no consent is necessary. In contrast, other cookies track a user’s activity and this data can be used for marketing or analytical purposes and requires consent.
| Remarketing or Retargeting Cookies
Jenny visits a website selling wild bird food, and the site places a cookie on her device showing that she has visited the site. Should she return to the site at a future date the site owners will know that was at least temporarily interested in wild bird food, that is partly how they know to influence the price offered. However, Jenny leaves that site and logs into her social media account and sees a targeted ad for wild bird food or related products. This is because the social media company has viewed what cookies have been dropped onto Jenny’s device and this influences their marketing activity. This shared cookie mechanism is called retargeting or remarketing and is highly invasive. If this type of cookie is to be used, the visitor must be clearly informed BEFORE the cookie is dropped and their explicit consent must be obtained. |
This is why post-GDPR and amendments to PECR mean that endless cookie popups were needed, to obtain that explicit consent. Just by using the website, a user is not giving the level of consent required for marketing. The new Data Protection and Digital Information Bill will be relaxing some of the rules around cookie consent.
Social Media Marketing
There are a lot of ads on social media, as organisations don’t necessarily need explicit consent to show them in a timeline or news feed. If those ads are targeted using a user’s data, then the social media company will need to acquire consent before the user’s profiles in accessed and ads are shown. Following pressure from non-profit privacy organisation noyb, Facebook and Twitter have now implemented an opt-in/opt-out for personalised ads on their platforms. So you will still see ads if you log onto these sites or apps, but unless you opt-in to it specifically, they cannot use your data to show you targeted ads.
Does your organisation send out marketing emails or other digital marketing communications? Make sure you are compliant with the law and avoid any future mishaps with our upcoming PECR workshop and certified Marketing and the Law course.
Author: Paul Adams LLB (HONS)
Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Glossary
1 PECR – The Privacy and Electronic Communications (EC Directive) Regulations 2003
2 Soft opt-in – Regulation 22(3) PECR