The Data Commissioner makes an example of ‘online recruitment’ firm
14th April 2023
The Data Commissioner makes an example of ‘online recruitment’ firm in a bid to deter others from sending spam emails.
The problem regarding the sending (and receiving) of spam emails is widely known and has often been reported in the media. This is one of the reasons that the ICO gave as to why it felt it necessary to issue a £130,000 fine to ‘Join the Triboo Limited’ for delivering 107 million emails to 437,324 distinct individuals.
The ICO basically said, and we round up several paragraphs of legal wording in our summary here . . Join the Triboo Ltd should have known better.
So as such, they have received a rather large fine, and this shot across the bows of the industry, and this kind of practice will not be tolerated by the ICO:
“The Commissioner’s underlying objective in imposing a monetary penalty notice is to promote compliance with PECR. The sending of unsolicited direct marketing messages is a matter of significant public concern. A monetary penalty in this case should act as a general encouragement towards compliance with the law, or at least as a deterrent against non-compliance, on the part of all persons running businesses currently engaging in these practices. The issuing of a monetary penalty will reinforce the need for businesses to ensure that they are only messaging those who specifically consent to receive direct marketing.” Point 79 of the ICO’s Monetary Penalty Notice to Join the Triboo Limited 12 April 2023.
What did Join the Triboo Limited do wrong?
Join the Triboo Limited run several ‘recruitment’ websites, but it appears that when you drill down, their main purpose ‘might’ be data collection.
The Privacy Policy (and they did have one) states that if you share your details with them, they may sell it on:
“With your consent, we may share, rent and sell your personal data or sell or rent our entire database to our partners and clients in any sector for any Commercial Purpose, including marketing activities. By marketing activities, we mean the communication directly to particular individuals by e-mail, post, telephone or SMS of any advertising or marketing material in respect of any product or service from us, our partners or clients.” Point 25 of the ICO’s Monetary Penalty Notice
Broadly speaking, the people who received the emails did consent to this – however, that does not make it legal.
Firstly, what they are consenting to (for example, the selling of their data to an unknown entity) is not permitted under PECR – the Privacy and Electronic Communication Regulation 2003, which regulates email marketing in this country.
Secondly, the ICO pointed out that it was UNCLEAR as to what individuals were consenting – again, this is not permitted under PECR.
This legislation says that organisations must only send marketing emails to individuals if they have agreed to receive them, except where there is a clearly defined customer relationship – for example, if you have recently bought a product or service from the organisation before.
An additional layer on top of PECR considerations is the GDPR which is concerned with the actual lawfulness of processing personal data. Under the GDPR, if you rely upon an individual’s consent to process their information and you wish to share this with other Controllers, then those Controllers must be clearly named at the time of the data collection. You cannot simply list sector or industry types which historically was the case.
The ICO make no bones about it in their Penalty Notice – they have widely publicised this fact and have published a lot of guidance for organisations. They are not accepting ignorance as a defence. (Especially in this case, as the ICO mention that Join the Triboo Ltd has been operating in this sphere for many years).
What does this mean for you?
Are you sending emails to individuals? Do you know what that means? The rules are different if you are emailing people at work (although if they are using a generic Gmail or Hotmail email address or if that work address is for a sole trader, the rules are different again).
You must also consider before you commence with any unsolicited electronic marketing, has the personal data has been collected and processed lawfully under the GDPR?
If you are not sure – please check. There is some guidance from the ICO here, or to make things easier for you and to prove due diligence on your part, why not enrol on our marketing and the law course, which covers all of this in a really user-friendly way to help you to understand how you can legally use personal information to carry out electronic marketing to grow your business?
If you have any immediate concerns, why not take advantage of your complimentary thirty-minute consultation with one of our specialists here?
Find out more about our Level 2 Marketing and the Law course OR our PECR virtual workshop here.
Peace of mind is just a click away.