Site navigation

58% Rise in Fines for Spam and Data Breaches

Henry Cazalet

,

Fines for companies breaking anti-spamming rules reach new highs in hopes of deterring  businesses that pester the public. 

Since August 2015, The Information Commissioners’ Office (ICO) has issued fines of £8.7 million to companies that have broken antispam and data protection law.

The ICO has the power to hand out fines of up £500,000 to organisations that ignore the rules and they have clearly signalled their intent with an increase in fines of 58% in 2017, a rise from £2.9 to £4.9 million.

The Head of Enforcement at the ICO, Steve Eckersley stated, “companies who pester the public must understand they won’t get away with it. The ICO will take action.”

With the new GDPR regulations coming into effect on May 25th 2018, it’s more important than ever that companies understand their consumer data protection obligations and have put the necessary plans in place before the deadline.

Improved Complaints Process

Consumers are no longer prepared to tolerate unwanted messages and The ICO have made it much easier to report spam or data breaches. The greatly improved report a concern section of the ICO website, means that people can raise a complaint or concern in less than a couple of minutes.

The easier process means that consumers are far more likely to pursue a complaint rather than put up with their lives being blighted by intrusive spam.

Nuisances Calls Account for Nearly Half of All Fines

The fines data, compiled by The SMS Works, revealed that 46% (£4,017,000) of all fines issued since August 2015 were for spam phone calls. Automated outbound phones systems allow unethical companies to target people at their home address on a colossal scale.

In May 2017, Keurboom Communications, a company responsible for 99.5m spam phone calls was fined £400,000 by the ICO, the highest fine ever issued.

Highest Number of Fines for Data Breaches

34% (£2,996,501) of all fines issued since August 2015 where for data breaches, where companies have failed to adequately protect the data that they hold on consumers.

Data breaches also attracted the largest numbers of fines. A total of 41 companies and organisations were fined, accounting for 39% of all fines issued.

In addition to the recently reported £400,000 penalty handed to Carphone Warehouse, one of the most startling data breaches was by another telecoms giant, Talk Talk Telecom.

In October 2016, they were presented with a £400,000 fine for security failings that allowed cyber criminals to download the personal details of 155959 customers and the bank details of 15656.

Financial Services Sector Receives Highest Number of Fines

Financial services topped the chart as the worst industry sector for attracting ICO fines. The sector has acquired an impressive 24 separate monetary penalties since August 2015, 23% of all fines.

Surprisingly, the charity sector was second on the list, with 11 fines being handed out, accounting for 10.5% of all fines issued.

For charities, the fines were predominantly for data breaches where organisations were caught sharing donor data with other charities without the appropriate consent.

The practice of ‘data enriching’, where donors can be profiled more accurately by combining information from multiple sources is likely to become more problematic when GDPR comes into effect.

Most consumers will be unlikely to consent to their data being handed round to third parties, so that they can receive even more direct marketing.

Average Fine for SMS Spam Tops £100,000

SMS offences received the highest average fine of a hefty £108,000. Email spammers, by comparison got off relatively lightly, with the average fine being just over £40,000.

The zero-tolerance approach to spam, adopted by the ICO, is largely responsible for spam rates tumbling in recent years. It wasn’t long ago that we were all inundated with unwanted texts from PPI, pay day loan and accident claims companies.

The situation will improve further when the much tougher GDPR rules apply from 25th May this year.

Using Third Party Data for Direct Marketing – a High-Risk Strategy

Companies should be very wary of using ‘bought in’ data for direct marketing of any kind. Responsibility for ensuring that the consumers on a list have given their permission to be contacted lies squarely with the company that is initiating the marketing campaign. It is their responsibility to check that the data they are proposing to use has the correct ‘opt in’.

Credit broker Digitonomy was fined £120,000 in December 2016 for being responsible for millions of texts being sent without proper consent.

Eckersley said, “depending on the word of another company is simply not acceptable and is not an excuse. Digitonomy is paying a hefty price for not meeting its responsibilities.”

Gloomy Outlook for Spammers

Companies that are thinking of breaking the rules or bending them to their advantage will find little room for manoeuvre in a post GDPR world.

The consumer is rightly being more strongly protected by the legislation and the penalties for organisations that break the rules will become more serious. Under GDPR, the ICO can impose fines of up to 20 million Euros or 4% of group worldwide turnover, whichever is greater.

The risks for marketers, strongly outweigh any perceived reward and ignorance of the rules will be no defence. It is the responsibility of organisations of all sizes to make sure that all their activities remain compliant with the regulations.

With GDPR just around the corner, we may be entering a new spam free era, where our mobiles and inboxes are less cluttered with junk and our spam folders strangely empty. That’s something we could all look forward to.

Henry Cazalet

Henry Cazalet

Director and co-founder, The SMS Works

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data