What Not to Do When the ICO Comes Calling

No one likes spam texts, even when they are done accidentally, or by someone who didn’t “know” they were sending them. In the past year, the ICO has identified and taken action against a variety of companies. Some of them were clearly deliberate violations of the regulations, but quite a few were not.
The most recent example (at the time of this writing), fell into the latter category. The company apparently thought they met the regulatory requirements. But the ICO felt differently. What happened next is the lesson of this blog.
Specifics of the case
Early in January 2016, the ICO began receiving complaints about PRS Media sending unsolicited text marketing messages. The complaints continued through May of that year, totaling 2,629 in five months.
It turned out the company runs a competition and prize draw website that it used to gather mobile numbers for marketing purposes. To enter a competition, a person must agree to their terms, which included statements about receiving marketing messages.
On the surface, that arrangement might sound reasonable. People signed up in order to enter the competition, so they shouldn’t complain about getting the messages, right? But that isn’t what the rules say about SMS marketing.
Based on the complaints, the ICO requested information from the company on their practices and proof that the people they messaged had provided consent. After further investigation, they found that 4.4 million text messages were sent by the company based on their website “consent” to terms and conditions.
Here's where it went wrong
PRS Media ignored the first two requests for information by the ICO. They simply didn’t do anything to address the concerns or complaints received.
Eventually, the ICO was compelled to take the formal route of sending an Information Notice that legally requires organisations to provide the information requested. This time, the company pointed the ICO to their privacy policy and terms and conditions listed on their website.
Later in August and September 2016, the ICO requested more information and never received a response.
As a result, this past March the company was fined £140,000 for sending 4.4 million spam texts.
It didn't have to be this way
Based on the description of how PRS operated it’s SMS marketing, they certainly were going to have some sort of penalty from the ICO. It’s no longer sufficient to have a check box where someone agrees to terms and conditions that they probably never read (does anyone?).
But the Commissioner has many options when it comes to the action it takes against companies. And it seems that many of the decisions (monetary ones especially) come down to how the company handled the problem.
For example, in the Monetary Penalty Notice issued to PRS Media Limited, it specifically states that the breach was not deliberate. In other words, the Commissioner didn’t believe the company was trying to scam or circumvent regulations on purpose. They weren’t following the regulations, but it wasn’t intentional (my interpretation of the notice), though they should have known better.
However, because of how the company responded, the penalty was greater than it might have otherwise been. Here are the “aggravating features” of the case identified in the notice:
“PRS Media Limited failed on two separate occasions to answer requests for information and it required the service of an Information Notice to compel a response.”
and
“The response received from PRS Media Limited to the Information Notice provided unsatisfactory answers to the questions asked and figures provided were at odds with the Commissioners own findings.”
The result of the company’s inaction in response to the ICO requests resulted in the seriously hefty fine.
If it happens to your company
Staying compliant with the regulations isn’t hard. Even though there are changes coming with the GDPR next year, the ICO publishes easy to follow guidance on how to make sure your company stays on track.
But if somehow you end up with spam complaints and a letter from the ICO asking for more information – do everything you can, as fast as you can, to comply with the request. There may be consequences for not doing something correctly, but things will be much worse if you try to hide, ignore or talk your way out of it.
Related Articles
How important is it to run an SMS opt in campaign?
A Demonstration on How Not to Build Your SMS List
Over the last month or so I've signed up for quite a lot of webinars. I'm always trying to learn more about technology, marketing, best practices – you get the idea. So I've been excited to see many organisations offering SMS reminders for webinars. But there is one experience I had with an SMS reminder for a webinar that I simply had to share.
What You Can Learn About SMS Marketing from These 7 Companies
The Information Commissioner’s Office (ICO) issued seven monetary penalties against companies this year. We’ve read through them all – so you don’t have to – and discovered two lessons every company should learn about SMS marketing if they want to be successful.
Why You Need a Blacklist and What It Can Teach You
One of the major metrics in SMS marketing is how many people opt in to receive your messages. But there’s a flip side to that metric: how many people opt out. In the ideal world, no one would ever leave your list and instead continue to make purchases or support your organisation for as long as you decide to message them.
Why you want to keep your SMS marketing database clean
SMS Marketing: An Essential Guide to PECR
The PECR Regulations, better known as the Privacy and Electronics Communications (EC Directive) Regulations 2003 are one of the most important pieces of legislation affecting those involved in SMS Marketing. They exist to safeguard the privacy and use of personal information when used for direct marketing through electronic means, including communications by SMS. Parts of it crossover with the Data Protection Act 1998 (DPA) and where it does so, both pieces of legislation should be complied with. Unlike the DPA, the PECR is obligatory whether or not you process personal data in the course of your business. Read this essential guide to PECR for SMS Marketing to ensure you know everything you need to know.
What Not to Do When the ICO Comes Calling
The regulations about SMS marketing are quite clear. But sometimes people, and companies, can make mistakes. Find out what happened to a company that reacted poorly to the ICO’s request for information, and how it made their situation so much worse.
Never Use SMS Marketing the Way This Company Did
You’d think a large, multinational company would have all the resources and planning it needed to run an SMS marketing campaign. But that isn’t always the case apparently. Find out the big mistake this one company made and how you can avoid doing the same thing in this blog.
Proof SMS Messaging Gets Results: Giveaways and Contests
Companies use contests and giveaways all the time. It turns out that doing them over SMS messaging works really well, and offers some advantages over other channels. Read our blog to see the types of results various companies achieved when using SMS giveaways.