What Not to Do When the ICO Comes Calling
No one likes spam texts, even when they are done accidentally, or by someone who didn’t “know” they were sending them. In the past year, the ICO has identified and taken action against a variety of companies. Some of them were clearly deliberate violations of the regulations, but quite a few were not.
The most recent example (at the time of this writing), fell into the latter category. The company apparently thought they met the regulatory requirements. But the ICO felt differently. What happened next is the lesson of this blog.
Specifics of the case
Early in January 2016, the ICO began receiving complaints about PRS Media sending unsolicited text marketing messages. The complaints continued through May of that year, totaling 2,629 in five months.
It turned out the company runs a competition and prize draw website that it used to gather mobile numbers for marketing purposes. To enter a competition, a person must agree to their terms, which included statements about receiving marketing messages.
On the surface, that arrangement might sound reasonable. People signed up in order to enter the competition, so they shouldn’t complain about getting the messages, right? But that isn’t what the rules say about SMS marketing.
Based on the complaints, the ICO requested information from the company on their practices and proof that the people they messaged had provided consent. After further investigation, they found that 4.4 million text messages were sent by the company based on their website “consent” to terms and conditions.
Here's where it went wrong
PRS Media ignored the first two requests for information by the ICO. They simply didn’t do anything to address the concerns or complaints received.
Later in August and September 2016, the ICO requested more information and never received a response.
As a result, this past March the company was fined £140,000 for sending 4.4 million spam texts.
It didn't have to be this way
Based on the description of how PRS operated it’s SMS marketing, they certainly were going to have some sort of penalty from the ICO. It’s no longer sufficient to have a check box where someone agrees to terms and conditions that they probably never read (does anyone?).
But the Commissioner has many options when it comes to the action it takes against companies. And it seems that many of the decisions (monetary ones especially) come down to how the company handled the problem.
For example, in the Monetary Penalty Notice issued to PRS Media Limited, it specifically states that the breach was not deliberate. In other words, the Commissioner didn’t believe the company was trying to scam or circumvent regulations on purpose. They weren’t following the regulations, but it wasn’t intentional (my interpretation of the notice), though they should have known better.
However, because of how the company responded, the penalty was greater than it might have otherwise been. Here are the “aggravating features” of the case identified in the notice:
“PRS Media Limited failed on two separate occasions to answer requests for information and it required the service of an Information Notice to compel a response.”
“The response received from PRS Media Limited to the Information Notice provided unsatisfactory answers to the questions asked and figures provided were at odds with the Commissioners own findings.”
The result of the company’s inaction in response to the ICO requests resulted in the seriously hefty fine.
If it happens to your company
Staying compliant with the regulations isn’t hard. Even though there are changes coming with the GDPR next year, the ICO publishes easy to follow guidance on how to make sure your company stays on track.
But if somehow you end up with spam complaints and a letter from the ICO asking for more information – do everything you can, as fast as you can, to comply with the request. There may be consequences for not doing something correctly, but things will be much worse if you try to hide, ignore or talk your way out of it.
All businesses are subject to the law when it comes to advertising and marketing. Companies cannot make false claims or mislead consumers via advertising materials, for example. Designed to protect consumers and commercial clients, the law regulates most forms of marketing in some way. With companies carrying out various forms of marketing activity, it can be difficult to keep on top of the relevant laws and guidelines. By working with SMS marketing experts, however, you can ensure that your marketing campaigns are fully compliant with the necessary laws and that you’re able to connect with your target audience lawfully and effectively.
Mobile marketing offers an unprecedented access to your customers virtually any time, anywhere. This is particularly true for SMS marketing because it is “always on”. Customers don’t have to be surfing the web, or using an app to receive messages. Instead, they see the marketing messages right alongside ones from their friends and family.
In last week’s blog I covered how the Trump campaign sent unsolicited SMS messages to voters. This week I’m stuck on the same topic, but from a totally different angle: what we can learn from that failure. Because honestly, their biggest issue might not be violating the law. It might be the people they have writing their SMS messages. It’s time to dissect the message that spawned the law suit, and learn what we can from it.
SMS marketing is very different to most other more traditional marketing tools, specifically because of its short-form, text only nature. This certainly shouldn't put you off though. We have put together our guide to both the best things about SMS marketing and some of the potential problems, and how to work around them.
Four years ago, reputable commentators in The Guardian were wondering if SMS - short message service or text messaging - had peaked in performance after a two-decade exponential rise. Here we look at the evidence which shows that SMS is not only going strong, but continuing to stand out as an essential marketing channel for many businesses.
Late last month reports surfaced that the Trump US presidential campaign had sent unsolicited SMS messages to voters in the Chicago area. One man, Joshua Thorne, and his lawyers have filed a class-action lawsuit alleging the Trump Campaign violated the Telephone Consumer Protection Act (TCPA, the US equivalent of the PECR).
The UK may be leaving the EU, but the GDPR is still coming. Find out what it means for your business, and your SMS messaging, in our post that looks ahead and reviews the ICO guidance to prepare for the new rules.
The first thing to remember is that legally, you must give the customer the chance to both opt-in and opt-out of your SMS campaign - but the good news is people are happy to opt-in - 49% of them according to a 2014 survey. So all you need to do is stay compliant and follow some basic guidelines to grow your list.