Security

Papa don't breach: UK data watchdog fines that other pizza place £10,000 over unsolicited marketing blitz

Papa John's falls foul of 'soft opt-in' exemption in PECR rules


Pizza takeaway and delivery outfit Papa John's has been fined £10,000 by the UK's data watchdog for sending marketing fluff to punters without their say-so.

Following a year-long investigation, the Information Commissioner's Office (ICO) found that the company had sent 168,022 "nuisance marketing messages to its customers without the valid consent required by law."

One of the unnamed complainants said they had "never [given their] consent for marketing text messages" resulting in "distress."

Another said they had received almost 100 messages in what was described as the "textbook definition of harassment."

The case hinges on rules in the Privacy and Electronic Communications Regulations (PECR) 2003.

In particular, the ICO found that Papa John's was relying on the "soft opt-in" exemption to send marketing texts and emails.

The "soft opt-in" exemption – for those unfamiliar with Regulation 22(3) PECR – means that organisations can send marketing messages by text and email to individuals whose details they've obtained in the course or negotiation of a sale, and in respect of similar products and services.

However, the organisation must also give the person a "simple opportunity to refuse or opt out of the marketing," both when first collecting the details and in every message after that.

This, ruled the regulator [PDF], was the snag.

"The law is clear and simple," said Andy Curry, ICO Head of Investigations. "When relying on the 'soft opt-in' exemption, companies must give customers a clear chance to opt out of their marketing when they collect the customers' details.

"Papa John's telephone customers were not given the opportunity to refuse marketing at the point of contact, which has led to this fine."

A Papa John's spokesperson told The Register: "Clearly, our intention was to reach only those potentially interested in our offers and we apologise unreservedly to any customers who were inconvenienced. Since this happened, we have performed a thorough review to ensure that we have got the correct permission from those we contact."

In May, American Express was fined £90,000 by the ICO after spamming people who opted out of its marketing emails with 4.1 million unwanted messages.

In the same month, the ICO fined Tested.me Ltd of St Albans £8,000 for sending 84,000 direct marketing emails without consent to people who had provided their personal data for contact-tracing purposes. ®

Send us news
19 Comments

Spam crusade lands charity in hot water with data watchdog

Penny Appeal sent more than 460,000 texts asking for money to help war-torn countries, no opt out

Cops visit school of 'wrong person's child,' mix up victims and suspects in epic data fail

Data watchdog reprimands police force for confusing 2 people with same name and birthday to disastrous results

ICO fines spam slinging financial services biz

It's all very well offering 'Free Debt Help,' but recipients were unwilling, says watchdog...

Home improvement marketers dial up trouble from regulator

ICO slaps penalties on two businesses that collectively made more than 3 million cold calls

Data regulator fines HelloFresh £140K for sending 80M+ spams

Messaging menace used text and email to bombard people

To BCC or not to BCC – that is the question data watchdog wants answered

The dos and don'ts of bulk emailing

Britain's Ministry of Defence fined £350K over Afghan interpreter BCC email blunder

UK GDPR penalty slashed from £1M after department agrees to improve processes

Manchester's finest drowning in paperwork as Freedom of Information requests pile up

Enforcement notice issued months after data regulator schooled police force

Watchdog bites back against blockage of $9M fine on US selfie-scraper Clearview AI

Britain's ICO claims tribunal misinterpreted law, wants case revisited

Regulator says stranger entered hospital, treated a patient, took a document ... then vanished

Scottish health group to tweak security checks, access authorization to avoid a repeat

UK's cookie crumble: Data watchdog serves up tougher recipe for consent banners

30 days to get compliant with tracking rules or face enforcement action

UK data watchdog fines three text spammers for flouting electronic marketing rules

'High-pressure' sales tactics targeted people registered with Telephone Preference Service