RISK

NEWS

Halfords fined for sending nearly 500,000 unwanted marketing emails

22 Sept 2022

The Information Commissioner’s Office (ICO) has fined Halfords Limited £30,000 for sending 498,179 unsolicited marketing emails to people without their consent.

Halfords came to the attention of the ICO following complaints in relation to a direct marketing email about a “Fix Your Bike” government voucher scheme, which was sent on 28 July 2020.

The government scheme allowed people to use a voucher worth up to £50 towards the cost of repairing a bicycle in any approved retailers or mechanics in England. However, Halfords’ marketing email encouraged people to book a free bike assessment and to redeem the voucher at their chosen Halfords store. This amounts to marketing its services, which would generate income for the company.

The ICO investigation found that Halfords’ email message clearly advertised a service provided by the company, and that Halfords could not rely on legitimate interest to send the marketing email, as claimed by the company.

According to electronic marketing rules, legitimate interest cannot be used as an alternative to consent when sending electronic marketing messages. The soft opt-in exemption, however, allows organisations to send electronic marketing messages to customers whose details have been obtained during the course of a sale or negotiations for similar services, but it must offer a simple way for people to opt out.

The ICO ruled that Halfords could not rely on the soft opt-in exemption for customers that received the email, as they had already not opted in to receive emails from the company.

Head of Investigations, Andy Curry said:

“It is against the law to send marketing emails or texts to people without their permission. Not only this, it is a violation of their privacy rights as well as being frustrating and downright annoying. Halfords are a household name and we expect companies like them to know and act better. This incident does not reflect well on the internal advice or processes and therefore a fine was warranted in this case. This also sends a message to similar organisations to review their electronic marketing operations, and that we will take necessary action if they break the law.”

Organisations can access ICO guidance and resources on the Privacy and Electronic Communications Regulations (PECR), which gives people specific privacy rights in relation to electronic marketing communications. The PECR give people specific privacy rights in relation to electronic communications. There are specific rules on:

  • Marketing calls, emails, texts and faxes;
  • Cookies (and similar technologies);
  • Keeping communications services secure; and
  • Customer privacy as regards traffic and location data, itemised billing, line identification, and directory listings.

Under the PECR, the ICO can issue fines of up to £500,000. It can also apply for court orders for winding-up companies and, by working closely with partners, get directors disqualified.

You may also be interested in

RELATED CONTENT

RELATED COURSES

Risk Assessment and Method Statements (RAMS) (old - don't update)
Risk Assessment and Method Statements (RAMS) (old - don't update)

The Risk Assessment and Method Statement (RAMS) course examines the HSE’s recognised five-step approach to risk assessment.

IOSH Managing Safely (old - do not use)
IOSH Managing Safely (old - do not use)

The world’s best-known health and safety certificate, designed for managers and supervisors in any sector or organisation.

IOSH Safety for Executives and Directors (OLD - DO NOT USE!)
IOSH Safety for Executives and Directors (OLD - DO NOT USE!)

IOSH Safety for Executives and Directors is designed for those who have operational or strategic accountability for a company.

Introduction to health and safety
Introduction to health and safety

Introduction to health and safety gives learners a basic introduction to managing safety in their workplace.

Data breaches: your best chance of survival
Data breaches: your best chance of survival

Data breaches: your best chance of survival

Data Sharing Code of Practice laid before Parliament
Data Sharing Code of Practice laid before Parliament

The government has laid a code of practice on data sharing before Parliament, which aims to assist organisations in legally sharing data.

Firms warned to be responsible when transferring client data
Firms warned to be responsible when transferring client data

The current economic climate is changing the way many firms operate, causing some to leave the market or merge with other firms. When this happens, th...

TikTok fined £12.7 million for misusing children’s data
TikTok fined £12.7 million for misusing children’s data

The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a ...