Blog

What happens if we don’t comply with the laws?

This is the last in our blog series looking into data compliance when you are marketing by email.

In our previous posts, we looked at the laws that apply when marketing using personal data and introduced the fictitious company All Things Stationery to help as we took a deeper dive into PECR and GDPR.

If you need a reminder or haven’t read them, we suggest going back to the beginning and starting with: An Introduction to Direct Marketing by Email.

Image of 2 notebooks & pencils on a white background. Top notebook is pastel pink, bottom notebook is marbled

We established that All Things Stationery can rely on the soft opt-in for individual subscribers under PECR, and today we’re going to look at what would happen if we didn’t meet those 5 requirements, but chose to continue to rely on it anyway. 

You may be able to guess.

The Information Commissioner’s Office (ICO) could undertake an investigation and they do take action against businesses who fail to comply with data protection laws.

Here’s a quick reminder of who the ICO are and what they do.

  • They are the UK’s independent body set up to uphold information rights.
  • They oversee the public, private & charity sector’s compliance of various legislation, including data protection law. Their role is to cover various legislation that relates to our rights as individuals, in particular data protection legislation. 
  • They prepare and publish codes of practice that sit alongside data protection legislation. You should comply with any published codes of practice.  These are more than just guidance.
  • They produce lots of guidance and tools for organisations to help them interpret the legislation and apply it within their organisation
  • They issue Regulatory Actions on organisations who do not comply with the data protection legislation e.g. enforcement notices, monetary penalty, compulsory audit.

One of the main roles they undertake is to improve the information rights practices of businesses by gathering and dealing with concerns raised by members of the public.

Each year they address tens of thousands of enquiries, written concerns, and complaints about information rights issues, including data protection.

Once a concern is raised with the ICO, they record and consider it.  Where necessary they will collect further information from the business about their data protection practices which helps them decide on any improvements they give to that business to undertake.

In cases where a clear and serious breach of data protection law has taken place, the ICO will take direct action.

If they decide that there has been a serious failure to comply with the law, they will provide advice and instruction to help ensure the business gets it right in the future.

If they find a business isn’t taking its responsibilities seriously, they have the power to take enforcement action.

Where there has been a serious contravention of GDPR, they can serve a monetary penalty of up £17.5 million, or 4% of your total worldwide annual turnover, whichever is higher. 

Could you imagine?

This is why it’s so important to ensure you have your data processes in check.

In June 2021, the ICO fined Papa John’s (the pizza company) £10,000 for not complying with all the requirements of soft opt-in.

That is a fair chunk of money for any small business to pay should they get the soft opt-in wrong.

In the case of Papa John’s, the ICO received 15 complaints from customers about the unwanted marketing they were receiving by text and email.

This is why it’s so important to ensure you have your data processes in check.

June 2021, the ICO fined Papa John’s (the pizza company) £10,000 for not complying with all the requirements of soft opt-in.

That is a fair chunk of money for any small business to pay should they get the soft opt-in wrong.

In the case of Papa John’s, the ICO received 15 complaints from customers about the unwanted marketing they were receiving by text and email.

In particular, these complaints noted the distress and annoyance the marketing messages were causing the individuals who hadn’t signed up for them.

As complaints had been made, the ICO, as we know, was duty-bound to investigate.

Image of a hand holding a phone. The phone has an email icon with the word SPAM underneath

So what did they find?

The ICO investigation found:

  • between 1 October 2019 and 30 April 2020, Papa John’s sent over 210,000 marketing messages.
  • that Papa John’s was claiming to rely on the ‘soft opt in’ exemption in order to send marketing texts and emails.

Now we know from our blog, What is PECR and what does it mean in Email Marketing? this exemption allows you to send electronic marketing messages to customers when you meet certain criteria. 

This includes when you have offered a simple way for people to refuse or opt-out when you first collect their personal data.

The ICO ruled that Papa John’s could not rely on this exemption for customers that had placed an order over the telephone, as they had not been given the option to opt-out at the point of contact. Additionally, the ICO found that these individuals were also not provided with a privacy notice.

This is what Andy Curry, ICO Head of Investigations had to say about it:

“The law is clear and simple. When relying on the ‘soft opt in’ exemption companies must give customers a clear chance to opt-out of their marketing when they collect the customers details. Papa John’s telephone customers were not given the opportunity to refuse marketing at the point of contact, which has led to this fine.

We will continue to take action against companies who may be gaining unfair advantage over those companies that adhere to the law and comply with electronic marketing law”

Note this last paragraph in bold – the ICO does and will take action against those that don’t comply. 

This is one of the reason’s why it’s really important to get your marketing activities and the use of personal data right as it’s an area that the ICO issues the most fines for. 

What’s more, the ICO names and shames businesses that aren’t compliant.

All the enforcement actions they have taken are published on their website.  You could risk getting your name up in lights!

Thinking about this another way is how it will affect your business if you get marketing wrong. 

Remember, marketing is a very emotive issue with individuals, you’ll find individuals are happy to give you their personal data for a service you provide but don’t necessarily want to be bombarded with marketing messages from businesses. 

They like to choose their marketing options.

So, the consequences of getting your marketing activities wrong include damage to your:

  • Reputation
  • Brand
  • Customer relationship
  • Finances
    • loss of income;
    • potential fine to pay

We’ve just shown you an example of your customers taking action if you fail to comply with your legal obligations. Our customers are much more aware of their rights and that knowledge continues to grow, if they think you are in breach, they may report you to ICO.

An interesting point to note here is it may not be your customers or clients that report you. 

It is getting to be fairly common that businesses will report their competitors or other businesses if they see wrongdoing – so it may not always be a complaint from a customer!

Just to re-iterate that if the ICO receives a complaint they are duty-bound to investigate. 

This doesn’t necessarily mean they are going to come knocking at your door and raid your office – like the Cambridge Analytica scandal.  But they will get in touch with you and they will ask you lots of questions about your processing and want to see evidence of how you are complying with data protection laws.

During this series, we have been looking specifically at direct marketing by email., However, there are many other ways of sending direct marketing, such as:

  • post
  • ‘live’ calls
  • automated calls
  • electronic mail
  • online advertising
  • social media
  • offline, such as:
    • prospecting and networking
    • events and exhibitions
    • referrals
  • other technologies, such as:
    • subscription tv and ‘over the top’ services;
    • facial recognition or detection;
    • in-game advertising;
    • mobile apps;
    • location-based;
    • connected devices

For each of the ways that you undertake marketing, you must check your compliance with both PECR and GDPR.  In particular, PECR as it sets out different rules for different ways to send marketing by an electronic method.

We bet you’re now thinking ‘OK, that’s brilliant, I have all the information I need, but where do I start?”

Don’t worry, we can help!

The first thing you need to do is review how you are undertaking all your marketing activities and from there you’ll see if there are any improvements that need to be made.

You can do this by asking yourself the following questions.

  • What methods do you use to send marketing? E.g. email.
  • Does PECR apply to your marketing?
  • Do you need to get the consent of the individual?
  • Which GDPR lawful ground are you going to rely on?
  • What did you tell people when you collected their personal data?
  • How are you letting people comply with their right to unsubscribe?

AND most importantly get help if you need it.

Don’t sit and struggle to understand if you are doing this right or not.

Data protection law is a complex area which is why it takes years of working in this profession to build up a robust knowledge of the laws and how to apply them.

If you need any questions or support with your data compliance, then please contact us via our Contact Form


As mentioned in our previous blog posts, we are applying UK data protection laws only as All Things Stationery only sells its products to businesses in the UK.  If you market to the EU or internationally you also have to comply with the domestic data protection and e-privacy laws applicable in the countries you specifically target. They do have different rules, so do be careful if you undertake marketing to customers or businesses in other countries.

Need a re-cap of the terminology used in GDPR & PECR, head to our blog here: Understanding the terminology used in GDPR & PECR

Information Commissioners Office (ICO): https://ico.org.uk/for-organisations/data-protection-fee/register/