The Irish authority welcomes the conviction for unsolicited marketing violations

The Irish Data Protection Commission (DPC) has initiated criminal proceedings against a company for repeated breaches in electronic marketing solicitation. The case highlights the data controller's responsibility, even in the event of a technical failure by a processor, and the consequences of failing to comply with opt-out requests.

Facts and context

The Irish data protection authority (Data Protection Commission, DPC) issued a statement regarding the outcome of criminal proceedings against Brown Thomas Arnotts Limited (including a conviction to pay €1,000 to a charity and €1,000 in legal costs) for breaches related to electronic marketing solicitation.

The case follows several complaints received by the authority concerning individuals' inability to unsubscribe from the company's marketing communications.

Grounds for the decision

The court found the company guilty of several violations of Irish privacy regulations in electronic communications, after it pleaded guilty to five charges out of a total of twenty-one. It is noteworthy that the company had already received a warning from the DPC in March 2022 for similar facts.

  • Obligation to provide an effective opt-out mechanism (Regulation 13, paragraph 12, of regulatory act 336 of 2011): The authority noted that the company did not provide recipients with a valid address allowing them to object to receiving future marketing emails. An intermittent technical issue related to third-party software rendered the opt-out function inoperative, constituting a violation of privacy regulations in electronic communications.
  • Obligation to obtain valid consent (Regulation 13, paragraph 1, of regulatory act 336 of 2011): It was established that the company continued to send marketing communications to individuals who had withdrawn their consent. In some cases, complainants had directly notified the company, in person or by phone, of their wish to no longer receive solicitations, but the mailings continued.

Authority's decision

Consequently, the court ordered Brown Thomas Arnotts Limited to make a charitable donation of €1,000 to the organization "Les Dîners à un Sou de la Petite Fleur" and to pay €1,000 in legal costs to the authority.

Lessons learned

This decision reminds that:

  • The data controller remains fully responsible for the compliance of data processing, including in the event of a technical failure attributable to a processor or software provider.
  • Opt-out mechanisms (objection) must not only be implemented but also tested and maintained to ensure their ongoing effectiveness and to take into account consent withdrawals expressed through any channel.
  • Breaches of electronic marketing regulations can lead to criminal proceedings, beyond the usual administrative sanctions.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire