Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • Outgrowing your MSP; businesses need a provider that scales with their growth
  • Level 7 apprenticeship funding cuts will cost UK employers over £200m
  • Groundbreaking compliance tool to futureproof UK fashion sector
  • How much experience do you need to be a FTSE 100 CEO?
  • Four steps businesses can take to prevent expense fraud
  • Belfor UK bolsters SME offering with key hire in major & complex loss
  • 10 Most Common First-Time Investing Mistakes to Avoid
  • TravelPerk launches new medical and baggage insurance add-on
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Features»Unless you gained ‘consent’, or ‘opt-in’, yourselves, using the data is very likely to land you in trouble.
GDPR General Data Protection Regulation for European Union concept, internet
GDPR General Data Protection Regulation for European Union concept, security of personal information and identity on internet

Unless you gained ‘consent’, or ‘opt-in’, yourselves, using the data is very likely to land you in trouble.

0
Posted By sme-admin on January 13, 2021 Features

Why?

Experian and the other Credit Reference Agencies (CRAs) had been receiving data from other data brokers, their suppliers, which had been collected on the basis of ‘consent’. Key Finding 4 of the “Investigation into data protection compliance in the direct marketing data broking sector” states:

None of the consents reviewed by auditors … were valid under the GDPR.

These are the same data brokers who you are most likely to get your data from. Experian, Equifax and Callcredit/TransUnion are not foolish, and they do not merely accept the assurances of these data suppliers. The problem is with the way these data brokers are gaining consent, and then how it is being used by the CRAs. You might well ask why aren’t the ICO taking action against these data brokers? As section 81 of the Enforcement Notice issued against Experian states:Other controllers in other or linked industries may also become the subject of regulatory investigation and action on the part of the Commissioner in due course.

 So it may just be a matter of time!

Just to clear up a misunderstanding we hear from time to time, when we talk about ‘consent’ and ‘opt-in’, they can seem like different things, they aren’t. Consent and opt-in are the same thing.

What about the consent gained by these data brokers means it is not fit for purpose?

Validity of consent

For consent to be valid it must be ‘informed’. The ICO has always been clear that this requires the data subject to know who will eventually be using the data, or ‘the identity of the controller’. Indeed, in their What is valid consent? webpage, the ICO explicitly states:

If you buy in ‘consented’ data, that consent is only valid for your processing if you were specifically identified.

Most data licensed from a ‘data broker’ will fail to meet the validity test, since your organisation will not have been explicitly named when it was collected.

Be aware, some brokers have tried to include huge lists of every company listed at Companies House, for example, as potential users of the data. This is also not valid, the ICO make it plain that the information must be readily understood by the data subject. In section 53 of the Experian Limited Enforcement Report the ICO explain that notifications can faile to be sufficiently transparent if they are  overly generic … overly simplistic … or overly long

If you use data on the basis of ‘consent’ which is not valid, you will have broken the law.

Using data on a different legal basis

You may believe you can use data for direct marketing because of your ‘legitimate interest’. This may be true in some circumstances, but using data on the legal basis of ‘legitimate interests’ when it was collected on the basis of ‘consent‘ is also not legal.

The ICO is clear, if data is gained on the basis of consent to direct marketing, then consent is the only basis upon which it may be used for direct marketing, that consent still needs to be valid of course. In fact, Section 3 of the Terms of the Enforcement Notice states that within 3 months Experian must:

Delete any data supplied on the basis of consent which is now being processed on the basis of Experian’s legitimate interests.

If you use data on the basis of ‘legitimate interest’ when it was gained on the basis of ‘consent’, you will have broken the law.

How does this matter to you?

Many data brokers claim to be able to provide you data ‘with consent’, or ‘opted-in’ data. The two points above show how this is very unlikely to be the case. If your data broker suggests this, you are probably being misled!

In the past, if things went wrong, you could point the finger at your data broker and suggest they should be responsible. NOT ANY MORE.

Accountability

GDPR has a core principle of ‘accountability’, meaning you are responsible. The only way you can avoid the blame is by ‘demonstrating you are in no way responsible’. This is a deliberately high bar.

Regulators have had enough of data subject rights violations being dodged by mutual finger-pointing. The law now says everyone involved is responsible, so blaming your data broker doesn’t get you off the hook, you just need a bigger hook, because you are both on it.

Isn’t this all a storm in a teacup?

That used to be one of the prevailing thoughts about GDPR, that nothing would happen, like Y2K. Recent events are shaking that view. The ICO used to be perceived as a weak regulatory body that seldom used the extent of its powers.

The Experian enforcement notice, together with actions against BA, Marriot Hotels and others, tell us those days are long gone. As data subjects, we should be delighted, as marketers, we should be cautious, and diligent.

What can you do about it?

Logic dictates if you use data from a pre-compiled list, it cannot have consent or be opt-in, because the data subject could not have known you would use it when they gave their consent, so it cannot be informed, and thus is not valid.

The only way consent or opt-in can be valid is if it was gained by you, or specifically for you, normally as a specialist research process, or list-build, where your use is mentioned when consent is given.

If any data broker tells you otherwise, don’t use them!

This isn’t news

Back in October of 2017, we published our blog item The problem with consent covering exactly this topic in even greater depth. The ICO are now showing our interpretation is correct.

One final thought

In case you didn’t already notice this, the ICO are now seeding ‘publicly available’ data on the web. They currently do this to understand how data is harvested and used, but it would be foolish to imagine this will never be used to identify those flouting the rules.

These sources could be LinkedIn, blogs, websites, social media, in fact any place where personal data could be displayed and harvested.

Undoubtedly the safest bet is to use a reputable data broker for your data needs.

First published by Corpdata on 17/11/2020

 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How much experience do you need to be a FTSE 100 CEO?

James Wilkinson CEO of Rock Face Talks to SME Today

Leading the future: Redefining leadership in the era of agentic AI

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
Get £100 of free trades - ii trading account

The Newsletter

Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

Sign Up
Events Calendar
    • Marketing
    June 25, 2025

    From PLT to Twitter X: Business Branding Decisions That Backfired

    June 20, 2025

    Fast fashion giant Shein accused of “dark marketing” – what does it mean for businesses?

    • Finance
    July 1, 2025

    Level 7 apprenticeship funding cuts will cost UK employers over £200m

    June 30, 2025

    Groundbreaking compliance tool to futureproof UK fashion sector

    • Health & Safety
    January 29, 2025

    UK takeaways guilty of shocking hygiene failures:

    December 18, 2024

    Comment on Covid Corruption Commissioner Investigation

    • Events
    June 19, 2025

    Windsor Expo Wows: A Showcase of Success, Innovation, and Local Business!

    May 27, 2025

    Jose Ucar Confirmed for Leadership Live 2025 Speaker Line-Up

    • Community
    June 23, 2025

    Celebrating One Year In Fairford Supporting The Community

    June 2, 2025

    National Charity Accelerates Children’s Reading Through New Corporate Partnership

    • Food & Drink
    June 23, 2025

    England Cricket Captain, Ben Stokes OBE, takes a stake in Spencer Matthews’ alcohol-free spirits brand, CleanCo

    June 16, 2025

    Hospitality industry risks collapse

    • Books
    April 24, 2025

    Values-Driven Professionalism: A Path to Client Loyalty

    December 2, 2024

    Banish the banshee boss: how to lead without fear – addressing the issue of fear-based management and how NOT to be this manager

    About

    SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

    Join Our Mailing List

    Receive the latest news and updates from SMEToday.
    Read our Latest Newsletter:


    Sign Up
    X (Twitter) YouTube LinkedIn
    Most Recent Posts
    July 1, 2025

    Outgrowing your MSP; businesses need a provider that scales with their growth

    July 1, 2025

    Level 7 apprenticeship funding cuts will cost UK employers over £200m

    June 30, 2025

    Groundbreaking compliance tool to futureproof UK fashion sector

    June 27, 2025

    How much experience do you need to be a FTSE 100 CEO?

    June 27, 2025

    Four steps businesses can take to prevent expense fraud

    Categories
    • Books
    • Community & Charity
    • Education and Training
    • Environment
    • Events
    • Features
    • Finance
    • Food and Drink
    • Health & Safety
    • HR & Recruitment
    • In Profile
    • Legal
    • Marketing
    • News
    • Property & Development
    • Sponsored Content
    • Technology
    • Transport & Tourism
    • Wellbeing & Mental Health

    Copyright © 2020 SME Today.

    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact
    Copyright © 2025 SME Today.
    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact

    Type above and press Enter to search. Press Esc to cancel.