Small company couldn't give a stuff about GDPR
Discussion
So I received an email yesterday from a company I'd bought something from 6 months ago regarding some promotions/sales etc, but they had sent this email to all of their customers and everyone's email address was exposed.
It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.
I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?
It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.
I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?
You could report them to the ICO depends how far you want to take it but they could in theory be fined 4% of their annual global turnover. They should have someone in the business that has overall responsibility for data and you could ask what they have done to make sure it doesn't happen again, they should have also told everyone affected that their data has been breached.
Thesprucegoose said:
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.
It's certainly Personal Data, and the actions the OP describes are exactly the kind of harm the legislation is there to prevent.I'd drop a line to the ICO as there may be others doing the same and a cluster of complaints about the same company is likely to get at least some response.
Most of the email addresses are first name.last name @domain.com so pretty clear what the recipients names are.
Looking at the ICO's site I need to send a email back to the sender to explain their actions and they have 30 days to respond, if that isn't satisfactory I then need to contact the ICO directly.
Looking at the ICO's site I need to send a email back to the sender to explain their actions and they have 30 days to respond, if that isn't satisfactory I then need to contact the ICO directly.
Thesprucegoose said:
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.
Your email address, even if it's mranonymous@mindyourown.com is still considered personal data, and is subject to the same privacy and security guidelines as a name and address, as far as GDPR is concerned.With regard to the OP's experience, I'm not surprised to hear that a small company couldn't give a stuff. I work for a software company, which doesn't specialise in GDPR or data security, but has offerings and some expertise in it. In my experience, medium sized and larger companies, and all of the big corporates are taking GDPR very seriously indeed, but there is a definite sense among smaller business that 'they' will go after the big names, and therefore it isn't a priority at all.
A great example is a small company we dealt with last year which freely admitted to keeping boxes of copied driving licenses and passports for temporary workers in a store cupboard that was often unlocked, and had no audit trail for who had accessed the room. No retention policy, no inventory etc etc. And the guy (the MD) honestly could not see why he should even consider doing something about this. This attitude is pretty common.
Freakuk said:
So I received an email yesterday from a company I'd bought something from 6 months ago regarding some promotions/sales etc, but they had sent this email to all of their customers and everyone's email address was exposed.
It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.
I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?
Wow, just imagine what they have done with your credit card details and personal information...It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.
I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?
Find out the name of the information/data controller, and write to them, if unsatisfactory escalate.
Limpet said:
Your email address, even if it's mranonymous@mindyourown.com is still considered personal data, and is subject to the same privacy and security guidelines as a name and address, as far as GDPR is concerned.
This, combined with a quick calculation of 4% of their turnover, should grab their attention, since it would be pretty bloody difficult to defend this breach. And perhaps a link to the ICO site detailing what's happening to BA - https://ico.org.uk/about-the-ico/news-and-events/n... , or Marriott, or....
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''
If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
You're taking it too literally. It's not that the email will give away the identity of the person. Broadly it's that the email address is personal to the subject and their private data. Your IP address might be personal data, for example.If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''
If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
What you are saying is opposed to both my own reading of the GDPR regs, and the position my company takes on it.If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''
If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
That's not true, I've known Spunky Bob and his wife for many years now. Lovely couple. Lots of fun.If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
Baby Shark doo doo doo doo said:
TwigtheWonderkid said:
I would be tempted to send a "reply to all" email telling everyone that you've complained about the email, the dismissive response you got, and invite them all to complain to the company also!
But I'm a very immature man.
This But I'm a very immature man.

t attitude in the first instance. Gassing Station | The Lounge | Top of Page | What's New | My Stuff





me too