Small company couldn't give a stuff about GDPR
Small company couldn't give a stuff about GDPR
Author
Discussion

Freakuk

Original Poster:

4,776 posts

180 months

Thursday 7th November 2019
quotequote all
So I received an email yesterday from a company I'd bought something from 6 months ago regarding some promotions/sales etc, but they had sent this email to all of their customers and everyone's email address was exposed.

It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.

I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?

eybic

9,212 posts

203 months

Thursday 7th November 2019
quotequote all
You could report them to the ICO depends how far you want to take it but they could in theory be fined 4% of their annual global turnover. They should have someone in the business that has overall responsibility for data and you could ask what they have done to make sure it doesn't happen again, they should have also told everyone affected that their data has been breached.

TwigtheWonderkid

49,082 posts

179 months

Thursday 7th November 2019
quotequote all
I would be tempted to send a "reply to all" email telling everyone that you've complained about the email, the dismissive response you got, and invite them all to complain to the company also!

But I'm a very immature man.

anonymous-user

83 months

Thursday 7th November 2019
quotequote all
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.

Wooda80

1,743 posts

104 months

Thursday 7th November 2019
quotequote all
The OP's reaction has got me wondering if he's on some kind of mailing list that he doesn't want other people to know about smile

You could always let the sender know that you have forwarded the email with all their customers' addresses to one of their competitors.

anonymous-user

83 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.
It's certainly Personal Data, and the actions the OP describes are exactly the kind of harm the legislation is there to prevent.

I'd drop a line to the ICO as there may be others doing the same and a cluster of complaints about the same company is likely to get at least some response.

InitialDave

15,110 posts

148 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.
I don't think that's correct.

Baldchap

9,625 posts

121 months

Thursday 7th November 2019
quotequote all
Typically email addresses will come under GDPR regs, unless it's specifically not personally identifying e.g.: info@mywork.com

Out of interest OP, was there an opt-out/unsubscribe on the mailing?

Freakuk

Original Poster:

4,776 posts

180 months

Thursday 7th November 2019
quotequote all
Most of the email addresses are first name.last name @domain.com so pretty clear what the recipients names are.

Looking at the ICO's site I need to send a email back to the sender to explain their actions and they have 30 days to respond, if that isn't satisfactory I then need to contact the ICO directly.

Limpet

6,624 posts

190 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
Does you emil adress clearly identify who you are, i.e your name. If not than it isn't really a breach.
Your email address, even if it's mranonymous@mindyourown.com is still considered personal data, and is subject to the same privacy and security guidelines as a name and address, as far as GDPR is concerned.

With regard to the OP's experience, I'm not surprised to hear that a small company couldn't give a stuff. I work for a software company, which doesn't specialise in GDPR or data security, but has offerings and some expertise in it. In my experience, medium sized and larger companies, and all of the big corporates are taking GDPR very seriously indeed, but there is a definite sense among smaller business that 'they' will go after the big names, and therefore it isn't a priority at all.

A great example is a small company we dealt with last year which freely admitted to keeping boxes of copied driving licenses and passports for temporary workers in a store cupboard that was often unlocked, and had no audit trail for who had accessed the room. No retention policy, no inventory etc etc. And the guy (the MD) honestly could not see why he should even consider doing something about this. This attitude is pretty common.

Baby Shark doo doo doo doo

15,078 posts

198 months

Thursday 7th November 2019
quotequote all
TwigtheWonderkid said:
I would be tempted to send a "reply to all" email telling everyone that you've complained about the email, the dismissive response you got, and invite them all to complain to the company also!

But I'm a very immature man.
This yes

anonymous-user

83 months

Thursday 7th November 2019
quotequote all
InitialDave said:
I don't think that's correct.
''Personal data is that which can be used to identify an individual''

If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.

Deesee

8,509 posts

112 months

Thursday 7th November 2019
quotequote all
Freakuk said:
So I received an email yesterday from a company I'd bought something from 6 months ago regarding some promotions/sales etc, but they had sent this email to all of their customers and everyone's email address was exposed.

It's not much but I emailed them back to inform them that they had shared their entire email subscription list and they should send something out as an apology, and to ensure this doesn't happen again... cut a long story short they've effective told be to FO and they couldn't care less.

I could do nothing I guess, but the attitude stinks and it worries me about the lack of controls they probably have, I won't start spamming hundreds/thousands of people who were as innocent as myself, I just want the company to acknowledge they got it wrong and apologise, any ideas?
Wow, just imagine what they have done with your credit card details and personal information...

Find out the name of the information/data controller, and write to them, if unsatisfactory escalate.

TwigtheWonderkid

49,082 posts

179 months

Thursday 7th November 2019
quotequote all
There's a patron saint of copying people in on emails.....St Francis of a cc

getmecoat

anonymous-user

83 months

Thursday 7th November 2019
quotequote all
Limpet said:
Your email address, even if it's mranonymous@mindyourown.com is still considered personal data, and is subject to the same privacy and security guidelines as a name and address, as far as GDPR is concerned.
This, combined with a quick calculation of 4% of their turnover, should grab their attention, since it would be pretty bloody difficult to defend this breach.

And perhaps a link to the ICO site detailing what's happening to BA - https://ico.org.uk/about-the-ico/news-and-events/n... , or Marriott, or....

anonymous-user

83 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''

If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
You're taking it too literally. It's not that the email will give away the identity of the person. Broadly it's that the email address is personal to the subject and their private data. Your IP address might be personal data, for example.

InitialDave

15,110 posts

148 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''

If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
What you are saying is opposed to both my own reading of the GDPR regs, and the position my company takes on it.

Rawwr

22,722 posts

263 months

Thursday 7th November 2019
quotequote all
Thesprucegoose said:
''Personal data is that which can be used to identify an individual''

If the email was spunkybob@hunter.com then it wouldn't identify a person, but if it is jack.jones etc then it would. It is pretty clear.
That's not true, I've known Spunky Bob and his wife for many years now. Lovely couple. Lots of fun.

irocfan

48,995 posts

219 months

Thursday 7th November 2019
quotequote all
TwigtheWonderkid said:
I would be tempted to send a "reply to all" email telling everyone that you've complained about the email, the dismissive response you got, and invite them all to complain to the company also!

But I'm a very immature man.
hehe me too

Andeh1

7,598 posts

235 months

Thursday 7th November 2019
quotequote all
Baby Shark doo doo doo doo said:
TwigtheWonderkid said:
I would be tempted to send a "reply to all" email telling everyone that you've complained about the email, the dismissive response you got, and invite them all to complain to the company also!

But I'm a very immature man.
This yes
I would do this and send it to ICO as well, especially if they had a st attitude in the first instance.