{"id":894,"date":"2020-11-11T14:46:02","date_gmt":"2020-11-11T19:46:02","guid":{"rendered":"https:\/\/encompass-digital.com\/?p=894"},"modified":"2020-11-14T19:55:05","modified_gmt":"2020-11-15T00:55:05","slug":"ico-issues-enforcement-notice-against-experian","status":"publish","type":"post","link":"https:\/\/encompass-digital.com\/pt\/ico-issues-enforcement-notice-against-experian\/","title":{"rendered":"ICO issues enforcement notice against Experian"},"content":{"rendered":"<div>\n<div class=\"WordSection1\">\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">October 27th 2020 saw the Information Commissioner issue an &#8216;Enforcement Notice&#8217; against Experian, under   DPA18, for its processing of personal data for &#8216;offline marketing services&#8217;.&nbsp;<a href=\"https:\/\/ico.org.uk\/media\/action-weve-taken\/enforcement-notices\/2618467\/experian-limited-enforcement-report.pdf\">The notice<\/a>&nbsp;covers 3 substantive issues:<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<ol start=\"1\" type=\"1\">\n<li class=\"MsoNormal\" style=\"color:#999999;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;line-height:18.0pt;mso-list:l0 level1 lfo1;background:white;box-sizing: border-box;counter-increment: item 1\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;letter-spacing:.6pt\">Fair &amp; Transparent Processing<o:p><\/o:p><\/span><\/li>\n<li class=\"MsoNormal\" style=\"color:#999999;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;line-height:18.0pt;mso-list:l0 level1 lfo1;background:white;box-sizing: border-box;counter-increment: item 1\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;letter-spacing:.6pt\">Article 14 GDPR (Failing to notify data subjects about Experian&#8217;s processing of their personal data)<o:p><\/o:p><\/span><\/li>\n<li class=\"MsoNormal\" style=\"color:#999999;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;line-height:18.0pt;mso-list:l0 level1 lfo1;background:white;box-sizing: border-box;counter-increment: item 1\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;letter-spacing:.6pt\">Failure to properly assess the lawful basis of processing<o:p><\/o:p><\/span><\/li>\n<\/ol>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">The ICO chose enforcement rather than fines because it assessed it was the &#8220;most effective and proportionate   way to achieve compliance&#8221;.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">This followed a 2 year&nbsp;<a href=\"https:\/\/ico.org.uk\/media\/action-weve-taken\/2618470\/investigation-into-data-protection-compliance-in-the-direct-marketing-data-broking-sector.pdf\">&#8216;Investigation   into data protection compliance in the direct marketing data broking sector&#8217;<\/a>.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">This document looks at how credit reference agencies have also been processing and supplying data for direct   marketing.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">The ICO recognised:<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" style=\"line-height:18.0pt;background:#F1F1F1\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">The data broking sector provides a valuable service to support organisations across the UK.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt;background:white\">Despite this they stated:<\/span><o:p><\/o:p><\/p>\n<p class=\"MsoNormal\" style=\"line-height:18.0pt;background:#F1F1F1\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">data brokers must comply with data protection law.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\" style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">Experian, a titan of the data world, fully cooperated with the ICO in the investigation. Experian believed   they had prepared thoroughly for GDPR and the new compliance regime, yet the ICO nonetheless perceived weaknesses.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">So, if you conduct direct marketing, you should be aware of the themes of non-compliance the ICO highlighted,   they demonstrate areas of concern and likely enforcement.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"transparency-and-fairness\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Transparency and fairness<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">You must provide the information required by Article 14 of GDPR, now commonly known as a&nbsp;<em><span style=\"font-family:\"arial\",sans-serif\">Fair Processing Notice<\/span><\/em>,   to each data subject. It must explain all the processing you undertake in clear and simple terms.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"processing-of-data-for-other-purposes\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Processing of data for other purposes<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">You must only process personal data for the purposes you have told the data subject about.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"lawful-basis-for-processing\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Lawful basis for processing<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">There are really only 2 suitable bases for processing for direct marketing purposes, &#8220;consent&#8221; or &#8220;legitimate interests&#8221;. You must choose the correct one, and you   must only use it in the way you have chosen. Any consent you rely upon must meet GDPR requirements for valid consent.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"legitimate-interest-assessments\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Legitimate interest assessments<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">These assessments allow you to show you have impartially considered your legitimate interests against the risks to the rights and freedoms of data subjects. You   should always conduct these and retain the evidence. (<strong><span style=\"font-family:\"arial\",sans-serif\">Please note:<\/span><\/strong>&nbsp;if you license data from Corpdata, we will normally help you to produce a draft Legitimate Interest Assessment free of charge!)<o:p><\/o:p><\/span><\/p>\n<h2 id=\"other-things-we-learn\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-family:\"arial\",sans-serif;color:#666666;letter-spacing:.6pt\">Other things we learn<o:p><\/o:p><\/span><\/h2>\n<h3 id=\"honeytraps-and-online-publicly-available-personal-data\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Honeytraps and online &#8216;publicly available personal data&#8217;<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">The ICO has undertaken proactive investigative work by &#8220;seeding personal data online&#8221; to show how data was obtained and used.<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\"><br style=\"box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <br \/>  <\/span><o:p><\/o:p><\/p>\n<p style=\"margin:0in;line-height:18.0pt;background:white\"><span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">If you harvest online information you may stumble across these &#8216;honeytraps&#8217;. If you process personal data   harvested online or process publicly available personal data, you must always provide a Fair Processing Notice to the data subject.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"proportionality\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Proportionality<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">Experian tried to assert it would require a disproportionate effort to provide a Fair Processing Notice to all data subjects (about 50 million). The ICO disagreed.   You may not rely upon this argument, especially where the processing is likely to be &#8216;unexpected&#8217; by the data subject.<o:p><\/o:p><\/span><\/p>\n<h3 id=\"due-diligence\" style=\"mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:16.5pt;font-family:\"arial\",sans-serif;color:#fc8000;letter-spacing:.6pt;font-weight:normal\">Due diligence<o:p><\/o:p><\/span><\/h3>\n<p style=\"margin:0in;line-height:18.0pt;background:white;box-sizing: border-box;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align:start;widows: 2;-webkit-text-stroke-width: 0px;text-decoration-style: initial;text-decoration-color: initial;word-spacing:0px\">  <span style=\"font-size:12.0pt;font-family:\"arial\",sans-serif;color:#999999;letter-spacing:.6pt\">The ICO is also keen to educate, so have published&nbsp;<a href=\"https:\/\/ico.org.uk\/for-organisations\/organisations-using-marketing-services-of-data-brokers\/\">information   for customers of data broking services<\/a>, including a non-exhaustive approach to due diligence. (If you would also like to see the advice about choosing a data supplier Corpdata produced in 2017,&nbsp;<a href=\"https:\/\/corpdata.co.uk\/due-diligence-questions-to-ask-data-suppliers.pdf\">you   can find it here<\/a>.)<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:14.0pt\"><o:p>&nbsp;<\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:14.0pt\">Source ** CorpData<o:p><\/o:p><\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size:14.0pt\">#privacy #gdpr #ccpa #data #dataprivacy #compliance<o:p><\/o:p><\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>October 27th 2020 saw the Information Commissioner issue an &#8216;Enforcement Notice&#8217; against Experian, under DPA18, for its processing of personal data for &#8216;offline marketing services&#8217;.&nbsp;The notice&nbsp;covers 3 substantive issues: Fair &amp; Transparent Processing Article 14 GDPR (Failing to notify data subjects about Experian&#8217;s processing of their personal data) Failure to properly assess the lawful basis&hellip;&nbsp;<a href=\"https:\/\/encompass-digital.com\/pt\/ico-issues-enforcement-notice-against-experian\/\" rel=\"bookmark\">Continue a ler &raquo;<span class=\"screen-reader-text\">ICO issues enforcement notice against Experian<\/span><\/a><\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-894","post","type-post","status-publish","format-standard","hentry","category-consulting"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts\/894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/comments?post=894"}],"version-history":[{"count":0,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/posts\/894\/revisions"}],"wp:attachment":[{"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/media?parent=894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/categories?post=894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/encompass-digital.com\/pt\/wp-json\/wp\/v2\/tags?post=894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}