The Information Commissioner’s Office (ICO) has hit financial services company LADH Limited with a £50,000 fine for violating General Data Protection Regulation (GDPR) standards, stemming from the inundation of clients with tens of thousands of unsolicited spam messages. Found guilty of sending over 31,000 letters without valid consent, the company neglected to offer recipients an option to opt out, running afoul of several fundamental GDPR principles.
GDPR lays out essential requirements for valid consent, necessitating that it must be freely given, specific, informed, and entail an unambiguous indication of the data subject’s agreement to personal data processing. Following the ICO fine, delving into GDPR’s nuances on consent reveals the complexities and safeguards essential for compliance.
As per GDPR, when processing hinges on the data subject’s consent, the controller must demonstrate the freely given and explicit nature of that consent. Particularly in cases involving written declarations on unrelated matters, safeguards should be in place to ensure the data subject comprehends the scope and implications of their consent.
Council Directive 93/13/EEC[1] further underscores that consent forms, pre-formulated by the controller, should be presented in a clear, easily accessible manner, utilising plain language and void of unfair terms. The data subject should, at a minimum, be aware of the controller’s identity and the specific purposes for processing their data for their consent to be deemed informed.
When the data subject faces constraints that impede their ability to make an independent choice, consent is not considered to be freely given. When there is a clear imbalance between the data subject and the controller, especially if the controller is a public authority, it is presumed that consent may not have been freely given.
To ensure genuine free will, consent should not serve as a valid legal basis when a significant imbalance exists. This is particularly relevant when a public authority is the controller, as the likelihood of freely given consent diminishes. Moreover, if separate consent cannot be provided for distinct personal data processing operations or if contractual performance depends on consent, questions arise regarding the authenticity of that consent. The ICO’s enforcement action against LADH Limited serves as a stark reminder of the importance of adhering to GDPR’s consent requirements to safeguard individuals’ privacy rights on our e-commerce platform.
[1] At the moment of writing this article, the ICO is using Regulation (EU) 2016/679 of the European Parliament and of the Council. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/lawful-basis-for-processing/consent/


