Leave.EU faces big fine over data law breaches
Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
The information commissioner, Elizabeth Denham, has revealed large fines for data misuse in the run-up to the EU referendum in 2016.
As explained on the commissioner's website, a move has been made to fine two companies a total of 135,000. Both Leave.EU and the Eldon Insurance company owned by the Brexit-backing Aaron Banks were fined 60,000 apiece for "serious breaches" of laws dictating electronic marketing. In addition, Leave.EU received an extra 15,000 fine for sending 300,000 emails to Eldon customers promoting Brexit.
"More than one million emails were sent to Leave.EU subscribers over two separate periods which also included marketing for GoSkippy [the trading name for Eldon] services, without their consent. This was a breach of PECR regulation 22," the report reads.
"We have issued a preliminary enforcement notice to Eldon Insurance under s40 of the DPA1998, requiring the company to take specified steps to comply with PECR regulation 22. We will follow this up with an audit of the company."
The report leaves the door to further action, with other investigations ongoing. "We are investigating allegations that Eldon Insurance Services Limited shared customer data obtained for insurance purposes with Leave.EU," the report reads, adding that the ICO is "still considering the evidence in relation to a breach of principle seven of the DPA1998 for the company's overall handling of personal data."
It isn't just the Leave side under investigation, though. "We are still looking at how the Remain side of the referendum campaign handled personal data, including the electoral roll, and will be considering whether there are any breaches of data protection or electoral law requiring further action," the report reads. "We investigated the collection and sharing of personal data by Britain Stronger in Europe and a linked data broker. We specifically looked at 11 inadequate third party consents and the fair processing statements used to collect personal data."
Amidst these words for those on both sides of the referendum battle, the ICO also highlighted the activities of Cambridge Analytica, writing that the company would be facing a "substantial fine for very serious breaches of principle one of the DPA1998" had it not already gone into administration following the scandal.
Key considerations for implementing secure telework at scale
Identifying the security risks and advanced requirements of a remote workforceDownload now
The State of Salesforce 2020
Your guide to getting the most from SalesforceDownload now
Fast, flexible and compliant e-signatures for global businesses
Be at the forefront of digital transformation with electronic signaturesDownload now
Rethink your cybersecurity strategy for the new world
5 steps to secure the enterprise and be fit for a flexible futureDownload now