Leave.EU faces big fine over data law breaches
Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
The information commissioner, Elizabeth Denham, has revealed large fines for data misuse in the run-up to the EU referendum in 2016.
As explained on the commissioner's website, a move has been made to fine two companies a total of 135,000. Both Leave.EU and the Eldon Insurance company owned by the Brexit-backing Aaron Banks were fined 60,000 apiece for "serious breaches" of laws dictating electronic marketing. In addition, Leave.EU received an extra 15,000 fine for sending 300,000 emails to Eldon customers promoting Brexit.
"More than one million emails were sent to Leave.EU subscribers over two separate periods which also included marketing for GoSkippy [the trading name for Eldon] services, without their consent. This was a breach of PECR regulation 22," the report reads.
"We have issued a preliminary enforcement notice to Eldon Insurance under s40 of the DPA1998, requiring the company to take specified steps to comply with PECR regulation 22. We will follow this up with an audit of the company."
The report leaves the door to further action, with other investigations ongoing. "We are investigating allegations that Eldon Insurance Services Limited shared customer data obtained for insurance purposes with Leave.EU," the report reads, adding that the ICO is "still considering the evidence in relation to a breach of principle seven of the DPA1998 for the company's overall handling of personal data."
It isn't just the Leave side under investigation, though. "We are still looking at how the Remain side of the referendum campaign handled personal data, including the electoral roll, and will be considering whether there are any breaches of data protection or electoral law requiring further action," the report reads. "We investigated the collection and sharing of personal data by Britain Stronger in Europe and a linked data broker. We specifically looked at 11 inadequate third party consents and the fair processing statements used to collect personal data."
Amidst these words for those on both sides of the referendum battle, the ICO also highlighted the activities of Cambridge Analytica, writing that the company would be facing a "substantial fine for very serious breaches of principle one of the DPA1998" had it not already gone into administration following the scandal.
Managing security risk and compliance in a challenging landscape
How key technology partners grow with your organisationDownload now
Evaluate your order-to-cash process
15 recommended metrics to benchmark your O2C operationsDownload now
AI 360: Hold, fold, or double down?
How AI can benefit your businessDownload now
Getting started with Azure Red Hat OpenShift
A developer’s guide to improving application building and deployment capabilitiesDownload now