Human resources at a click

Company fined £80,000 for selling personal data without owners’ consent

The ICO has fined data brokering company Verso Group (UK) Ltd £80,000 for a serious and deliberate contravention of the Data Protection Act 1998 (DPA).

An ICO investigation found that the company had supplied personal data to two other companies who then used the data for telemarketing purposes (including nuisance calls). Verso failed to ensure it had appropriate consents from the data subjects to forward their personal data on in this way.

In determining the amount of the fine, the ICO considered:

  • The contravention involved large volumes of personal data and data subjects;
  • Verso’s contraventions were systemic, deliberate and not isolated or one-off;
  • These contraventions occurred over a period of years; and
  • Verso’s conduct during the investigation was found to be “unhelpful and obstructive.”

An ICO investigation found that the company had supplied personal data to two other companies who then used the data for telemarketing purposes (including nuisance calls).

Organisations should keep in mind that the GDPR is replacing the DPA in May 2018, and under the new law consent will be even harder to obtain as a basis to process data.

The GDPR places an even greater focus on organisations being transparent on information being provided to individuals before their data is processed. The ICO’s findings and sanction also emphasise the importance of assisting the ICO in any investigations they carry out.

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Anonymous author

Related Articles

Data Subject Access Requests (DSARs) are very rarely the subject of litigation, rarer still in the High Court, so the...

If you have employees who bring their own devices into the workplace and use said devices to deal with company...

In our article, Data Use and Access Bill – how will it impact business and their dealings with Data Protection,...

Related Resources

Data breaches factsheet

Facts and examples of personal data breaches and information required to report a data breach. Personal Data Breach What is...

Monitoring policy

This monitoring policy provides a brief overview of how a company should approach monitoring in the workplace. Employees and other...

International transfers factsheet

International transfers factsheet provides and overview on data protection requirement for international transfers. Introduction The UK General Data Protection Regulation...

Human resources at a click