Skip to main content

Talk to us: 0333 004 4488 | hello@brabners.com | Contact us

Marketing to existing contacts — what the BrewDog story tells us about UK GDPR & PECR

AuthorsPaddy FearnonSara Ludlam

Blue 3D letters spelling BREWDOG mounted on a pale stone building facade with arched windows and decorative stonework.

Image credit: Tosh Lubek, stock.adobe.com

"It was only one email."

Organisations may assume that if they already hold someone's contact details, sending a marketing or stakeholder communication presents little regulatory risk. However, recent reports concerning BrewDog founder James Watt demonstrate that the position is far more complex.

According to The Guardian, complaints have been submitted to the ICO following emails sent to former BrewDog ‘Equity Punks’ shareholders in connection with Watt's proposed buy-back of BrewDog through a new venture called Second Best. Some recipients reportedly questioned how their data had been obtained, while Watt stated that the communications were sent using lawfully obtained information and were linked to shareholders' legitimate interests. The ICO has confirmed that it’s assessing the information provided. 

Importantly, no findings have been made and no regulatory breaches have been established. However, the story provides a useful reminder that data protection compliance extends beyond identifying a lawful basis under UK GDPR. Organisations must also consider wider data protection principles and, crucially, whether the Privacy and Electronic Communications Regulations (PECR) apply to the communication that they intend to send.

Here, Paddy Fearnon and Sara Ludlam explain why a ‘legitimate interests’ assessment is only one part of the compliance exercise and outline the practical steps that organisations should take before contacting existing customers, members, investors or stakeholders.

 

Lawfully collected data doesn't mean unlimited use

Much of the discussion surrounding the BrewDog story has focused on the origins of the contact details and whether recipients expected to be contacted.

While these are important considerations, organisations should also ask themselves:

Even if you lawfully hold someone's personal data, can you use it for the communication that you want to send?

A business may possess personal data entirely lawfully. However, that doesn’t automatically mean that it can hold that data indefinitely or use it for any future purpose.

Before sending communications, organisations should consider whether the proposed use aligns with the data protection principles of transparency, fairness and purpose limitation. They should also consider whether the communication falls within the scope of PECR.

 

What ‘legitimate interests’ mean for marketing & UK GDPR compliance

‘Legitimate interests’ is one of the six lawful bases available under UK GDPR and is often relied upon for business communications, customer relationship management and certain forms of marketing.

This lawful basis requires organisations to demonstrate and record:

  1. A legitimate interest on behalf of the business wishing to use the personal data.
  2. That the processing is necessary to achieve that interest.
  3. That the interest isn’t overridden by the rights and freedoms of the individuals concerned.
     

Whether recipients would reasonably expect the communication and the potential impact on individuals are important questions. A useful rule of thumb is that if recipients are likely to be surprised by receiving the communication, additional scrutiny may be required.

 

Reusing contact lists: when does it become a compliance risk?

UK GDPR requires personal data to be collected for specified, explicit and legitimate purposes. When an organisation wishes to use personal data for a different objective, it should assess whether that new use is compatible with the original purpose for which the information was collected.

In practice, organisations often encounter this issue when seeking to make further use of an existing marketing or stakeholder database to:

 

Before using existing contact details for a new purpose, organisations should ask:

  • Why was the data originally collected? Does that purpose cover the new purpose?
  • What information was provided to individuals at the time? Did you tell them the proposed purpose and would that information include the new purpose?
  • Would recipients reasonably expect this new communication? 

If those questions can’t be answered appropriately, the organisation should pause before proceeding.

 

Why GDPR compliance alone won't keep your marketing lawful

Perhaps the most significant lesson arising from the publicity surrounding the BrewDog complaints is that data protection compliance and marketing compliance aren’t the same thing.

PECR sits alongside the UK GDPR and the Data Protection Act 2018 — it’s not simply an extension of data protection law. Instead, it gives individuals and organisations specific privacy rights in relation to electronic communications, including marketing emails, texts, calls and similar communications.

PECR can apply even where personal data isn’t being ‘processed’ in the UK GDPR sense. Also, some PECR rules protect companies as well as individuals, meaning that businesses shouldn’t assume that it’s irrelevant simply because it’s using general business contact details (for example, info@abclimited.co).

Even where an organisation is comfortable that it’s identified an appropriate lawful basis under UK GDPR, it may still need to comply with PECR when sending electronic marketing communications. 

Non-compliance can have significant consequences. The ICO has powers to investigate complaints, require organisations to change their practices and take regulatory action where it considers that data protection or electronic marketing laws have been breached.

Getting this wrong can result in more than an irritated recipient. Complaints can lead to ICO scrutiny, organisations being required to change their marketing practices, financial penalties and reputational damage.

 

Don't assume the ‘soft opt-in’ exemption applies

Another common misunderstanding concerns the ‘soft opt-in’ exemption under PECR.

It’s a common misconception that holding a customer's contact details automatically entitles a business to send marketing communications. In reality, the soft opt-in is subject to specific conditions. 

Broadly speaking, these are that: 

  • the individual must have previously bought or enquired about a product or service
  • the marketing must relate to similar products or services 
  • the individual must have been given a clear opportunity to opt-out when their details were collected 
  • every subsequent communication must include a simple opt-out mechanism.

This means that organisations should be cautious before relying on the soft opt-in for historic contacts, former stakeholders or individuals whose details were collected in an entirely different context. Just because an organisation already holds contact details, doesn’t automatically mean that it can market to that individual.

 

B2B marketing isn't a free pass

Organisations should also remember that the rules can apply differently depending on whether they’re communicating with an individual or a business. While B2B marketing communications may be subject to a different regulatory framework in some circumstances, PECR and UK GDPR obligations don’t disappear altogether.

For example, business marketing emails should still be relevant to the recipient's role and recipients should be provided with a clear opportunity to opt-out of future communications. Businesses should also take particular care when dealing with sole traders, who may be treated as individuals for data protection and marketing purposes.

 

Key takeaway & next steps

The ICO's assessment of the BrewDog complaints is ongoing and it remains to be seen whether any further action will follow. However, organisations don’t need to wait for the outcome before taking practical lessons from the publicity surrounding the case. 

The key takeaway is that possessing personal data and identifying a lawful basis to process it doesn’t automatically entitle an organisation to send marketing communications.

If your organisation uses customer, prospect, investor, donor, member or stakeholder databases for marketing or business development activities, now is a good opportunity to:

  • Review whether your practices comply with both UK GDPR and PECR requirements.
  • Ensure that you’ve undertaken an assessment of any processing done on the basis of ‘legitimate interest’ and recorded it. If it was undertaken some time ago, it should be re-examined and a record of the re-examination and outcome should be kept.

 

Talk to us

Our data protection team advises organisations on lawful basis assessments, PECR compliance, direct marketing activities, privacy notices, data sharing arrangements and regulatory investigations.

To discuss how this applies to your organisation, talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.

Paddy Fearnon

Paddy is a Trainee Solicitor in our commercial and intellectual property team.

Read more
Paddy Fearnon

Sara Ludlam

Sara is a Partner and Chartered Trade Mark Attorney in our commercial and intellectual property (IP) team.

Read more
Sara Ludlam

Talk to us

Loading form...

Related insights

Data Protection FAQs

Working on laptop at night bokeh

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

Read more