home| T: 0118 955 3001| contact us| print page
marketing data

marketing data

If your organisation is involved in direct marketing activities, it is important to refer not only to the Data Protection Act, but also to the associated Privacy and Electronic Communications Regulations.

Under the Act, individuals must be made aware if their data is to be used for marketing purposes. A fair processing notice must be given at the time of data collection or as soon as practicable, so that they have the opportunity to raise objections if they have any.

There should be an option to either "opt in" or "opt out" of marketing, and the implications of either opting in or failing to opt out (depending on which option has been given) should be fully explained. For example, if there is an opt out box to be ticked, but it is not in a visible place, then the data subject may not be aware that they will receive direct marketing.

The Regulations complement individual rights under the Act, but they also offer some protection to corporate bodies as well. Under the Regulations, there are two Preference Services (for telephone and fax) which must be checked by organisations carrying out marketing, so that those who have signed up do not receive unsolicited direct marketing. The rules differ slightly for individual and corporate subscribers, so it is worth seeking guidance before beginning any direct marketing campaigns.

In summary, the main questions to ask are:

  • Is fair processing notice provided where you intend to use personal data for direct marketing?
  • Is the data subject able to opt in or out easily, and are the implications of opting in / not opting out clear?
  • Is it easy for recipients of marketing communications to unsubscribe?
  • Are the correct procedures followed when someone contacts you to advise that they no longer wish to receive your direct marketing? If their details are simply deleted, there is the risk of them being re-entered at a later stage and the data subject receiving marketing that they have specifically asked not to receive.
  • Is data only being kept for as long as necessary?