Latest
news

Things to consider with email marketing

E-Marketing (also known as electronic marketing) can be a significant driver of new business. It can help with many aspects such as brand recognition and product campaigns and – most importantly – can enable you to reach your target audience via email marketing.

In this guest post, Ravi Ahluwalia from RA Data Protection Ltd explains the ins and outs.

There are two distinct types of customers, those in the B2C bracket and those in the B2B bracket. These two customer types can be targeted in the same way – eg using emails and text messages – but how do you ensure that what you’re doing doesn'tt infringe their data protection rights?

In the UK we have three distinct data protection laws:

When it comes to e-marketing communications and the customers you are targeting, the law that applies is the PECR, and not necessarily the UK GDPR as many people believe.

What is the PECR?

The PECR sits alongside the UK GDPR and DPA and is the main law in the UK mandating areas such as e-marketing communications and website cookies, and applies quite heavily to the telco industry. The Information Commissioner's Office (the ICO) is the data protection supervisory authority (ie the regulator) in the UK and has produced detailed guidance to the PECR (and other areas) which you can find here.

The PECR applies to both B2C and B2B direct e-marketing communications, whether that is done via phone, email, text messages or fax, and to whom the ICO refer as “the sender” or “instigator” of the e-marketing communications. Even if you are using a webmail provider or marketing software, you may still have responsibility for ensuring PECR compliance.

For the purposes of this guidance we are focusing on direct email marketing.

For most direct email marketing to be carried out, there is the requirement for an individual's consent. For the consent to be valid it must be freely given (pre-ticked boxes are not permissible), specific to what it is needed for and clearly distinguishable from other matters. It is highly recommended that a record of consents is kept somewhere, so ensuring you have sufficient email marketing software that captures and stores consents is encouraged.

Individuals must also be able to withdraw their consent (ie opt out) just as easily as they opted in. Not having the opt out ability for direct marketing emails and ensuring these are documented and recorded can result in a breach of the PECR and the ICO taking enforcement action against an organisation.

The sections below look into the different ways you can demonstrate compliance with PECR requirements and direct email marketing.

Website Opt Ins

One of the best ways of capturing consent for direct marketing emails is by having an ‘opt in’ form on your website, and ensuring it only captures the minimal amount of personal data needed. Most websites tend to ask for names and email addresses and ask for the consent by ticking a blank tick box and then clicking on a subscribe button, which is perfectly fine. It is recommended that each marketing email that's sent has an opt out ability, which once clicked records the opt out and ensures the recipient is no longer contacted. Most email marketing software can help with this.

Soft Opt Ins

Another form of consent is known as the ‘soft opt in’. This is when a business is negotiating or in the process of making a sale and at the point personal data is collected an individual is given the opportunity to opt out of receiving such communications.

The ICO guidelines for soft opt ins are quite strict and specify the soft opt in only applies to the organisation whose products/services are being acquired and not those of a third party. Also, a company can only market their own products and services, and the ability to opt out should be made at the point of data collection (as per above) and in every direct email marketing communication. For more information on the soft opt in you can refer to the ICO guidance here.

It should be noted the soft opt in only applies to the commercial marketing of products or services and does not apply to fundraising or campaigns, which require a separate opt in.

B2B Direct Email Marketing

In order to grow a customer email marketing database most businesses will have an opt in form (as described above) on their website to enable individuals from different businesses to opt in to receiving direct marketing emails. This is perfectly fine as it helps to streamline their direct email marketing activities and keep things simple.

Under the PECR, businesses such as companies and limited liability partnerships (“LLP”) are referred to as “corporate subscribers” and sole traders and certain other partnerships (ie non LLPs) are referred to as “individual subscribers”.

If you're sending direct email marketing to someone who falls under a corporate subscriber, the PECR consent requirements do not apply, so consent for B2B direct email marketing is not necessarily needed, however, the ability to opt out does still need to be in each email. This is because the UK GDPR will apply, and the ICO state in their guidance as you are processing personal data (i.e. names and email addresses) this still falls under the definition of personal data, and the UK GDPR allows for individuals the right to object for direct marketing purposes. So even though an opt in is not needed individuals still have the right to opt out at all times, and as above these opt outs should be recorded and stored as necessary.

Sole traders and certain other partnerships under the PECR are treated as individuals so you are still are required to have their consent to send them direct marketing emails, or you can use the soft opt in approach as described above (where applicable). There is, however, the risk of sole traders and certain other partnerships using generic email addresses such as “@gmail.com” or” @outlook.com” so it isn't always possible to distinguish if the email address is a personal one or a business one. In these cases companies can run the risk of breaching PECR so it is advisable to ensure that the opt in form is used to help mitigate a potential PECR breach from occurring.

What can happen if a business does not comply with PECR requirements?

If a business fails to comply with PECR requirements, the ICO can:

  1. Serve an enforcement notice to the organisation in question to stop sending direct marketing emails that are in breach of PECR; and/or
  2. Serve a monetary penalty notice which can lead to a fine up to £500,000 against the organisation or its directors

What is the best solution for businesses?

How a business decides to conduct their direct email marketing campaigns is completely up to them, as they may be able to use the web form opt in approach and the soft opt in approach, but that may result in duplication of consents and may be difficult to ensure opting out for one is replicated for the other.

Email marketing software can be useful in streamlining and automating consents and opt outs as needed, and there are multiple companies who can offer help and support with PECR compliance requirements.

The key thing is to ensure careful planning is carried out and consideration is given to an individual's rights with direct email marketing and where differences may lie with those who fall in the B2C bracket and those who may fall in the B2B bracket. This careful planning and consideration can help with privacy by design requirements under the UK GDPR, as it forms part of the wider data protection landscape to which businesses are required to adhere.

So in a nutshell, data protection is something of a minefield and it's advisable to speak to a specialist such as Ravi at RA Data Protection Ltd. Ravi can review your direct email marketing processes and give help, advice and best practice recommendations. To set up an inital meeting please give Ravi a call on 07851 159235 or visit his website.

From our portfolio

Wellcome Genome Campus

Wellcome Genome Campus

Advanced Cleaning Services

Advanced Cleaning Services

Keepers Kitchen & Bar

Keepers Kitchen & Bar

The Workspace Consultants

The Workspace Consultants

LandQart AG

LandQart AG

London Swimming Pool Company

London Swimming Pool Company

Wellcome Sanger Institute

Wellcome Sanger Institute

Art of Flooring

Art of Flooring

View all

Our clients include

Postscript have done a wonderful job with our marketing collateral. Their creativity and technical expertise has resulted in materials that are light years ahead of where we were, and they have set us up perfectly to showcase our bank notes and technology. One of the things that has impressed us most is the careful attention to detail given to our product range, which is captured in the excellent photography and the use of these images across our collateral.

LandQart AG

View project

Latest news