Sending direct marketing – what requirements does the GDPR have?

Sending direct marketing – what requirements does the GDPR have?

Sending direct marketing – what requirements does the GDPR have?

A good way for a company to attract new customers is to advertise its services and products by sending promotional e-mails to potential customers. The GDPR allows sending direct marketing, but it is important to be aware of when a company is acting lawfully when sending such e-mails, as unlawful data processing may result in data protection fines.

When does the GDPR apply?

The GDPR is a European Union regulation that is directly applicable in Hungary. The GDPR applies to the processing of personal data – for example, sending e-mails, the collection and storage of e-mail addresses constitute data processing if the e-mail address contains personal data.

Therefore, in the case of an e-mail address, it must first be determined whether or not it constitutes personal data, as this determines whether the GDPR applies. The GDPR defines the concept of personal data broadly; it includes any information relating to an identified or identifiable natural person. At first glance, it may seem clear what constitutes personal data, but interpreting the regulations of GDPR is not always so straightforward.

An e-mail address does not necessarily have to contain the data subject’s full name to be classified as personal data. What matters is whether the data controller – that is, the company sending the direct marketing – can identify the individual in question based on the e-mail address. If, for example, an e-mail address contains only a first name, but the data controller has other information available about the person associated with that e-mail address – such as their date and place of birth or their address – and knows that this person uses that e-mail address, then the e-mail address is considered personal data and the GDPR applies.

If an e-mail address contains a generic term, such as ‘info@’ or ‘office@’, one might assume that the GDPR certainly does not apply to that e-mail address. However, if the data controller is aware that the e-mail address is used exclusively by one person and can identify that person, then even an e-mail address containing a generic term may be classified as personal data.

From what sources can e-mail addresses be collected?

If a company wishes to collect e-mail addresses to which it would send marketing e-mails, the company must examine the purpose for which the e-mail address was published and ensure that this purpose includes the company sending marketing e-mails.

What content must the e-mail contain?

The e-mail must include information on the right to object. This means that the recipient must be informed that they may, at any time and free of charge, request that the sender to stop sending them marketing e-mails in future and that the company no longer processes their e-mail address for marketing purposes.

It is important that this information is displayed prominently in the e-mail, clearly separated from the rest of the text.

What has to do the company if the recipient exercises their right to object?

If the recipient asks the company to stop sending them marketing e-mails and to cease processing their e-mail address for marketing purposes, the company has no discretion in the matter but is obliged under the GDPR to comply with this request.

In complying with the request, the company is obliged not only to refrain from sending further marketing e-mails, but also to cease processing the e-mail address for marketing purposes; in other words, to delete the e-mail address from its own internal system, such as its marketing list. In addition, the recipient must be informed that the company will no longer process the e-mail address for marketing purposes.

What are the potential consequences of breaching the GDPR in Hungary?

If the company collects or sends marketing e-mails in a manner that does not comply with the provisions of the GDPR, fails to delete the e-mail address despite the recipient’s request, or sends further marketing e-mails, the recipient may file a complaint with the courts or the National Authority for Data Protection and Freedom of Information (‘NAIH’). NAIH may initiate proceedings on the basis of the complaint, in which it will examine whether the company’s data processing was lawful or not.

If NAIH concludes that the data processing was not appropriate – for example, if the company sends a further marketing e-mail despite the recipient’s request not to do so – it may impose a data protection fine. Furthermore, if NAIH deems the case to be of significant gravity, it may decide to publish the decision establishing the infringement on its website. In this case, the company found to have breached data protection rules, the facts of the case, and the amount of the fine imposed will all be made publicly available.

It is important that the company complies with the provisions of the GDPR throughout its data processing activities; therefore, it must be thoroughly examined whether an e-mail address constitutes personal data, and whether the collection of e-mail addresses, the sending of direct marketing communications and their content comply with the GDPR.

Share on XShare via emailShare on LinkedIn

Go to
Offices

Go to Offices