ICO fines HelloFresh £140,000 for spam texts and emails

12 Jan 2024 12:58 PM

The Information Commissioner’s Office (ICO) has fined food delivery company HelloFresh £140,000 for a campaign of 79 million spam emails and 1 million spam texts over a seven-month period.

The marketing messages were sent based on an opt-in statement which did not make any reference to the sending of marketing via text. Whilst there was a reference to marketing via email, this was included in an age confirmation statement which was likely to unfairly incentivise customers to agree.

Customers were also not given sufficient information that their data would continue to be used for marketing purposes for up to 24 months after cancelling their subscriptions.

An investigation by the ICO began in March 2022 following complaints made directly to the regulator, as well as to the 7726 spam message reporting service. As part of this investigation, it was also discovered that the company continued to contact some individuals even after they had requested this to stop.

Following the investigation, we found that the company (Grocery Delivery E-Services UK Limited) contravened regulation 22 of the Privacy and Electronic Communications Regulations 2003 and it has now been served with a fine of £140,000.

Andy Curry, Head of Investigations at the Information Commissioner's Office, said:

“This marked a clear breach of trust of the public by HelloFresh. Customers weren’t told exactly what they’d be opting into, nor was it clear how to opt out. From there, they were hit with a barrage of marketing texts they didn't want or expect, and in some cases, even when they told HelloFresh to stop, the deluge continued.

“In issuing this fine, we are showing that we will take clear and decisive action where we find the law has not been followed. We will always protect the right of customers to choose how their data is used.

“The investigation that led to this fine began following complaints filed by the public, both to the ICO and to the 7726 service. This shows just how important it is that if you are being contacted with nuisance calls, texts or emails, that you report it straight away.”

Further details of contraventions

ICO’s work to tackle nuisance communications

The ICO enforces the Privacy and Electronic Communications Regulations 2003 (PECR), which cover the rules for organisations wishing to make direct marketing calls, texts or emails.

We have issued more than £2,440,000 million in fines against companies responsible for nuisance calls, texts and emails since April 2023. Some of these investigations began with a single complaint from a member of the public.

For more information about the ICO’s work to tackle nuisance calls, emails and texts visit ico.org.uk/nuisancecalls.

Advice for the public

To help you, your friends and relatives stop unlawful marketing calls, texts or emails you can:

Notes for editors

  1. The Information Commissioner’s Office (ICO) is the UK’s independent regulator for data protection and information rights law, upholding information rights in the public interest, promoting openness by public bodies and data privacy for individuals.
  2. The ICO has specific responsibilities set out in the Data Protection Act 2018 (DPA2018), the United Kingdom General Data Protection Regulation (UK GDPR), the Freedom of Information Act 2000 (FOIA), Environmental Information Regulations 2004 (EIR), Privacy and Electronic Communications Regulations 2003 (PECR) and a further five acts and regulations. 
  3. The ICO can take action to address and change the behaviour of organisations and individuals that collect, use and keep personal information. This includes criminal prosecution, non-criminal enforcement and audit. 
  4. To report a concern to the ICO telephone our helpline 0303 123 1113 or go to ico.org.uk/concerns.