Information Regulator slaps first spam calling company with enforcement notice

Information Regulator slaps first spam calling company with enforcement notice

The Information Regulator of South Africa has recently issued its inaugural enforcement notice as a consequence of a direct marketing complaint. This notice was directed towards FT Rams Consulting, an educational institution, following the Information Regulator's determination that the organization had violated various provisions of the Protection of Personal Information Act (POPIA).

The impetus for this action was the Regulator's decision to incorporate a clause regarding marketing through telephone communication into Section 69 of POPIA. The enforcement notice stemmed from a complaint lodged by an affected individual, who had been inundated with numerous direct marketing messages. Despite repeated attempts to opt out and requests to be removed from the company's email distribution list, FT Rams Consulting conspicuously disregarded the data subject's pleas and persisted in sending marketing messages via email.

Upon investigation, the regulator ascertained that FT Rams Consulting impeded the protection of the data subject's personal information, thereby violating the stipulated conditions for legally processing such information. Furthermore, the organization was found to be in contravention of Section 69 of POPIA, which governs direct marketing through electronic communications.

Consequently, FT Rams Consulting has been directed to cease sending unsolicited direct marketing messages through any electronic communication means without the explicit consent of the data subject. The company is obligated to ensure that its initial communication with data subjects explicitly requests their consent, limiting such requests to a single instance per data subject.

The regulator has mandated that FT Rams Consulting furnish evidence of its compliance with these directives within a 90-day period. Failure to adhere to these instructions may result in severe penalties, including fines of up to R10 million or imprisonment for a maximum of ten years.

Pansy Tlakula, the Chair at the Information Regulator, emphasized a shift away from leniency regarding direct marketing through unsolicited electronic communications. Non-compliance by responsible parties, whether public or private entities, with Section 69 of POPIA is viewed as an infringement on the rights of data subjects.

The regulator's scrutiny revealed that FT Rams Consulting violated not only Section 69 but also various other sections of POPIA by directly marketing to the data subject without obtaining prior consent, persistently sending unsolicited direct marketing communications via email, and offering an "Opt Out" option but failing to cease communications upon the data subject's exercise of this choice.

Section 69 (1) of POPIA explicitly prohibits companies from engaging in direct marketing to customers through any electronic communication without securing prior consent. Additionally, Section 69 (2) stipulates that marketers are permitted to solicit consent from a data subject only once.

The regulator clarified that the initial communication from FT Rams Consulting to the data subject should have been a request for consent, as defined by POPIA as a voluntary, specific, and informed expression of will permitting the processing of personal information. The data subject, upon consenting, should have also indicated the preferred means of communication for receiving direct marketing messages.

FT Rams Consulting was found to have neglected to use the prescribed form to obtain written consent from the data subject. In a broader context, the Information Regulator has identified 14 other entities as potential offenders, intending to issue enforcement notices to them in due course.

StormWarning! CyberSecurity Consultants

Are your marketing and email campaigns PoPiA Compliant?..

                           ...Best you contact StormWarning! today not only will we will do our very best to answer that question for you and your organisation, but we will diligently endeavor to assist your organisation become Privacy legislation compliant  while adhering to the constraints of your budget.

CONTACT US NOW!

 

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.