ICO fine pregnancy and parenting club £400k for unlawful sharing of member data

Share This Post

Bounty (UK) Limited have been fined £400,000 by the ICO for unlawfully sharing personal data with third-parties. Whilst the data subjects were asked to opt into receiving third-party marketing materials, it was not made clear that Bounty may also share their data with other types of business.

As well as operating as a pregnancy and parenting support club, Bounty operated as a data broker which is how they came to share the data with the likes of Axciom, Equifax, Indicia, Sky and over 30 other organisations. Between June 2017 and April 2018 Bounty shared around 34 million data records.

The ICO’s issue was not so much that the data was being shared per-se but with whom the data was shared. It was not made clear to the data subjects that there data would be shared with organisations not directly linked to pregnancy or parenting, such as credit reference, marketing and media companies. Thus the ICO found Bounty in breach of the Data Protection Act 1998’s principles regarding fairness of processing.

Steve Eckersley, ICO’s Director of Investigations, said:

“The number of personal records and people affected in this case is unprecedented in the history of the ICO’s investigations into data broking industry and organisations linked to this.

“Bounty were not open or transparent to the millions of people that their personal data may be passed on to such large number of organisations. Any consent given by these people was clearly not informed. Bounty’s actions appear to have been motivated by financial gain, given that data sharing was an integral part of their business model at the time.

“Such careless data sharing is likely to have caused distress to many people, since they did not know that their personal information was being shared multiple times with so many organisations, including information about their pregnancy status and their children”

It should be noted the ICO have taken action under old data protection (DPA1998) as the incident and investigation took place before GDPR.

More To Explore

Eat. Sleep. GDPR. Repeat.

We live and breathe GDPR and ePrivacy compliance, so you don’t have too. Our GDPR UNLIMITED helpline is all about offering you help and support, whenever you need it most. As well as the unlimited helpline, you get up to 4 hours “hands-on” help each month, which we can configure to help you in anyway you need such as a GDPR review, or acting as your DPO.

As well as the unlimited helpline and hands-on help you get GDPR and privacy updates, access to our GDPR knowledge centre and webinars.

Unlimited email & phone support

Unlimited email and phone support. Email or organise a voice call as often as you need each month.​

Up to 4 hours "hands-on" help per month

We use these "hands-on" hours to do the GDPR work for you, such as reviews, acting as your DPO, checking DPIA, dealing with breaches, training your staff, etc. (Additional hours: £100+VAT per hour)

Online resources

Our Knowledge Centre gives you access to information, guidance, topic related guides and other tools to support your GDPR and PECR compliance

Updates, alerts & briefings

We provide updates and alerts and a monthly compliance briefing. You can either sign into the Knowledge Centre or sign up via email to receive an email every time we add a new update or alert

DPO services

Whether mandated or not we can act as your Data Protection Officer (DPO) and manage your day to day compliance

Webinars, workshops & training

Whether updates on the latest issue, workshops or team training, it's all included in your monthly retainer.

LIKE WHAT YOU'RE READING? join our email list

Sign up for monthly briefings and the occasional emails about our webinars and services

Want to know more about how we use your data? Check out our privacy policy