Data Protection Legislation Bears Teeth: Bounty (UK) Limited fined £400,000

The ICO this week issued a timely reminder that failure to comply with data protection legislation can have serious consequences.

No items found.

Any business that holds even the most minimal amount of personal data will surely by now have heard the words “€20,000,000 or 4% of worldwide annual turnover, whichever is higher”, being the maximum fine possible under the General Data Protection Regulation (“GDPR”). However, since the GDPR came into force on 25 May 2018, we are yet to see the Information Commissioner’s Office (“ICO”) truly flex its muscle and exercise its powers under the GDPR.

The ICO this week issued a timely reminder that failure to comply with data protection legislation can have serious consequences. Whilst it does not fall under the GDPR, by virtue of the offences occurring prior to 25 May 2018, the ICO’s decision to fine Bounty (UK) Limited (“Bounty”) £400,000 because of a serious contravention of the Data Protection Act 1998 (“DPA 1998”) should be a warning shot to any business who believes they can ignore data protection legislation.

Key facts

Bounty’s main service is the provision of “Bounty Packs” (sample packs for the different stages of pregnancy and after birth) which are distributed to new parents. Bounty also provides a mobile app with a number of functions which include enabling expectant mothers to track their pregnancies. In operating this service, Bounty collected a large amount of personal data, some of which would be deemed “sensitive personal data” under the DPA 1998.

Separate to its primary function, Bounty also operated a data broking service, providing hosted marketing on behalf of third parties and, until 30 April 2018, it supplied data to third parties for the purpose of electronic marketing. This function resulted in Bounty sharing approximately 34.4 million records relating to over 14 million individuals with a number of organisations, including credit reference and marketing agencies between June 2017 and April 2018.

Basis for processing

Bounty believed that it could rely on having obtained the consent of data subjects to share their personal data with third parties, such as Acxiom, Equifax, Indicia and Sky, for the purposes of direct electronic marketing. However, as we will see below, the ICO found a number of issues with the consent obtained by Bounty.

69% of Bounty’s customer database had signed up to Bounty’s service using offline “claim cards”. These claim cards did not have a specific “opt in” to marketing option, instead saying that “While you are a member, we may share your information with a selected group of companies who also have services, free samples, offers and product information that may be of interest to you”. If an individual wished to sign up to Bounty’s service, they had no choice but to accept this marketing.

Furthermore, as the individuals who registered through the claim cards did so offline, they did not have access to Bounty’s privacy policy, available on its website, at the time they signed up. As such, the individuals were not informed about how their personal data may be used, which is a requirement under both the DPA 1998 and the GDPR.

Bounty’s argument was that it sent its Privacy Policy to the email address provided within “a very short period of registration”. The ICO rejected this point, however, saying that fair processing information should be provided at the point of collection, not afterwards (even where it is a short period afterwards).

In addition to being provided late, the ICO stated that Bounty’s Privacy Policy was deficient in that it did not share specific details of the organisations with whom personal data was to be shared (i.e. Acxiom, Equifax, Indicia and Sky).

In failing to provide an adequate Privacy Policy at the time the personal data was provided, the ICO considered that the “fairness” principle under the DPA 1998 had been breached. This principle also required an organisation to consider an individual’s reasonable expectations as to how their personal data might be used. In this situation, the ICO was quite clear that a pregnant mother who registered with a pregnancy club would not reasonably expect personal data to be shared with credit reference, marketing and profiling agencies.

Consent – properly obtained?

Consent was not defined under the DPA 2018, but it has been interpreted by the courts by reference to the Data Protection Directive (95/46/EC) to mean “any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed”.

Under the GDPR, consent has been defined, and for consent to be properly given under GDPR, in addition to what was required under the DPA 2018, it must also be “unambiguous” and include “a statement or by a clear affirmative action”. Therefore the threshold for consent to have been correctly obtained has been increased by the GDPR.

The ICO found that the consents obtained by Bounty were not “specific” or “informed”, as required, given that the data subjects were not told that their data would be shared with Acxiom, Equifax, Indicia and Sky. In the case of the consents collected offline through the claim cards, the ICO concluded that these were not “freely given”, seeing as the data subjects had no choice but to give consent if they wished to use the service.

In the ICO’s written reasons, they suggested that the only other potentially applicable ground that Bounty could have relied on for processing the personal data could have been “legitimate interests”. However, Bounty did not seek to rely on this ground, and the ICO concluded that even if it had, it would have failed on this ground as well.

Penalty

Given that Bounty’s transfer of personal data to third parties was found to be both unfair, and not on the basis of an applicable ground for processing, the ICO considered that a monetary penalty would be appropriate. Under the DPA 1998 the ICO had the power to issue monetary penalties up to a maximum of £500,000.

This ICO deemed the infringement by Bounty to be of a kind likely to cause “substantial damage or substantial distress”, as those involved would not wish for information about their pregnancy status or children being shared without their explicit consent. Additionally, the number of individuals affected by the actions taken by Bounty resulted in the cumulative impact clearly passing the threshold of “substantial” under the DPA 1998.

Having considered the above, the ICO took the decision to levy a fine on Bounty of £400,000, representing 80% of the maximum potential fine.

What does this mean?

Ironically, Bounty confirmed to the ICO at the beginning of its investigation that it had planned to change its marketing practices prior to the GDPR coming into force, as it was aware that its data sharing practices would not be compliant under GDPR. In the ICO’s judgment they note that, had Bounty considered its marketing practices earlier, it would have been aware that they contravened the DPA as well.

However, it is just as well that Bounty committed the offences under the DPA 1998 as opposed to the current regime, as the potential fines could be much greater if a similar offence was committed today given the increase in the maximum fines available.

With the standard for obtaining a valid consent being more onerous under the GDPR, this decision serves as a timely reminder that data protection legislation can bear teeth. Therefore, it is important for businesses to regularly consider which ground for processing they are relying on, and ensure that they have adequate policies and procedures in place for the purposes of demonstrating data protection compliance.

If this article raises any questions for you or your business, or you have any other data protection queries, please speak to our data protection experts by calling 01603 610911 or emailing info@leathesprior.co.uk. For further information about the team please see here.

Note: The content of this article is for general information only and does not constitute legal advice. Specific legal advice should be taken in any specific circumstance.

Article by
Jack Horwitz
April 16, 2019
Article by
Leathes Prior Team
April 16, 2019
You might also like...

LP Celebrates 150th Anniversary

To begin a year of celebrations, this week Leathes Prior are delighted to reveal our refreshed brand identity and website.

Peter Lambert
05.01.2026

The Future of EOTs: Less Tax Relief, Still Strong Potential

Hugo Persad, Trainee Solicitor in our Corporate Team, summarises the impact of reduced Capital Gains Tax (“CGT”) relief on sales to Employee Ownership Trusts (“EOTs”) following the Autumn Budget.

Hugo Persad
18.12.2025

Autumn Budget 2025: Agricultural Property Relief & Business Property Relief Changes

It was announced in the 2025 Budget that from 6 April 2026, changes will be made to agricultural property relief and business property relief. These changes bring APR and BPR in line with the nil-rate band rules, meaning unused allowances can be transferred to a surviving spouse or civil partner. This is a significant step towards making estate planning easier for families who own farms or businesses.

Claire Woolliscroft TEP
18.12.2025

The Employment Rights Act 2025 is expected to come into force tomorrow (18 December 2025)

After an extended period of back-and-forth amendments between Parliament and the House of Lords, on 16 December 2025, the ERB finally received approval from the House of Lords, with the formality of Royal Assent due to take place tomorrow (18 December 2025). Head of LP Employment, Dan Chapman, explains...

Dan Chapman
17.12.2025

More industry insights

Stay informed with our latest legal insights.

View All

LP Celebrates 150th Anniversary

To begin a year of celebrations, this week Leathes Prior are delighted to reveal our refreshed brand identity and website.

Peter Lambert
05.01.2026

The Future of EOTs: Less Tax Relief, Still Strong Potential

Hugo Persad, Trainee Solicitor in our Corporate Team, summarises the impact of reduced Capital Gains Tax (“CGT”) relief on sales to Employee Ownership Trusts (“EOTs”) following the Autumn Budget.

Hugo Persad
18.12.2025

Autumn Budget 2025: Agricultural Property Relief & Business Property Relief Changes

It was announced in the 2025 Budget that from 6 April 2026, changes will be made to agricultural property relief and business property relief. These changes bring APR and BPR in line with the nil-rate band rules, meaning unused allowances can be transferred to a surviving spouse or civil partner. This is a significant step towards making estate planning easier for families who own farms or businesses.

Claire Woolliscroft TEP
18.12.2025

The Employment Rights Act 2025 is expected to come into force tomorrow (18 December 2025)

After an extended period of back-and-forth amendments between Parliament and the House of Lords, on 16 December 2025, the ERB finally received approval from the House of Lords, with the formality of Royal Assent due to take place tomorrow (18 December 2025). Head of LP Employment, Dan Chapman, explains...

Dan Chapman
17.12.2025

Charity of the Month: The Matthew Project

Leathes Prior is delighted to be supporting The Matthew Project as our Charity of the Month for December 2025. The Matthew Project supports young people and adults across Norfolk, Suffolk, and Essex to overcome issues around drugs, alcohol, and mental health, empowering them to rebuild confidence and lead fulfilling lives.

Rhiannon Bond
10.12.2025

Leathes Prior’s Milan Pandit appointed President of the Norfolk & Norwich Law Society

Leathes Prior Solicitors is proud to announce that Milan Pandit, Solicitor in our Corporate & Commercial Team, has been appointed President of the Norfolk & Norwich Law Society (NNLS) for 2025/26.

Peter Lambert
04.12.2025

Leathes Prior advises Mapus-Smith & Lemmon LLP on the acquisition Kathryn Gigg Chartered Accountants

Leathes Prior’s Corporate Team has advised Mapus-Smith & Lemmon LLP on the acquisition of Kathryn Gigg Chartered Accountants, Business Advisors & Tax Consultants.

Peter Lambert
03.12.2025

The Autumn Budget 2025: A Summary

Lucy Matthews, Solicitor in our Commercial Team summarises the Autumn Budget 2025 presented by Chancellor of the Exchequer, Rachel Reeves.

Lucy Matthews
26.11.2025

Commercial Lease Renewals: A guide for Landlords & Tenants

Commercial lease renewals are a topic that every commercial landlord and business that rents commercial premises should have at the forefront of their minds. It is essential for good succession planning, though it is often neglected until the expiry of an existing lease term is looming or once the existing term has come to an end and the tenant is holding over. In this article, our newly qualified solicitor, Maggie Berry explores the process that landlords and tenants can expect when navigating this complex area of law.

Maggie Berry
24.11.2025

Our Guidance, Your Legacy: What is a Will, and why should I make one?

Not only is a Will one of the most important steps you can take to protect your loved ones and ensure your wishes are respected, but it also limits the likelihood of a claim/dispute following your death. To ensure your loved ones and the causes you care about benefit from your estate, a Will is essential to ensuring this happens. Find out more in this article.

Ejike Ndaji
24.11.2025

Lease extensions: The essentials to getting started

Extending your lease can seem complex, but taking the right steps early can make the process much smoother. Jake Mowatt, Associate and Harry Smith, Trainee Solicitor in our Residential Property Team outlines the key essentials every leaseholder should understand prior to extending their lease.

Jake Mowatt
14.11.2025

Leathes Prior acted for Hatfield Investments Limited on the sale of Crossways Residential Home

Leathes Prior's Corporate, Commercial Property & Employment Teams acted for Hatfield Investments Limited on the sale of Crossways Residential Home.

Peter Lambert
13.11.2025

Leathes Prior assists Greenhaul Limited with sale to Ascent Acquisitions Limited

Leathes Prior’s Corporate Team has advised the shareholders of Greenhaul Limited, a family-owned Norfolk transport business, on its sale to Ascent Acquisitions Limited.

Peter Lambert
13.11.2025

Upcoming changes to bringing employment law claims: What these mean for you

The highly anticipated Employment Rights Bill (ERB) is set to increase the time limits in which employees can bring an employment tribunal claim. Gareth Stevens & Rose Woolterton explain what this means for employers & employees.

Gareth Stevens
12.11.2025

Charity of the Month: The Benjamin Foundation

Leathes Prior is thrilled to be supporting The Benjamin Foundation as our Charity of the Month and participating in Sleep Out 2025 this month.

Jess Bullimore
12.11.2025

Service Charges in Residential Leases: FAQs

Service charges are forever a hot topic in the world of property disputes, and it remains one of the most contentious areas between freeholders and leaseholders, particularly in long residential leases. Danny Turpin, Associate, discusses frequently asked questions regarding service charges on long residential leases.

Danny Turpin
31.10.2025

Property Disputes Team helps local landlords

The Leathes Prior Property Disputes Team advises a local landlord on forfeiture in respect of two of its units and a residential landlord on a complex residential possession claim.

Peter Lambert
27.10.2025

Our Charity of the Month: Norfolk and Waveney Mind

With today being World Mental Health Day, Leathes Prior is pleased to be supporting Norfolk and Waveney Mind as our Charity of the Month for October 2025.

Rhiannon Bond
10.10.2025

Leathes Prior winners in nine categories in the prestigious Legal 500 Future Laywer Survey

We are thrilled to announce that the firm has placed once again in the Legal 500 Future Lawyer survey as No.1 in the UK for our Social Life; a ranking we have held in the survey for seven years out of the past nine years.

Jess Bullimore
03.10.2025

Leathes Prior advises Phoenix Support Ltd on EOT structure

Leathes Prior is delighted to have advised Phoenix Support Limited on its transition to an employee-owned business under an Employee Ownership Trust (EOT) structure.

Peter Lambert
29.09.2025

Jess’s Rule – New Guidelines for GPs

A new initiative is being rolled out across GP practices across England in the hope of preventing serious illnesses being missed by GPs where patients present with the same, or deteriorating, symptoms on multiple occasions. Kimberley Nelson in our Personal Injury & Clinical Negligence Team discusses new guidelines for GPs.

Kimberley Nelson
23.09.2025

Our Charity of the Month: The Feed

Leathes Prior is delighted to be supporting The Feed as our Charity of the Month for September 2025. Founded in 2014, The Feed is a Norwich-based charity dedicated to helping our local community to eat well, live well, and feel connected.

Rhiannon Bond
19.09.2025

Leathes Prior expands Employment Team with key appointment

Leathes Prior is delighted to announce the further expansion of our Employment Team with the appointment of Daniel Hughes as a Solicitor.

Peter Lambert
18.09.2025

Leathes Prior are excited to announce that four Trainee Solicitors qualify at the firm

Leathes Prior is excited to announce that four of our amazing trainees, Eleanor Chapman, Maggie Berry, Alex Robinson, and Georgia Sartin, have successfully completed their training contracts and are now qualifying as Solicitors at the firm.

Peter Lambert
15.09.2025

Leathes Prior welcomes five new Trainee Solicitors to the firm

Leathes Prior is delighted to welcome five new Trainee Solicitors to the firm, Dylan Owen, Eleanor Feltwell, Harry Smith, Zumiqo Johnson, and Imogen Fraser.

Peter Lambert
12.09.2025

Get in Touch

By clicking submit, you agree to our Privacy Policy

Submit
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.