What happened
On 7 September 2026, before Judge Halpin at the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one, for breaches of Regulation 13 of Statutory Instrument 336 of 2011, the Irish rules on unsolicited marketing communications. The Court applied the Probation of Offenders Act and, in light of the conviction, ordered a payment of one thousand euro to a local charity and one thousand euro towards the authority's legal costs.
The origin of the problem is the part that most resembles what happens to everyone. A technical fault at the third-party software provider made it intermittently impossible to unsubscribe from marketing communications. Not a choice, not an aggressive strategy: a fault. And the defence did not help, because the controller remains the party accountable for what those working for it do with the data.
- Three charges: failure to provide a valid address to opt out, contrary to Regulation 13(12).
- Two charges: sending marketing communications without valid consent, Regulation 13(1).
- Some complainants had withdrawn consent in person or by telephone, and kept receiving messages.
- The authority had already issued a warning to the same company in March 2022.
The third point is the one a DPO should take to a client tomorrow morning. People had said stop using the channels at hand — in store, by phone — and the system kept writing to them because the only door wired up was the unsubscribe link. It is exactly the pattern of the Italian decision against BBVA this September: the person's wish recorded in one place and never propagated to the system that sends.
Why two thousand euro is not the story
In Ireland, breaches of the ePrivacy marketing rules do not end in an administrative fine: they are prosecuted criminally, and the authority takes the company before a judge. What remains is not the payment, which is symbolic, but the conviction of a listed retailer on the court record. Anyone assessing marketing risk by looking at the size of fines is reading the wrong column.
And there is the 2022 warning. A fault can happen to anyone; a fault on the very matter you were warned about four years earlier is something else, and that is what turns a technical problem into a prosecution. The practical question to put to every client who sends newsletters is one, and it is not about consent: who checks, and how often, that the unsubscribe link actually works and that a withdrawal arriving by another channel reaches the system that sends?
Official source:Data Protection Commission — DPC welcomes outcome of prosecution of marketing offences (08/09/2026)Official source:Data Protection Commission — Latest newsLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free