Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement September 7, 2026 5 min

The vendor's bug turned into a criminal conviction

An Irish department store pleaded guilty to five charges out of twenty-one over marketing emails you could not unsubscribe from. The cause was a third-party software fault. It did not help

What happened

On 7 September 2026, before Judge Halpin at the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one, for breaches of Regulation 13 of Statutory Instrument 336 of 2011, the Irish rules on unsolicited marketing communications. The Court applied the Probation of Offenders Act and, in light of the conviction, ordered a payment of one thousand euro to a local charity and one thousand euro towards the authority's legal costs.

The origin of the problem is the part that most resembles what happens to everyone. A technical fault at the third-party software provider made it intermittently impossible to unsubscribe from marketing communications. Not a choice, not an aggressive strategy: a fault. And the defence did not help, because the controller remains the party accountable for what those working for it do with the data.

  • Three charges: failure to provide a valid address to opt out, contrary to Regulation 13(12).
  • Two charges: sending marketing communications without valid consent, Regulation 13(1).
  • Some complainants had withdrawn consent in person or by telephone, and kept receiving messages.
  • The authority had already issued a warning to the same company in March 2022.

The third point is the one a DPO should take to a client tomorrow morning. People had said stop using the channels at hand — in store, by phone — and the system kept writing to them because the only door wired up was the unsubscribe link. It is exactly the pattern of the Italian decision against BBVA this September: the person's wish recorded in one place and never propagated to the system that sends.

Why two thousand euro is not the story

In Ireland, breaches of the ePrivacy marketing rules do not end in an administrative fine: they are prosecuted criminally, and the authority takes the company before a judge. What remains is not the payment, which is symbolic, but the conviction of a listed retailer on the court record. Anyone assessing marketing risk by looking at the size of fines is reading the wrong column.

And there is the 2022 warning. A fault can happen to anyone; a fault on the very matter you were warned about four years earlier is something else, and that is what turns a technical problem into a prosecution. The practical question to put to every client who sends newsletters is one, and it is not about consent: who checks, and how often, that the unsubscribe link actually works and that a withdrawal arriving by another channel reaches the system that sends?

Official source:Data Protection Commission — DPC welcomes outcome of prosecution of marketing offences (08/09/2026)Official source:Data Protection Commission — Latest news

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min
Enforcement
72hours of retention never justified

Cameras in the changing rooms since 2007: the defence lists what they did not film, and loses

The defence brief is a list of things that were not visible: not the cubicles, not the showers, not the toilets; and near the lockers there are no benches «that might induce someone undressing to sit there and so be captured by the video system». It is reasoning by subtraction, and in a changing room it does not work. For the DPO, though, the passage to keep is another: among the provisions breached is Art. 5(1)(e), because the seventy-two hours of retention declared were not supported by any assessment showing they were necessary.

Sep 22, 2026New 5 min