Live data from Hacker News

ICO fines HelloFresh £140k for spam texts and emails

ico.org.uk

131–140 of 144 posts

Re: ICO fines HelloFresh £140k for spam texts and emails

#131

Earlier quoted context omitted.

Indeed. If someone is going to argue credibly for treating everything from commercial sources as spam then they also need to explain how businesses can provide any information they are actively required to provide to their customers either by law or by whatever method the customer is using to pay them. In general the merchants have no say in this and the penalties for failing to provide the information can be far mor…

It is their choice to pollute the channel they use to communicate with customers with spam. They don’t have to send spam, and if they offer the option they shouldn’t make opting out difficult or dark-patterned. Same thing with crying wolf and all that.

The problem is that there are people who will classify any unsolicited mail from any business they've dealt with as spam. And by "classify" I mean hitting whatever button they have in their email client that says so - which for online email services is likely to affect future processing of mail from related sources for themselves and potentially for others as well.

It doesn't matter to those people whether there was a quick and easy way to unsubscribe or change preferences. It doesn't matter to those people that they actively requested that kind of mail a few months ago and have forgotten. It doesn't matter to those people that they might end up blocking important messages they do want later. It doesn't even matter to those people that they're flagging information that is required by law to be provided to them. There is no nuance here. Got mail. Hit "spam". Done.

Some of these people even think that marking the transactional "thanks for your payment" mail as spam will somehow end their subscription to your service or get them out of a long-term contract early! Then they'll issue a chargeback that is also totally inappropriate and in violation of contract and claim that they gave notice to cancel by "unsubscribing" from the emails by marking them as spam.

Dealing with customer support for those people is not fun. In a perfect world it would go both ways and we could have a system that notified us of such behaviour immediately so we could choose not to do business with those people in the future. It is as sure an indicator of a customer who is not worth the trouble as I have ever found after people attempting actually criminal behaviour.

Spam is a difficult problem. Obviously a lot of senders really are abusing the recipients in ways that are not welcome and should ideally be stopped. But there are plenty of recipients abusing the senders of legitimate messages too.

Re: ICO fines HelloFresh £140k for spam texts and emails

#132

Earlier quoted context omitted.

I just mark all marketing emails as spam now. Since I never want them, I can't have opted in to it so it's spam. Seems very effective at having my email provider forward all future emails from them to spam and hopefully tarnishes their sender trust rating a little.

The trouble is you may end up with transactional emails in your spam folder.

That's not really a trouble at all if you're used to dealing with mail

Re: ICO fines HelloFresh £140k for spam texts and emails

#133
post #40
post #23

Earlier quoted context omitted.

Yesterday I created an account on John Lewis' website, and I was please to see that during sign-up, they had an unchecked "Tick here if you want our newsletter." Then, later I placed an order, and during credit card checks I noticed a "Tick here if you do NOT want our newsletter", which was of course unchecked and that's how the fuckers got me. Fuck this dark pattern, and fuck the Product Manager that requested it. T…

> There literally should be a law that says you cannot ask a user to check a box NOT to give away their data. There is!

[deleted]

Re: ICO fines HelloFresh £140k for spam texts and emails

#134
post #23

Earlier quoted context omitted.

Yesterday I created an account on John Lewis' website, and I was please to see that during sign-up, they had an unchecked "Tick here if you want our newsletter." Then, later I placed an order, and during credit card checks I noticed a "Tick here if you do NOT want our newsletter", which was of course unchecked and that's how the fuckers got me. Fuck this dark pattern, and fuck the Product Manager that requested it. T…

The ICO calls this a soft opt-in and it’s perfectly legal.

Legal, but wrong. There is no such thing as a ambiguous consent, and it's a fucking catastrophe that we've legislated ambiguous consent into our statute.

Re: ICO fines HelloFresh £140k for spam texts and emails

#135

Earlier quoted context omitted.

The ICO calls this a soft opt-in and it’s perfectly legal.

Legal, but wrong. There is no such thing as a ambiguous consent, and it's a fucking catastrophe that we've legislated ambiguous consent into our statute.

It’s not consent, it’s legitimate interest.

Re: ICO fines HelloFresh £140k for spam texts and emails

#136

Earlier quoted context omitted.

It is their choice to pollute the channel they use to communicate with customers with spam. They don’t have to send spam, and if they offer the option they shouldn’t make opting out difficult or dark-patterned. Same thing with crying wolf and all that.

The problem is that there are people who will classify any unsolicited mail from any business they've dealt with as spam. And by "classify" I mean hitting whatever button they have in their email client that says so - which for online email services is likely to affect future processing of mail from related sources for themselves and potentially for others as well. It doesn't matter to those people whether there was…

> The problem is that there are people who will classify any unsolicited mail from any business they've dealt with as spam.

I'd agree if this was the edge-case, but the truth is that most businesses tend to lean towards sending more email than they need to, so overzealous use of the spam button is an expected reaction in response.

> which for online email services is likely to affect future processing of mail from related sources for themselves and potentially for others as well.

That's the system working as designed - if in aggregate most people signal that they don't want to receive a certain piece of mail or all mail from a certain sender, chances are I will agree with their decision.

> But there are plenty of recipients abusing the senders of legitimate messages too.

I'll be happy to change my mind once email becomes strictly opt-in and senders would err on the side of caution and the default is no email at all and you must explicitly opt into every distinct category of email, with the opt-in being located in the same annoying and hard-to-reach places as the opt-outs currently are.

That's not (yet?) the case, suggesting the spam button isn't being pressed enough. You're trying to guilt people about liberal use of the mark-as-spam button but you seem to have no issues with senders liberally using the "send spam" button.

Re: ICO fines HelloFresh £140k for spam texts and emails

#137

Earlier quoted context omitted.

Maybe if this was an isolated incident then you’d be right, but the ICO has a history of being useless. Keep in mind that merely building a complaint is a very high bar (which gives plenty of opportunity for the company to rectify the situation), so when a complaint does make it through I’d expect it to lead to appropriate punishment since the company already got a chance to address your concern if they wanted to. I’…

"Useless" seems unfair and inaccurate. In this case it appears they have successfully addressed a problem for example. Like most UK government services the ICO are currently operating with a fraction of the resources they need to meet the responsibilities they've been given. While I respect your personal effort to get bad actors to change and I share your disappointment that the officials who should be helping have n…

> the ICO are currently operating with a fraction of the resources

But the amount of resources shouldn't dictate the penalty amount once resources have already been expended on the investigation?

My problem with the ICO as it stands is that the bar for a complaint is very high, giving the company many chances to selectively rectify the situation but only for the complainant - imagine if the penalty for theft was just to give back the stolen property and only if you got caught.

The very high bar with regards to complaints should mean that for a complaint to be considered valid the company must've ignored the multiple attempts they get to rectify the situation, so the fine should be substantial.

As it stands, not only does the complaints process effectively set the example that it's OK to breach the GDPR as long as you can selectively apply it to the very small minority that complains, but even that when a complaint does make it through it turns out the consequences are not a problem.

Re: ICO fines HelloFresh £140k for spam texts and emails

#138
post #15

HelloFresh seems to be optimising for user count above all else (incl profit). They keep offering their big -40% loss leader promos to people that cancelled. Must be costing them an ungodly amount.

1) they will sign you up via this or another dark pattern so that you will have to threaten legal action and otherwise waste time demanding they refund you – I imagine many people agree to receive their low quality food for some time instead of wasting the energy on arguing with them 2) the produce they sent us in Germany was lowest possible quality, soft potatoes, discounter stuff that might have been at the end of its shelf life, so even at 4€ per meal they are profiting for sure

Re: ICO fines HelloFresh £140k for spam texts and emails

#139

Earlier quoted context omitted.

The problem is that there are people who will classify any unsolicited mail from any business they've dealt with as spam. And by "classify" I mean hitting whatever button they have in their email client that says so - which for online email services is likely to affect future processing of mail from related sources for themselves and potentially for others as well. It doesn't matter to those people whether there was…

> The problem is that there are people who will classify any unsolicited mail from any business they've dealt with as spam. I'd agree if this was the edge-case, but the truth is that most businesses tend to lean towards sending more email than they need to, so overzealous use of the spam button is an expected reaction in response. > which for online email services is likely to affect future processing of mail from re…

You're trying to guilt people about liberal use of the mark-as-spam button but you seem to have no issues with senders liberally using the "send spam" button.

On the contrary. I dislike spam as much as the next person and I have never allowed my own businesses to engage in "common" practices I consider unacceptable even when that has almost certainly cost us money.

I'm just saying there are two sides to this story and extreme solutions in favour of either one side will probably have undesirable side effects for innocent parties.

Re: ICO fines HelloFresh £140k for spam texts and emails

#140

Earlier quoted context omitted.

Legal, but wrong. There is no such thing as a ambiguous consent, and it's a fucking catastrophe that we've legislated ambiguous consent into our statute.

It’s not consent, it’s legitimate interest.

Yea, if only the laws reflected what people actually want. "legitimate" is only as good as the laws that back it.
Post reply on HN