Carphone Warehouse was fined €1,250 on each of two charges relating to the sending of an unsolicited email marketing messages. The court heard the company had previously been warned in relation to similar breaches, although it had no previous convictions.Pro tip: if you're going to spam, try not to spam the Data Protection Commissioner's Director of Investigations.
Meteor was also prosecuted over the sending of an unsolicited marketing email. The customer who complained to the Data Protection Commissioner had previously gone to "some lengths" to ensure he would not be contacted by the company, the court heard. While the customer was the only one who complained, the message had been sent to between 11,000 and 18,500 people who should not have received it, the court heard. Counsel for the Data Protection Commissioner agreed that while Meteor had no previous convictions for such offences, it had previously had the benefit of the Probation Act. Judge O'Neill said that if the company paid €5,000 to Temple Street children's hospital by December 17th, he would strike out the charge. If the money was not paid by that date he would convict and impose a fine of €5,000.
Hutchison 3G, trading as Three, was prosecuted on three counts - one of sending an unsolicited email, one in relation to an unsolicited phone call, and a third in relation to an unsolicited marketing text message sent to deputy data protection commissioner Gary Davis.
Judge O'Neill asked the company to pay €2,500 to Crumlin children's hospital by December 17th. He said if such payment was made he would strike out the charge. He took two of the three charges into account.
Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts
Monday, December 03, 2012
Irish mobile phone companies: still spammy
Saturday, January 10, 2009
Data Protection Commissioner may prosecute for spam without seeking negotiated settlement - High Court
As we've seen before ("How to be sued by space cadets") Realm Communications has been trying to stymie prosecutions being brought against it for spam. Their claim has been that the Data Protection Commissioner is under a statutory duty to seek an amicable resolution before resorting to the heavy guns of a criminal prosecution.
In the recent statutory instrument amending data protection law the Minister sought to preempt this argument for future cases, by including a provision stating that:
The High Court has now rejected the argument that an amicable resolution must be sought, McCarthy J. holding (according to the Irish Times report) that "the absence of resolution attempts did not erase the fact that regulations were breached". This is an unsurprising result - the legislation certainly doesn't expressly provide that there must be an attempt at settlement, and while it might be best practice to do so, a strict duty would tie the hands of the DPC (especially when dealing with repeat offenders) and would undermine the effectiveness of the criminal penalty. But though the result might have been predictable the ruling is still useful, particularly as it clarifies the position in respect of other pending prosecutions. (Edited to add: full judgment now available here.)
In the recent statutory instrument amending data protection law the Minister sought to preempt this argument for future cases, by including a provision stating that:
If of the opinion that the circumstances relating to a complaint investigated under Regulation 17 involve the commission of an offence under these Regulations, the Commissioner may bring and prosecute proceedings for the offence without attempting to bring about an amicable resolution of the complaint.But this still left the position in doubt in respect of offences committed and prosecutions commenced before this change.
The High Court has now rejected the argument that an amicable resolution must be sought, McCarthy J. holding (according to the Irish Times report) that "the absence of resolution attempts did not erase the fact that regulations were breached". This is an unsurprising result - the legislation certainly doesn't expressly provide that there must be an attempt at settlement, and while it might be best practice to do so, a strict duty would tie the hands of the DPC (especially when dealing with repeat offenders) and would undermine the effectiveness of the criminal penalty. But though the result might have been predictable the ruling is still useful, particularly as it clarifies the position in respect of other pending prosecutions. (Edited to add: full judgment now available here.)
Monday, December 22, 2008
Increased criminal penalties for spammers
In good news for Irish internet and mobile phone users the sending of spam has for the first time become an indictable offence, carrying a possible maximum penalty of €250,000 or up to 10% of a company's turnover (Sunday Times, Silicon Republic). Most cases will presumably remain in the District Court, where the maximum penalty is increased to €3,000. The changes should substantially strengthen the hand of the Data Protection Commissioner in dealing with persistent offenders.
Update - 12 January 2009: The full text of the amending statutory instrument is now available. Other changes made by the SI include extending to two years the period in which summary prosecutions can be brought, providing that in prosecutions where consent is an issue the burden of proof rests on the defendant to show that a subscriber opted in, clarifying the scope of the soft opt-in provision in respect of similar goods or services, and providing that an officer of a company can be prosecuted without the need first to proceed against or convict the company of the offence.
Update - 12 January 2009: The full text of the amending statutory instrument is now available. Other changes made by the SI include extending to two years the period in which summary prosecutions can be brought, providing that in prosecutions where consent is an issue the burden of proof rests on the defendant to show that a subscriber opted in, clarifying the scope of the soft opt-in provision in respect of similar goods or services, and providing that an officer of a company can be prosecuted without the need first to proceed against or convict the company of the offence.
Thursday, July 14, 2005
Tackling spam - some freedom of expression problems
Wendy McElroy explains that new US anti-spam / child protection laws could criminalise perfectly ordinary email mailing lists, while attempting to comply with the laws will involve handing a list of recipients over to the government for vetting:
Both Utah and Michigan have created a 'child protection registry' for email addresses that belong to children or to which children have access. It functions like a 'no call list.' Spamfo.co explains, 'Once an email address is on the registry, commercial emailers are prohibited from sending it anything containing advertising, or even just linking to advertising, for a product or service that a minor is otherwise legally prohibited from accessing, such as alcohol, tobacco, gambling, prescription drugs, or adult-rated material.' In short, e-newsletters (such as ifeminists.net) are not permitted to send to registered email addresses if those newsletters include URLs to news sites that, in turn, link to child-inappropriate commerical information or products such as casino or viagra ads, tobacco or alcohol for sale.There's more on these new laws from Declan McCullagh at News.com.
Many credible news sources -- especially British ones, it seems -- offer links to adult-themed sites or products. These links can change constantly, which means that it is impossible to check a URL and 'clear' it of so-called objectionable links or ads.
Moreover, e-mailing to registered addresses is illegal even if the newsletter was requested, and the legal penalties for doing so are imposed without notifying the offender so that he/she can rectify the situation. What are those penalties? To quote Prof. Mitchell again, 'Under these laws...that email sender faces strict liability which can include up to 3 years in prison, and fines of $30,000 or more. In addition, ISPs and the individuals whose email addresses are on the registry have a right of action against the sender, as does the state attorney general.'
The only protection is for the emailer to make sure that a particular address is not 'illegal' by matching his/her mailing list against the registries. That process requires at least two things that I am unwilling to do: 1) turn my mailing list over to the government; and 2) pay a per-address fee.
Tuesday, April 19, 2005
Political Spam
The 2004 Report of the Data Protection Commissioner (pdf - summary in word format) has just been released. There are several interesting case studies - one of which confirms that political spam is alive and well in Ireland. Note the unrepentent attitude of the politician in question:
(There are two uncertainties raised by this case though. First, how did the councillor breach the 2003 Regulations by his actions in June 2003, when those Regulations only came into force on 6 November 2003? Second, under Irish law there is now an exemption for "direct mailing ... in the course of political activities" (s.1 of the Data Protection Act 1988 as amended). Is the term "direct mailing" wide enough to cover email (allowing this type of spam), or would it be limited to snail mail?)
[A] complaint ... was received in late 2003 ... about an unsolicited email of a political nature which had been sent by a County Councillor, Jon Rainey, of Fingal County Council. It was alleged that in June 2003 he had “harvested” email addresses from the address line of an email sent by a third party – who was also a County Councillor but of another party. (“Harvesting” refers to the addition to one’s own mailing list of any email address received on the “to” or “cc” line of the email). This was in contravention of the provisions of S.I. No. 535 of 2003 (European Communities (Electronic Communications Networks and Services (Data Protection) Regulations 2003) which provides for prior consent for unsolicited emailing of individuals for direct marketing purposes, including political purposes. I only name Mr. Rainey in my Report as he failed to cooperate with my investigations and only acknowledged the facts of the complaint 6 months after I had first raised them and then only when I had to formally issue him with an Information Notice under sections 10 and 12 of the Acts. At that late stage, he confirmed that the details of email addresses “harvested” from another email had been deleted from his system and that no further details had been obtained in this manner. However, his attitude to my Office was that the matter was of little consequence and he complained that I had “pestered” him. It is important that public representatives and candidates for elective office realise the importance of their obligations under the Acts and that, in so far as responding to legitimate investigations from statutory office holders is concerned, in no sense should they consider themselves above the law.Irish politicians have been active spammers in the past, with the 2002 election campaign seeing voters annoyed by automated recorded phone calls and sms text messages, which were ultimately stopped by the intervention of the Data Protection Commissioner.
(There are two uncertainties raised by this case though. First, how did the councillor breach the 2003 Regulations by his actions in June 2003, when those Regulations only came into force on 6 November 2003? Second, under Irish law there is now an exemption for "direct mailing ... in the course of political activities" (s.1 of the Data Protection Act 1988 as amended). Is the term "direct mailing" wide enough to cover email (allowing this type of spam), or would it be limited to snail mail?)
Friday, November 26, 2004
ISP resorts to denial of service attacks on spammers
From The Register:
Before you ask: Lycos isn't necessarily shielding itself from liability by "making sure that no server stops working". Some jurisdictions do seem to require an attack which brings down a server, but equally some of the US laws mentioned in that article criminalise the degradation of service as well as an outright denial of service.
"Lycos Europe has started to distribute a special screensaver in a controversial bid to battle spam. The program - titled Make Love Not Spam, and available for Windows and the Mac OS - sends a request to view a spam source site. When a large number of screensavers send their requests at the same time the spam web page becomes overloaded and slow.This is an interesting twist on the usual denial of service attack. Is Lycos exposing itself (and potentially the users of the screensavers) to criminal liability? In Ireland and the UK the answer would most likely be no - as I argue in this article on computer crime, current law fails to address this sort of attack, which falls outside the unauthorised access offences and the damage offences. However, Lycos might well be in trouble if it targets US based spammers - see Jeff Nemerofksy's piece on "Interruption of Computer Services to Authorised Users".
The servers targeted by the screensaver have been manually selected from various sources, including Spamcop, and verified to be spam advertising sites, Lycos claims. Several tests are performed to make sure that no server stops working. Flooding a server with requests so that the server is unable to respond to the volume of requests made - a process known as a distributed denial of service (DDoS) attack - is considered to be illegal.
Lycos believes the program will eventually hurt spammers. 'Spamvirtised' sites typically don't sell advertising, so they have to pay for bandwidth. Therefore more requests means higher bills, Lycos argues."
Before you ask: Lycos isn't necessarily shielding itself from liability by "making sure that no server stops working". Some jurisdictions do seem to require an attack which brings down a server, but equally some of the US laws mentioned in that article criminalise the degradation of service as well as an outright denial of service.
Subscribe to:
Posts (Atom)
