Skip to content
Enforcement · ICO (UK) ·Allay Claims Ltd EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ICO (UK) - Allay Claims Ltd

Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services.

€120,000 Fine
United Kingdom

Holding

The DPA noted that the controller did not obtain valid consent from the data subjects for electronic direct marketing messages. Subsequently, the DPA analysed if the controller could have relied on the soft opt-in exception. However, the DPA found that data subjects did not have the opportunity to refuse direct marketing communications at the moment of collection of customer details. Thus, the DPA found that the controller breached Regulation 22(3)(c) PECR, ordered the cessation of unlawful direct marketing communications and fined the controller GBP 120,000 (approximately €138,000).

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Case note 2 findings

Case note by GDPRhub — an account of the decision, not the decision itself. Read the decision

Paragraphs carrying a topic or an applied provision show those connections inline
§

Facts — Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000 complaints regarding the direct marketing messages sent by the controller over the course of one year. The controller claimed it relied on the soft opt-in in Regulation 22(3) of the Privacy and Electronic Communications Regulations 2003 (PECR), where an organisation may send direct marketing communications to its customers even if they did not specifically consent to electronic mail. However, only the organisation that collected the contact details can rely on the soft opt-in rule. The controller therefore argued that it did not require the consent of the individuals for such direct marketing messages. It further argued that the recipients of the messages were previous customers. Holding — The DPA noted that the controller did not obtain valid consent from the data subjects for electronic direct marketing messages.

§

Subsequently, the DPA analysed if the controller could have relied on the soft opt-in exception. However, the DPA found that data subjects did not have the opportunity to refuse direct marketing communications at the moment of collection of customer details. Thus, the DPA found that the controller breached Regulation 22(3)(c) PECR, ordered the cessation of unlawful direct marketing communications and fined the controller GBP 120,000 (approximately €138,000). Holding — The DPA noted that the controller did not obtain valid consent from the data subjects for electronic direct marketing messages. Subsequently, the DPA analysed if the controller could have relied on the soft opt-in exception. However, the DPA found that data subjects did not have the opportunity to refuse direct marketing communications at the moment of collection of customer details. Thus, the DPA found that the controller breached Regulation 22(3)(c) PECR, ordered the cessation of unlawful direct marketing communications and fined the controller GBP 120,000 (approximately €138,000). Comment — Share your comments here!

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB May 4, 2020 Consent Data Portability Personal Data
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… CJEU Mar 27, 2025 Telecommunications Personal Data Marketing
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Legitimate Interest Right to Restriction
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). ·CJEU Jan 9, 2025 IP Address Retention Period Identification
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian… CJEU ·First Chamber Nov 13, 2025 Telecommunications Personal Data Legitimate Interest