American Express Services Europe Limited – €105,300 Fine (United Kingdom, 2021)
American Express was fined EUR 105,300 for sending marketing emails to subscribers who had opted out. This case matters because it shows that companies must respect users' preferences regarding marketing communications.
What happened
AMEX sent over 4 million marketing emails to users who had opted out of receiving such communications.
Who was affected
Subscribers who had opted out of receiving marketing emails from American Express.
What the authority found
The UK's Information Commissioner's Office found that AMEX sent marketing emails without adequate consent, violating data protection rules.
Why this matters
This case highlights the need for companies to have clear consent mechanisms in place. Businesses should regularly review their marketing practices to ensure compliance with data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Entities Involved
Between 1 June 2018 to 31 May 2019, a total of 4,098,841 direct marketing messages were sent to subscribers who had opted-out to receiving marketing emails by, or at the instigation, of AMEX. These messages contained direct marketing material for which subscribers had not provided adequate consent. AMEX says the emails had not been classified as "marketing emails" but "servicing" emails " feeling that Card Members would be at a disadvantage if they were not aware of these campaigns and promotional periods". They consequently argued such emails did not demand consent under the UK PECR. The ICO was satisfied that these emails constituted "direct marketing" as defined by section 122(5) of the UK Data Protection Act 2018, because each of the emails encouraged customers to use their AMEX credit cards to make purchases. One category of emails (the AMEX app emails) also encouraged customers to download and/or use the AMEX app. Additionally, the ICO pointed out that AMEX's "International Email Policy - United Kingdom" indicates that "servicing" emails involve advertising and marketing content. The ICO considered that the contravention was serious as between the 12-month period, a confirmed total of 4,098,841 direct marketing messages were sent containing direct marketing material for which subscribers had not provided adequate consent. Further, AMEX had failed to take reasonable steps to prevent the contraventions. The ICO therefore fined AMEX £90,000.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for American Express Services Europe Limited in UK
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
17 May 2021
Authority
Information Commissioner's Office
Fine Amount
€105,300
90,000 GBP
GDPRhub ID
gdprhub-3494About this data
Cite as: Cookie Fines. American Express Services Europe Limited - United Kingdom (2021). Retrieved from cookiefines.eu
Last updated: