ICO fines HelloFresh £140k for spam texts and emails

UK regulator ICO has fined meal-kit company HelloFresh £140,000 for sending around 80 million marketing emails and 1 million texts without valid consent and in some cases continuing after users tried to opt out. Commenters argue the penalty, amounting to a fraction of a penny per message, is too small to deter large firms and risks being treated as a routine cost of doing business. The case feeds into broader concerns about weak enforcement of privacy and anti-spam laws, dark patterns in subscriptions and consent, and the limits of current regulatory frameworks to protect consumers.

Scale and Deterrent Effect of the Fine

  • Many argue £140k for ~80M messages is negligible (fractions of a penny per message) and will not deter similar behavior; seen as “cost of doing business.”
  • Others note regulators often start with small “first-time” fines, escalating sharply for repeat offenses; HelloFresh is now “on the radar.”
  • Some want much harsher initial penalties (e.g., high per-email fines, % of turnover) to prevent companies treating the first violation as a free warning.
  • Counterpoint: regulators’ remit is mainly compliance, not punishment; excessively punitive first fines could be disproportionate and vulnerable to legal challenge.

Assessment of the ICO

  • Several commenters view the ICO as weak, under-enforcing its powers and issuing symbolic fines that set a bad precedent.
  • Others defend the ICO as one of the few active privacy watchdogs outside the EU, constrained by limited resources and legal proportionality.
  • Debate over whether complaint processes and modest outcomes actually incentivize selective compliance (fixing only for those who complain).

HelloFresh Practices and User Experience

  • Multiple reports of persistent SMS, email, and postal spam, rotating phone numbers, weak or broken opt-outs, and continued contact after explicit GDPR deletion requests.
  • Some describe difficult or buggy cancellation flows and dark patterns around subscriptions, “free” boxes, and reactivation offers.
  • Others say cancellation worked fine for them and find the core service convenient, though many criticize recipe quality, pricing, and excessive packaging.

Consent, Dark Patterns, and Legal Loopholes

  • Strong frustration with pre-ticked boxes, “tick to NOT receive” tricks, slow or nonfunctional unsubscribe mechanisms, and “soft opt-in” interpretations.
  • Some emphasize GDPR requires clear, opt-in consent, but practice lags: cookie banners, marketing preferences, and “legitimate interest” are widely abused.
  • Discussion of how current rules and caps (e.g., maximum fine per period, not per message) structurally favor large senders.

Broader Spam and Policy Ideas

  • Some users routinely mark all marketing as spam, accepting the risk of missing transactional emails; others argue this harms legitimate communication.
  • Suggestions include strict opt-in for all corporate contact, high per-message penalties, or protocol/postal reforms to embed consent and reduce spam at the channel level.