ICO fines HelloFresh £140k for spam texts and emails
UK regulator ICO has fined meal-kit company HelloFresh £140,000 for sending around 80 million marketing emails and 1 million texts without valid consent and in some cases continuing after users tried to opt out. Commenters argue the penalty, amounting to a fraction of a penny per message, is too small to deter large firms and risks being treated as a routine cost of doing business. The case feeds into broader concerns about weak enforcement of privacy and anti-spam laws, dark patterns in subscriptions and consent, and the limits of current regulatory frameworks to protect consumers.
Scale and Deterrent Effect of the Fine
- Many argue £140k for ~80M messages is negligible (fractions of a penny per message) and will not deter similar behavior; seen as “cost of doing business.”
- Others note regulators often start with small “first-time” fines, escalating sharply for repeat offenses; HelloFresh is now “on the radar.”
- Some want much harsher initial penalties (e.g., high per-email fines, % of turnover) to prevent companies treating the first violation as a free warning.
- Counterpoint: regulators’ remit is mainly compliance, not punishment; excessively punitive first fines could be disproportionate and vulnerable to legal challenge.
Assessment of the ICO
- Several commenters view the ICO as weak, under-enforcing its powers and issuing symbolic fines that set a bad precedent.
- Others defend the ICO as one of the few active privacy watchdogs outside the EU, constrained by limited resources and legal proportionality.
- Debate over whether complaint processes and modest outcomes actually incentivize selective compliance (fixing only for those who complain).
HelloFresh Practices and User Experience
- Multiple reports of persistent SMS, email, and postal spam, rotating phone numbers, weak or broken opt-outs, and continued contact after explicit GDPR deletion requests.
- Some describe difficult or buggy cancellation flows and dark patterns around subscriptions, “free” boxes, and reactivation offers.
- Others say cancellation worked fine for them and find the core service convenient, though many criticize recipe quality, pricing, and excessive packaging.
Consent, Dark Patterns, and Legal Loopholes
- Strong frustration with pre-ticked boxes, “tick to NOT receive” tricks, slow or nonfunctional unsubscribe mechanisms, and “soft opt-in” interpretations.
- Some emphasize GDPR requires clear, opt-in consent, but practice lags: cookie banners, marketing preferences, and “legitimate interest” are widely abused.
- Discussion of how current rules and caps (e.g., maximum fine per period, not per message) structurally favor large senders.
Broader Spam and Policy Ideas
- Some users routinely mark all marketing as spam, accepting the risk of missing transactional emails; others argue this harms legitimate communication.
- Suggestions include strict opt-in for all corporate contact, high per-message penalties, or protocol/postal reforms to embed consent and reduce spam at the channel level.