ICO - Monetary penalty to CRDNN

From GDPRhub
Revision as of 14:48, 3 March 2020 by AL (talk | contribs)
ICO - Enforcement notice to CRDNN
Authority: ICO (UK)
Jurisdiction: United Kingdom
Relevant Law:
[ Section 40 Data Protection Act 1998]
[ Regulations 19 and 24 Privacy and Electronic Communication Regulations 2003]
Type: Investigation
Outcome: Violation found
Decided: 26. 2. 2020
Published: 2. 3. 2020
Fine: 500,000 £
Parties: n/a
National Case Number/Name: Enforcement notice to CRDNN
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): English
Original Source: ICO (in EN)
Initial Contributor: {{{Initial_Contributor}}}


English Summary


CRDNN was raided by the ICO which after investigation found that the company had instigated 193.606.544 attempted automated calls for the purpose of direct marketing, of which 63.615.075 were connected. CRDNN came to the attention of the ICO when more than 3.000 complaints were made about the nuisance calls.



The ICO found that there was no consent for these calls and in fact many of the complainants had sought to opt-out but CRDNN had not facilitated that. Thus, there was violation of regulation 19 PECR.

The ICO also found that the calls were carried out from spoofed CLIs while during the calls no company information or contact details were provided. In result, people who received the calls could not identify who was making them. Thus, there was violation of regulation 24 PECR.


Feel free to add your comment here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

Not applicable. Please see the English original.