Who is the data controller in the outsourcing of marketing services?

16 February 2023

The entity that commissions the processing of personal data on its behalf for the purposes of direct marketing, while specifying the principles of marketing activities and methods of data processing, is considered the data controller. This will be the case regardless of whether it has access to the addresses to which the messages will be sent or not.

Commissioning Services in Direct Marketing – Who is Who?

It is well known that the foundation of every entrepreneur's activity is an appropriate customer base. In order to acquire customers, entities undertake actions using various forms of direct marketing, including sending SMS messages or emails, and making phone calls. Very often, as part of outsourcing, the execution of advertising tasks is entrusted to specialized entities.

In such cases, questions arise – who is responsible for the processing of personal data? Who is the data controller, and who acts as the data processor?

Proceedings Before the Swedish Data Protection Authority (IMY)

The Swedish Data Protection Authority (IMY) provided answers to the above issues in a decision dated June 27, 2022, issued in connection with a complaint by an individual regarding violations of their personal data by the Swedish bank - Nordax Bank AB. The allegations concerned: the failure to fulfill the right of access by Nordax (Article 15 GDPR) and the failure to delete personal data of the entity at their request (Article 17 GDPR).   

Nordax Bank utilized the services of an external entity – Iper Direkt AB (Iper), which, at the request of Nordax and based on the criteria specified by Nordax, selected specific entries from its address register, which were then transferred to another data processor on behalf of Nordax for the purpose of conducting Nordax's direct marketing. It is significant that Nordax determined the purposes and means of data processing.

Nordax claimed that the agreements concluded between Iper and Nordax stipulated that the processing of personal data for direct marketing would be carried out by Iper, acting on behalf of Nordax. Nordax also asserted that, in connection with the agreement with Iper, Iper is the data controller of the address register and, as such, is responsible for managing the rights of individuals whose data is available in this register. According to Nordax, it neither processed nor stored any personal data, as the data provided to Nordax by Iper was devoid of identity – it was pseudonymized.

To better illustrate the presented topic, it is worth citing an example from IMY, in which company ABC commissioned company XYZ to obtain information about which type of consumers is most interested in the products of company ABC. At the same time, company ABC instructed company XYZ on what type of information it was interested in and provided a list of questions that needed to be asked to the individuals participating in the market research. Company ABC received statistical information from company XYZ, without access to the personal data of the individuals participating in the study. In this example, it is significant that it was company ABC that decided that data processing should take place at all; furthermore, the processing was carried out for the purpose specified by ABC, and company ABC provided company XYZ with detailed instructions regarding what information should be obtained. For these reasons, in the described example, company ABC should be considered the data controller, while company XYZ is the data processor (acting in accordance with the instructions of company ABC).

In considering the case, the Swedish data protection authority first examined whether Nordax was at all a data controller and whether this entity was obliged to address the complainant's requests to exercise their rights. 

Does the data controller need to have access to the data?

During the proceedings, Nordax repeatedly indicated that it was not dealing with personal data, as the data provided to Nordax by Iper did not allow for the identification of the individuals concerned. Moreover, Nordax did not process or store the personal data of the complainant, and therefore the complainant should direct their requests regarding their personal data directly to Iper.

However, IMY stated that in order to be recognized as a data controller in the case of processing, an entity does not need to have access to or store the data. What matters is that such an entity decides on the purposes and means of processing the data. In this case, such action on the part of Nordax did occur – although the data was processed by Iper, the processing was carried out on behalf of Nordax and based on the selection criteria established by this entity. Since Nordax determined the purposes and means of processing, Nordax should be recognized as the data controller in terms of the processing. In practice, this meant that Nordax was responsible for handling the complainant's requests.

Furthermore, the IMY stated that the fact of receiving data from Iper that lacked identifying features had no bearing on Nordax's liability for processing the complainant's request. The IMY indicated that even information that may indirectly identify a natural person, including information that is coded, encrypted, or pseudonymized, but can be linked to a natural person, constitutes personal data.

DPO Function - it is well transferred

IMY's Position

Given that the IMY recognized Nordax as the data controller in relation to the processing that was the subject of the complaint, Nordax was responsible for ensuring that the complainant's requests to exercise rights under the GDPR were addressed.  

During the proceedings, the IMY found violations on the part of Nordax concerning the complainant, consisting of the failure to grant the complainant access to their personal data, the failure to address the complainant's request for data deletion, and the failure to inform the complainant about the measures taken by Nordax in response to the complainant's request regarding the exercise of their right to object to the processing of data for direct marketing purposes. Consequently, the IMY issued a reprimand to Nordax and obligated it to take specific actions on behalf of the complainant. 

Liability for Failure to Obtain Consent in the Context of Direct Marketing Services, Based on the Resolution of the Supreme Court (III SZP 7/15)

In the context of the discussed topic, it is worth examining the position taken by the Supreme Court in its resolution of February 17, 2016 (case reference III SZP 7/15).

In this case, at the request of the plaintiff – a telecommunications entrepreneur, an external entity conducted a lottery for the plaintiff's clients. The plaintiff provided this entity with information regarding subscribers along with their consents concerning the transmission of information. Lottery announcements were sent using the plaintiff's infrastructure. During the lottery, SMS text messages and IVR voice messages were sent to the plaintiff's subscribers and end users via automated calling systems (ACS).

During the proceedings conducted by the President of the Office of Electronic Communications, it was found that the plaintiff failed to fulfill the obligations of obtaining consent from subscribers or end users of the plaintiff's telecommunications network for the use of automatic calling systems (ASW) for direct marketing purposes and the use and application of ASW in relation to these subscribers or end users for direct marketing purposes, including sending SMS text messages or IVR voice messages encouraging participation in a lottery. Ultimately, the President of the UKE imposed a financial penalty on the plaintiff, against which the plaintiff appealed.

In the context of the ongoing proceedings, the Court of Appeal – considering the case as a second-instance court, due to the emergence of a legal issue raising serious doubts, referred a legal question to the Supreme Court:

„Is it permissible to impose a financial penalty, based on Article 209(1)(25) of the Act of July 16, 2004, Telecommunications Law (Journal of Laws No. 171, item 1800, as amended) in connection with Article 172(1) and Article 174(1) of this Act, on a telecommunications entrepreneur, in a situation where they commissioned another entity to conduct a promotional campaign for their services, which was carried out using automatic calling systems for direct marketing purposes without obtaining consent from the subscribers or end users who are the recipients of such actions?".

In order to answer the posed question, the Supreme Court was obliged to first examine whether, despite the fact that the entrepreneur commissions another entity to use automatic calling systems (ASW) for the purpose of promoting their services, providing a database of subscriber or end user numbers to which SMS messages are to be directed, it violates the prohibition on using automatic calling systems without having marketing consents? Or does the commissioning of this service to an external entity exempt this entrepreneur from the obligation to obtain consents?

When we talk about the use of automatic calling systems

Dr RODO
GDPR Compliance Diagnosis.
Do it yourself
Utilize a flexible tool for inventory, auditing, conducting DPIA, and risk analysis.
MEET DR RODO
The Supreme Court ruled that the use of Automated Calling Systems (ASW) is constituted by merely commissioning such an action to another external entity for promotional purposes of the plaintiff's services and providing them with a database of subscriber and end-user numbers to which SMS messages are to be directed.

The plaintiff determined the conditions for organizing and conducting the lottery, including the details related to communication with subscribers and end-users of the plaintiff's network regarding the lottery. It should not be forgotten that it was the plaintiff who chose ASW as the method for directing direct marketing communications, which, in the opinion of the Supreme Court, resulted in the plaintiff actually using ASW for direct marketing purposes.

The Supreme Court emphasized that in a situation where the provider specifies the principles of marketing activities, the target group, provides mobile numbers to which calls are to be made via ASW, and includes marketing consents, it should be considered that this constitutes the use of ASW within the meaning of the Telecommunications Law, and such use requires prior consent from the subscriber or end-user.

Therefore, despite the fact that the plaintiff did not independently use ASW, but commissioned such action for direct marketing purposes addressed to subscribers and end-users to a third party, it is considered that the plaintiff was using ASW.

For this reason, the obligation to obtain the subscriber's consent for the use of ASW burdens not only the entity that actually uses ASW but also the entrepreneur who commissions the use of ASW to another entrepreneur for direct marketing purposes addressed to subscribers and end-users, whose database was provided to that other entrepreneur. Consequently, in connection with the breach of obligations arising from the Telecommunications Law, the plaintiff was also subject to the liability resulting from it.

Position of the Supreme Court

The Supreme Court also took this position, stating that there are no obstacles to imposing a financial penalty on the telecommunications entrepreneur who commissioned another entity to use ASW for direct marketing purposes of that entrepreneur's services among its subscribers or end-users based on the database of provided phone numbers.

Summary

In response to the questions posed at the outset:

  • who is the data controller in the context of commissioning direct marketing services?
  • who bears responsibility for violations of obligations regarding obtaining consents in such cases?

It should be acknowledged that the data controller will typically be the entity that engages any other legal person to process personal data on its behalf. The data processor is the entity to which these tasks have been delegated. The responsibility for data processing lies with the entity that commissioned such action to another entity, deciding on the means of processing personal data, the purposes, and the methods of processing. It is important to remember that outsourcing direct marketing to an external entity does not relieve the principal of responsibility, for example, for failing to obtain the appropriate consents.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.