I could/should probably have used some sort of emoji to show that “dunno where they’re digging up my cv from” was meant as a tongue in cheek comment. In the last few years I’ve also had emails allegedly from a couple of the agencies I was signed up with when I was out of work, I replied saying I was in employment and asking to be removed from the database, a few months later I got emails again and when I complained they said they had no record of my asking to be removed.
It's frustrating that so many companies are so bad at data protection even with GDPR and the potential for massive fines.
I once looked at joining a Bannatyne's gym. They don't put the prices on the website so you have to contact them, which they then use for marketing (dubious that this is allowed in its own right). Anyway, I fill out the form, get the phone call with prices, and say I'll think about it. A few days later, I get a marketing email from them as a prospective customer. But it wasn't only me who got the email - it was sent to around 50 people, all with our email addresses and names in the 'To' field instead of a Bcc or individual mail merge emails.
Few months back I hired a car. I returned the car, accidentally left some cheap toolkit in the boot. Helpfully they tried to contact me, fine. I didn't answer 2 calls spreading over 15 hours because I was busy. As a result, they phoned my 'Next of Kin', didn't go into any useful detail about why they were calling me, and informed my mother that they'd been unable to get hold of me for 15 hours. My mum phones me panicked thinking I've crashed a car and am in hospital or something. Like surely people don't think 'next of kin' just means 'backup contact number'? The regional manager agreed with me that it should be reserved for much more serious needs than a £20 Argos toolset left in a boot.
Recently I've been getting post for the previous owner of our house. Eventually she wasn't coming to collect the post, and I wouldn't mind, but a lot of these letters were from debt collectors. I don't really want debt collectors at my doorstep even if they'd end up walking away quite quickly. So I text the old homeowner and said understand you're busy, so I'll return them to sender when they arrive as the postbox is only a minute walk away. In my mind, this was a way of ensuring the companies are actually being informed that this isn't their current address. Even after returning to sender, I've had a couple of companies continue to send post here, so I've found email contact details and requested they mark this address as obsolete or remove it. All of them have complied so far, except Tesco Bank, who told me that
legally they cannot remove the address. Not wanting to get into a protracted debate about data protection I just (politely) said ok but I don't believe that's right as the personal information isn't being kept up-to-date, so if more post arrives, I'll raise it with the ICO. Strange how every other company managed to comply.
To work out where spam emails come from, I've started using the '+' feature in Gmail. If an email address is
johnsmith@gmail.com, you can use
johnsmith+amazon@gmail.com when joining Amazon, the emails will go to the same inbox, but you'll see it was sent to
johnsmith+amazon@gmail.com. This way, if the email address is shared or stolen, and spam starts arriving addressed to
johnsmith+amazon@gmail.com, we know the email was leaked from Amazon somehow. I've made a few DPA complaints on the back of this after finding websites have shared, sold, or had stolen contact info.
Most of these things get an apology and a promise to change processes so I don't bother escalating things or whatever, but I do wonder sometimes if they do actually change their working practices, or just say they will then forget about it.