• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Is this a GDPR violation?

Status
Not open for further replies.

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,592
Location
Scotland
I'm not sure if this scenario is a GDPR violation or not and would appreciate some thoughts.

I was searching for flights and got a link to flightoffice.co.uk. Started going through the booking process and entered my contact details (name, phone number and email) but closed the page without completing the booking. Then about half an hour later I got a call from them (which I didn't answer) and an email which says "We request you to make an urgent call back on [telephone number] to speak to [Person] or reply to the email".

To my mind this feels like a violation since they've stored and used my PII when no business relationship exists between us, but I'm not 100% sure since I did click the 'Continue' button to get to the second page of the booking process. Does that constitute grant of consent? Would this be classed as a marketing call since they're trying to sell me something, or are they attempting to provide a service that I've indicated an interest in? Either way, it doesn't strike me as particularly good business practice.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

BanburyBlue

Member
Joined
18 May 2015
Messages
878
It sounds like it to me. Did they ask whether they could keep your information, and what your contact preferences were?
 

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,962
Almost certainly a violation, as they had no reason to store your personal information.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,800
Location
Epsom
I spent nearly 40 years working in market research, the last decade or so of course under GDPR, and I'd say that's 100% a violation and you should definitely make a formal complaint about that.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,592
Location
Scotland
Their privacy policy reads as if it's been passed through Google Translate or similar a few times. For example:

Privacy Policy of Flightoffice.co.uk​

www.flightoffice.co.uk regard the trust of the website user/visitor in the highest faith and implement standard measures to safeguard the privacy of the Personal Identifiable Information, while also keeping the monetary transactions secured. The details that are furnished by website user/visitor or our customer at the time of flight booking or making travel arrangements with us shall be maintained, or secured, or shared or divulged by us on various levels. Therefore, it is suggestible to website user/visitor to go through the Privacy Policy and gain an insight on the protocols that they need to adhere to and for familiarising themselves with regard to gathering and disseminating the practices as well as security measures that Flightoffice.

 

styles

Established Member
Joined
7 Dec 2014
Messages
4,683
Location
Gwynedd
The whole site looks dodgy to be honest, I wouldn't trust them to keep my information secure. I also wouldn't trust them as a travel agency.

Flights can be cheaper on third party websites but if things go wrong you can be dealing with a company which isn't even contactable, let alone care enough about your issue to give a satisfactory resolution. The tales I've heard from mates who have used overseas OTAs are enough for me to steer clear.
 

The exile

Established Member
Joined
31 Mar 2010
Messages
9,319
Location
Somerset
Almost certainly a violation, as they had no reason to store your personal information.
I suppose the one query would be as to how long (and from what point) details of an incomplete transaction should be retained and what it is ethical to do at the moment that period is about to elapse. I can think of a couple of occasions when I would have been extremely grateful to be contacted and asked whether I knew I hadn’t completed a transaction. However, if you haven’t got as far as starting an actual booking (ie have only entered your own details and haven’t actively consented to their use) using those details to contact you does sound a step too far.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,683
Location
Gwynedd
I suppose the one query would be as to how long (and from what point) details of an incomplete transaction should be retained and what it is ethical to do at the moment that period is about to elapse. I can think of a couple of occasions when I would have been extremely grateful to be contacted and asked whether I knew I hadn’t completed a transaction. However, if you haven’t got as far as starting an actual booking (ie have only entered your own details and haven’t actively consented to their use) using those details to contact you does sound a step too far.
If they're going to do that though, they really ought to make it clear on the page that this is what they'll use it for. It's basically marketing otherwise, which is normally on the consent lawful basis for processing.

The first time the user gets informed of their privacy rights is on the next page, where there is a link to a 'Privacy & Policy' (yes the ampersand is there). The privacy notice in question is poorly-written and I suspect copied and translated from somewhere else.
 

Bantamzen

Established Member
Joined
4 Dec 2013
Messages
10,490
Location
Cheshire
On the GDPR issue I'd agree with others, this seems like a breach for me. As for the site, yeah that looks a bit dodgy to say the least. Lots of Google / AI translation with little or no QA going on. Personally I wouldn't touch it with a bargepole!
 

robbob700

Member
Joined
17 Aug 2009
Messages
148
I would avoid this company - check reviews for Travelopedia who run flightoffice.co.uk.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,592
Location
Scotland
The whole site looks dodgy to be honest, I wouldn't trust them to keep my information secure. I also wouldn't trust them as a travel agency.

Flights can be cheaper on third party websites but if things go wrong you can be dealing with a company which isn't even contactable, let alone care enough about your issue to give a satisfactory resolution. The tales I've heard from mates who have used overseas OTAs are enough for me to steer clear.

I would avoid this company - check reviews for Travelopedia who run flightoffice.co.uk.
Agreed. That's why I didn't complete the transaction, the whole thing felt shoddy.
 

Royston Vasey

Established Member
Joined
14 May 2008
Messages
2,992
Location
Cambridge
I think the circumstances described would be quite easily defensible as a "legitimate interest" in that you've used their website to get far enough beyond scraping a quote, to voluntarily add your details and go a substantial way to making a purchase before backing out. I believe you've shown enough engagement for it to be legitimate to follow up with you.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,592
Location
Scotland
I think the circumstances described would be quite easily defensible as a "legitimate interest" in that you've used their website to get far enough beyond scraping a quote, to voluntarily add your details and go a substantial way to making a purchase before backing out. I believe you've shown enough engagement for it to be legitimate to follow up with you.
My counter to that is that nowhere on that page do they say that they'll use my details for that purpose, nor have they given any opportunity to provide or deny consent.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,059
Location
"Marston Vale mafia"
My counter to that is that nowhere on that page do they say that they'll use my details for that purpose, nor have they given any opportunity to provide or deny consent.

Consent isn't required for use of the legitimate interest basis. Making people aware of how their details are used absolutely is.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,683
Location
Gwynedd
I think the circumstances described would be quite easily defensible as a "legitimate interest" in that you've used their website to get far enough beyond scraping a quote, to voluntarily add your details and go a substantial way to making a purchase before backing out. I believe you've shown enough engagement for it to be legitimate to follow up with you.
Legitimate interest is a broad basis, but even so I think it's a stretch to say that contacting somebody who abandons a shopping cart before they've even been presented with terms and conditions or a privacy notice, let alone started to input payment details, is anything other than marketing.

One solicitor firms' position for example:

However, there is an exception that allows direct advertising without explicit prior consent in certain situations. If a company has obtained a customer’s email address during the sale of goods or services, they may use that email for marketing purposes related to their own similar products or services. This exception applies as long as the customer is clearly informed, both at the time of data collection and with every marketing communication, that they can opt-out or object to this use at any time.


On the 'Clapham omnibus' test, would the average person expect that, without agreeing to it, a booking/purchase which they choose to abandon where they happened to have provided their mobile number would be used to chase them on the sale be acceptable use of their personal data? I expect not.

I would even go as far as suggesting that this is the sort of scenario GDPR, and the DPA in the UK specifically, is designed to protect against.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,592
Location
Scotland
I emailed them to ask the basis on which they were using my PII - unsurprisingly I've heard nothing.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,800
Location
Epsom
I emailed them to ask the basis on which they were using my PII - unsurprisingly I've heard nothing.
After a week with no reply, e-mail them again but openly CC in the Information Commissioner's Office. Even if the ICO does nothing, the very fact of them being copied in openly should cause some sort of reaction from the company. At the very least it'll plant a seed of concern with whoever reads the mail.
 

bleeder4

Member
Joined
19 Jan 2019
Messages
792
Location
Worcester
Lots of companies do this sort of thing. We have some sales guys at our place that watch the website traffic logs in real-time to see which IP addresses are currently active on our website. They'll then then WHOIS the IP addresses to see if they can get contact details. Lots of business internet connections have static IP addresses, so the WHOIS information the ISP has specified for the IP range will often display the name of the company. They then get a call from our sales guys...

Broadband providers used to be notorious for it as well. Put your phone number in their checker to see what speed you can get with them and you would often get a follow-up call a bit later on. Not so effective now that landlines are dying out though.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,683
Location
Gwynedd
Lots of companies do this sort of thing. We have some sales guys at our place that watch the website traffic logs in real-time to see which IP addresses are currently active on our website. They'll then then WHOIS the IP addresses to see if they can get contact details. Lots of business internet connections have static IP addresses, so the WHOIS information the ISP has specified for the IP range will often display the name of the company. They then get a call from our sales guys...

Broadband providers used to be notorious for it as well. Put your phone number in their checker to see what speed you can get with them and you would often get a follow-up call a bit later on. Not so effective now that landlines are dying out though.
GDPR applies to personal information, not (generally) business information, so using the corporate contact information from a WHOIS lookup is (generally) fair game.

That said, domain privacy services have been around for as long as I've been doing web development. Easiest way of avoiding spam from WHOIS lookups is by using a privacy service, or a TLD which allows leaving the contact information blank.
 
Status
Not open for further replies.

Top