Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

DPC welcomes prosecution outcome for Brown Thomas Arnotts Limited over marketing offences

Brown Thomas Arnotts Limited pleaded guilty to five sample charges in Dublin Metropolitan District Court on 7 September 2026, concerning breaches of regulations governing unsolicited marketing communications. The Data Protection Commission (DPC) welcomed this outcome, which included a court order for the company to pay EUR 1000 to a local charity and EUR 1000 towards the DPC's legal fees. These charges specifically addressed failures to provide an unsubscribe function and sending marketing without valid consent.

Three of the sample charges related to the failure to provide recipients with a valid address to opt out of further marketing emails, contravening Regulation 13(12) of the ePrivacy Regulations. Two additional charges involved sending marketing communications without obtaining valid consent from individuals, which contravened Regulation 13(1) of the ePrivacy Regulations. The court applied the Probation of Offenders Act to Brown Thomas Arnotts Limited, noting the organisation's engagement with the Data Protection Commission and its mitigation measures.

Judge Halpin was informed that a technical issue with a third party software provider caused an intermittent inability to unsubscribe from marketing communications. This led to multiple complaints to the Data Protection Commission, some of which involved individuals directly informing Brown Thomas of their consent withdrawal but continuing to receive direct marketing. The Data Protection Commission had previously issued a warning to the defendant in March 2022 regarding similar issues.

The persistent challenge of ensuring effective consent management and unsubscribe mechanisms in electronic marketing continues to generate enforcement actions, as evidenced by the DPC's prosecution of Brown Thomas Arnotts Limited.

Prosecution proceedings taken by the Data Protection Commission in Dublin Metropolitan District Court

Who this binds
Organisations engaging in electronic marketing practices in Ireland are bound by Regulation 13 of Statutory Instrument 336 of 2011.
What changed
The Dublin Metropolitan District Court applied the Probation of Offenders Act to Brown Thomas Arnotts Limited, and ordered the company to pay EUR 1000 to a charity and EUR 1000 towards the DPC's legal fees.
What to check
Organisations should review their electronic marketing systems to ensure compliance with Regulation 13(1) and 13(12) of Statutory Instrument 336 of 2011, particularly regarding consent and unsubscribe functionalities.
What this does not mean
This outcome does not mean that all marketing related ePrivacy breaches will result in criminal prosecution, as the court applied the Probation of Offenders Act in this specific instance.

Send this to your team

The Data Protection Commission welcomed the outcome of prosecution proceedings on 7 September 2026, where Brown Thomas Arnotts Limited pleaded guilty to five charges related to breaches of Regulation 13 of Statutory Instrument 336 of 2011, resulting in a court order for charitable and legal fee payments.

Today's question

A retail organisation in Ireland was prosecuted for breaches of regulations governing unsolicited marketing communications. Which of the following best describes the nature of these breaches?

  1. Failing to provide an unsubscribe function and sending marketing communications without valid consent.
  2. Collecting personal data without a lawful basis and transferring it outside the European Economic Area.
  3. Processing special categories of personal data without explicit consent and failing to conduct a Data Protection Impact Assessment.
  4. Not implementing appropriate technical and organisational measures to protect personal data from unauthorised access.

Answer this question on the site

Worth knowing

  1. Rhysida ransomware group publishes Berlin government data after €2 million extortion demand refused

    Public sector organisations, like the State of Berlin, face significant pressure from ransomware groups to pay ransoms, but their refusal to do so often leads to the public release of stolen data, triggering extensive breach notification obligations.

  2. EDPB and European Commission to host stakeholder event on data protection and competition law interplay guidelines

    Privacy counsel and DPOs should monitor the EDPB's upcoming guidelines on the intersection of data protection and competition law, as these will shape compliance strategies for organisations operating in competitive digital markets.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.