Edit
Contact us
Salocin Group Leaders in data and AI-enabled connected customer experiences
Edit Engineers of connected customer experiences
Join the Dots Independent, data-led media thinking for sustainable growth
Wood for Trees Optimisers of future fundraising performance
  • Home
  • Our services
    • Cloud solutions
    • Data science
    • Modern Data Platform
    • Privacy and AI compliance
  • Our partners
    • Apteco
    • Creatio
    • Microsoft
    • Salesforce
  • Our insights
    • Blog
    • Case studies
    • Reports
    • Webinars
    • Whitepapers
  • About Salocin Group
    • Careers
  • Contact Salocin Group
  • Home
  • Who we are
    • B Corp
    • Careers
  • Our work
  • What we do
    • Intelligent data
    • Marketing technology
    • Transformational CRM
    • Our technology partners
    • Privacy review
  • Our insights
    • Blog
    • Case studies
    • Reports
    • Webinars
    • Whitepapers
  • Contact Edit
  • Home
  • Broadcast media
  • Digital media
  • Print
    • Direct mail
  • Data
    • Our work with Herdify
    • EPiC
  • Media agency
  • Our insights
    • Blog
    • Case studies
    • Reports
    • Webinars
    • Whitepapers
  • About Join the Dots
    • Careers
  • Contact Join the Dots
  • Home
  • Services
    • Actionable insight
    • Data discovery
    • Data engineering
    • Data hygiene
    • Privacy review
  • Products
    • InsightHub
    • Apteco
    • Microsoft
    • Data management
    • Consent and preference management
  • Our insights
    • Blog
    • Case studies
    • Reports
    • Webinars
    • Whitepapers
  • About Wood for Trees
    • Operating principles
    • Careers
  • Contact Wood for Trees
Blog

The Direct Mail Code of Practice: What you need to know

By Edit | 3 Feb 2020

We’ve waited with bated breath but it’s finally here – the direct marketing industry is getting its first code of practice.

The change comes after the Information Commissioner’s Office (ICO) publication of a draft of the new direct marketing code of practice, which gives the industry a legal rulebook to follow rather than just offering guidance.

The code aims to consolidate all the ICO’s previous guidance around GDPR, the Privacy and Electronics Regulation (PECR) and cookies.

Whilst industry bodies such as the Data & Marketing Association have issued guidance, as a marketing community, we’ve never had a legal framework.

If brands and marketers don’t follow this, they will find it difficult to show they are complying with the GDPR, which means they could be on the sharp end of an eye-watering fine.

Here at Edit, we’ve spent some time digesting the code, and below are some of the key takeouts.

 

The scope of direct marketing

Little new to be discovered here: the scope of direct marketing continues to be defined in common sense terms.

New details and guidance on accountability and planning of marketing campaigns 

Data protection by design continues to be a prominent concept here, with steadfast emphasis on the need for a data protection impact assessment for data matching.

There is useful clarification around when legitimate interests and consent are appropriate. The ICO position seems to be that it’s difficult to demonstrate legitimate interest when creating personality profiles from large amount of combined data.

Lead generation and collecting contact details

Many companies have overlooked a point made clear here: the GDPR requirement to inform individuals that their personal data is being processed within one month of receiving the data from another source. The draft indicates reliance on “disproportionate effort” to do so within the timeframe.

Profiling and data enrichment

There are no surprises when it comes to data cleansing, matching and enrichment, but there is a useful checklist of due diligence questions to consider when engaging third party suppliers.

Sending direct marketing messages

Interestingly, this section implies that the use of Direct Mail may move towards full consent rather than having to rely on legitimate interest.
Other than that, there’s no further clarification on “negotiations for a sale of a product or service” in the context of soft opt-ins for email marketing, which would have been useful.

Online advertising and new technologies

Lookalike targeting comes under unexpected scrutiny here, stating that consumers are unlikely to expect it; therefore, consent is required, along with the process being drawn to the attention of individuals outside of standard privacy policies. This is at odds with other content in the draft which makes clear that such forms of marketing are outside its remit.

Selling or sharing data

The code makes clear that a reliance on legitimate interest to disc lose or sell data is only relevant in certain circumstances. Detailed guidance is also given on how to comply transparency and consent requirements if you’re a data broker.

Data subject rights

The messaging is consistent regarding informing data subjects via privacy notice, of their right to object to direct marketing. Guidance is given as to how a user may exercise that right.

Additionally, when relying upon consent to process personal data for direct marketing purposes, it’s reiterated that when an individual withdraws consent you cannot swap from consent to another basis.

There are clearly some areas that may come as a surprise if you haven’t previously read the former iterations. Lookalike audiences in social now require consent, as does showing an ad on social networks. In app advertising is now also consent driven. There are still several outstanding issues in areas such as cookies and digital advertising that the code does not solve, although the ICO has issued some separate thoughts on these areas.

The draft is open for consultation is open until 4 March 2020.

Share this

  • Email
  • WhatsApp
  • LinkedIn
  • Facebook
  • X (Twitter)

More insights

AI isn’t going to take your job (unless you really want it to) 
Blog

AI isn’t going to take your job (unless you really want it to) 

By Edit | 18 Jun 2024
Customer relationship marketing: How generative AI is revolutionising engagement  
Blog

Customer relationship marketing: How generative AI is revolutionising engagement  

By Edit | 4 Apr 2024
Personalisation as a process
Blog

Personalisation as a process

By Edit | 8 Mar 2024
  • Privacy policy
  • Cookie policy
  • Ts&Cs
  • Report a concern

© 2025 Edit, part of Salocin Group Ltd. All rights reserved. Company no.: 0362​4881. VAT no.: 4208​34911.

Salocin Group Certified B Corporation | Cyber Essentials Certified | British Assessment Bureau, ISO 27001 Information Security Management
Salocin Group
Your cookie preferences

We use cookies to ensure this website functions properly, to analyse website traffic and for marketing purposes.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}