A mobile gaming company collects players' phone numbers during account registration to support two-factor login. A year later, its marketing team begins sending the same players unsolicited SMS messages advertising in-app purchases, without asking whether they wish to receive marketing texts and without offering any way to refuse in the messages. The company assumes that because the players are existing account holders, no further step is needed. Under the ePrivacy regime governing electronic marketing, what is the principal compliance failure here?
- ASending marketing SMS without prior consent and without offering a simple means to refuse in each message breaches the ePrivacy rules on unsolicited electronic communications. Correct
- BMarketing by SMS to these players is unlawful only if a national supervisory authority has separately registered each recipient on a do-not-contact list before the messages are sent.
- CThere is no failure, because collecting the numbers for two-factor login automatically authorises their later use for any related commercial purpose the company chooses.
- DThe only breach is the failure to carry out a data protection impact assessment before sending the marketing texts, which would have legitimised the campaign.
Why A is correct: Correct: the ePrivacy Directive treats SMS as electronic marketing requiring consent, and even where a limited existing-customer exception could apply the controller must offer an easy opt-out in every message, which the company failed to provide.
Why B is wrong: Wrong because the lawfulness of marketing SMS does not depend on prior registration of recipients on an authority-held list; the ePrivacy rules require consent or a qualifying existing-customer relationship plus an opt-out, neither met here.
Why C is wrong: Tempting because the numbers were lawfully collected, but a number gathered for authentication may not be repurposed for unconsented marketing; the original security purpose does not extend to marketing SMS.
Why D is wrong: Wrong because a DPIA is not what legitimises a marketing channel; the governing requirement is the ePrivacy consent and opt-out rule for unsolicited electronic communications, which the campaign ignored.