Electronic Communications Policy
Policy Statement (PECR Compliance)
vapeMons Limited and all associated companies (hereinafter referred to as the "Company") send electronic marketing messages, use cookies, and provide electronic communication services. As such, we are bound by obligations under the Privacy and Electronic Communications Regulations 2003 (PECR). This policy works alongside our data protection policies to ensure individuals’ privacy rights are upheld regarding these activities.
The Company recognizes the importance of PECR and has developed this policy to ensure employees understand their obligations and users/subscribers know their rights. We have implemented policies, procedures, controls, and measures to ensure compliance with the Regulation, including staff training, procedure documents, audit measures, and assessments. Ensuring and maintaining the security and confidentiality of personal information and electronic communication is one of our top priorities. We operate under a Privacy by Design approach.
Purpose
This policy ensures that the Company meets its legal, statutory, and regulatory obligations under the PECR and, where applicable, the UK GDPR. The Company provides services or uses technologies covered by the PECR and must implement specific policies, controls, and measures to ensure the security and compliance of all activities.
Scope
This policy applies to all staff within the Company (permanent, fixed-term, temporary staff, third-party representatives or sub-contractors, agency workers, volunteers, interns, and agents engaged with the Company in the UK or overseas). Adherence to this policy is mandatory.
Definitions
-
Bill: Includes invoices, accounts, statements, or similar documents.
-
Call: A connection established via telephone service enabling two-way communication in real-time.
-
Communication: Any information exchanged via a public electronic communications service.
-
Communications Provider: A provider of an electronic communications network or service.
-
Consent: A freely given, specific, informed, and unambiguous indication of the data subject's wishes.
-
Corporate Subscriber: A subscriber who is a legal entity (company, partnership, etc.).
-
Electronic Communications Network: A system used to convey signals of any description by electrical, magnetic, or electro-magnetic energy.
-
Electronic Communications Service: A service that conveys signals over an electronic communications network.
-
Electronic Mail or Email: Text, voice, sound, or image messages sent over a public electronic communications network.
-
Individual: A living individual or unincorporated body of such individuals.
-
Information Society Service: A service provided remotely and electronically upon individual request.
-
The Commissioner: The Information Commissioner's Office (ICO), responsible for PECR enforcement.
-
Traffic Data: Data processed for the purpose of conveying communication over a network or billing.
-
UK GDPR: The General Data Protection Regulation as adapted for the UK.
-
User: Any individual using a public electronic communications service.
What is the PECR?
The Privacy and Electronic Communications Regulations 2003 (PECR) implement the European Directive 2002/58/EC into UK law. The regulations provide rules on:
-
Marketing by electronic means: calls, emails, SMS, faxes.
-
Use of cookies: Tracking information about users on websites.
-
Privacy of communications: Protection of traffic and location data, and billing information.
PECR and Data Protection
The PECR works alongside the UK GDPR, with both regulations sharing the same consent requirements for processing personal data. Depending on services provided or technology used, an organization may need to comply with both the UK GDPR and PECR.
The Information Commissioner’s Office (ICO)
The ICO is an independent regulatory body responsible for enforcing the PECR and the UK GDPR. They can issue enforcement notices and fines for breaches in privacy and data protection regulations.
Objectives
We are committed to ensuring all electronic communications activities and personal data processing comply with the PECR and, where applicable, the UK GDPR. This includes:
-
Ongoing training on PECR requirements.
-
Ensuring users are informed of our traffic and location data usage and obtain consent when necessary.
-
Reviewing and ensuring direct marketing complies with PECR.
-
Providing clear information on cookie usage and obtaining user consent.
Direct Marketing
The Company’s Direct Marketing Policy ensures that we obtain consent and provide necessary information when sending unsolicited marketing (phone, email, SMS, etc.). We adhere to both UK GDPR and PECR requirements for consent.
Cookies and Similar Technologies
In line with the PECR, cookies must not be stored without user consent, and clear, detailed information on their purpose must be provided. Users are given the option to accept or reject non-essential cookies.
Security
The Company ensures appropriate technical and organizational measures to safeguard the security of electronic communications services. Detailed security measures are outlined in our Information Security & Usage Policy.
Consent
Consent must be obtained for processing traffic data, location data, and marketing. The Company adheres to UK GDPR consent standards, ensuring it is transparent, specific, informed, and verifiable.
Data Breach
We maintain a data breach incident management system, ensuring compliance with both the PECR and UK GDPR for breach reporting and management.
Audits and Monitoring
To ensure continued compliance with PECR, we regularly review and monitor our policies and practices through internal audits.
Training
We ensure all staff members are trained on PECR and UK GDPR requirements through workshops, assessments, and ongoing support.