Skip to main content

lhiconsult

One Promotion, Three Problems: When Financial Promotions, Consumer Duty and GDPR Collide

LHI Consulting No comments

This series has covered financial promotions compliance, Consumer Duty obligations, and GDPR requirements across separate pieces – because each regime is substantial enough to warrant its own treatment. But the regimes do not operate in isolation. In practice, a single piece of marketing activity can simultaneously engage all three, and a failure in one dimension is frequently a failure in all three.

This piece does not re-explain the individual regimes as those have been covered in detail previously. What it addresses is the intersection: what happens at the point where a single marketing decision triggers obligations across all three frameworks simultaneously, and why managing these as separate compliance workstreams misses the actual exposure.

The Scenario

A crypto firm sends a promotional email to its customer base. The email promotes a new token listing, includes a referral incentive offering existing customers a bonus for introducing new investors, and is sent to all customers on the marketing list — including customers who have not actively engaged with the firm for over a year.

This is not an unusual scenario. Versions of it happen regularly across the crypto sector. And it is simultaneously:

A financial promotions breach — the referral incentive is prohibited under the FCA’s financial promotions regime regardless of how it is structured, and the email constitutes a direct offer financial promotion that must comply with all content requirements including the mandated risk warning.

A Consumer Duty failure — sending a high-risk investment promotion to the full customer base without distinguishing between customers for whom the promotion is appropriate and those for whom it is not — including potentially vulnerable customers — does not meet the FCA’s consumer understanding or fair treatment standards.

A GDPR breach — sending marketing to customers whose consent was obtained more than a year ago without a recent engagement signal, and without a current consent record that meets the ICO’s evidencing standard, is sending marketing on a basis that may not withstand scrutiny.

The firm has one problem. Its compliance team has three.

Why Siloed Workstreams Miss It

Most firms manage financial promotions compliance, Consumer Duty, and GDPR as separate functions — often with separate policy owners, separate review processes, and separate reporting lines.

In theory, each team catches the issues within their remit. In practice, the scenario above slips through three separate review processes because each team is looking at a different dimension of the same piece of content.

The financial promotions review may focus on the risk warning, the cooling-off period, and the incentive prohibition — and catch the incentive breach. But it is not looking at whether the promotion is being sent to customers for whom it is appropriate under Consumer Duty, or whether the consent basis for the send is current and evidenced.

The Consumer Duty review may consider whether the promotion is clear and fair — and conclude that it is, in isolation. But it may not catch that the promotion is being sent to the full customer base without any segmentation for vulnerable customers or appropriateness considerations.

The GDPR review — if it happens at all for an individual email send — may confirm that there is a consent flag on the customer record. But it may not assess whether that consent record meets the current evidencing standard or whether the consent is recent enough to still be valid.

The result is a piece of marketing that has passed three separate reviews and is still non-compliant across all three dimensions.

The Points of Intersection

Understanding where the three regimes intersect in a single piece of marketing is the starting point for addressing the gap.

The audience. Who the promotion is sent to is simultaneously a financial promotions question (has the recipient completed an appropriateness assessment?), a Consumer Duty question (is the promotion appropriate for this customer’s circumstances, including whether they may be vulnerable?), and a GDPR question (is there a current, evidenced lawful basis for sending marketing to this individual?).

The content. What the promotion says is primarily a financial promotions question — risk warning, prominence, no incentives, clear and fair. But it is also a Consumer Duty question: does the promotion support genuine consumer understanding of a high-risk product? And it is a GDPR question: is the content consistent with what the individual consented to receive?

The incentive. An investment-linked incentive is prohibited outright under the financial promotions regime. It is also likely to be a Consumer Duty fair value question — does an incentive structure that encourages investment behaviour serve the customer’s genuine interests? And it may be a GDPR question if the incentive involves processing personal data of the referred individual.

The channel. How the promotion reaches the customer is a financial promotions question (is the risk warning prominent in this format?), a PECR/GDPR question (is there a consent basis for this channel?), and potentially a Consumer Duty question (is this channel appropriate for customers who may have low digital literacy?).

What an Integrated Compliance Review Looks Like

The firms that manage this intersection effectively have built a pre-send review process that asks all three sets of questions before a promotion is approved — not three separate review processes, but a single integrated review that considers all dimensions simultaneously.

In practice, this means:

Audience segmentation before send. Before a promotional email is approved, the audience list should be reviewed against: appropriateness assessment status (financial promotions), vulnerability flags and customer circumstances (Consumer Duty), and consent record currency and evidencing standard (GDPR). Customers who fail any of these checks should be excluded or subject to a modified communication.

Content review against all three regimes. The promotional content should be reviewed not just against financial promotions content requirements but against the Consumer Duty consumer understanding standard and the GDPR purpose limitation principle.

Channel confirmation. The channel should be confirmed against the PECR consent basis, the risk warning prominence standard in that format, and the Consumer Duty consumer support standard.

A single sign-off that covers all three. Where the three review processes are separate, it is possible for each to approve without the others being complete. A single integrated sign-off — where the approver confirms compliance across all three dimensions – makes the gaps visible.

Our compliance marketing service supports firms in building integrated promotional review processes — see how we can help.

The Practical Starting Point

For most firms, building a fully integrated compliance review process from scratch is a multi-week exercise. The practical starting point is a gap analysis – mapping the firm’s current promotional workflow against each of the three regimes and identifying where the checks are missing, duplicated, or disconnected.

The questions to ask of the current process: Who reviews promotional content before it is sent, and against which requirements? Is the audience list reviewed against GDPR consent status before each send? Is there a vulnerability screening step before high-risk investment promotions go to the full customer base? Is there a single record of approval covering all three compliance dimensions?

Final Thought

The three regimes addressed in this series were not designed together and are administered by different regulators. But they operate on the same piece of marketing activity, at the same moment, with the same customer. A firm that manages them as separate workstreams is managing three partial pictures of a single compliance problem.

The firms best placed going into autumn 2026 are those that have recognised this and built their promotional review process to reflect it — asking all three sets of questions of every piece of marketing before it goes out, and treating a failure in any one dimension as a failure in all three.

If you want to understand where your promotional review process stands across all three regimes, speak to our team.

Contact LHI Consulting for a free 30-minute consultation.


This article is for general information purposes only and does not constitute legal or regulatory advice. LHI Consulting is a trading style of LHI Holdings Ltd, registered in England and Wales, No. 11496647.

FAQs

Do financial promotions compliance, Consumer Duty and GDPR always overlap in marketing?
Not always — but they overlap more often than most firms recognise. Any direct marketing communication involving a financial product to a retail customer will typically engage all three. The more targeted and personalised the communication, the more likely all three are engaged simultaneously.

We have separate teams for each regime. Is that a problem?
Not inherently — but it is a risk if the three teams are reviewing the same promotional content independently without a mechanism for catching the gaps between them. The issue is not the team structure but whether the review process produces a complete picture across all three regimes before a promotion is approved.

What is the most common gap when all three regimes are considered together?
The audience list. Most promotional review processes assess the content of the communication but fewer assess the specific audience list against GDPR consent status, vulnerability flags, and appropriateness — before the send, not after.

If a promotion has been section 21 approved, does that cover Consumer Duty and GDPR as well?
No. A section 21 approval assesses financial promotions content requirements only. It does not assess Consumer Duty appropriateness for the specific audience or the GDPR lawful basis for the send. All three require separate review.

Where should a firm start if it wants to build an integrated review process?
Take your last three significant promotional sends and map each one against all three regimes retrospectively. This will quickly identify where the gaps are in the current process and what a complete review would need to cover.

Leave a comment