11 March 2025
When Profiling Becomes a Problem: TikTok, Sky Betting and others in the spotlight
By Jess Pembroke, Director of Information Law Services
Data is the lifeblood of the modern economy, driving growth and innovation across industries. Used ethically, data can enhance user experiences, ensuring that people discover products and services relevant to their needs. Companies that effectively leverage data contribute significantly to economic development by creating jobs and fostering technological advancements.
With the right controls, profiling and targeted marketing can be conducted lawfully and ethically; however, big organisations need to recognise that they hold all the “power”. Data Protection law at its heart is about human rights, and the rights of individuals, who in some cases may not be able to withstand pressure of some of today’s marketing and targeting techniques – leading them to make decisions or take actions they regret or didn’t understand.
Some recent cases highlight cases of the significant power targeted data processing can wield. The UK’s Information Commissioner’s Office (ICO) has launched investigations into TikTok, Reddit, and Imgur1 over concerns regarding their handling of children’s personal data and whether they adequately protect young users from harmful content. Additionally, Sky Betting & Gaming was found to have violated UK data protection laws by targeting a vulnerable customer with non-compliant marketing practices in relation to an individual with a gambling addiction2. Subsequently, the ICO has “reprimanded Sky Betting & Gaming for unlawfully processing people’s data through advertising cookies without their consent”3.
The TikTok Investigation
The ICO’s investigation into TikTok centres on how the platform uses the personal information of 13–17-year-olds to generate content recommendations. TikTok has been fined previously for misuse of personal data4.
This case underscores the responsibility of digital platforms to safeguard young users.
The Children’s Code (Age-Appropriate Design Code) establishes specific standards for online services handling children’s data. When it comes to profiling, the code mandates:
- Profiling for Targeted Advertising – The code advises against profiling children for targeted advertising unless strict privacy protections are in place. This includes obtaining valid consent and ensuring profiling does not exploit or harm children.
- Use of Personal Information in Recommender Systems – Platforms must use children’s personal data with their best interests in mind, ensuring recommendations do not lead to exposure to inappropriate or harmful content.
The Sky Betting & Gaming Case
A recent High Court ruling further reinforced the importance of responsible data usage. Sky Betting & Gaming (SBG) was found to have violated data protection laws by aggressively marketing to a vulnerable customer. The company harvested transactional data via cookies, profiling the individual as a high-value target. This led to persistent marketing that exacerbated the customer’s gambling addiction.
This case illustrates that GDPR is not just a regulatory burden, but a framework designed to prevent real-world harm. Companies must recognise that failure to comply with data protection laws can have severe consequences for individuals, and this matters if they care about their customers and users (and reputation).
Ethical and Responsible Data Use
While GDPR may seem like a challenge, there are too many cases of organisations choosing to press on without pausing to see if small (or sometimes) larger changes to their processes could allow them to proceed in a more fair and lawful way, without overly compromising their end goals. In conclusion, these cases illustrate how profiling is a powerful tool, but it must be applied with care, transparency, and respect for individuals’ rights. Organisations that prioritise compliance not only protect their customers but also build long-term trust and credibility.
Naomi Korn Associates can assist you in proactively demonstrating your compliance, so that you can show your commitment to data protection and build trust with potential buyers. We offer a range of practical services to help your business with Data Protection, Copyright and IP.
Naomi Korn Associates are thrilled to be new UKIE members and are offering UKIE members 15% off our comprehensive CPD accredited training courses. For more information, find us in the UKIE Directory of Member Benefits or email our Training Manager at info@naomikorn.com.