Guides · Freebies · Bounty
Did Bounty share baby data with Equifax?
What did the ICO actually find?
On 9 April 2019 the Information Commissioner issued a monetary penalty of £400,000 against Bounty (UK) Limited under the Data Protection Act 1998. The BBC reported the ICO’s description of the case as “unprecedented”. The High Court later summarised the same decision in [Underwood v Bounty UK Ltd [2022] EWHC 888 (QB)](https://www.bailii.org/ew/cases/EWHC/QB/2022/888.html).
The finding was about fairness and transparency, not a claim that every later Bounty email is unlawful. The Commissioner held that any consent Bounty relied on was not informed: people could not have foreseen that their data would go to the named third parties. Bounty had processed the data unfairly and without a Schedule 2 condition. The ICO’s later data-broking sector report lists the Bounty penalty alongside other broker fines issued under the 1998 Act.
The broking window the ICO examined ran from 1 June 2017 to 30 April 2018. Bounty told the Commissioner it stopped supplying data to third parties for electronic direct marketing on 30 April 2018. Official records of that period are not a finding about how Bounty processes data today.
Which child fields were in those records?
In the ICO investigation Bounty said the records it collected included: full name; parent’s date of birth; email address; postal address and postcode; pregnancy status; whether the mother was a first-time mother; and the name, gender and date of birth of children (and, by extension, the child’s address). The High Court records that Bounty said it shared 35,027,373 personal data records in that eleven-month window with the four largest recipients, and that each record represented one person. The BBC rounded the same period to “more than 14 million people” and “34.3 million records”.
Swipe sideways for the full table
| Organisation named | How the court described it | What the ICO said about the data |
|---|---|---|
| Acxiom | Marketing and profiling agency | Among the four largest recipients of the 35 million records |
| Equifax | Credit reference agency | Among the four largest recipients |
| Indicia | Marketing agency | Among the four largest recipients; in the Underwood subject-access reply it had received the family’s full file, including an IP address |
| Sky | Telecommunications company | Among the four largest recipients |
| 35 other organisations | Not named one by one in the published judgment summary | Bounty confirmed 39 recipients in total |
The data shared with each organisation “varied slightly”, the court said, but in each case it comprised the majority, if not all, of the data collected on that person. Bounty’s fair-processing notices at the time gave no indication that personal data might be shared with those organisations.
Was Equifax fined as well?
Not in the Bounty notice. The ICO fined Bounty for sharing. Equifax appears in that case as a recipient. A later ICO report on credit-reference agencies records a separate audit of Equifax, Experian and TransUnion. Equifax and TransUnion withdrew non-compliant marketing products and were not issued enforcement notices in that later piece of work. That is a different investigation from the 2019 Bounty penalty.
So the accurate sentence is: Bounty shared mum and child records with Equifax in 2017–18. It is not accurate to say the 2019 fine was an Equifax fine, or that Equifax is still receiving Bounty club files under that old broking contract.
What changed after April 2018?
Bounty told the BBC it had ended relationships with data brokers, kept fewer records for less time, and trained staff for the newer law. Its current privacy policy (updated 20 May 2025) says it will not sell personal information to Bounty Partners, and that partner emails are sent by Bounty unless you have consented to a partner writing to you directly. Optional membership clubs are a separate, named hand-off — see what partner clubs pass at signup.
A current published policy is not a certificate that every historic copy has vanished from every recipient. The ICO’s right to erasure guidance says a controller should tell other organisations it shared data with, unless that is impossible or disproportionate. That right has limits, including legal-claim and legal-obligation exceptions.
How do I check what Bounty holds now?
- Ask Bounty for a copy Email [email protected] and ask for the personal data it holds on you and your child. The policy names that address for access requests. The UK representative is Bounty Media Limited, Kings Court, London Road, Stevenage, SG1 2NG.
- Ask who else has a copy If you want the 2017–18 trail, ask which organisations received your record and on what date. Bounty’s reply to the Underwood subject-access request listed nine third parties for that family, which is narrower than the 39-recipient industry total.
- Ask for deletion if you want the file gone Bounty’s help page asks people to email [email protected] with the subject “Deletion of Account”, plus name, address and postcode. Say if portraits should be included. The ICO says a controller normally has one calendar month to respond.
In shortIn short: yes, Equifax was a named recipient of Bounty’s 2017–18 broking files, which included children’s names, genders and dates of birth. The ICO fined Bounty £400,000 for that period. Treat that as history unless a fresh official finding says otherwise, and use access or erasure rights for the file that exists now.
Questions parents ask
- Is Bounty still selling my baby’s data to Equifax?
- The ICO case covers sharing up to 30 April 2018, when Bounty said it stopped supplying data to third parties for electronic direct marketing. The current published policy says Bounty will not sell personal information to Bounty Partners. That is not the same as a live ICO finding about every later transfer. If you want the file gone, use Bounty’s deletion route and the ICO erasure right.
- Did the shared records include my child’s name?
- Bounty told the Commissioner that collected records included the name, gender and date of birth of children. The High Court records that wording. Whether your own child’s fields were in a particular recipient’s copy depends on what Bounty held and what that recipient bought.
- Can I sue Equifax because of the 2019 fine?
- The published ICO penalty was against Bounty (UK) Limited. A later High Court claim against an NHS trust over a 2017 bedside visit failed. MayTally cannot advise on litigation. The ICO explains how to complain about a controller, and you can take independent legal advice.
- Is today’s Bounty the same company that was fined?
- The penalty was against Bounty (UK) Limited. The 2022 judgment records that company went into administration in November 2020 and that part of the business was sold to Bounty Joy Limited. The 2025 privacy policy names Joy Memories Inc as controller, with Bounty Media Limited as the UK GDPR representative.
Sources
Official pages first. If this page and the official page disagree, the official page wins.
- BBC News — Bounty pregnancy club fined £400,000 over data handling — checked 10 September 2026
- BAILII — Underwood v Bounty UK Ltd [2022] EWHC 888 (QB) — checked 10 September 2026
- ICO — Investigation into data protection compliance in the direct marketing data broking sector — checked 10 September 2026
- ICO — Your right to get your data deleted — checked 10 September 2026
- Bounty — Privacy Policy (updated 20 May 2025) — checked 10 September 2026
This is information, not a guarantee of any payment, and not medical, legal or product-safety advice for your home. Prices and rules change; figures carry the date they were checked. Recall status comes from official records only — a product we cannot find is not a safety all-clear. Tell us if we got a fact wrong.