Join our Newsletter — 33% off our NHI Course

Unsolicited Information

Unsolicited information is information sent through a computer or online channel without the recipient’s consent. The legal concern is not normal commercial messaging, but unwanted transmission that creates nuisance, privacy harm, or pressure on the recipient. Organisations should treat consent, purpose, and audience as core controls.

What unsolicited information means in practice

Unsolicited information is not just “extra” contact, it is information delivered without the recipient’s consent or invitation. The core issue is the sender’s choice to transmit, not whether the content is commercial, legal, or informational.

That distinction matters because consent changes the legitimacy of the communication channel. A message can be accurate, lawful in other respects, and still be inappropriate if it reaches an audience that did not agree to receive it.

The term is defined by the relationship between sender, recipient, and purpose. If the recipient did not ask for the information, the sender needs a strong justification for why the transmission was appropriate, proportionate, and targeted.

In practice, this makes audience control and purpose limitation central. Organisations should be careful not to treat broad distribution, default opt-ins, or recycled contact lists as implied permission.

This is one reason privacy-oriented control language often appears alongside communication governance. EU General Data Protection Regulation (GDPR) is relevant where unsolicited transmission overlaps with personal data processing, consent, and lawful-purpose boundaries.

Where the harm comes from

The harm is often less about the information itself and more about its effect on the recipient. Unsolicited transmissions can create nuisance, pressure, distraction, unwanted profiling, or exposure of personal contact details to further reuse.

It can also erode trust. When people cannot predict who will contact them, for what reason, and through which channel, they are less able to distinguish legitimate communication from spam, manipulation, or privacy-invasive outreach.

At the control level, this is why information governance, consent records, and addressability rules matter. Unwanted transmission usually reflects a failure in audience selection, permission handling, or suppression logic rather than a content problem alone.

Why organisations treat it as a governance issue

Unsolicited information becomes a governance concern when senders cannot demonstrate a valid basis for contact or when systems make it too easy to send broadly by default. That is especially true where the same processes support marketing, notifications, onboarding, or relationship management.

Good practice is to separate who may send, what they may send, and who may receive it. That reduces the chance that one approved workflow becomes a blanket channel for messages that were never intended for that audience.

For organisations that manage regulated communications, broader information security controls can help frame the discipline. ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls both support controlled handling of information, including access, authentication, and documented control selection.

Risk and Threat Considerations

Unsolicited information can become a practical security and privacy risk when the same channels are used for spam, phishing, harassment, or repeated contact that overwhelms the recipient’s ability to filter legitimate messages. The risk increases when distribution lists, consent status, or audience rules are weakly managed.

Failure mechanism: The sender relies on broad or stale recipient data, then transmits information without current consent or a valid purpose check. That failure can be amplified by automation, list reuse, or poor suppression controls.

Impact: Recipients may experience nuisance, loss of trust, privacy exposure, or unwanted pressure, while organisations may face complaints, reputational damage, and regulatory scrutiny over consent and purpose handling.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
GDPR Art. 5 — Principles Relating to Processing of Personal Data Unsolicited contact can conflict with consent, purpose limitation, and data minimization
Recommendation — Limit recipient targeting to a lawful basis and a clearly defined purpose before sending personal-data communications.
ISO/IEC 27001:2022 A.5.15 — Access Control Audience restriction and approved distribution depend on controlled access to information and recipient data
A.5.34 — Privacy and Protection of PII Unsolicited transmission can expose personal data and create privacy harm
Recommendation — Restrict who can access and use recipient lists so broadcasts only reach approved audiences. Handle personal contact data under documented privacy controls before using it for outreach.

Practitioner Guidance

Governance implication: Treat unsolicited transmission as a permission and audience-control problem, not only a messaging problem. The practical question is whether the organisation can show why each recipient was appropriate for that message at that time.

What to watch for: Default opt-ins, stale distribution lists, repurposed contact data, and overly broad broadcast tools are common signals that consent and audience controls are too weak. Tightening those controls reduces both privacy friction and avoidable exposure.