Unsolicited information is information sent through a computer or online channel without the recipient’s consent. The legal concern is not normal commercial messaging, but unwanted transmission that creates nuisance, privacy harm, or pressure on the recipient. Organisations should treat consent, purpose, and audience as core controls.
What unsolicited information means in practice
Unsolicited information is not just “extra” contact, it is information delivered without the recipient’s consent or invitation. The core issue is the sender’s choice to transmit, not whether the content is commercial, legal, or informational.
That distinction matters because consent changes the legitimacy of the communication channel. A message can be accurate, lawful in other respects, and still be inappropriate if it reaches an audience that did not agree to receive it.
How consent and audience shape the meaning
The term is defined by the relationship between sender, recipient, and purpose. If the recipient did not ask for the information, the sender needs a strong justification for why the transmission was appropriate, proportionate, and targeted.
In practice, this makes audience control and purpose limitation central. Organisations should be careful not to treat broad distribution, default opt-ins, or recycled contact lists as implied permission.
This is one reason privacy-oriented control language often appears alongside communication governance. EU General Data Protection Regulation (GDPR) is relevant where unsolicited transmission overlaps with personal data processing, consent, and lawful-purpose boundaries.
Where the harm comes from
The harm is often less about the information itself and more about its effect on the recipient. Unsolicited transmissions can create nuisance, pressure, distraction, unwanted profiling, or exposure of personal contact details to further reuse.
It can also erode trust. When people cannot predict who will contact them, for what reason, and through which channel, they are less able to distinguish legitimate communication from spam, manipulation, or privacy-invasive outreach.
At the control level, this is why information governance, consent records, and addressability rules matter. Unwanted transmission usually reflects a failure in audience selection, permission handling, or suppression logic rather than a content problem alone.
Why organisations treat it as a governance issue
Unsolicited information becomes a governance concern when senders cannot demonstrate a valid basis for contact or when systems make it too easy to send broadly by default. That is especially true where the same processes support marketing, notifications, onboarding, or relationship management.
Good practice is to separate who may send, what they may send, and who may receive it. That reduces the chance that one approved workflow becomes a blanket channel for messages that were never intended for that audience.
For organisations that manage regulated communications, broader information security controls can help frame the discipline. ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls both support controlled handling of information, including access, authentication, and documented control selection.
Risk and Threat Considerations
Unsolicited information can become a practical security and privacy risk when the same channels are used for spam, phishing, harassment, or repeated contact that overwhelms the recipient’s ability to filter legitimate messages. The risk increases when distribution lists, consent status, or audience rules are weakly managed.
Failure mechanism: The sender relies on broad or stale recipient data, then transmits information without current consent or a valid purpose check. That failure can be amplified by automation, list reuse, or poor suppression controls.
Impact: Recipients may experience nuisance, loss of trust, privacy exposure, or unwanted pressure, while organisations may face complaints, reputational damage, and regulatory scrutiny over consent and purpose handling.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 5 — Principles Relating to Processing of Personal Data | Unsolicited contact can conflict with consent, purpose limitation, and data minimization |
| Recommendation — Limit recipient targeting to a lawful basis and a clearly defined purpose before sending personal-data communications. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access Control | Audience restriction and approved distribution depend on controlled access to information and recipient data |
| A.5.34 — Privacy and Protection of PII | Unsolicited transmission can expose personal data and create privacy harm | |
| Recommendation — Restrict who can access and use recipient lists so broadcasts only reach approved audiences. Handle personal contact data under documented privacy controls before using it for outreach. | ||
Practitioner Guidance
Governance implication: Treat unsolicited transmission as a permission and audience-control problem, not only a messaging problem. The practical question is whether the organisation can show why each recipient was appropriate for that message at that time.
What to watch for: Default opt-ins, stale distribution lists, repurposed contact data, and overly broad broadcast tools are common signals that consent and audience controls are too weak. Tightening those controls reduces both privacy friction and avoidable exposure.
Related resources from NHI Mgmt Group
- Who is accountable when an AI concierge gives guests incorrect or harmful information?
- Who is accountable when unauthorized use of personal information occurs?
- What do teams get wrong about least privilege for confidential information?
- Who is accountable when confidential information is exposed through poor handling?