BrewDog founder James Watt is facing complaints to the UK data privacy watchdog over emails sent to thousands of former shareholders, raising serious questions about GDPR compliance and investor rights. The controversy erupted after Watt contacted so-called “equity punks” with an offer to join his new venture, Second Best, using contact details that many recipients say they never authorized for such use.
How the BrewDog GDPR controversy unfolded
In March, BrewDog’s brand, UK breweries, and 11 bars were sold to US cannabis firm Tilray for £33 million, leaving over 200,000 crowdfunding investors with worthless shares. On Wednesday, Watt announced a plan to buy back control via Second Best, offering investors the “exact same stake” they held in BrewDog for free. But the emails sent to thousands of shareholders quickly sparked backlash.
Get the #1 Wireless Door Camera
REOLINK Bestseller: 2K Weatherproof Video Doorbell, No Monthly Fees.
Several recipients told the Guardian they had no idea how Watt obtained their contact details. One source said, “How’s this joker got my details?” Another former equity punk, Marc Knox, has written to Second Best and is prepared to file a formal complaint. The Information Commissioner’s Office (ICO) is now assessing the incident for potential GDPR breaches.
What GDPR rules apply to shareholder communications?
Under UK GDPR, organizations must have a lawful basis to process personal data. Common bases include consent, contractual necessity, or legitimate interests. Watt claims the emails were sent “following legal advice, using lawfully obtained data” and in connection with shareholders’ legitimate interests. However, many experts argue that contacting investors for a new venture—not the original company—may exceed the original purpose of data collection.
| GDPR Requirement | How BrewDog’s Case May Violate It |
|---|---|
| Lawful basis for processing | Shareholder data used for a separate business venture (Second Best) may not qualify as legitimate interest |
| Data minimization | Contacting thousands of investors without clear opt-in could breach proportionality |
| Transparency | Recipients were not told how their data was obtained or used |
| Right to object | Investors had no easy way to stop unwanted emails |
Key takeaways from the BrewDog data privacy scandal
- GDPR fines can reach up to 4% of global turnover or £17.5 million, whichever is higher
- Using shareholder data for unrelated ventures without explicit consent is risky
- The ICO has the power to compel organizations to change data practices
- Investors should always check privacy policies before sharing contact details
What happens next for James Watt and Second Best?
The ICO is “assessing the information provided” and may launch a formal investigation. If a breach is found, Watt could face significant penalties and reputational damage. Meanwhile, former equity punks are organizing to demand answers. The case highlights the growing importance of data privacy in corporate communications, especially when dealing with crowdfunded investors.
FAQ
What is GDPR and why does it matter for BrewDog?
GDPR stands for General Data Protection Regulation, a UK and EU law that governs how personal data is collected, stored, and processed. In BrewDog’s case, using shareholder emails without clear consent may violate these rules.
Can James Watt be fined for sending those emails?
Yes. If the ICO finds a GDPR breach, Watt or Second Best could face fines up to £17.5 million or 4% of annual global turnover. The ICO can also order changes to data practices.
What should former BrewDog investors do if they received an email?
Investors can file a complaint with the ICO directly. They should also request details on how their data was obtained and ask to be removed from future communications.