Selected cases

Court of Appeal of England and Wales · [2026] EWCA Civ 140

DSG Retail Limited v The Information Commissioner

The duty was a proportionate safeguarding duty, not a guarantee of perfect security.

Court of Appeal of England and Wales19 Feb 2025

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • If your business can identify a person from information in its systems, you should usually treat that information as needing appropriate protection, even where an...
  • DSG Retail Limited v The Information Commissioner [2026] EWCA Civ 140 is a Court of Appeal decision on the scope of the old Data Protection Act 1998 security duty.

Use this to check

  • The Court of Appeal rejected a narrow reading of the old data security duty under the Data Protection Act 1998.
  • If information is personal data from the controller’s perspective, the security duty can apply even if an attacker could not identify the individuals from the stolen data alone.
  • The duty is a safeguarding duty requiring proportionate technical and organisational measures, not a guarantee against every breach.

Decision snapshot

  1. What happened

    • DSG Retail Limited operated major retail brands including Dixons and Currys PC World.
    • In 2017 to 2018, its systems were hit by a cyber attack that lasted about nine months.
    • The attackers obtained millions of items of data by scraping transaction details from point-of-sale terminals or card readers as transactions were made, storing the scraped data on DSG’s servers and attempting to exfiltrate it.
    • More than 5.6 million payment cards were affected.
  2. What the court had to decide

    • The Court of Appeal had to decide the scope of the security duty under the Data Protection Act 1998.
    • The specific question was whether a data controller had to take appropriate technical and organisational measures against unauthorised or unlawful processing by a third party where the data were personal data in the controller’s hands, because the controller could identify the individuals, but not personal data in the third party’s hands because the third...
  3. What the court decided

    • The Court of Appeal allowed the Information Commissioner’s appeal.
    • It held that the security duty under the Data Protection Act 1998 did require a data controller to safeguard personal data against unauthorised or unlawful processing by a third party even where the third party could not identify the individuals from the data obtained.
    • The court said the Upper Tribunal’s narrower reading was not supported by the statutory language, the Directive or the legislation’s protective purpose, and would create surprising gaps in protection.

Practical impact

Practical read

  • If your business can identify a person from information in its systems, you should usually treat that information as needing appropriate protection, even where an outsider who steals one part of the dataset could not identify the...
  • The court described the duty as a safeguarding duty, not a guarantee of perfect security.
  • That means proportionate controls, not impossible standards.
  • In practice, businesses should map what data they can link back to people, include indirectly identifying and pseudonymised datasets in security reviews, and document why their controls are appropriate to the risks.

Useful next steps

  • The Court of Appeal rejected a narrow reading of the old data security duty under the Data Protection Act 1998.
  • If information is personal data from the controller’s perspective, the security duty can apply even if an attacker could not identify the individuals from the stolen data alone.
  • The duty is a safeguarding duty requiring proportionate technical and organisational measures, not a guarantee against every breach.
  • The judgment does not finally decide whether DSG’s actual controls were adequate because the case was remitted.
  • For modern businesses, the practical lesson is to protect all data you can link back to individuals, including indirectly identifying datasets.

Snapshot

This case is about the scope of a business’s duty to protect personal data from cyber risks. The Court of Appeal looked at the old Data Protection Act 1998 and asked whether a company had to protect data that were personal data to the company, even if an attacker who obtained that data could not identify the individuals from the stolen data alone.

The court said yes. If the information is personal data from the controller’s perspective, the security duty can apply. The duty is about safeguarding personal data you control with appropriate technical and organisational measures.

That does not mean a business guarantees that no incident will ever happen. The court was clear that this is a proportionate duty to guard against risk. But it does mean a business cannot shrink the duty by focusing only on what the attacker could identify from one slice of stolen data.

Practical sense check

  • The relevant starting point is whether the data are personal data to the controller
  • A criminal hack does not remove the need for appropriate security controls
  • The duty is proportionate and risk-based, not absolute
  • The court rejected a narrow attacker-focused interpretation
  • The case was remitted, so the appeal did not finally decide whether DSG’s actual controls were adequate

The story

DSG Retail Limited owned and operated major retail brands including Dixons and Currys PC World. In 2017 to 2018, its systems were targeted in a cyber attack that lasted about nine months. The attackers scraped transaction details from point-of-sale terminals or card readers as transactions were made, stored the scraped data on DSG’s servers and attempted to exfiltrate it.

More than 5.6 million payment cards were affected. In around 8,000 cases, the attackers obtained the 16-digit card number, expiry date and cardholder name. But for the great majority of cards, because of the chip-and-pin system known as EMV, the attackers obtained only the card number and expiry date.

That distinction drove the legal dispute. On the assumptions used for the appeal, the attackers did not have the names or other information needed to identify the cardholders from the EMV data alone. DSG, however, could identify the individuals from its own wider records.

After investigating, the Information Commissioner concluded that DSG had breached the seventh data protection principle under the Data Protection Act 1998 and issued a monetary penalty notice for £500,000. DSG challenged that decision through the tribunal system.

The case then moved through three levels. The First-tier Tribunal rejected DSG’s narrow argument and upheld the penalty notice, although it reduced the penalty by half. The Upper Tribunal accepted DSG’s narrower reading of the duty. The Information Commissioner then appealed to the Court of Appeal on that single legal issue.

Details that matter

  • Cyber attack on DSG systems during 2017 to 2018
  • Attackers scraped payment transaction details from point-of-sale terminals or card readers
  • More than 5.6 million payment cards were affected
  • Most of the disputed data were EMV data consisting of card number and expiry date only
  • The legal question turned on whether DSG still had a duty to protect that data

What the court decided

The Court of Appeal allowed the Information Commissioner’s appeal. Lord Justice Warby, with Lady Justice Elisabeth Laing and Lord Justice Moylan agreeing, held that the Upper Tribunal’s narrow interpretation was wrong.

The court described the security duty as a protective duty, or safeguarding duty. It requires a data controller to take proportionate steps to guard against risk. It is not a guarantee that no breach will ever happen. But it does apply to personal data for which the controller is responsible, even where the wrongdoer could not identify the individuals from the data obtained.

The court placed weight on the wording of section 4(4) of the 1998 Act, which imposed a duty on a data controller to comply with the data protection principles in relation to all personal data with respect to which it was the data controller. It also looked at the seventh principle itself, which required appropriate technical and organisational measures against unauthorised or unlawful processing of personal data.

In the court’s view, nothing in that wording justified cutting down the duty by asking whether the data would still count as personal data in the hands of the attacker. If the data were personal from the controller’s perspective, that was enough for the duty to arise.

The court also accepted that the narrower reading produced surprising consequences. On that approach, a business might have no duty to guard against malicious deletion, alteration, extraction or encryption of personal data where the attacker could not identify the individuals concerned. The court regarded that as inconsistent with the protective purpose of the legislation.

Practical sense check

  • The relevant perspective was the controller’s perspective
  • The duty applied to all personal data for which the controller was responsible
  • The court rejected the idea that the attacker’s inability to identify individuals removed the duty
  • The duty remained proportionate and risk-based
  • The appeal was allowed and the case was remitted to the First-tier Tribunal

How the court reached that view

The court relied on the language, context and purpose of the legislation. It said the broader interpretation was more consistent with the wording of the 1998 Act and the Data Protection Directive that sat behind it.

One important point was the structure of the 1998 Act. The general duty applied to all personal data with respect to which the controller was the data controller. The court treated that as an unqualified starting point. It did not see wording in the seventh principle that cut the duty down by reference to the perspective of the wrongdoer.

The court also looked at the Directive. It noted that the Directive’s security provisions were aimed at protecting personal data against unauthorised disclosure, access and other unlawful forms of processing, taking account of the state of the art, implementation cost, the risks involved and the nature of the data to be protected.

The judgment stressed practical consequences too. On DSG’s reading, a business could fall outside the security duty in situations where attackers could not identify the people concerned but could still delete, alter, extract or encrypt the data. The court saw that as a serious gap that Parliament and the EU legislature were unlikely to have intended.

The court also considered earlier case law about anonymised data and freedom of information. It concluded that those authorities did not decide the issue in this appeal because they dealt with a different context, namely deliberate disclosure of data that had been rendered anonymous before release.

That mattered because this case was not about a controller intentionally creating a truly anonymised dataset and disclosing it. It was about whether a controller had any duty at all to protect personal data in its systems against unauthorised third-party processing. The court’s answer was clear. If the information remains personal data from the controller’s perspective, the security duty applies for so long as that remains true.

What the court did not decide

The appeal did not decide every issue in the wider enforcement action. The court was careful to limit itself to one point of legal principle.

It did not decide whether DSG’s actual technical and organisational measures were appropriate on the facts. It did not decide whether any breach was serious enough to justify a monetary penalty notice. And it did not decide whether the amount of any penalty was ultimately appropriate after applying the correct legal test.

Instead, the court allowed the appeal and remitted the matter to the First-tier Tribunal to be determined in accordance with its judgment. So this decision is important on legal interpretation, but it is not the final word on the underlying enforcement outcome.

How businesses should read it

The practical lesson is wider than payment card data. Many businesses hold information that may not identify a person on its own, but does identify them when combined with other records the business holds. That can include customer numbers, account references, transaction histories, booking records, device logs and internal identifiers.

This case says you should not assume those datasets fall outside your security duty just because an outsider who steals one slice of the data could not immediately name the person. If your business can identify the person from the data and related information in your systems, you should assume the data need appropriate protection.

The judgment is also useful because it links legal compliance with practical cyber security. The court did not prescribe a fixed control list. It focused on proportionate safeguarding measures, taking account of risk, the nature of the data, the state of technology and the cost of implementation.

That means the right question is usually not, could a hacker identify the customer from this field alone? The better question is, is this personal data in our environment, and what controls are appropriate to reduce the risk of unauthorised access, misuse, alteration, loss or destruction?

The judgment itself notes that the modern security duty now appears in GDPR and UK GDPR. This case is not a direct ruling on those regimes, but it is still a useful reminder that security obligations are framed broadly and are tied to the data you control, not just to the immediate usefulness of one stolen extract.

In practice

  • Treat indirectly identifying and linked datasets as part of your security perimeter
  • Do not rely on narrow arguments about what a criminal could identify from one extracted dataset
  • Document your risk assessment and the reasons your controls are appropriate
  • Review payment environments and connected systems carefully
  • Remember that proportionate security is still a legal question, not just an IT question

Documents and conduct

For a business owner or manager, this case is a prompt to check whether your data governance and cyber security work together. The court’s reasoning supports a joined-up approach rather than a narrow legal defence after an incident.

You should be able to show what personal data you hold, how individuals can be identified within your systems, what risks exist, and what technical and organisational measures you have chosen in response. That record matters because the duty is about appropriate measures, not just good intentions.

Even though the case arose from a large retailer and payment card environment, the same thinking applies to smaller businesses. If you hold customer account data, booking records, staff files or device-linked logs, you should know which of those records can be linked back to a person and how they are protected.

Documents to keep in order

  • Data maps showing what information can be linked back to individuals
  • Security risk assessments covering unauthorised access, scraping, extraction, deletion and encryption
  • Access control policies and user permission reviews
  • Patch management and vulnerability management records
  • Network and endpoint protection arrangements
  • Payment environment controls and segmentation records where relevant
  • Monitoring, logging and incident response procedures
  • Supplier and processor security checks where third parties handle relevant systems or data
  • Board or management reporting on cyber and privacy risks
  • Records explaining why the chosen controls are proportionate to the risks

Dates and status

The judgment was handed down on 19 February 2026. The hearing took place on 4 December 2025. The case concerns a cyber attack in 2017 to 2018 and the security duty under the Data Protection Act 1998.

The court allowed the Information Commissioner’s appeal and remitted the matter to the First-tier Tribunal. That means the decision is authoritative on the legal interpretation point decided by the Court of Appeal, but it does not finally resolve the wider enforcement dispute.

The judgment itself notes that the modern security duty now appears in GDPR and UK GDPR. So while the ruling is about the 1998 Act, it remains useful when thinking about present-day security obligations at a high level.

Practical sense check

  • Court: Court of Appeal (Civil Division)
  • Neutral citation: [2026] EWCA Civ 140
  • Hearing date: 4 December 2025
  • Judgment handed down: 19 February 2026
  • Result: Appeal allowed and matter remitted to the First-tier Tribunal

Common questions

What was the main point the Court of Appeal decided?

The court decided that the old Data Protection Act 1998 security duty could apply where data were personal data from the controller’s perspective, even if a third party who obtained the data could not identify the individuals from that data alone.

Did the court say businesses must prevent every cyber attack?

No. The court described the duty as a protective or safeguarding duty. It requires proportionate steps against risk, not a guarantee of a particular outcome.

Was DSG finally found liable for inadequate security by the Court of Appeal?

No. The Court of Appeal resolved the legal interpretation issue and remitted the matter to the First-tier Tribunal. It did not finally decide in this appeal whether DSG’s actual measures were appropriate.

Does this case still matter now that the 1998 Act has been replaced?

Yes. It remains an authority on the 1998 Act, and the judgment itself notes that today the security duty appears in GDPR and UK GDPR. That makes the reasoning useful at a high level when thinking about current security obligations.

What kind of business data does this reasoning affect?

It is relevant to any dataset that your business can link back to an individual, including customer references, account numbers, transaction records, booking data, device logs and other indirectly identifying information.

Related topics

How Sprintlaw can help