This case is about the scope of a business’s duty to protect personal data from cyber risks. The Court of Appeal looked at the old Data Protection Act 1998 and asked whether a company had to protect data that were personal data to the company, even if an attacker who obtained that data could not identify the individuals from the stolen data alone.
The court said yes. If the information is personal data from the controller’s perspective, the security duty can apply. The duty is about safeguarding personal data you control with appropriate technical and organisational measures.
That does not mean a business guarantees that no incident will ever happen. The court was clear that this is a proportionate duty to guard against risk. But it does mean a business cannot shrink the duty by focusing only on what the attacker could identify from one slice of stolen data.