Thursday, 1 October 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Court of Appeal says firms must secure data hackers cannot identify

The ICO wins its appeal over the 2017–18 cyberattack on DSG Retail. The ruling settles which stolen data falls inside the security duty, whoever ends up holding it

The facts
  • Neutral citation: [2026] EWCA Civ 140
  • Judges: Lord Justice Moylan, Lady Justice Elisabeth Laing and Lord Justice Warby
  • Provision in dispute: the seventh data protection principle of the 1998 Act, known as the security duty
  • Next step: the case returns to the First-tier Tribunal to apply the ruling to the facts
What to do now

Stop treating partial, tokenized or pseudonymized datasets as out of scope because a thief could not put names to them. If the business can link the records to people, they belong in the same risk assessment, access controls and monitoring as named customer data. Mid-sized firms that take card or account data should check their incident plans and supplier contracts on that basis.

“With the rising threat of cyber crime, this decision strengthens our ability to take robust action in the future and sends a clear message to all organisations: you have a protective duty to safeguard the personal data you hold.”Binnie Goh, general counsel, Information Commissioner’s Office

The Court of Appeal ruled on 19 February 2026 that organizations must protect personal data against unauthorized processing even when an attacker could not identify the people it relates to, allowing an appeal by the Information Commissioner’s Office (ICO) in DSG Retail Ltd v The Information Commissioner. The ICO had fined DSG £500,000 over the attack.

The case stems from a cyberattack on DSG’s systems in 2017–18. According to the court’s summary, attackers scraped transaction details as payments were made, stored them on DSG’s servers and tried to exfiltrate them. For most cards, which were protected by chip-and-PIN, they obtained only the card number and expiry date, with no names. The ICO says the attack affected the personal data of at least 14 million people.

DSG argued that the security duty did not cover data that would not identify anyone in the attackers’ hands, and the Upper Tribunal agreed. The Court of Appeal disagreed: it is enough that the individuals are identifiable to the organization holding the data. The court, in a lead judgment by Lord Justice Warby, said the narrower reading would leave no obligation to guard against deliberate interference such as ransomware attacks, and that guarding against these risks would not add significantly to the burden of the security duty.

The case was decided under the Data Protection Act 1998. The ICO says the court’s reading of the security duty offers an important guide to similar requirements under current data protection law.

Sources
  1. Information Commissioner’s Office, “ICO wins Court of Appeal case in DSG Retail ruling”, news release, 19 February 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/ico-wins-court-of-appeal-case-in-dsg-retail-ruling/
  2. Courts and Tribunals Judiciary, “DSG Retail Limited v The Information Commissioner”, [2026] EWCA Civ 140, judgment page, 19 February 2026. https://www.judiciary.uk/judgments/dsg-retail-limited-v-the-information-commissioner/
  3. Court of Appeal, “DSG Retail Ltd v The Information Commissioner [2026] EWCA Civ 140”, summary of judgment, 19 February 2026. https://www.judiciary.uk/wp-content/uploads/2026/02/ICO-v-DSG.Summary.FINAL_.260219-002.pdf
AdvertisementZoomInfo
More from The BriefAll briefs
Google DeepMind

DeepMind CEO questions OpenAI’s fast move to ads in ChatGPT

Made Tech Group

Made Tech lifts revenue 28% while new bookings fall by two-thirds

Extreme Networks

Extreme Networks refocuses partner program on predictable rebates and MSPs

Distology · Tenable

Distology Tenable deal signals shift toward value-led distribution

Get the briefs every week in The VETTDD Briefing.