Case details
Summary
For the seventh data protection principle, a data controller’s duty to take appropriate technical and organisational measures is anticipatory. However, where the relevant risk is unauthorised or unlawful processing by third parties, the tribunal must assess whether the data exposed by the security shortcoming would be personal data in those third parties’ hands.
A primary account number and card expiry date do not directly identify a living individual. They are not personal data in themselves. The applicable security standard under Data Protection Act 1998 Schedule 1 must be assessed by reference to the data actually put at risk and the harm that might result.
A serious contravention under section 55A requires an assessment of both the applicable standard and how far the controller fell below it.
Factual background
DSG Retail Limited appealed against a decision of the First-tier Tribunal (General Regulatory Chamber), which had reduced an information commissioner monetary penalty from £500,000 to £250,000 following a cyber-attack on DSG’s payment systems.
The attackers obtained payment-card primary account numbers and expiry dates from over five million EMV-protected cards, together with other undisputed personal data. The First-tier Tribunal held that at least some of the card data was personal data because DSG could combine it with other information in its own systems.
The central questions were whether that approach was correct under the seventh data protection principle, whether the EMV data was personal data in itself, and whether the First-tier Tribunal had lawfully found a serious contravention for the purposes of section 55A of the Data Protection Act 1998.
Held
Appeal allowed. The First-tier Tribunal made material errors of law. Its substituted monetary penalty decision was set aside and the appeal was remitted to an entirely fresh First-tier Tribunal.
The seventh data protection principle imposed an anticipatory duty on DSG, as data controller, to take appropriate technical and organisational measures. A breach does not depend on an attack actually occurring. But, for the distinct risk of third-party unauthorised or unlawful processing, the tribunal had to determine whether the data placed at risk would be personal data in the hands of persons able to access it. It was not enough that DSG itself held other information capable of identifying the cardholder.
The EMV data, comprising a primary account number and expiry date, did not directly identify a living individual. It was therefore not personal data in itself. On remission, the First-tier Tribunal must decide whether a motivated attacker could link it with other data put at risk by DSG’s security shortcomings, or with externally obtained information, so as to identify cardholders.
The First-tier Tribunal had also failed to apply paragraph 9 of Part II of Schedule 1 to determine the appropriate level of security by reference to the harm that might result from the relevant exposure of personal data. Its inconsistent reliance on DSG’s own ability to link the EMV data infected its findings on seriousness, substantial distress and penalty.
A serious contravention under section 55A required a distinct assessment of the applicable standard and the extent of DSG’s departure from it. Likely consequences could be relevant, but could not replace that assessment. Reasonable public expectations that personal data would be adequately protected were not irrelevant and could be treated as common sense.
The fresh tribunal was directed to proceed on the uncontested basis that the non-financial data and the data from 8,628 non-EMV cards containing cardholder names were personal data, while reconsidering whether the security shortfalls exposed other personal data.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Appellate history
- Upper Tribunal (Administrative Appeals Chamber): Allowed DSG’s appeal, set aside the relevant parts of the First-tier Tribunal’s decision, and remitted the matter to a freshly constituted tribunal: [2024] UKUT 287 (AAC).
- First-tier Tribunal (General Regulatory Chamber): On 5 July 2022, held that the Information Commissioner’s original £500,000 monetary penalty was wrong in law and substituted a £250,000 penalty in case EA/2020/0048. That substituted decision was set aside in the respects directed by the Upper Tribunal.
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.