DSG Retail Limited v The Information Commissioner

[2024] UKUT 287 (AAC)

Case details

Case citations
[2024] UKUT 287 (AAC)
Court
Upper Tribunal (Administrative Appeals Chamber)
Judgment date
23 September 2024
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Data protection Administrative law Personal data
Keywords
Data Protection Act 1998 seventh data protection principle data security monetary penalty notice cyber-attack personal data primary account number EMV card data serious contravention procedural fairness
Outcome
appeal allowed; first-tier tribunal decision set aside in part and remitted to a freshly constituted tribunal
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

For the seventh data protection principle, a data controller’s duty to take appropriate technical and organisational measures is anticipatory. However, where the relevant risk is unauthorised or unlawful processing by third parties, the tribunal must assess whether the data exposed by the security shortcoming would be personal data in those third parties’ hands.

A primary account number and card expiry date do not directly identify a living individual. They are not personal data in themselves. The applicable security standard under Data Protection Act 1998 Schedule 1 must be assessed by reference to the data actually put at risk and the harm that might result.

A serious contravention under section 55A requires an assessment of both the applicable standard and how far the controller fell below it.

Factual background

DSG Retail Limited appealed against a decision of the First-tier Tribunal (General Regulatory Chamber), which had reduced an information commissioner monetary penalty from £500,000 to £250,000 following a cyber-attack on DSG’s payment systems.

The attackers obtained payment-card primary account numbers and expiry dates from over five million EMV-protected cards, together with other undisputed personal data. The First-tier Tribunal held that at least some of the card data was personal data because DSG could combine it with other information in its own systems.

The central questions were whether that approach was correct under the seventh data protection principle, whether the EMV data was personal data in itself, and whether the First-tier Tribunal had lawfully found a serious contravention for the purposes of section 55A of the Data Protection Act 1998.

Held

  1. Appeal allowed. The First-tier Tribunal made material errors of law. Its substituted monetary penalty decision was set aside and the appeal was remitted to an entirely fresh First-tier Tribunal.

  2. The seventh data protection principle imposed an anticipatory duty on DSG, as data controller, to take appropriate technical and organisational measures. A breach does not depend on an attack actually occurring. But, for the distinct risk of third-party unauthorised or unlawful processing, the tribunal had to determine whether the data placed at risk would be personal data in the hands of persons able to access it. It was not enough that DSG itself held other information capable of identifying the cardholder.

  3. The EMV data, comprising a primary account number and expiry date, did not directly identify a living individual. It was therefore not personal data in itself. On remission, the First-tier Tribunal must decide whether a motivated attacker could link it with other data put at risk by DSG’s security shortcomings, or with externally obtained information, so as to identify cardholders.

  4. The First-tier Tribunal had also failed to apply paragraph 9 of Part II of Schedule 1 to determine the appropriate level of security by reference to the harm that might result from the relevant exposure of personal data. Its inconsistent reliance on DSG’s own ability to link the EMV data infected its findings on seriousness, substantial distress and penalty.

  5. A serious contravention under section 55A required a distinct assessment of the applicable standard and the extent of DSG’s departure from it. Likely consequences could be relevant, but could not replace that assessment. Reasonable public expectations that personal data would be adequately protected were not irrelevant and could be treated as common sense.

The fresh tribunal was directed to proceed on the uncontested basis that the non-financial data and the data from 8,628 non-EMV cards containing cardholder names were personal data, while reconsidering whether the security shortfalls exposed other personal data.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  • Upper Tribunal (Administrative Appeals Chamber): Allowed DSG’s appeal, set aside the relevant parts of the First-tier Tribunal’s decision, and remitted the matter to a freshly constituted tribunal: [2024] UKUT 287 (AAC).
  • First-tier Tribunal (General Regulatory Chamber): On 5 July 2022, held that the Information Commissioner’s original £500,000 monetary penalty was wrong in law and substituted a £250,000 penalty in case EA/2020/0048. That substituted decision was set aside in the respects directed by the Upper Tribunal.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.