Back to Blog

Big Data

Setting The Record Straight: UK Court of Appeal backs a Controller Centric Interpretation in UK Data Law

On 19 February 2026, the UK Court of Appeal (The Court) handed down its decision in DSG Retail Limited v The Information Commissioner [2026] EWCA Civ 140[1]. The Court overturned an Upper Tribunal (UT) decision, confirming that a controller’s duty to safeguard personal data applies to data that is “personal” from the perspective of the controller, irrespective of whether third parties could identify individuals from the dataset.

Note that the legal context of the case is provided by the UK Data Protection Act 1998 (DPA 1998)[2]. However, the decision carries significant interpretive weight due to the similarities of the data security duty under the Data Protection Act 2018[3] and UK GDPR[4] as it was under the DPA 1998. The Court also considered more recent jurisprudence from the European Court of Justice (CJEU).

Background

Between 2017 and 2018, DSG Retail Limited (DSG) experienced a sustained cyber-attack on its in-store payment systems, with the attackers scraping transaction-level data that affected more than 5.6 million payment cards. For most transactions, the attackers only obtained card numbers and expiry dates, not directly identifying information about cardholders such as their names.

The Information Commissioner’s Office (ICO) found DSG to be in breach of its data security duty under DPA 1998 and issued a monetary penalty notice[5]. DSG unsuccessfully appealed to the First-tier Tribunal (FtT), and then to the UT, which accepted the appeal on the basis that the security duty under the DPA 1998 is assessed from the third party’s perspective. Since the attackers could not link the scraped data to specific individuals, there was no “personal data”, and thus no security duty violation.

Decision of the Court of Appeal

The Court found that the FtT had reached the right conclusion, and overturned the UT’s ruling based on the following reasoning:

  • The CJEU’s decision in SRB v EDPS[6] confirmed that the characterisation of data as “personal data” depends on the circumstances of the processing of the data. Since the security duty is part of the legal relationship between the data subject and data controller, the duty concerns the information in relation to that data subject as it was transmitted to the controller. On this basis, data is “personal data” for as long as the individuals to whom they relate are indirectly identifiable to the controller, regardless of whether the data is personal “in the hands of” or “from the perspective” of another person.
  • It would be surprising if the legislature intended to narrow the scope of the data security duty so that a data controller would have no obligation to safeguard against ransomware attacks or any other interference that harms data subjects without direct identification of the individuals. This would run contrary to the protective aims of the EU Data Protection Directive[7] that the DPA 1998 sought to implement.

Implications for businesses and consumers

The Court’s decision makes clear that data controllers must implement appropriate technical and organisational measures for all data that is personal from their perspective, even if the data appears anonymised or pseudonymised to third parties.

The judgment serves as an emphatic reminder to UK businesses that incomplete data does not excuse them from responsibility, and they must align their privacy frameworks accordingly.

The case will now return to the FtT to apply the Court’s legal interpretation to the facts of the cyber-attack.

What UK controllers should do now

  • Update incident‑classification playbooks to reflect that breaches involving incomplete, fragmentary, or tokenised data should be treated as personal data breaches when the controller can identify the individuals behind the data.
  • Treat all compromises of partial datasets, including card numbers and expiry dates, pseudonymised data, and transaction fragments, as potential full personal data breaches rather than lower‑risk incidents.
  • Reassess breach‑notification triggers, as more incidents may now meet the threshold for reporting to the UK ICO and, where relevant, to affected individuals.
  • Ensure internal breach‑response guidance and escalation pathways reflect a controller‑centric assessment of identifiability.
  • Train incident‑response staff to avoid relying on an attacker’s perspective and instead classify incidents based on the controller’s ability to link data to individuals.

 

Please contact Jose Saras and Xavier Prida for detailed advice on the above.

The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.

This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.

[1] DSG Retail Limited -v- The Information Commissioner – Courts and Tribunals Judiciary

[2] Data Protection Act 1998

[3] Data Protection Act 2018

[4] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)

[5] [ARCHIVED CONTENT] National retailer fined half a million pounds for failing to secure information of at least 14 million people | ICO

[6] EUR-Lex – 62023CJ0413 – EN – EUR-Lex

[7] Directive – 95/46 – EN – Data Protection Directive – EUR-Lex

A practical way forward

Tell us about the matter.

Speak to us