Front facade of the Royal Courts of Justice

Court of appeal backs ICO in £500,000 Currys/Dixons data breach fine

The Court of Appeal has revived a £500,000 fine against DSG Retail – the then parent company of Currys PC World and Dixons Travel – in a long-running legal battle with the Information Commissioner’s Office (ICO). 

At the heart of the case was a deceptively simple question: are 16-digit card numbers and expiry dates “personal data” if they don’t include a name? 

The answer from Lord Justice Warby was clear. Yes. 

What happened in the original breach?

In 2017, attackers installed malware on more than 5,000 tills across DSG’s stores. The malicious software remained undetected for nine months. 

During that time, hackers captured:

  • Around 5.6 million payment card details (16-digit numbers and expiry dates)
  • Personal information belonging to approximately 14 million individuals.  

The ICO later described the failings as relating to “basic, commonplace security measures” and issued a £500,000 penalty in 2020 under the Data Protection Act 1998 – the maximum fine available at the time, before GDPR came into force.

DSG challenged the fine. And that is where the legal argument became more nuanced.

The dispute did not centre on the wider personal information taken in the breach. Instead, it focused specifically on the card details – the long number and expiry date, but not the cardholder’s name.

DSG accepted that it, as the retailer, could link those numbers to real individuals. But it argued that the attackers could not identify customers from the card details alone.

Therefore, it said, those details should not count as “personal data” in the hands of the hackers.

The Upper Tribunal agreed with that reasoning and overturned the ICO’s fine. But the Court of Appeal has now reversed that decision. 

Why the Court of Appeal sided with the ICO

Lord Justice Warby rejected the idea that personal data should be assessed solely from the perspective of the attacker. Instead, he confirmed that data must be viewed from the perspective of the data controller – in this case, DSG Retail.  

If the organisation can link the data to an identifiable individual, then it is personal data. Full stop.

That means the legal duty to protect it applies, even if a third party cannot immediately identify someone from the information in isolation.

The judgment also addressed a wider risk: so-called “jigsaw identification”. In today’s world, fragments of data can be combined with other publicly available information to build a fuller picture of an individual.

Technology has made it far easier to locate, assemble and cross-reference disparate data sources. Even information that does not identify someone on its own may do so when combined with other datasets.

The court was clear that organisations cannot dismiss such risks as harmless. 

Why this matters beyond one retailer

This ruling is about more than a £500,000 fine from nearly a decade ago. 

It clarifies that:

  • Organisations must protect all personal data they process
  • They cannot avoid liability by arguing that hackers could not immediately identify individuals 
  • The duty to safeguard data does not disappear simply because stolen data is incomplete. 

Had the Upper Tribunal’s reasoning stood, the implications could have been significant. It might have weakened regulatory enforcement in cases involving ransomware or partial datasets. Instead, the Court of Appeal has strengthened the ICO’s hand at a time when cyber-attacks are becoming more frequent and more sophisticated. 

The case will now return to the First-tier Tribunal to be reconsidered in light of the Court of Appeal’s judgment. DSG could seek to appeal further, potentially taking the matter to the Supreme Court. For now, however, the ICO’s position has been vindicated. 

For consumers, that is good news: it reinforces that companies cannot sidestep responsibility for protecting your data simply because stolen information does not immediately include your name. 

This information is for general guidance only and does not constitute legal or financial advice.

Found this helpful? Share it

Facebook
Twitter
WhatsApp
LinkedIn
Email

Or

You may also like:

BMW faces legal action over emissions-cheating software. Learn what the scandal involves, who is affected, and what it means for UK diesel car owners.
Capita’s data breach exposed pension holders’ personal data. Stay updated on the latest legal action, investigations, and regulatory responses.
Confused about Jaguar Land Rover DPF claims vs. Dieselgate? Learn the key differences, legal actions, and how to check if you qualify for compensation.

Latest news & insights

Discover 10 essential facts about group litigation for first-time claimants. Learn how joining a group...
Delayed 3+ hours or had a cancelled flight? You could claim up to £520 under...
Massive UK collective actions could return billions to consumers, yet awareness remains low. Discover the...

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.