DSG Retail Ltd v Information Commissioner [2026] EWCA Civ 140 (19 February 2025)

DSG Retail Ltd v Information Commissioner [2026] EWCA Civ 140 (19 February 2025)

The security duty under the Data Protection Act 1998 requires a data controller to take appropriate technical and organisational measures against unauthorised or unlawful processing of personal data, including by third parties, regardless of whether those third parties can identify the data subjects. The scope of 'personal data' for this duty is determined by identifiability to the data controller, not to third parties. This interpretation aligns with the statutory language, legislative purpose, and relevant EU law and case law.

Citation
[2026] EWCA Civ 140
Parties
Respondent/appellant: DSG Retail Limited; Appellant/respondent: The Information Commissioner
Jurisdiction
England and Wales
Judgment Date
19 February 2025
Procedural Posture
Appeal / Court of Appeal (civil Division) Judgment
Outcome
Appeal allowed
Legal Topics
Security Duty, Personal Data Definition, Data Controller Obligations, Interpretation of Data Protection Act 1998, Directive 95/46/ec, Appropriate Technical and Organisational Measures

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 5 Authorities cited 21 Party arguments 2 Amounts and remedies 4
Sign in to unlock

Parties

DSG Retail Limited

Respondent/appellant

The Information Commissioner

Appellant/respondent

Procedural Posture

Appeal / Court of Appeal (civil Division) Judgment

  1. 1 Does the security duty under the Data Protection Act 1998 require a data controller to take measures against unauthorised processing by third parties who cannot identify the data subjects?
  2. 2 Is the scope of 'personal data' for security duty purposes determined by identifiability to the data controller or to third parties?

Ratio Decidendi

The security duty under the Data Protection Act 1998 requires a data controller to take appropriate technical and organisational measures against unauthorised or unlawful processing of personal data, including by third parties, regardless of whether those third parties can identify the data subjects. The scope of 'personal data' for this duty is determined by identifiability to the data controller, not to third parties. This interpretation aligns with the statutory language, legislative purpose, and relevant EU law and case law.

Court Disposition

Appeal allowed

Orders

  • Case remitted to the First-tier Tribunal to be determined in accordance with this judgment