Case Study 16: Major Retailer - Credit card slips discarded [2012] IEDPC 16 (2012)

Case Study 16: Major Retailer - Credit card slips discarded [2012] IEDPC 16 (2012)

The retailer breached its data protection obligations by failing to securely dispose of credit card receipts, but mitigated the breach by cooperating with the regulator, recovering most receipts, and implementing improved procedures.

Citation
[2012] IEDPC 16
Parties
Data Controller: Major Retailer; Regulator: Irish Data Protection Commission
Jurisdiction
Ireland
Procedural Posture
Data Protection Investigation / Final Decision
Outcome
Breach found; remedial actions accepted
Legal Topics
Data Security Breach, Credit Card Data, Data Controller Obligations, Notification Procedures

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 2 Authorities cited 1 Party arguments 2 Amounts and remedies 3
Sign in to unlock

Parties

Major Retailer

Data Controller

Irish Data Protection Commission

Regulator

Procedural Posture

Data Protection Investigation / Final Decision

  1. 1 Whether the retailer failed to securely dispose of customer credit card receipts
  2. 2 Whether the retailer complied with data protection obligations after the breach

Ratio Decidendi

The retailer breached its data protection obligations by failing to securely dispose of credit card receipts, but mitigated the breach by cooperating with the regulator, recovering most receipts, and implementing improved procedures.

Court Disposition

Breach found; remedial actions accepted

Orders

  • Retailer to implement new data disposal procedures
  • Retailer to update data protection and disposal policies