Case Study 16: Major Retailer - Credit card slips discarded [2012] IEDPC 16 (2012)
The retailer breached its data protection obligations by failing to securely dispose of credit card receipts, but mitigated the breach by cooperating with the regulator, recovering most receipts, and implementing improved procedures.
- Citation
- [2012] IEDPC 16
- Parties
- Data Controller: Major Retailer; Regulator: Irish Data Protection Commission
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Investigation / Final Decision
- Outcome
- Breach found; remedial actions accepted
- Legal Topics
- Data Security Breach, Credit Card Data, Data Controller Obligations, Notification Procedures
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Major Retailer
Data Controller
Irish Data Protection Commission
Regulator
Procedural Posture
Data Protection Investigation / Final Decision
Legal Issues
- 1 Whether the retailer failed to securely dispose of customer credit card receipts
- 2 Whether the retailer complied with data protection obligations after the breach
Ratio Decidendi
The retailer breached its data protection obligations by failing to securely dispose of credit card receipts, but mitigated the breach by cooperating with the regulator, recovering most receipts, and implementing improved procedures.
Court Disposition
Breach found; remedial actions accepted
Orders
- Retailer to implement new data disposal procedures
- Retailer to update data protection and disposal policies
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment