Security Duty Under DPA 1998: Controllers Must Safeguard Personal Data Against Unauthorised/Unlawful Third-Party Processing Even Where the Third Party Cannot Identify Data Subjects

Case: DSG Retail Ltd v Information Commissioner Citation: [2026] EWCA Civ 140
Court: England and Wales Court of Appeal (Civil Division)  |  Date: 19 February 2025

1. Introduction

This appeal concerned the scope of the data security obligation (the “security duty”) imposed on data controllers to take “appropriate technical and organisational measures” (“ATOMs”) to protect personal data. Although modern equivalents sit in Articles 5(1)(f) and 32 GDPR/UK GDPR, the relevant legal framework here was the Data Protection Act 1998 (“1998 Act”), implementing Directive 95/46/EC (“the Directive”), and specifically the seventh data protection principle (DPP7).

The factual backdrop was a 2017–2018 cyber-attack on DSG’s point-of-sale environment. Attackers “scraped” payment card transaction data. In the great majority of cases they obtained only the card number (PAN) and expiry date (the “EMV data”), without cardholder names or other direct identifiers, and (for the purpose of the legal issue) the attackers could not identify the individual cardholders. The Information Commissioner issued a monetary penalty notice (MPN). DSG’s core argument on this issue was that DPP7 did not require ATOMs against acquisition of EMV data because (on the attacker’s side) it would not be “personal data”.

The First-tier Tribunal (FtT) rejected DSG’s contention. The Upper Tribunal (UT) accepted it, holding that the DPP7 risk must be assessed from the third party’s perspective: if the third party cannot identify individuals, the data are not “personal data in their hands”, and thus the controller need not protect against that acquisition as “unauthorised or unlawful processing of personal data”.

The Court of Appeal allowed the Commissioner’s appeal, holding that the UT’s “third-party perspective” limitation was legally wrong and unduly narrow.

Key legal issue

Whether DPP7 requires a controller to take ATOMs against unauthorised or unlawful processing by a third party where the data are personal data to the controller, but (on the assumed facts) not personal data to the third party because the third party cannot identify the data subjects.

2. Summary of the Judgment

  • Appeal allowed. The Court held that DPP7 does require controllers to safeguard personal data (as defined by reference to the controller’s ability to identify the data subject) against unauthorised/unlawful processing by third parties, even if the third party cannot identify individuals.
  • Perspective for “personal data” under DPP7: If the data are personal data from the controller’s perspective (notably where individuals are indirectly identifiable to the controller), it is unnecessary to ask whether the data are personal data “in the hands” of the attacker/recipient for DPP7’s engagement.
  • Statutory construction: The Court found the broader reading better aligned with (i) the language of ss 1 and 4(4) of the 1998 Act and DPP7, (ii) the Directive’s aims and structure, (iii) practical consequences, and (iv) relevant domestic/EU authorities.
  • Remittal: The case was remitted to the FtT for determination in accordance with the Court of Appeal’s construction (the Court did not decide whether DSG’s measures were “appropriate”, nor the appropriateness of the MPN amount).

3. Analysis

3.1 Precedents Cited

A. Interpretation and EU-consistent construction

  • Vidal-Hall v Google Inc [2015] EWCA Civ 311, [2016] QB 1003
    Influence: Cited for the duty to interpret and apply the 1998 Act compatibly with the Directive. This underpinned the Court’s willingness to read the domestic scheme through the Directive’s purposes and wording (including Recital (26) and Article 17(1)).
  • Farley v Paymaster (1836) Ltd t/a Equiniti [2025] EWCA Civ 1117
    Influence: Cited for the post-IP Completion Day approach: binding effect of pre-IP Completion Day CJEU decisions and the ability to “have regard” to later CJEU decisions. This mattered because the Court considered Gesamtverband Autoteile-Handel EV v Scania CV AB ("Scania") and the later CJEU decision in Single Resolution Board v European Data Protection Supervisor ("SRB v EDPS").
  • R v Secretary of State for the Environment, Transport and the Regions ex p Spath Holme Ltd [2001] AC 349, R (O) v Secretary of State for the Home Department [2022] UKSC 3, [2023] AC 255, R v Luckhurst [2022] UKSC 23, [2022] 1 WLR 3818, Fry v Inland Revenue Commissioners [1959] Ch 86
    Influence: These were deployed as the interpretative toolkit: objective legislative intention from statutory language; context and purpose; and the relevance of consequences of competing constructions. They supported the Court’s critique of the UT’s narrow reading, particularly its “surprising” and policy-incongruent outcomes.

B. “Personal data” and anonymisation in the FOI context

  • Common Services Agency v Scottish Information Commissioner [2008] UKHL 47, [2008] 1 WLR 1550 ("CSA")
    Influence: Binding authority but distinguished. The UT had treated FOI/anonymisation jurisprudence as supporting a “recipient perspective” approach. The Court of Appeal held CSA concerned a different problem: whether data rendered anonymous before public disclosure cease to be “personal data” such that disclosure would not engage the 1998 Act principles. It did not answer the DPP7 security-duty question where (as assumed here) data remain personal data to the controller throughout.
  • APPGER v Information Commissioner [2011] UKUT 153 (AAC) ("APPGER"), R (Department for Health) v Information Commissioner [2011] EWHC 1430 (Admin) ("DoH"), Information Commissioner v Miller [2018] UKUT 229 (AAC) ("Miller")
    Influence: These authorities were discussed as part of the FOI “personal data” exemption line following CSA. The Court’s essential point was not to deny their relevance in FOI disclosure questions, but to reject the UT’s extrapolation from FOI disclosure/anonymisation to the distinct architecture and purpose of DPP7 (a protective safeguarding duty within the controller–data subject relationship).

C. EU “perspective” cases: identifiability depends on context

  • Gesamtverband Autoleile-Handel EV v Scania CV AB ("Scania") (C-319/22, [2024] 2 CMLR 40)
    Influence: Used to show that data “in themselves” impersonal may become personal depending on who has means “reasonably likely” to identify individuals. The Court treated Scania as demonstrating the Directive/GDPR’s broad conception of “personal data”, and noted the CJEU’s formulation that data may be personal “for” the recipient and “indirectly” for the discloser/controller when put at the disposal of those with identification means. Importantly, Scania did not support narrowing DPP7 by requiring third-party identifiability as a precondition for the controller’s security duty.
  • Single Resolution Board v European Data Protection Supervisor ("SRB v EDPS") (GCEU: Case T-557/20, [2024] 2 CMLR 46; CJEU appeal allowed: C-413/23, judgment 4 September 2025)
    Influence: Central to correcting the UT’s approach. The UT relied on the GCEU’s “put oneself in the recipient’s position” reasoning. The Court of Appeal noted that the CJEU later undermined that as a general proposition: the relevant perspective depends on the specific duty and processing context. For the transparency duty, the CJEU held identifiability is assessed at collection and from the controller’s perspective because the duty is part of the controller–data subject relationship. The Court of Appeal used this to support the analogous conclusion for DPP7: it too is an incident of that legal relationship; thus, if data are personal to the controller, DPP7 is engaged without asking if they are personal to the attacker.

D. Cyber-risk judicial notice and examples

  • Clarkson plc v Persons Unknown [2018] EWHC 417 (QB), University College Union v Persons Unknown [2025] EWHC 192 (KB)
    Influence: Not cited as data protection authorities but as illustrations of the notoriety and prevalence of hacking/blackmail/ransomware. They supported the Court’s reasoning that harm to data subjects from malicious interference (encryption, deletion, exfiltration) does not depend on the attacker’s ability to identify individuals.

3.2 Legal Reasoning

A. The statutory architecture points to a controller-focused duty

The Court’s reasoning begins with the 1998 Act’s internal structure:

  • Section 4(4) imposes an unqualified duty on a data controller to comply with the data protection principles “in relation to all personal data” for which it is the controller.
  • Section 1(1) defines “personal data” (relevantly) as data relating to an individual identifiable (a) from the data, or (b) from the data plus other information in the possession of (or likely to come into the possession of) the data controller.
  • DPP7 then requires ATOMs “against unauthorised or unlawful processing of personal data” and against accidental loss/destruction/damage.

From this, the Court derived a straightforward construction: once data qualify as “personal data” by the statutory test (including indirect identifiability by the controller under s 1(1)(b)), DPP7 attaches to those data. Nothing in DPP7’s text indicates that “personal data” should be re-defined by reference to what an attacker can identify. To adopt the UT’s approach would require the same statutory term (“personal data”) to take a narrower, situational meaning in DPP7 than its defined meaning in s 1(1) and its use in s 4(4), without textual warrant.

B. The Directive expands (not contracts) protection

The Court accepted that the Directive’s Recital (26) and Article 2 define “personal data” more broadly than the 1998 Act’s phrasing (notably by considering means “likely reasonably to be used” by the controller or any other person). However, that broader EU definition logically pushes toward expanding the scope of the security duty, not narrowing it. The Court found nothing in Recital (46) or Article 17(1) that supports DSG’s “third party must be able to identify” limitation.

C. Purpose and “entrustment” logic: security is part of the controller–data subject relationship

A core strand is purposive coherence: data subjects provide/entrust data to controllers within a regulated framework (including the first and second principles and associated “fair processing notices”). DPP7 is an obligation owed by the controller to the data subject to safeguard what has been entrusted, not merely a duty to prevent third parties from learning named identities.

D. The UT’s approach produces “surprising” gaps and misaligns with real-world harms

The Court treated consequences as a legitimate interpretative indicator. On the UT’s reading, a controller could owe no DPP7 obligation to guard against malicious third-party actions affecting confidentiality, integrity, or availability (e.g., extraction, deletion, ransomware encryption) where the attacker cannot identify individuals. The Court rejected the implicit premise that such events are harmless absent identification, noting that material and non-material harms can arise regardless (service disruption, denial of access, fraud risks, distress, blackmail dynamics, and loss of control).

E. Authority does not compel the UT’s “recipient perspective” for DPP7

The Court carefully separated contexts:

  • CSA (and FOI cases) concern whether a deliberately anonymised dataset can be disclosed without engaging the data protection principles—an outcome-driven, disclosure-specific context, anchored to Recital (26)’s anonymisation proviso.
  • SRB v EDPS (CJEU) establishes that “perspective” is context-sensitive; for duties integral to the controller–data subject relationship (there, transparency at collection), identifiability is assessed from the controller’s viewpoint. The Court extended that logic to DPP7.

3.3 Impact

A. Immediate doctrinal effect (DPA 1998 / legacy cases)

The Court’s key doctrinal holding is that DPP7 is engaged where data are “personal data” to the controller. The controller must take proportionate ATOMs against unauthorised/unlawful processing by third parties even if those third parties cannot identify data subjects. This removes the UT’s proposed “identifiability-by-attacker” threshold and restores a broader regulatory perimeter under the 1998 Act.

B. Practical significance for cyber incidents and enforcement

Although decided in the DPA 1998 framework, the reasoning strongly resonates with modern security governance:

  • Risk models: Organisations cannot treat “pseudonymous/partial” datasets as outside security duties merely because attackers cannot immediately name individuals.
  • Regulatory reach: The Commissioner’s ability to take action is not confined to breaches enabling identification-by-attacker; it extends to failures exposing controller-personal data to hostile processing affecting confidentiality, integrity, or availability.
  • Security by design: The decision reinforces that the security duty is protective and proportionate (risk-based), not outcome-guaranteeing—controllers must assess and address foreseeable risks, including modern “jigsaw” re-identification and downstream combination risks.

C. Likely influence beyond DPA 1998

The Court expressly noted the modern equivalent duties under GDPR/UK GDPR. While not formally deciding GDPR/UK GDPR issues, the judgment’s logic (relationship-based duties; context-sensitive “perspective”; harm not limited to identifiability) is likely to be persuasive in interpreting and applying contemporary security obligations—especially where controllers argue that compromised data were “not personal to attackers”.

4. Complex Concepts Simplified

  • Security duty / safeguarding duty: A duty to take proportionate steps (ATOMs) to protect personal data against specified risks. It is not a promise that no breach will ever occur.
  • ATOMs (“appropriate technical and organisational measures”): Practical security controls (technical and managerial) calibrated to technology, cost, the nature of data, and the harms/risks (Schedule 1 Part II paragraph 9).
  • “Personal data” under s 1(1) DPA 1998:
    • Direct identifiability: you can identify the person from the data alone.
    • Indirect identifiability: you can identify the person by combining the data with other information held by (or likely to come to) the controller.
  • “Personal data in the hands of a third party”: A shorthand used below that suggests data cease to be personal if the recipient cannot identify anyone. The Court held this is not the correct gating concept for DPP7’s application.
  • Anonymisation vs pseudonymisation:
    • Anonymised data: rendered so that individuals are no longer identifiable (CSA context).
    • Pseudonymised data: identifiers are replaced/segregated, but individuals can still be re-identified with a “key” or additional information.
  • “Jigsaw identification”: Re-identifying individuals by combining multiple datasets or fragments, increasingly feasible with modern data availability and automation (a reason the Court viewed the UT’s line-drawing as impractical).

5. Conclusion

The Court of Appeal established a clear principle for the DPA 1998 security duty: if data are personal data from the controller’s perspective, the controller must take appropriate security measures against unauthorised/unlawful third-party processing even if the third party cannot identify the individuals. In doing so, the Court rejected the UT’s “third-party perspective” limitation, distinguished FOI anonymisation jurisprudence (CSA line) as context-specific, and drew support from the CJEU’s context-sensitive approach in SRB v EDPS. The judgment strengthens the protective, risk-based character of data security obligations and avoids a significant enforcement and protection gap in cases of modern cyber-attacks.