DSG Retail Limited settles 7-year legal action with ICO for £200k
Published: 07/10/2026
| ICO
The Information Commission (ICO) has announced the conclusion of a seven-year legal battle with DSG Retail Limited, after the First-tier Tribunal approved an agreement between the parties, ending proceedings nine years after the initial incident.
The legal action began after the ICO issued a monetary penalty notice on 9 January 2020, following a major 2017 cyberattack that affected Currys PC World and Dixons Travel, in which more than 5.6 million payment cards were compromised after the company failed to complete step two of a critical 2014 Microsoft software patch. The personal data breach initially resulted in a maximum £500,000 penalty under the Data Protection Act 1998 (DPA98). Although the First-tier Tribunal previously upheld findings that DSG contravened data protection law by failing to maintain appropriate technical and organisational security measures, the case was subsequently remitted by the Court of Appeal (CoA). However, rather than pursue another protracted tribunal hearing, the parties agreed to settle, with DSG paying a reduced financial penalty of £200,000.
Beyond the financial settlement, Robert Bateman of the Privacy Partnership Podcast discusses the ruling's significance in a LinkedIn post.
As Bateman highlights, the proceedings address a critical legal question concerning the relativity of personal data. DSG argued that stolen card details did not constitute personal data in the hands of an attacker who lacked the means to identify the victims, a position the Upper Tribunal (UT) initially accepted. However, the CoA upheld the ICO's appeal, reversed the UT's decision, and drew directly on the Court of Justice of the European Union (CJEU) ruling in European Data Protection Supervisor (EDPS) v Single Resolution Board (SRB).
Delivering the judgment, Lord Justice Warby confirmed that a data controller's statutory obligations apply strictly to the personal data it holds and processes, irrespective of whether the compromised information ceases to be identifiable once in the hands of a third-party hacker.
The ruling establishes that organisations cannot outsource statutory liability when delegating IT security functions and underscores that protective duties extend beyond confidentiality, as encryption or pseudonymisation does not prevent attackers from maliciously deleting or encrypting records.
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.