Legal News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Legal Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
LegalNewsICO Wins Appeal over Data Protection Obligations in Currys Cyber Attack
ICO Wins Appeal over Data Protection Obligations in Currys Cyber Attack
GovTechLegalCybersecurity

ICO Wins Appeal over Data Protection Obligations in Currys Cyber Attack

•February 19, 2026
0
ComputerWeekly – DevOps
ComputerWeekly – DevOps•Feb 19, 2026

Why It Matters

The judgment clarifies data‑protection duties, forcing companies to apply robust security measures regardless of data identifiability, and signals tougher future ICO enforcement.

Key Takeaways

  • •ICO upheld £500k fine for Currys data breach
  • •Court ruled organisations must protect all personal data
  • •Interpretation applies even if data not directly identifiable
  • •Decision strengthens ICO’s future enforcement capabilities
  • •Businesses must implement robust technical and organisational measures

Pulse Analysis

The Currys Group breach, stemming from malware on point‑of‑sale devices between 2017 and 2018, exposed millions of credit‑card numbers and limited personal details. The ICO’s 2020 fine of £500,000 under the pre‑GDPR Data Protection Act highlighted gaps in the retailer’s security posture, including missing firewalls, unpatched software, and inadequate network segregation. While the breach pre‑dated GDPR, the case became a litmus test for how legacy data‑protection statutes apply to modern cyber threats, especially when stolen data is partially pseudonymised.

In a decisive Court of Appeal ruling, Lord Justice Warby affirmed that the seventh data‑protection principle obliges controllers to protect any personal data they process, irrespective of whether a third‑party can readily identify individuals. The judgment rejected DSG’s argument that EMV‑protected card details fell outside the scope of “appropriate technical and organisational measures.” By emphasizing a broader statutory construction, the court reinforced the ICO’s stance that pseudonymised or seemingly harmless data still warrants full protection, setting a precedent for future tribunals interpreting DPA obligations.

For the wider industry, the ruling sends a clear signal: compliance frameworks must treat all data as sensitive and implement comprehensive safeguards such as regular penetration testing, strict access controls, and continuous patch management. Companies can no longer rely on the perceived anonymity of encrypted or tokenised information to mitigate liability. As cyber‑crime escalates, regulators are likely to pursue more aggressive enforcement, making proactive data‑security investments not just best practice but a legal necessity. Organizations that adapt now will reduce exposure to fines, reputational damage, and costly remediation efforts.

ICO wins appeal over data protection obligations in Currys cyber attack

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...