UK Court of Appeal Ruling on DSG Retail's Data Security Responsibilities

UK Court of Appeal Ruling on DSG Retail's Data Security Responsibilities

First seen 27 Feb 2026, 13:11 UTC DatabreachesBurges-Salmon 26.3

Article Content

Browse articles
ThreatCluster

On February 19, 2026, the UK Court of Appeal ruled in the case of DSG Retail Limited v The Information Commissioner, clarifying that a data controller's security obligations extend to all personal data it manages. This decision comes in the context of a cyber attack on DSG's point-of-sale systems that occurred between 2017 and 2018, affecting the company's data security practices.

Timeline

2017-01-01
Cyber attack on DSG Retail's point-of-sale systems began
2018-12-31
Cyber attack on DSG Retail's point-of-sale systems ended
2026-02-19
UK Court of Appeal ruling issued