Court declines to impose a general data security duty after cyber-hacking incident

  • Buckles
  • Posts
  • Blog
  • Court declines to impose a general data security duty after cyber-hacking incident
Data Protection and Privacy Group Buckles provides a broad range of data protection, privacy and related compliance advice to clients....
When your business is confronted with a commercial dispute – whether it involves a contractual issue, shareholder disagreement, or customer...

The High Court has rejected a claim for distress by an individual whose personal data was breached following a cyber-attack and has held that the law does not impose a separate data security duty on the holders of information. The case has wide ramifications, and is likely to significantly reduce the potential for claims to be brought by individuals whose data has been compromised by cyber-attacks.

DSG Retail Limited is a well-known retailer operating the “Currys PC World” and “Dixons Travel” brands. Between July 2017 and April 2018, it was the victim of a complex cyber-attack which installed malware on 5,390 point of sale terminals and, over a nine-month period, was able to obtain unauthorised access to around 5.6 million payment card details and the personal data of around 14 million customers. The captured data included names, contact numbers, postal addresses and email addresses.

Following an investigation by the Information Commissioner’s Office, multiple failures were identified in the way in which DSG kept its data secure. The ICO fined DSG £500,000 and, in response, DSG is currently in the process of appealing that decision.

A customer of DSG, Mr Warren, issued proceedings against DSG in the High Court claiming damages of £5,000 for distress he suffered as a result of his personal data being compromised and lost. The progression of this claim is being closely watched as, of course, if Mr Warren is successful then this could lead to the floodgates opening for other claims.

Mr Warren based his claim for distress on four causes of action (1) breach of confidence (2) misuse of private information (3) common law negligence and (4) breach of the Data Protection Act.

One reason why Mr Warren might have wanted to pursue a claim for breach of confidence or misuse of private information is because of the availability of After The Event (ATE) legal expenses insurance in such cases. ATE insurance allows a Claimant to pursue a case knowing that if they are unsuccessful, an insurance company will step in and pay their opponents costs. In most cases, Claimants cannot recover the costs of the ATE premium from their opponent, so they have to pay it themselves out of their damages. However, in cases relating to breach of confidence and misuse of private information, there is still the potential to have the ATE premium paid by your opponent.

The Court made the following findings:

  1. Breach of Confidence: Although there was a failure by DSG which allowed cyber-attackers to access individuals’ personal data, there was no positive conduct by DSG which amounted to a breach of confidence. DSG was the victim of the attack.
  2. Misuse of Private Information: Again, whilst there was a failure by DSG which allowed the cyber-attackers access to the private information, DSG did not itself misuse that information.
  3. Common Law Negligence: There is no separate duty of care imposed by the law over and above what is in the Data Protection legislation. In addition, Mr Warren suffered no loss; a state of anxiety was not sufficient to amount to damages.
  4. Breach of the Data Protection Act: The Seventh Data Protection Principle requires “appropriate technical and organisational measures to be taken against unauthorised or unlawful processing of data”. Mr Warren might still have a claim against DSG for its breach of statutory duty, but that claim would be stayed pending DSG’s appeal of the ICO decision.

The dismissal of the claims relating to breach of confidence, misuse of confidential information and common law negligence is good news for data controllers, and is likely to mean a reduction in cases brought by individuals as a result of cyber-hacking. As well as the causes of action being limited to breaches of the Data Protection Act, the findings stop Claimants recovering ATE premiums and may discourage claims being brought in the first place.

Recent News

Ready to speak to a specialist?

Speak to any one of our lawyers from across Europe about your needs and specific requirements.