Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DSG Retail—known in contemporary coverage as Dixons Carphone—was fined £500,000 by the UK Information Commissioner’s Office (ICO) in January 2020 after malware was installed on 5,390 tills in Currys PC World and Dixons Travel stores. Reporting at the time said personal information relating to about 14 million people was exposed, while payment-card details relating to 5.6 million people were affected. In February 2026, the Court of Appeal ruled on the scope of the security duty and sent the case back to the First-tier Tribunal; it did not decide whether DSG’s security measures were adequate or whether the fine was appropriate.

What happened in the DSG Retail breach?

Attackers installed malware on 5,390 tills in Currys PC World and Dixons Travel stores. The malware went undetected for about nine months, from July 2017 to April 2018, according to The Guardian’s January 2020 account.

The figures reported at the time describe two different sets of information. Personal information relating to approximately 14 million people was exposed; payment-card details related to 5.6 million people. The personal information included full names, postcodes, email addresses and details of failed credit checks. The figures should not be combined: the larger number refers to personal information, not payment-card details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did the ICO fine DSG Retail?

In January 2020, the ICO imposed a £500,000 penalty on DSG Retail, the company commonly referred to as Dixons Carphone in contemporaneous coverage. The regulator cited poor security arrangements and inadequate steps to protect personal data. Contemporary reports described £500,000 as the maximum fine available under the Data Protection Act 1998, the legislation relevant to the incident period before GDPR enforcement began. See the Sky News report and CyberScoop’s explanation of the pre-GDPR penalty context.

Then-ICO director of investigations Steve Eckersley said: “The contraventions in this case were so serious that we imposed the maximum penalty under the previous legislation, but the fine would inevitably have been much higher under the GDPR.” That statement describes the ICO’s view of the available penalty framework; the £500,000 was imposed under the earlier law.

What did the company say about the breach?

DSG’s then chief executive, Alex Baldock, said the company disputed some of the ICO’s findings, had invested in information security and had no confirmed evidence of customers suffering fraud or financial loss as a result, as reported by The Guardian. The absence of confirmed fraud in that company statement does not establish that the exposure carried no risk.

What did the Court of Appeal decide in 2026?

On 19 February 2026, the Court of Appeal handed down DSG Retail Ltd v The Information Commissioner, [2026] EWCA Civ 140. It allowed the ICO’s appeal on a legal question: whether the security duty can apply when data can identify people in the controller’s hands, even if a third party that obtained the data cannot identify them from it. The court remitted the case to the First-tier Tribunal. The judgment is available from the Court of Appeal.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The court described the duty as protective rather than a guarantee of a particular outcome. Lord Justice Warby wrote: “This is a protective duty, to take proportionate steps to guard against risk, not to guarantee a particular outcome.”

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unresolved after the appeal?

The Court of Appeal’s decision did not determine whether DSG’s actual security measures were appropriate, whether any breach was serious enough to merit a monetary penalty, or whether the original penalty was appropriate. Those questions were not finally resolved by the appellate ruling; the case was sent back to the First-tier Tribunal. The sources cited here establish the remittal but do not establish whether the tribunal has issued a subsequent decision.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.