News: 1628073009

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Sueball over breach of more than 5 million payment cards at Dixons Carphone hit for six

(2021/08/04)


A Brit who tried to sue Dixons Carphone over the 2018 hack of 10 million customers' details, including 5.9 million payment cards, has had his case booted out of the High Court.

Not only was Cardix owner DSG Retail Ltd almost completely successful in its application to strike out Darren Warren's case against it, the one count Dixons didn't succeed on saw the case relegated to the county court because of its low value.

Warren wanted to sue the retailer over a [1]digital break-in that saw nearly 6,000 point-of-sale terminals infected with malware. DSG discovered the data-slurping malware almost a year after it was planted, [2]prompting a £500,000 fine from the Information Commissioner's Office.

[3]

He was caught up in that, he told the court, and wanted £5,000 in damages from DSG for "distress" after his personal data was obtained by criminals.

[4]

[5]

In total 5,646,417 payment cards were exposed to the crooks who compromised DSG, including 5,529,349 chip-and-PIN cards that showed the primary account number and expiry date. Names, addresses, phone numbers, email addresses, dates of birth, and more were also exposed.

It must have come as a surprise to Warren, therefore, when Mr Justice Saini ruled: "If a burglar enters my home through an open window (carelessly left open by me) and steals my son's bank statements, it makes little sense to describe this as a 'misuse of private information' by me."

[6]Lockdown-induced gadgetry rush sent Dixons Carphone's online sales skywards – and repaid £73m of furlough wages

[7]33 'unsustainably loss-making' Dixons Travel outlets set to be shuttered affecting 400 staff

[8]What a difference 6 months makes: UK retailer Dixons Carphone returns to profitability on the back of high online sales

[9]Brit mobile network EE follows O2 by ending trading relations with retailer Dixons Carphone

Warren's legal team had argued that DSG was liable for two civil wrongs: misuse of private information (MPI) and breach of confidence (BOC). Failing to properly secure its servers against intrusion was enough to see the company fined for breaching the Data Protection Act 1998 – but cut little ice with the High Court.

Branding the case against DSG "unconvincing," the judge ruled that Warren's arguments that MPI and BOC applied to the retailer simply wouldn't work. BOC, he said in his [10]written ruling , meant an "obligation not to disclose confidential information." This is different from merely being crap at security: BOC requires the defendant to actively disclose the confidential thing to a third party. As Mr Justice Saini said: "Here, it was not DSG that disclosed the Claimant's personal data, or misused it, but the criminal third-party hackers."

[11]

MPI wouldn't fit the legal bill either, in the judge's words:

I accept that a 'misuse' may include unintentional use, but it still requires a 'use': that is, a positive action. In the language of Article 8 ECHR (the basis for the MPI tort), there must be an 'interference' by the defendant, which falls to be justified. I have not overlooked the Claimant's argument that the conduct of DSG was "tantamount to publication". Although it was attractively presented, I do not find it persuasive.

Warren's case had the potential, if the judge accepted it, to create a new method for aggrieved people to sue companies that suffered breaches which exposed their data. Mr Justice Saini wasn't prepared to do that, however, saying: "In my judgment, there is no room (nor indeed any need identified) to construct a concurrent duty in negligence when there exists a bespoke statutory regime for determining the liability of data controllers. That regime provides for relief of precisely the same nature as is claimed in negligence in this claim."

Warren's case was struck out except for one claim for breach of statutory duty under the seventh data protection principle, which [12]says data ought to be protected against "unauthorised or unlawful processing." That claim will be transferred to the county court. ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2018/07/31/dixons_carphone_breach_10m_records/

[2] https://www.theregister.com/2020/01/09/dixons_store_group_fined_500000_by_ico_for_crap_security_that_exposed_56_millino_customers_payment_cards/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQq5t4S4iJ2ZVLZAlfAZygAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQq5t4S4iJ2ZVLZAlfAZygAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQq5t4S4iJ2ZVLZAlfAZygAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/06/30/dixons_carphone_full_year/

[7] https://www.theregister.com/2021/04/28/dixons_travel_closure/

[8] https://www.theregister.com/2020/12/16/dixons_carphone_returns_to_profitability/

[9] https://www.theregister.com/2020/09/14/ee_ends_trading_agreement_dixons_carphone/

[10] https://www.bailii.org/ew/cases/EWHC/QB/2021/2168.html

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQq5t4S4iJ2ZVLZAlfAZygAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/

[13] https://whitepapers.theregister.com/



Home Page Image

wjake

That's a baseball, not a cricket ball!

Unfortunately...

Mike 137

Sadly, that seems to be an impeccable judgement according to current law, given the bases for the action. However Article 82 of the GDPR provides for judicial remedy and compensation for " material or non-material damage as a result of an infringement of this Regulation ", so maybe Warren just made the wrong choice of cause.

Re: Unfortunately...

macjules

+1 since you beat me to it.

Makes Cash Payments Sound Superior

Richard Jones 1

At least with cash, there is nothing for a crook to hold against the unfortunate customer. Only the careless merchant suffers, which in the case of DSG makes it something of a rare case. Usually, it is the customer who suffers after dealing with them.

Big costs implications

sictransit

Significant because “misuse of private information” and “breach of confidence” claims can be covered by after-the-event insurance for legal costs, but a pure data protection claim is not similarly insurable, exposing claimants to defendants’ potentially huge costs (as well as their own) if they lose. [1]https://panopticonblog.com/2021/07/30/important-new-high-court-judgment-on-data-breach-litigation/ So narrowing the scope like this strongly deters speculative claims.

[1] https://panopticonblog.com/2021/07/30/important-new-high-court-judgment-on-data-breach-litigation/

Although I understand the judge's judgement . .

Pascal Monett

. . and I accept that said judgement was made with respect to the law, I still find myself frustrated that a multi-million data breach from a company raking in almost £5B results in punishment that represents barely a pitiful 1 hour of annual revenue.

Come on ! If the fines do not become significant, nobody will make the effort to secure properly !

Here I am at the flea market but nobody is buying my urine sample bottles ...