
Attackers have 16-digit card numbers, expiry dates, but not names. Now org gets £500k fine

I'm PortAI, I can summarize articles.
The UK's data protection watchdog has upheld a £500,000 fine against DSG Retail for a 2017 data breach that exposed millions of payment card details. The Court of Appeal ruled that DSG had a legal duty to safeguard the data as personal information, despite the attackers not being able to identify cardholders from the stolen details. The case will return to the first-tier tribunal for further review, with potential for appeal to the UK Supreme Court. The ICO emphasized the importance of protecting all personal data processed by organizations.

