“110. (m)…notwithstanding the complexity of the DSG IT domain and the challenges described of rolling out security patches across the entire estate, the approach within DSG to software patching and to the management of passwords/domain administrator password accounts amounted to a failure to take appropriate technical and organisational measures against the unauthorised or unlawful processing of personal data…..Further, and in the absence of evidence of any risk assessment, we are satisfied that any decision made by DSG in relation to adopting appropriate technical and organisational measures in this regard ought not to be viewed as an exercise of judgement of the nature anticipated in Morrisons, whether or not that decision was taken positively or default. We are satisfied that DSG’s failure to take appropriate measures in relation to this risk was a contravention of DPP7 for which it is appropriate to hold DSG to account. (n) When reaching this conclusion, we have approached any evidence of use by the Attackers of the vulnerability created by the contravention as being solely confirmation of the potential risks. We are satisfied from the evidence before us that the Attackers were sophisticated criminals and that their ability to gain access to DSG’s domain should not be taken as an indication that DPP7 obligations cannot have been met.”
“111…. a. The fact that the personal data of approximately 25 million individuals were stored on DSG’s IT system at the relevant time; b. The nature of this personal data, which comprised names, postal addresses, email addresses, dates of birth, and credit check information, as well as an unknown quantity of PAN capable of being used to indirectly identify a living individual, and c. The reasonable expectation of individuals and society that a body of personal data of this nature would be adequately protected, given the potential consequences of unauthorised or unlawful processing.”
“113. In contrast to the approach taken in the MPN, we are not persuaded that the most significant risk arising from contravention was that of the fraudulent use of payment cards. We note from expert evidence that the use of PAN and expiry date alone provides only limited opportunity for unauthorised use. This appears to be reflected in the limited extent to which such data may have been used by the Attackers in this case. However, we find it more likely than not that individuals, whether customers or employees, who became aware that their names, dates of birth, addresses and email addresses had been accessed by a sophisticated criminal group would be caused substantial distress. As previously stated, we find in addition that, in relation to an unknown number of individuals, these records of personal data could potentially be linked to their payment card PAN, a circumstance we are satisfied is likely to compound feelings of distress. We therefore conclude that the personal data in relation to which this contravention occurred was of a kind likely to cause substantial distress both qualitatively and quantitatively.”
“120. We note again that the identified contravention is serious for reasons already given relating to the nature and volume of data processed by DSG and the number of individuals whose data was put at risk. 121. We are not persuaded that the number of PAN accessed by the Attackers is an additional, relevant consideration for the purpose of identifying the quantum of any MPN imposed in this context. As previously stated, we have concluded that the exact number of PAN meeting the definition of personal data remains unknown. Rather, we consider the overall volume of personal data, both financial and non-financial, which is known to have been unlawfully processed to be a more relevant consideration.”
“I give the DSG Retail Limited permission to appeal. The grant of permission to appeal is limited to grounds one and three as identified and explained below.”
“Permission to appeal is given because I consider that it is arguable with a realistic prospect of success that First-tier Tribunal erred in law in the decision it made on5 July 2022 on the grounds set out below. These are grounds one and three (but as identified and explained below – see, for example, paragraphs 23 and 37 below).[…]”
“22. …I have concluded that DSG’s argument here is not unarguable. I therefore give permission to appeal on ground 1. The ground should be the subject of full(er) argument and would benefit from a binding decision of the Upper Tribunal on an appeal. 23. Ground 1 also has a sub-ground within it or associated with it, on which I give DSG permission to appeal as well. The argument here, as I understood it, is that even if the First-tier Tribunal was right as a matter of law about in whose hands the information must constitute personal data for the purposes of the DPA 1998, the late basis on which it did so meant that DSG was not in a position to properly address this case against it…It appears conceded by the Information Commissioner that at no stage in the First-tier Tribunal proceedings was he arguing for the approach the First-tier Tribunal settled on in its decision in relation to the PANs. 24. DSG’s argument under this associated aspect of ground 1 is that it had no, or no sufficient opportunity to put before the First-tier Tribunal (a) evidence about the systems it had in place at the time of the attack to protect the PANs alone from exfiltration, and/or (b)…evidence about the other information it held which when linked to the PAN could identify a living individual, and how that other information was protected.” [Emphasis in the original.]
“12. I plainly intended to give permission to appeal on the ‘issue of principle’ (and on Ground 1(b)). Whether the first ground of appeal was otherwise limited to that ‘issue of principle’ (and Ground 1(b)) may, trying to read the grant of permission as objectively as I can, require the word “here”…to do some heavy lifting. 13. Second, the grant of permission of appeal, save for the words “as identified and explained below” did not expressly limit the grant of permission to appeal under the first ground of appeal and did not expressly exclude sub-paragraphs (3) and (4) of paragraph 19 in DSG’s grounds of appeal. 14. Third, the arguments which fall properly within the scope of the grant of permission to appeal in respect of the first ground of appeal cannot involve arguments for which permission has been refused under the second, fourth, fifth and sixth grounds of appeal.” [Emphasis in the original.]
“ … It has also been recognised that a generous interpretation ought to be given to a tribunal’s reasoning. It is to be expected, of course, that the decision will set out the facts. That is the raw material on which any review of its decision must be based. But the quality which is to be expected of its reasoning is not that to be expected of a High Court judge. Its reasoning ought to be explained, but the circumstances in which a tribunal works should be respected. The reasoning ought not to be subjected to an unduly critical analysis.” 65. The reasons of the tribunal below must be considered as a whole. Furthermore, the appellate court should not limit itself to what is explicitly shown on the face of the decision; it should also have regard to that which is implicit in the decision. R v Immigration Appeal Tribunal, ex parte Khan[1983] QB 790 (per Lord Lane CJ at page 794) was cited by Floyd LJ in UT (Sri Lanka) v SSHD[2019] EWCA Civ 1095 at [27] as explaining that the issues which a tribunal decides and the basis on which the tribunal reaches its decision may be set out directly or by inference.” “ … It has also been recognised that a generous interpretation ought to be given to a tribunal’s reasoning. It is to be expected, of course, that the decision will set out the facts. That is the raw material on which any review of its decision must be based. But the quality which is to be expected of its reasoning is not that to be expected of a High Court judge. Its reasoning ought to be explained, but the circumstances in which a tribunal works should be respected. The reasoning ought not to be subjected to an unduly critical analysis.”
“if there is ambiguity arising from the language of the Reasons given then […] such ambiguity is to be resolved in favour of the applicant: particularly where the opening part of the Order concerning the actual grant of permission was unqualified”
“In the present case the apparently unqualified grant of permission to appeal must be read in the context of the reasons which Judge Spencer gave for his decision, which make it quite clear that he intended to limit it to the ground that he had identified based onsection 47 of the Immigration, Asylum and Nationality Act 2006 .”
“… it shall be the duty of a data controller to comply with the data protection principles in relation to all personal data with respect to which he is the data controller”
“Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.”
“55A Power of Commissioner to impose monetary penalty (1) The Commissioner may serve a data controller with a monetary penalty notice if the Commissioner is satisfied that— (a) there has been a serious contravention of section 4(4) by the data controller, (b) the contravention was of a kind likely to cause substantial damage or substantial distress, and (c) subsection (2) or (3) applies. (2) This subsection applies if the contravention was deliberate. (3) This subsection applies if the data controller— (a) knew or ought to have known— (i) that there was a risk that the contravention would occur, and (ii) that such a contravention would be of a kind likely to cause substantial damage or substantial distress, but (b) failed to take reasonable steps to prevent the contravention. … (4) A monetary penalty notice is a notice requiring the data controller to pay to the Commissioner a monetary penalty of an amount determined by the Commissioner and specified in the notice. (5) The amount determined by the Commissioner must not exceed the prescribed amount. (6) The monetary penalty must be paid to the Commissioner within the period specified in the notice. (7) The notice must contain such information as may be prescribed.”
“Limb (i): data which identifies a living individual directly; Limb (ii): Data which identifies a living individual indirectly when combined with other information in the possession of (or likely reasonably to be in the possession of) the data controller; and Limb (iii): As limb (ii), but where the additional information is or is likely reasonably to be in the possession of a third party.”
“Whereas the principles of protection must apply to any information concerning an identified or identifiable person; whereas, to determine whether a person is identifiable, account should be taken of all the means likely reasonably to be used either by the controller or by any other person to identify the said person; whereas the principles of protection shall not apply to data rendered anonymous in such a way that the data subject is no longer identifiable; …”
“’personal data’ shall mean any information relating to an identified or identifiable natural person (‘data subject’); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;”
“The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments. The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.”
“A specific pitfall is to consider pseudonymised data to be equivalent to anonymised data. The Technical Analysis section will explain that pseudonymised data cannot be equated to anonymised information as they continue to allow an individual data subject to be singled out and linkable across different data sets. Pseudonymity is likely to allow for identifiability, and therefore stays inside the scope of the legal regime of data protection.”
“10. The correct approach to the application of section 1(1)(b) to disclosure of anonymised data was addressed by the House of Lords in Common Services Agency v Scottish Information Commissioner[2008] 1 WLR 1550 . That decision was discussed by the Administrative Court in R (Department of Health) v Information Commissioner [2011] EWHC1430 (Admin). Cranston J explained that the House of Lords had decided that, even though the data controller holds the key to identification of individuals to which the data relates, whether it is personal information when disclosed depends on “whether any living individuals can be identified by the public following disclosure of the information” (paragraph 52). In Information Commissioner v Magherafelt District Council [2013] AACR 14 the Upper Tribunal said that the decision in Department of Health meant that the proper approach to whether anonymised information is personal data within section 1(1)(b), for the purposes of a disclosure request, is to consider whether an individual or individuals could be identified from it and other information which is in the possession of, or likely to come into the possession of a person other than the data controller after disclosure. 11. In the Department of Health case Cranston J said at paragraph 66 that the assessment of the likelihood of identification included “assessing a range of every day factors, such as the likelihood that particular groups, such as campaigners, and the press, will seek out information of identity and the types of other information, already in the public domain, which could inform the search.” 12. As for the likelihood of identification, Recital 26 of the preamble to the Directive provides that “account should be taken of all the means likely reasonably to be used”
“37 …A ‘motivated intruder’ was ‘…a person who starts without any prior knowledge but who wishes to identify the individual or individuals referred to in the purportedly anonymised information and will take all reasonable steps to do so.’. The question was then one of assessment by a public authority as to ‘… whether, taking account of the nature of the information, there would be likely to be a motivated intruder within the public at large who would be able to identify the individuals to whom the disclosed information relates.” 13. While not expressly adopting that test, the approach of the Upper Tribunal in that case was consistent with it. A similar approach was taken by the Court of Session (Inner House) in Craigdale Housing Association v The Scottish Information Commissioner[2010] CSIH 43 at paragraph 24: “…it is not just the means reasonably likely to be used by the ordinary man on the street to identify a person, but also the means which are likely to be used by a determined person with a particular reason to want to identify the individual…using the touchstone of, say, an investigative journalist…” 14. The Information Commissioner’s Code of Practice on “Anonymisation: managing data protection risk” provides guidance at page 22/23 on the application of the “motivated intruder” test: “The approach assumes that the ‘motivated intruder’ is reasonably competent, has access to resources such as the internet, libraries, and all public documents, and would employ investigative techniques such as making enquiries of people who may have additional knowledge of the identity of the data subject or advertising for anyone with information to come forward. The ‘motivated intruder’ is not assumed to have any specialist knowledge such as computer hacking skills, or to have access to specialist equipment or to resort to criminality such as burglary, to gain access to data that is kept securely.” 15. The guidance also addresses the risk of re-identification where one individual or group of individuals already knows a great deal about another individual, such as a family member, colleague or doctor, and says at page 26: “The starting point for assessing re-identification risk should be recorded information and established fact. It is easier to establish that particular recorded information is available, than to establish that an individual – or group of individuals - has the knowledge necessary to allow re-identification. However, there is no doubt that non-recorded personal knowledge, in combination with anonymised data, can lead to identification. It can be harder though to substantiate or argue convincingly. There must be a plausible and reasonable basis for non-recorded personal knowledge to be considered to present a significant re-identification risk.” (my emphasis) 16. The guidance also distinguishes between identification and an educated guess: “[Identification] implies a degree of certainty that information is about one person and not another. Identification involves more than making an educated guess that information is about someone; the guess could be wrong. The possibility of making an educated guess about an individual’s identity may present a privacy risk but not a data protection one because no personal data has been disclosed to the guesser. Even where a guess based on anonymised data turns out to be correct, this does not mean that a disclosure of personal data has taken place.” “37 …A ‘motivated intruder’ was ‘…a person who starts without any prior knowledge but who wishes to identify the individual or individuals referred to in the purportedly anonymised information and will take all reasonable steps to do so.’. The question was then one of assessment by a public authority as to ‘… whether, taking account of the nature of the information, there would be likely to be a motivated intruder within the public at large who would be able to identify the individuals to whom the disclosed information relates.” “…it is not just the means reasonably likely to be used by the ordinary man on the street to identify a person, but also the means which are likely to be used by a determined person with a particular reason to want to identify the individual…using the touchstone of, say, an investigative journalist…” “The approach assumes that the ‘motivated intruder’ is reasonably competent, has access to resources such as the internet, libraries, and all public documents, and would employ investigative techniques such as making enquiries of people who may have additional knowledge of the identity of the data subject or advertising for anyone with information to come forward. The ‘motivated intruder’ is not assumed to have any specialist knowledge such as computer hacking skills, or to have access to specialist equipment or to resort to criminality such as burglary, to gain access to data that is kept securely.” “The starting point for assessing re-identification risk should be recorded information and established fact. It is easier to establish that particular recorded information is available, than to establish that an individual – or group of individuals - has the knowledge necessary to allow re-identification. However, there is no doubt that non-recorded personal knowledge, in combination with anonymised data, can lead to identification. It can be harder though to substantiate or argue convincingly. There must be a plausible and reasonable basis for non-recorded personal knowledge to be considered to present a significant re-identification risk.” (my emphasis) “[Identification] implies a degree of certainty that information is about one person and not another. Identification involves more than making an educated guess that information is about someone; the guess could be wrong. The possibility of making an educated guess about an individual’s identity may present a privacy risk but not a data protection one because no personal data has been disclosed to the guesser. Even where a guess based on anonymised data turns out to be correct, this does not mean that a disclosure of personal data has taken place.”
“126. We consider there is force in Baroness Hale’s analysis, which Mr Hickman strongly urged us to adopt. It is difficult to imagine any situation where disclosure of anonymised information about living individuals, whose identities were known to the data controller, would not be regarded as disclosure of personal data, if one were required to take into account, in determining whether individuals were identifiable, the data controller’s own knowledge of their identity. At first sight, that cannot be right, since it would have the result of retaining protection for anodyne information not affecting anyone’s privacy (what Lord Rodger called “plain vanilla data”). The Commissioner similarly urged on us that the MOD’s construction would give rise to absurdities. Mr Hooper submitted that on the MOD’s construction, the number of individuals who had died of heart disease in the UK over the last decade would amount to “personal data” if this number were in the hands of a data controller that held the underlying records identifying each individual concerned, however large that number might be, but it would plainly not be a sensible construction of the DPA to require all processing of such a wholly general piece of information to comply with the data protection principles. 127. We cannot accept the Commissioner’s argument in full. As we understand the reasoning of Lord Hope, it is important to remember in this context that the definition of ‘processing’ does not only cover disclosure. Information or data are also processed when they are merely held, or indeed when they are destroyed (so that no one can any longer be identified). Anonymisation by redaction is itself a form of processing. If the data controller carries out such anonymisation, but also retains the unredacted data, or retains the key by which the living individuals can be identified, the anonymised data remains “personal data” within the meaning of paragraph (b) of the definition and the data controller remains under a duty to process it only in compliance with the data protection principles. On this basis, therefore, and contrary to the submissions of the Commissioner, we consider that the analysis of the essence of Lord Hope’s reasoning by the Information Tribunal in Department of Health v Information Commissioner and Prolife Alliance EA/2008/0074 (15 October 2009 ) at paragraphs 30-43 was probably correct. 128. However, we remain concerned at the use of this analysis in such a way as would have the effect of treating truly anonymised information as if it required the protection of the DPA, in circumstances where that is plainly not the case and indeed would be absurd. Lord Hope’s reasoning appears to lead to the result that, in a case where the data controller retains the ability to identify the individuals, the processing of the data by disseminating it in a fully anonymised form, from which no recipient can identify individuals, can only be justified by showing that it is effected in compliance with the data protection principles. Certainly the whole of the information still needs the protection of the DPA in the hands of the data controller, for as long as the data controller retains the other information which makes individuals identifiable by him. But outside the hands of the data controller the information is no longer personal data, because no individual can be identified. We therefore think, with diffidence given the difficulties of interpretation which led to such divergent reasoning among their Lordships, the best analysis is that disclosure of fully anonymised information is not a breach of the protection of the Act because at the moment of disclosure the information loses its character as personal data. It remains personal data in the hands of the data controller because the controller holds the key, but it is not personal data in the hands of the recipients, because the public cannot identify any individual from it. That which escapes from the data controller to the outside world is only plain vanilla data. We think this was the reasoning that Baroness Hale had in mind, when she said at [92]: “For the purpose of this particular act of processing, therefore, which is disclosure of these data in this form to these people, no living individual to whom they relate is identifiable”.” “For the purpose of this particular act of processing, therefore, which is disclosure of these data in this form to these people, no living individual to whom they relate is identifiable”.”
“46. Lord Hope's reasoning began by pointing out that disclosure is only one of the ways in which a data controller can process information. The data controller must comply generally with data protection principles. It could [not] exclude personal data from the duty to comply with the data protection principles simply by editing the data so that a third party would not find it possible from that part alone, without the assistance of other information, to identify a living individual: [22]. If the definition of personal data could be read in a way that excluded information that had been rendered fully anonymous, putting it into that form would take it outside the scope of the agency's duty as data controller: [23]. Lord Hope continued that the relevant part of the definition was limb B, since a living individual could not be identified from those data, ie the barnardised statistics themselves (limb A). Data would not be personal data if the other information was incapable of adding anything, and the data itself could not lead to identification, or if the data had been put into a form from which individuals to whom they related could not be identified at all, even with the assistance of the "other information" from which they were derived: [24]. In the latter situation, a person who had access to anonymised data and "other information" held by the data controller would find nothing in the anonymised data that would enable identification. It would be the "other information" only, and not anything in the anonymised data, which would result in the identification: [24]. 47. Lord Hope then referred to the wording of recital 26 of the preamble to Directive 95/46/EC, noting that the definition of personal data contained in Section 1(1) of the DPA gives effect to it. The first two parts of the recital refer to situations set out expressly in Section 1(1), the third part casting further light on what member states were expected to achieve when implementing the directive: [25]. Lord Hope's analysis is then completed at paragraphs 26 to 27, which deserve quoting in extensio. "26. The effect of barnardisation would be to conceal, or disguise, information about the number of incidences of leukaemia among children in each census ward. The question is whether the data controller, or anybody else who was in possession of the barnardised data, would be able to identify the living individual or individuals to whom the data in that form related. If it were impossible for the recipient of the barnardised data to identify those individuals, the information would not constitute 'personal data' in his hands. But we are concerned in this case with its status while it is still in the hands of the data controller, as the question is whether it is or is not exempt from the duty of disclosure that the 2002 Act says must be observed by him. "27. In this case it is not disputed that the agency itself holds the key to identifying the children that the barnardised information would relate to, as it holds or has access to all the statistical information about the incidence of the disease in the health board's area from which the barnardised information would be derived. But in my opinion the fact that the agency has access to this information does not disable it from processing it in such a way, consistently with recital 26 of the Directive, that it becomes data from which a living individual can no longer be identified. If barnardisation can achieve this, the way will then be open for the information to be released in that form because it will no longer be personal data. Whether it can do this is a question of fact for the commissioner on which he must make a finding. If he is unable to say that it would in that form be fully anonymised he will then need to consider whether disclosure of this information by the agency would be in accordance with the data protection principles and in particular would meet any of the conditions in Schedule 2. This is the more difficult of the two routes I have mentioned. As the issues were fully argued I shall say what I think about them. But there is no doubt that the commissioner's task will be greatly simplified if he is able to satisfy himself that the process of barnardisation will enable the data to be sufficiently anonymised.” "26. The effect of barnardisation would be to conceal, or disguise, information about the number of incidences of leukaemia among children in each census ward. The question is whether the data controller, or anybody else who was in possession of the barnardised data, would be able to identify the living individual or individuals to whom the data in that form related. If it were impossible for the recipient of the barnardised data to identify those individuals, the information would not constitute 'personal data' in his hands. But we are concerned in this case with its status while it is still in the hands of the data controller, as the question is whether it is or is not exempt from the duty of disclosure that the 2002 Act says must be observed by him. "27. In this case it is not disputed that the agency itself holds the key to identifying the children that the barnardised information would relate to, as it holds or has access to all the statistical information about the incidence of the disease in the health board's area from which the barnardised information would be derived. But in my opinion the fact that the agency has access to this information does not disable it from processing it in such a way, consistently with recital 26 of the Directive, that it becomes data from which a living individual can no longer be identified. If barnardisation can achieve this, the way will then be open for the information to be released in that form because it will no longer be personal data. Whether it can do this is a question of fact for the commissioner on which he must make a finding. If he is unable to say that it would in that form be fully anonymised he will then need to consider whether disclosure of this information by the agency would be in accordance with the data protection principles and in particular would meet any of the conditions in Schedule 2. This is the more difficult of the two routes I have mentioned. As the issues were fully argued I shall say what I think about them. But there is no doubt that the commissioner's task will be greatly simplified if he is able to satisfy himself that the process of barnardisation will enable the data to be sufficiently anonymised.”
“51. In my view, the only interpretation open of Lord Hope's order is that it recognised that although the Agency held the information as to the identities of the children to whom the requested information related, it did not follow from that that the information, sufficiently anonymised, would still be personal data when publicly disclosed. All members of the House of Lords agreed with Lord Hope's order demonstrating, in my view, their shared understanding that anonymised data which does not lead to the identification of a living individual does not constitute personal data. 52. In my judgment, this conclusion maintains faith with Lord Hope's reasoning. […] 53. Secondly, the conclusion reflects the legal backdrop to the definition of personal data in the DPA, which is recital 26 of Directive, with the ambit of protection drawn in the third part of the recital so as not to apply to data rendered anonymous in such a way that the data subject is no longer identifiable… 54. Finally, any other conclusion seems to me to be divorced from reality. The Department of Health's interpretation is that any statistical information derived from reporting forms or patient records constitutes personal data. If that were the case, any publication would amount to the processing of sensitive personal data. That would be so notwithstanding the statistical exemption in Section 33, since that exemption does not exclude the requirement to satisfy Schedule 3 of the DPA. Thus, the statistic that 100,000 women had an abortion in a particular year would constitute personal data about each of those women, provided that the body that publishes this statistic has access to information which would enable it to identify each of them. That is not a sensible result and would seriously inhibit the ability of healthcare organisations and other bodies to publish medical statistics.”
“There is clear legal authority for the view that where an organisation converts personal data into an anonymised form and discloses it, this will not amount to a disclosure of personal data. This is the case even though the organisation disclosing the data still holds the data that would allow re-identification to take place. This means that the DPA no longer applies to the disclosed data …”
“45 That definition is applicable where, by reason of its content, purpose and effect, the information in question is linked to a particular natural person (judgment of8 December 2022 , Inspektor v Inspektorata kam Visshia sadeben savet (Purposes of the processing of personal data – Criminal investigation), C-180/21, EU:C:2022:967, paragraph 70). In order to determine whether a natural person is identifiable, directly or indirectly, account should be taken of all the means likely reasonably to be used either by the controller, within the meaning of Article 4(7) of the GDPR, or by any other person, to identify that person, without, however, requiring that all the information enabling that person to be identified should be in the hands of a single entity (see, to that effect, judgment of19 October 2016 , Breyer, C-582/14, EU:C:2016:779, paragraphs 42 and 43). 46 As the Advocate General observed in points 34 and 39 of his Opinion, a datum such as the VIN – which is defined by Article 2(2) of Regulation No 19/2011 as an alphanumeric code assigned to the vehicle by its manufacturer in order to ensure that the vehicle is properly identified and which, as such, is not ‘personal’ – becomes personal as regards someone who reasonably has means enabling that datum to be associated with a specific person. 47 It follows from point II.5 of Annex I to Directive 1999/37 that the VIN must appear on the registration certificate for a vehicle, as must the name and address of the holder of that certificate. In addition, under points II.5 and II.6 of that annex, a natural person may be designated in that certificate as the owner of the vehicle, or as a person who can use the vehicle on a legal basis other than that of owner. 48 In those circumstances, the VIN constitutes personal data, within the meaning of Article 4(1) of the GDPR, of the natural person referred to in that certificate, in so far as the person who has access to it may have means enabling him to use it to identify the owner of the vehicle to which it relates or the person who may use that vehicle on a legal basis other than that of owner. 49 As the Advocate General observed in points 34 and 41 of his Opinion, where independent operators may reasonably have at their disposal the means enabling them to link a VIN to an identified or identifiable natural person, which it is for the referring court to determine, that VIN constitutes personal data for them, within the meaning of Article 4(1) of the GDPR, and, indirectly, for the vehicle manufacturers making it available, even if the VIN is not, in itself, personal data for them, and is not personal data for them in particular where the vehicle to which the VIN has been assigned does not belong to a natural person.”
“Whereas the protection of the rights and freedoms of data subjects with regard to the processing of personal data requires that appropriate technical and organizational measures be taken, both at the time of the design of the processing system and at the time of the processing itself, particularly in order to maintain security and thereby to prevent any unauthorized processing; whereas it is incumbent on the Member States to ensure that controllers comply with these measures; whereas these measures must ensure an appropriate level of security, taking into account the state of the art and the costs of their implementation in relation to the risks inherent in the processing; and the nature of the data to be protected;”
“Member States shall provide that the controller must implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected.”
“The seventh principle does not impose a duty to take “reasonable care” as such. Those words do not appear in the statute. This might suggest that the draftsman was aiming at a rather different target when he required that “appropriate” measures be taken. The word comes from the Directive: it is likely therefore to bear an autonomous meaning, which will apply in each member state of the European Union…to whom it is addressed. However, it is clear that the principle is a qualified one. The mere fact of disclosure or loss of data is not sufficient for there to be a breach. Rather, “appropriate” sets a minimum standard as to the security which is to be achieved. This is expressly subject to both the state of the technological development and the cost of measures. Thus the fact that a degree of security may technologically be achievable, which has not been implemented, does not of itself amount to a failure to reach an appropriate standard…the following words in DPP7 indicate that a balance has to be struck between the significance of the cost of preventative measures and the significance of the harm that might arise if they are not taken.”
“it is a first principle of fairness that each party to a judicial process shall have an opportunity to answer by evidence and argument any adverse material which the tribunal may take into account when forming its opinion.”
“40. Judicial notice is the acceptance by the courts of facts or a state of affairs which are so notorious, or so clearly established, that evidence of their existence is deemed unnecessary. As Cross and Tapper on Evidence 12th ed (2010), p 76 state: “Judicial notice refers to facts which a judge can be called upon to receive and to act upon either from his general knowledge of them, or from inquiries to be made by himself for his own information from sources to which it is proper for him to refer.” 41. Moreover, the party seeking judicial notice of a fact “has the burden of convincing the judge (a) that the matter is so notorious as not to be the subject of dispute among reasonable men, or (b) the matter is capable of immediate accurate demonstration by resort to readily accessible sources of indisputable accuracy” - Morgan, Some Problems of Proof under the Anglo-American System of Litigation 36.” “Judicial notice refers to facts which a judge can be called upon to receive and to act upon either from his general knowledge of them, or from inquiries to be made by himself for his own information from sources to which it is proper for him to refer.”