Gongalong Posted May 21, 2018 Posted May 21, 2018 If I recall correctly, this is the first fine of an educational organisation i.e. nursery, school, college, uni https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/05/the-university-of-greenwich-fined-120-000-by-information-commissioner-for-serious-security-breach/ (University of Greenwich fined £120k) 2
pete Posted May 21, 2018 Posted May 21, 2018 The investigation centred on a microsite developed by an academic and a student in the then devolved University’s Computing and Mathematics School, to facilitate a training conference in 2004. After the event, the site was not subsequently closed down or secured and was compromised in 2013. In 2016 multiple attackers exploited the vulnerability of the site allowing them to access other areas of the web server. The personal data included contact details of 19,500 people including students, staff and alumni such as names, addresses and telephone numbers. However, around 3,500 of these included sensitive data such as information on extenuating circumstances, details of learning difficulties and staff sickness records and was subsequently posted online. I forsee the responsible dept having a 96K budget shortfall.
TheSysAdminLife Posted May 21, 2018 Posted May 21, 2018 I wonder how much this fine would have been under GDPR... I don't know if this is the right number, but: "Total revenues in the year to 31 July 2017 were £200.5m" - from a PDF here. 4% of £200,000,000 = £8,000,000
Gongalong Posted May 21, 2018 Author Posted May 21, 2018 I suspect they take various factors into account when sizing the fine, although this is data on a very large number of people.
SteveSaywell Posted May 21, 2018 Posted May 21, 2018 I would suggest that under GDPR the fine would be £120k. The ICO can currently fine up to £500k yet this fine doesn't come close to that limit. There has been nothing to suggest the ICO will alter their approach to fining.
TheSysAdminLife Posted May 21, 2018 Posted May 21, 2018 That makes sense. It would be scarier for organisations if the ICO bumped up their fines up, which is kind of the point of GDPR if you look at it from a certain perspective. "Percentage of maximum fine" based rather than "value of fine" based... if that's worded correctly.
TechMonkey Posted May 21, 2018 Posted May 21, 2018 Not the first, just not been done in a while: https://www.redstor.com/en-gb/news/12-penalties-issued-ico-schools-data-lapses-last-2-years Oldham school breaches Data Protection Act | IT PRO Hampshire school breaches data protection rules | IT PRO 1
Gongalong Posted May 21, 2018 Author Posted May 21, 2018 First that's been *fined* though? I know there have been several edu orgs with undertakings.
TechMonkey Posted May 21, 2018 Posted May 21, 2018 First that's been *fined* though? I know there have been several edu orgs with undertakings. Ah, the second and third didn't include fines, sorry I thought they did. The first one I assumed included fines as they mentioned fines.
mjk Posted May 21, 2018 Posted May 21, 2018 So let me get this straight; the fine is 120k but it's only £96k if they pay quickly. But this was for releasing data on 20,000 students and staff - which is about £6 per person, or £4.8 with the discount. So for a large school of 2000 pupils and staff we'd be looking at about 12k or less than 10k with the discount, and that's for a full data breach. Seems like a gamble the school would take.
TheSysAdminLife Posted May 21, 2018 Posted May 21, 2018 So let me get this straight; the fine is 120k but it's only £96k if they pay quickly. But this was for releasing data on 20,000 students and staff - which is about £6 per person, or £4.8 with the discount. So for a large school of 2000 pupils and staff we'd be looking at about 12k or less than 10k with the discount, and that's for a full data breach. Seems like a gamble the school would take. This is the crux of the issue. Under DPA the fines just aren't big enough to scare anyone into being compliant. The fines being boosted under GDPR for everyone should change this attitude, though I'm not sure the ICO will fine schools quite as highly as a bank or other commercial enterprise. I think they should, but I don't think they will.
Gongalong Posted May 21, 2018 Author Posted May 21, 2018 Ah, the second and third didn't include fines, sorry I thought they did. The first one I assumed included fines as they mentioned fines. The Redstor link? I think that's just talking about potential fines, rather than saying edu orgs have been fined. This is a list of all orgs that have received fines, none of which are edu. Obviously the University of Greenwich are to be added, once the amount has been paid https://ico.org.uk/media/2014859/civil-monetary-penalties.csv
Gongalong Posted May 21, 2018 Author Posted May 21, 2018 This is the crux of the issue. Under DPA the fines just aren't big enough to scare anyone into being compliant. There's the embarrassment factor, and also the procedural undertakings that the ICO can force, or try and force. It would be pretty heartless to fine a state school, but...
maturelady Posted May 21, 2018 Posted May 21, 2018 Yes I think @Gongalong is right. There's been quite a few knuckles wrapped in education but this is the first fine that I can recall. I hope it brings home what constitutes a data breach. This is not about data collected today, this data was collected many years ago and just forgotten, left 'somewhere' online. How many teachers or even ex and retired teachers have very sensitive data still sitting on their laptops, data sticks, DVDs, or even floppies? You can argue that you can't be responsible but you are - the school is the data controller. This university was fined under the CURRENT DPA introduced in 1998 not GDPR. If you, as standard practice, ask staff to clear out information they don't need or not entitled to, as part of your current DP process you are in a better position. We are a profession and expect employees to carryout instructions. This is a very good example to use as part of your whole school GDPR training. 1
Gongalong Posted May 22, 2018 Author Posted May 22, 2018 I believe there were 12 edu orgs between 2010 and 2015 that signed undertakings, not sure about after that. These are the ones I've looked up detail on: Bay House School (Gosport, Hants) – hacking attack on website, student data potentially compromised. Staff member used same password for two different accounts. Cherubs Community Playgroup (Coventry) – onsite out-of-ours theft of unencrypted laptop with data on ethnicity of children. Laptop left under desk. Surbiton Children’s Centre Nursery (Surrey) – offsite theft of an unencrypted memory stick and paperwork. Freehold Community School (Oldham) – unencrypted laptop and paperwork on 90 pupils stolen from boot of car while parked at home. Norwich City College of Further and Higher Education – student files put in insecure waste and disposed of in skip. Godalming College – staff email containing sensitive attachment accidentally sent to lower sixth-form students. Media publicity resulted. Phoenix Nursery School (Wolverhampton) – lost unencrypted backup tape containing SIMS data. Holly Park School (London) – onsite theft of an unencrypted laptop containing data for 9 pupils. Stored in locked filing cabinet in unlocked office.
Gongalong Posted May 22, 2018 Author Posted May 22, 2018 (edited) The ICO have got this useful site which seems to have data from Nov 2015 onwards, and no edu orgs here, except for the University of Greenwich and two they've miscategorised https://ico.org.uk/action-weve-taken/enforcement Edited May 22, 2018 by Gongalong
enjay Posted May 22, 2018 Posted May 22, 2018 So let me get this straight; the fine is 120k but it's only £96k if they pay quickly. But this was for releasing data on 20,000 students and staff - which is about £6 per person, or £4.8 with the discount. So for a large school of 2000 pupils and staff we'd be looking at about 12k or less than 10k with the discount, and that's for a full data breach. Seems like a gamble the school would take. There is another way to view the size of the fine - it was £120K on a maximum of £500k, so roughly a quarter of the maximum. Under GDPR, the maximum (for schools) would be £20m, a quarter of which is £5m. Reduce down for a 2000 pupil school not a 20,000 person university and you get £500k. I don't think many schools would take that gamble. To be honest, I don't think many schools would gamble for the £10k you worked out, either.
mthomas08 Posted May 22, 2018 Posted May 22, 2018 Yes I think @Gongalong is right. There's been quite a few knuckles wrapped in education but this is the first fine that I can recall. I hope it brings home what constitutes a data breach. This is not about data collected today, this data was collected many years ago and just forgotten, left 'somewhere' online. How many teachers or even ex and retired teachers have very sensitive data still sitting on their laptops, data sticks, DVDs, or even floppies? You can argue that you can't be responsible but you are - the school is the data controller. This university was fined under the CURRENT DPA introduced in 1998 not GDPR. If you, as standard practice, ask staff to clear out information they don't need or not entitled to, as part of your current DP process you are in a better position. We are a profession and expect employees to carryout instructions. This is a very good example to use as part of your whole school GDPR training. Exactly. This is why data mapping is very important. You need to know from every staff member where personal data is located and especially sensitive information. Got to ask the questions: Who needs it, who has access, is it secure, have you got consent etc. I hate to say this but we need more examples popping up. It is the only way education will learn because there are schools that are STILL ignoring GDPR or others not taking it serious. The real silly part is... we are doing what should have been done under the Data Protection Act which is what 20 years old now.. Data is treated without care and using a basic scare monger tactic (I know it's not the best) seems to be working for us. We have leadership on board and presenting power points to staff by the HT with basic bits really helped. You know it's working when staff are sick and tired of the term GDPR and our paper shredding has gone through the roof!
enjay Posted May 22, 2018 Posted May 22, 2018 This is why data mapping is very important. You need to know from every staff member where personal data is located and especially sensitive information. Got to ask the questions: Who needs it, who has access, is it secure, have you got consent etc. It does support the practice of reviewing the data map perhaps annually, to check a) all new processing activities have been added, and in this instance b) where a data processing activity is no longer required, contracts have been cancelled and all data removed.
Disease Posted May 22, 2018 Posted May 22, 2018 In regards to Bay house, how could you possible check for staff using duplicate passwords in 2 different systems, apart from asking them their passwords? Seems a bit harsh.
Gongalong Posted May 22, 2018 Author Posted May 22, 2018 I don't think there can be any other way than spot checking staff "manually".
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now