sigma Posted September 19, 2018 Posted September 19, 2018 https://ico.org.uk/for-organisations/report-a-breach/capita-sims-data-breach/ The ICO has been made aware of a data breach involving the Capita SIMS system that has affected a number of schools who use their services. We understand that Capita have added messages to the system to update schools and to help them identify if their data has been involved. Schools should establish if they have been affected by the breach and if so assess which pupils’ data have been affected and how. Under the GPDR, which came into force on 25 May 2018, controllers have an obligation to report data security breaches to the ICO unless there is unlikely to be a risk to individuals. Before 25 May 2018 there was no legal obligation to report to the ICO. If your school has been affected by the Capita SIMS incident and you have enough information to establish that there may be a risk to your pupils or parents, you should report the breach to the ICO. If we need further information we will be in contact with you. You should consider how your pupils or parents may be affected by the breach. If you think there is a high risk to their rights and freedoms, you need to tell them about the breach without delay. You should tell them about any steps you are taking to mitigate the effects of the breach and provide them with advice on what to do to protect themselves. Self-assessment Take our self-assessment to determine whether your school needs to report to the ICO. ICO breach notification form – Capita Business Services Ltd (SIMS) breach only ICO question Controller response Name and contact details of the person reporting What were you using SIMS for when the breach occurred? (ie sending correspondence to parents) What type of data has been compromised? Are you aware of any data breach incidents at your school as a result of this matter? How many? How have you arrived at this figure? Were you informed about the issue with SIMS by Capita? If so, when? If not, how did you discover the issue? Any other information that you think it would be useful to provide? 4
enjay Posted September 20, 2018 Posted September 20, 2018 So the ICO are putting the responsibility on the schools too? That's an interesting precedent.
ir0n_jaw Posted September 20, 2018 Posted September 20, 2018 So the ICO are putting the responsibility on the schools too? That's an interesting precedent. As data controller, the school has responsibility to report the breach, if affected. We're filing our report today.
matt40k Posted September 20, 2018 Posted September 20, 2018 I don't think Capita are out of the woods yet... Were you informed about the issue with SIMS by Capita? If so, when? If not, how did you discover the issue? Other interesting one is: What were you using SIMS for when the breach occurred? (ie sending correspondence to parents)
Ditto Posted September 20, 2018 Posted September 20, 2018 Watching with interest. My workplace is non-SIMS, but my governance school is SIMS, as are all others in the MAT. If it transpires the ICO decide, in due course, a fine is appropriate, could Capita get fined for each school that suffered a breach? If the school gets fined, is it reasonable for the school to look for reimbursement? I can see the small print in the contracts being called uponfore - you know the sort of thing - "we exclude ourselves from responsibility if our software fails".
ir0n_jaw Posted September 20, 2018 Posted September 20, 2018 Watching with interest. My workplace is non-SIMS, but my governance school is SIMS, as are all others in the MAT. If it transpires the ICO decide, in due course, a fine is appropriate, could Capita get fined for each school that suffered a breach? If the school gets fined, is it reasonable for the school to look for reimbursement? I can see the small print in the contracts being called uponfore - you know the sort of thing - "we exclude ourselves from responsibility if our software fails". I think this case will potentially set a precedent in our sector - but I fear our schools are too ill-prepared to want to hold Capita to account. I'm stunned by the apathy around this issue. RE contracts and small print - this is exactly what they do and exactly why we renegotiated data protection clauses with Capita around GDPR go-live as they work very hard to avoid any liability. I would urge all of you to check your contracts - not that it would hold up in law necessarily. 1
sigma Posted September 20, 2018 Posted September 20, 2018 There are other parties with a finger in this pie too. Where a school buys SIMS with SIMS support from their County or other supplier and that party has failed to notify the school about the problems, I would think they also have a liability.
Ditto Posted September 20, 2018 Posted September 20, 2018 There are other parties with a finger in this pie too. Where a school buys SIMS with SIMS support from their County or other supplier and that party has failed to notify the school about the problems, I would think they also have a liability. Very good point. I'm not sure if my school utilise the LA - they went from a maintained school to Academy a long time ago and I know MIS switch something there was not appetite for. I also believe they are using RM - not sure if hosted or just remote support? Does that mean RM may also have to report?
pete Posted September 20, 2018 Posted September 20, 2018 If the school gets fined, is it reasonable for the school to look for reimbursement? I can see the small print in the contracts being called uponfore - you know the sort of thing - "we exclude ourselves from responsibility if our software fails". Most software providers make no guarantee that their software will do anything. So you'll get nowhere with that. A better angle would be whether Capita informed affected schools of the problem (including implications) in a timely manner.
KeyData Posted September 24, 2018 Posted September 24, 2018 (edited) This may be useful to people working on this issue. ICO webpage on the Capita SIMS data breach with quick self assessment on whether to self report to ICO or not. https://ico.org.uk/for-organisations/report-a-breach/capita-sims-data-breach/ Edited September 24, 2018 by KeyData
Popular Post 5tu Posted April 3, 2019 Popular Post Posted April 3, 2019 (edited) Here we go again..... You couldn't make this up! Dear SSU colleague We are investigating one incident with CTF for schools who have taken the latest Spring Release. We are assessing currently the specific scenarios where this incident arises and the exact scope of its impact. Our current precautionary advice is not to use the CTF mechanism to share pupil and contact details with other schools until further notice. If you have sent a CTF file to another school (after Friday 22 March) we suggest you contact the recipient school to check the details that they have loaded are correct. Please note that this issue does not relate to data transferred prior to the spring release (i.e. schools on the autumn release transferring data to schools also on the autumn release are unaffected). Capita ESS apologises for any impact on schools and their support partners that may arise from this incident. We continue to investigate and will update once the full details and implications are known. We will post updates via My Account in due course but will also continue to give important updates via email. Kind regards Capita SIMS Edited April 3, 2019 by gybe78 5
mavhc Posted April 3, 2019 Posted April 3, 2019 Good job it's free, otherwise we might expect them to have an automated test suite to find such flaws. 2
DrCheese Posted April 3, 2019 Posted April 3, 2019 haha, I called it! I knew it! http://www.edugeek.net/forums/mis-systems/205208-sims-spring-2019-release.html#post1755644
bobsmith Posted April 3, 2019 Posted April 3, 2019 So it's a good thing I postponed upgrading until after Easter?
CAM Posted April 3, 2019 Posted April 3, 2019 I no longer have access to My Account, what's going on now?
jinnantonnixx Posted April 3, 2019 Posted April 3, 2019 (edited) So it's a good thing I postponed upgrading until after Easter? But if everyone did that, who'd do the testing? Edited April 3, 2019 by jinnantonnixx
Hardeep_Sco Posted April 3, 2019 Posted April 3, 2019 (edited) I too had a gut feeling that we would see this again, also. Summer is going to be fun again if we have to apply patches again and the Capita Helpdesk is not going to be able to cope again. I dont have access to MyAccount either at the minute, but have they said anything about SIMS Pay? Edited April 3, 2019 by Hardeep_Sco
5tu Posted April 3, 2019 Posted April 3, 2019 Can't see anything on MyAccount..... I just got the email above
Arthur Posted April 3, 2019 Posted April 3, 2019 (edited) Can't see anything on MyAccount..... I just got the email above https://myaccount.capita-cs.co.uk/Notifications/sims-newsfeed-ctf-spring-2019/ https://myaccount.capita-cs.co.uk/hot-topics/ctf/ Edited April 3, 2019 by Arthur
round2it Posted April 3, 2019 Posted April 3, 2019 Why do we have to deal with this crud it's not fit purpose give me the money back.
matt40k Posted April 3, 2019 Posted April 3, 2019 Why do we have to deal with this crud it's not fit purpose give me the money back. Switch MIS then, sorted
Ditto Posted April 3, 2019 Posted April 3, 2019 I'm mean this as a serious question, but what is stopping your school from looking at alternatives?
DrBeaker Posted April 3, 2019 Posted April 3, 2019 I'm mean this as a serious question, but what is stopping your school from looking at alternatives? SLT normally due to "this is the way we've always done it"
matt40k Posted April 4, 2019 Posted April 4, 2019 But if you listen to some of the sales people it'll save you mega £££, make you healthier and make you 10x more efficient 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now