E_G_R2 Posted October 10, 2018 Posted October 10, 2018 An email was sent by mistake to a student rather than a teacher discussing another student. By a stoke of luck the student isn't in and I was able to retrieve the email from their account so it remain unread by them. Does this constitute a data breach?
elsiegee40 Posted October 10, 2018 Posted October 10, 2018 (edited) Technically, yes. You were lucky the other student didn’t see it, but it was still private information sent to a third party in error. Will the ICO take action on reporting it? Very unlikely Does the school need to take steps to ensure it doesn’t happen again? Definitely Edited October 10, 2018 by elsiegee40
synaesthesia Posted October 10, 2018 Posted October 10, 2018 Surely it's no different than a USB stick full of info left on someone's back seat with the window open but the rightful owner of that info reaching in to pick it up and resecuring it; it still needs remedial action taken by the data owners to reduce the chance of it happening again but it's not a breach by any stretch of the imagination. For the time it was in that inbox unread, it was a potential breach and nothing more.
E_G_R2 Posted October 10, 2018 Author Posted October 10, 2018 Technically, yes. You were lucky the other student didn’t see it, but it was still private information sent to a third party in error. Will the ICO take action on reporting it? Very unlikely Does the school need to take steps to ensure it doesn’t happen again? Definitely So would you report it?
GrumbleDook Posted October 10, 2018 Posted October 10, 2018 Yes, however mitigating action was taken so there was there was no risk to the data subject. Not reportable. 3
PotNoodleTech Posted October 10, 2018 Posted October 10, 2018 It is a breech, so you need to fill in all your internal data breech paperwork - just no need to actually report it to the ICO IMHO. 1
synaesthesia Posted October 10, 2018 Posted October 10, 2018 So where's this line between a potential breach and a breach?
SBDDrumB Posted October 10, 2018 Posted October 10, 2018 There was a breach, you used your internal procedures to remedy the breach and no information was made public. Needs to be logged internally and written up as to what was done to secure the data. Member of staff concerned should get a letter on their file from the head given how difficult this could have been had the student been in school. I assume your network does not allow the students to log in from home or via their phones. Are you certain they didn't read it?
elsiegee40 Posted October 10, 2018 Posted October 10, 2018 (edited) So where's this line between a potential breach and a breach? The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party. Edited October 10, 2018 by elsiegee40
Jawloms Posted October 10, 2018 Posted October 10, 2018 So where's this line between a potential breach and a breach? I'd say if data is where it shouldn't be, it's a breach. Whilst on this occasion the data wasn't looked at by anyone, it was where it shouldn't be.
synaesthesia Posted October 10, 2018 Posted October 10, 2018 Cheers, think I'm being too black & white as per the norm
Bigbird7 Posted October 10, 2018 Posted October 10, 2018 Agree with most of the others here, no risk to the data subjects so no need to report to ICO. Record on your own systems, making sure that you put things in place to prevent a recurrence.
PotNoodleTech Posted October 10, 2018 Posted October 10, 2018 So where's this line between a potential breach and a breach? It seems fairly clear to me. A potential breech is the risk that a breech could happen, a breech is it DID happen. The email was sent to the wrong person, so it is a breech. We use office365 for teacher to teacher communication and google for teachers and pupil communication. This way someone sending an email in office365 can't accidentally send it to a pupil as there are no pupils in the address book. I think you can do that kind of separation in google now but I don't see the need to change something that works well so I'll keep it as it is! 1
GrumbleDook Posted October 10, 2018 Posted October 10, 2018 The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party. Not reportable. Due to action taken there was no risk to the data subject. 1
enjay Posted October 11, 2018 Posted October 11, 2018 The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party. Not quite the same. In your example of a lost memory stick, you don't know for sure it wasn't found, or even accessed then left lying round again. In this instance, we know the email wasn't read. That said, do we know with 100% certainty the email hadn't been read? I can think of two different ways I can view the contents of an email without it getting marked as read - one is the drag-down preview from the top of my phone screen, and the other is the preview pane in Outlook which (depending on settings) doesn't mark an email as read until you move away from it. So, the fact the email was marked unread in the student's inbox is not, to me, a certainty the email wasn't viewed. ICO certainly aren't going to take action, but I would still report it to your DPO so you can formally record the steps you have taken to ensure this doesn't happen again, or at least to reduce the chance of it happening again.
MatthewL Posted October 11, 2018 Posted October 11, 2018 Might be a good time to teach/remind staff how to recall a message if using Exchange and this happens within your organisation.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now