Jump to content

Recommended Posts

Posted

An email was sent by mistake to a student rather than a teacher discussing another student.

 

By a stoke of luck the student isn't in and I was able to retrieve the email from their account so it remain unread by them.

 

Does this constitute a data breach?

Posted (edited)

Technically, yes. You were lucky the other student didn’t see it, but it was still private information sent to a third party in error.

 

Will the ICO take action on reporting it? Very unlikely

 

Does the school need to take steps to ensure it doesn’t happen again? Definitely

Edited by elsiegee40
Posted
Surely it's no different than a USB stick full of info left on someone's back seat with the window open but the rightful owner of that info reaching in to pick it up and resecuring it; it still needs remedial action taken by the data owners to reduce the chance of it happening again but it's not a breach by any stretch of the imagination. For the time it was in that inbox unread, it was a potential breach and nothing more.
Posted
Technically, yes. You were lucky the other student didn’t see it, but it was still private information sent to a third party in error.

 

Will the ICO take action on reporting it? Very unlikely

 

Does the school need to take steps to ensure it doesn’t happen again? Definitely

 

So would you report it?

Posted

There was a breach, you used your internal procedures to remedy the breach and no information was made public.

 

Needs to be logged internally and written up as to what was done to secure the data.

 

Member of staff concerned should get a letter on their file from the head given how difficult this could have been had the student been in school. I assume your network does not allow the students to log in from home or via their phones. Are you certain they didn't read it?

Posted (edited)
So where's this line between a potential breach and a breach?

 

The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant

 

You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party.

Edited by elsiegee40
Posted
So where's this line between a potential breach and a breach?

 

I'd say if data is where it shouldn't be, it's a breach. Whilst on this occasion the data wasn't looked at by anyone, it was where it shouldn't be.

Posted
Agree with most of the others here, no risk to the data subjects so no need to report to ICO. Record on your own systems, making sure that you put things in place to prevent a recurrence.
Posted
So where's this line between a potential breach and a breach?

 

It seems fairly clear to me. A potential breech is the risk that a breech could happen, a breech is it DID happen. The email was sent to the wrong person, so it is a breech.

 

We use office365 for teacher to teacher communication and google for teachers and pupil communication. This way someone sending an email in office365 can't accidentally send it to a pupil as there are no pupils in the address book.

 

I think you can do that kind of separation in google now but I don't see the need to change something that works well so I'll keep it as it is!

  • Thanks 1
Posted
The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant

 

You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party.

 

Not reportable. Due to action taken there was no risk to the data subject.

  • Thanks 1
Posted
The data was sent to the wrong person. It’s a reportable breach. The fact they didn’t read it is irrelevant

 

You would have to report a lost memory stick with personal data on it as soon as you become aware of the loss and even if it was never found by a third party.

 

Not quite the same. In your example of a lost memory stick, you don't know for sure it wasn't found, or even accessed then left lying round again. In this instance, we know the email wasn't read.

 

That said, do we know with 100% certainty the email hadn't been read? I can think of two different ways I can view the contents of an email without it getting marked as read - one is the drag-down preview from the top of my phone screen, and the other is the preview pane in Outlook which (depending on settings) doesn't mark an email as read until you move away from it. So, the fact the email was marked unread in the student's inbox is not, to me, a certainty the email wasn't viewed.

 

ICO certainly aren't going to take action, but I would still report it to your DPO so you can formally record the steps you have taken to ensure this doesn't happen again, or at least to reduce the chance of it happening again.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...