Zammo Posted January 24, 2020 Posted January 24, 2020 (edited) "Aha, so Joe Bloggs, the man with an injunction against me because reasons, is working at Smith School in Smithtown. Now I can continue to maim him with the view to do more". Just because they're staff, doesn't mean they're any less vulnerable in some cases than students who have similar reasons to not be named in public. A highly unlikely scenario for starters. Not impossible but on the plausibility scale it ranks pretty low. Also no sensitive data (as defined by the ICO) was leaked. Most fines are handed out for deliberate abuse of data, theft of data or leaking highly sensitive data. Look at the list of fines levied by the ICO : https://ico.org.uk/action-weve-taken/enforcement/ This doesn’t come close to meeting the threshold for fines in my opinion. If I’m wrong I’ll hold my hands up, but I just can’t see it. Not a commentary on the rights and wrongs of the situation, I’m just saying they almost certainly won’t get fined for this. Edited January 24, 2020 by Zammo
synaesthesia Posted January 24, 2020 Posted January 24, 2020 Unfortunately likely, but there's a high chance that school staff in that list don't want to be public for whatever reason - this is usually true more among support staff and that's where this email is targeted, so I'd say more likely than you'd think! Full names and email addresses as opposed to shortened would likely be worrying for those as it can narrow down a name and a specific location.
maark Posted January 24, 2020 Posted January 24, 2020 a lot of finance contacts on the list bursar@ finance@ - useful for phishers
msi_school Posted January 27, 2020 Posted January 27, 2020 I don't want my or my business manager email address public because it presents a surface area for phishing attacks, however generic accounts such as we use for capita are hardly obscure most schools have bursar@ or finance@. Username@ email address whilst private are not sensitive and in a lot of cases are already public knowledge. Using the ICO self Assessment form https://ico.org.uk/for-organisations/report-a-breach/pdb-assessment/y I would say that this would not even reportable except for the amount of email addresses released and is not worthy of a fine. On the other hand if this is displaying a pattern of poor data security and one of a number of data breaches then that is a different matter although I don't know if the ICO is able to take this into account. 1
DJ-1701 Posted February 3, 2020 Posted February 3, 2020 I left Capita over 3 years ago! Congratulations. 2
DrCheese Posted February 3, 2020 Posted February 3, 2020 I left Capita over 3 years ago! bwhahaha no one ever truly leaves
Jawloms Posted April 27, 2021 Posted April 27, 2021 Anyone know what the outcome of this was? For no reason other than curiosity........
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now