Jump to content

Recommended Posts

Posted (edited)

Afternoon,

 

A member of staff has accidently sent an email out to prospective parents and cc'd the other parents into the same email. In effect giving out all the email addresses to the other parents. There was nothing in the email to link the parents to children and was just an informational one that highlights upcoming pre visits to the school.

 

Is this deemed as a data breach and if so can any advise as to the next stage we'd need to follow?

 

TIA

Edited by gpjt
Posted

From what I've seen, yes it is. When you link up that the addresses would all be linked to children, potentially students of the school, that this was data being controlled by the school and that it has been disclosed then the parents would have a cause to be concerned.

 

The next step is for this to be reported to your DPO, who will manage what happens and whether it's reported to the ICO (which is a bit more involved).

  • Thanks 2
Posted

Yup - this would be a data breach. Need to get your DPO on the case. Get them to call the ICO and ask for advice (they can be very helpful), and they will inform you whether or not you need to report it officially or not.

 

Pete

  • Thanks 1
Posted
Yes. From experience, get this communicated out to parents ASAP and the steps you have taken so far with an apology. Looks far better than when they start coming back at the school.
  • Thanks 1
Posted
yep would probably go down as data breach would probably be best to recall the email and send a follow up email with an apology
Posted

Definitely a data breach. Low level mostly, but there could be some fall-out. While the names aren't linked to students in that email, it isn't rocket science to link some of them, then it just takes two kids to have a falling out and one parent to use the information provided by the school to contact the parents of the other child, then it all gets a bit messy.

 

Report to your DPO, they'll tell you the next steps (you won't be the first person they've dealt with who has done this!)

Posted

 

Report to your DPO, they'll tell you the next steps (you won't be the first person they've dealt with who has done this!)

 

Our DPO at the local authority did it once, when sending out the DPO newsletter to all schools!

Posted
Our DPO at the local authority did it once, when sending out the DPO newsletter to all schools!

 

Oops! They should know what to do, then :-) At least it was work addresses not parents' home addresses.

Posted
Our DPO at the local authority did it once, when sending out the DPO newsletter to all schools!

I saw an email from a chap pushing his GDPR training sessions who did this too :-/

It can happen to any of us I guess, but how you respond is critical.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...