xicor Posted September 12, 2021 Posted September 12, 2021 Hi all i just discovered a council "without mentioning which one" has been sending a google forms to schools to fill in children's details, that form however was sent in edit mode meaning any recipient can download the results of the other schools, private information about their children,parents contact details etc. My question is how is google forms managed on the top level ? and does google forms have an audit trail showing who and when the results were downloaded and from which IP address ? P.S that form had the details of 7000+ children free to download by any school that got that link.... Best Regards, Omar
Ditto Posted September 12, 2021 Posted September 12, 2021 Hi all i just discovered a council "without mentioning which one" has been sending a google forms to schools to fill in children's details, that form however was sent in edit mode meaning any recipient can download the results of the other schools, private information about their children,parents contact details etc. My question is how is google forms managed on the top level ? and does google forms have an audit trail showing who and when the results were downloaded and from which IP address ? P.S that form had the details of 7000+ children free to download by any school that got that link.... Best Regards, Omar The control of the form is not easy to explain in this forum, but I do know this scenario can happen, the error is easily resolved, but there is a serious failing in the permissions. Much more importantly, this looks like a very serious breach. Although it doesn't sound like your data, I feel you should notify both the council and the ICO immediately. The nature of the breach and safeguarding concerns need to be reviewed now. @GrumbleDook, could you wade in on this one. I suspect it doesn't need saying, but please don't publish the council details or anything more. 1
GrumbleDook Posted September 12, 2021 Posted September 12, 2021 Please report to the council immediately. Feel free to PM me with the details as well. Without knowing more details I wouldn’t want to make a longer comment other than it is a real concern. 3
xicor Posted September 13, 2021 Author Posted September 13, 2021 I have indeed reported this to everyone in the council that I could find an email for ! I got a call from the DPO today, saying that they have closed the form now, they however told me that they cannot find out who downloaded the form results or not. I don't use google forms so I don't know if they have a log that can show who downloaded the form results or not, does anyone here uses google forms and can confirm ?
paulkerton Posted September 13, 2021 Posted September 13, 2021 I have indeed reported this to everyone in the council that I could find an email for ! I got a call from the DPO today, saying that they have closed the form now, they however told me that they cannot find out who downloaded the form results or not. I don't use google forms so I don't know if they have a log that can show who downloaded the form results or not, does anyone here uses google forms and can confirm ? They should be able to find it in the Drive Audit Log inside Google Admin Console's reporting tools to see who has accessed the form, and therefore the data. Doesn't matter if they've downloaded the results or not if they've been able to see the responses inside the form itself.
xicor Posted September 13, 2021 Author Posted September 13, 2021 problem is they shared this with every school in the borough, 100s of people would have accessed the from, is there any way to filter by who downloaded the data rather than just accessed the form ?
paulkerton Posted September 13, 2021 Posted September 13, 2021 (edited) problem is they shared this with every school in the borough, 100s of people would have accessed the from, is there any way to filter by who downloaded the data rather than just accessed the form ? Not that I'm aware of for CSV (if there is a responses Google Sheet, you can see who has viewed that) but like I say - anyone who has accessed the form with the editable link will have been able to see the data, so downloading that data is irrelavant - it has been exposed through sharing the edit link and exposing the "Responses" tab on the form. You have to assume that whoever had that link has opened it and been able to see the data/do something with it. Edited September 13, 2021 by paulkerton 1
xicor Posted September 13, 2021 Author Posted September 13, 2021 Not that I'm aware of for CSV (if there is a responses Google Sheet, you can see who has viewed that) but like I say - anyone who has accessed the form with the editable link will have been able to see the data, so downloading that data is irrelavant - it has been exposed through sharing the edit link and exposing the "Responses" tab on the form. I see what you mean, apparently the DPO doesn't think this should be reported to the ICO as it was only sent to schools
paulkerton Posted September 13, 2021 Posted September 13, 2021 I see what you mean, apparently the DPO doesn't think this should be reported to the ICO as it was only sent to schools It absolutely should be. When these changes kicked in Councils around the country were very determined to say schools were not part of their organisations and were on their own. If you don't share a DPO, then it should be reported as a breach.
TechMonkey Posted September 13, 2021 Posted September 13, 2021 I'd count it a bit like safeguarding. Report it and let the ICO decide.
elsiegee40 Posted September 13, 2021 Posted September 13, 2021 (edited) 1. It doesn’t matter who could download it. An unauthorised party reading it is a data breach; no download has to be involved. Someone could have taken a screenshot, a photo with their phone camera or simply copied data belonging to your students onto paper using a pen. 2. It must be reported to the ICO. If they don’t do it then you must. Data from your school has been potentially* breached due to this form, so I suggest you get your own DPO to report your school’s data asap. *Reporting doesn’t only involve known data breaches. It also involves potential data breaches. You don’t know if your data was accessed by unauthorised parties, but it could have been; that makes it reportable to the ICO. Edited September 13, 2021 by elsiegee40 3
Ditto Posted September 13, 2021 Posted September 13, 2021 1. It doesn’t matter who could download it. An unauthorised party reading it is a data breach; no download has to be involved. Someone could have taken a screenshot, a photo with their phone camera or simply copied data belonging to your students onto paper using a pen. 2. It must be reported to the ICO. If they don’t do it then you must. Data from your school has been potentially* breached due to this form, so I suggest you get your own DPO to report your school’s data asap. *Reporting doesn’t only involve known data breaches. It also involves potential data breaches. You don’t know if your data was accessed by unauthorised parties, but it could have been; that makes it reportable to the ICO. All of the above and should be reported within 72 hours, but in this case there is no need to delay. For ICO guidance, see https://ico.org.uk/for-organisations/sme-web-hub/72-hours-how-to-respond-to-a-personal-data-breach/
psydii Posted September 13, 2021 Posted September 13, 2021 (edited) By your school's policy who is responsible for reporting breaches? This is their problem. Put it in writing to them and leave it well alone. I've edited this post from how it may appear on the homepage. I kind of misread a couple of replies here. Initially I also wrote: "If they don't do it you must" I would advise that you call your union for support before bypassing your DPO and going against what the LA DPO has advised. I now realise the the "you" meant "your employer", so the call your union bit is unnecessary, however you are aware of the breach and may disagree with the DPO's assessment, so it is probably worth bouncing this off your Union for advice in case things come unstuck later. Edited September 13, 2021 by psydii
GrumbleDook Posted September 13, 2021 Posted September 13, 2021 Did your school put any data up there? If so, it is also your breach as you were sharing data with the LA as another controller (I don't know the purpose of the form but so far it sounds like a data gathering exercise by the LA for something ... don't really need to know what, only whether it was for their benefit or not). Did you do any checks to see if it was a secure area? Was it checked against any DSA you may have in place, or legislation/regulation/instruction meaning you have to share the data? See .... lots of reasons why you can kick up a fuss. It might not be reportable, depending on the personal data involved and the risks (if any) to the individuals. I don't think the LA can acertain this fully and so they should be discussing it with schools to see what the impact is ... and quickly. 3
paulkerton Posted September 14, 2021 Posted September 14, 2021 Better to report it as a breach and it not be needed, then fail to report it and it actually should've been, as far as I see it. It's a safeguarding issue as much as anything else.
xicor Posted September 14, 2021 Author Posted September 14, 2021 I just thought I'd give abit more context, the form is sent to all schools its a de-registration form from what I understand its used when a child leaves the schools the admin uses the form to fill in the child's details, why they are leaving the school and contact information for the parents etc this also includes the child's full name, dob, parents details I spoke with the ICO and they informed me that it depends on the organisation if they want to report it or not, they say they have to prove that the information leak will not cause harm to the individual
Popular Post GrumbleDook Posted September 16, 2021 Popular Post Posted September 16, 2021 So we have the name of a child and DoB, their parents(s), their address, other contact details and the reasons for leaving (which can vary a *lot*). And this is on an online form, that anyone with the link to it can access, that anyone with that link has full edit rights to all the data. And these could be children who have left due to a lot of difficulties or sensitive circumstances? OK, look at it this way. You are being asked to shared data with another organisation. You have a responsibility to make sure that suitable controls are in place for the security of that data. Do you have an agreement in place with the Council? Has there been any risk assessment on this? Are there any children at your school who could be at risk if their data was not kept secure? If so, then you can raise a concern to your DPO about this as a data breach for the school. Just because it is the council, it does not mean it is automatically ok. It also does not mean that a risk assessment done 18 months ago will have covered something like this. 5
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now