Jump to content

Recommended Posts

Posted

Hi all

 

i just discovered a council "without mentioning which one" has been sending a google forms to schools to fill in children's details, that form however was sent in edit mode meaning any recipient can download the results of the other schools, private information about their children,parents contact details etc.

 

My question is how is google forms managed on the top level ? and does google forms have an audit trail showing who and when the results were downloaded and from which IP address ?

 

P.S that form had the details of 7000+ children free to download by any school that got that link....

 

Best Regards,

Omar

Posted
Hi all

 

i just discovered a council "without mentioning which one" has been sending a google forms to schools to fill in children's details, that form however was sent in edit mode meaning any recipient can download the results of the other schools, private information about their children,parents contact details etc.

 

My question is how is google forms managed on the top level ? and does google forms have an audit trail showing who and when the results were downloaded and from which IP address ?

 

P.S that form had the details of 7000+ children free to download by any school that got that link....

 

Best Regards,

Omar

The control of the form is not easy to explain in this forum, but I do know this scenario can happen, the error is easily resolved, but there is a serious failing in the permissions.

 

Much more importantly, this looks like a very serious breach. Although it doesn't sound like your data, I feel you should notify both the council and the ICO immediately. The nature of the breach and safeguarding concerns need to be reviewed now. @GrumbleDook, could you wade in on this one.

 

I suspect it doesn't need saying, but please don't publish the council details or anything more.

  • Thanks 1
Posted

Please report to the council immediately. Feel free to PM me with the details as well.

Without knowing more details I wouldn’t want to make a longer comment other than it is a real concern.

  • Thanks 3
Posted

I have indeed reported this to everyone in the council that I could find an email for !

 

I got a call from the DPO today, saying that they have closed the form now, they however told me that they cannot find out who downloaded the form results or not. I don't use google forms so I don't know if they have a log that can show who downloaded the form results or not, does anyone here uses google forms and can confirm ?

Posted
I have indeed reported this to everyone in the council that I could find an email for !

 

I got a call from the DPO today, saying that they have closed the form now, they however told me that they cannot find out who downloaded the form results or not. I don't use google forms so I don't know if they have a log that can show who downloaded the form results or not, does anyone here uses google forms and can confirm ?

 

They should be able to find it in the Drive Audit Log inside Google Admin Console's reporting tools to see who has accessed the form, and therefore the data. Doesn't matter if they've downloaded the results or not if they've been able to see the responses inside the form itself.

Posted
problem is they shared this with every school in the borough, 100s of people would have accessed the from, is there any way to filter by who downloaded the data rather than just accessed the form ?
Posted (edited)
problem is they shared this with every school in the borough, 100s of people would have accessed the from, is there any way to filter by who downloaded the data rather than just accessed the form ?

 

Not that I'm aware of for CSV (if there is a responses Google Sheet, you can see who has viewed that) but like I say - anyone who has accessed the form with the editable link will have been able to see the data, so downloading that data is irrelavant - it has been exposed through sharing the edit link and exposing the "Responses" tab on the form. You have to assume that whoever had that link has opened it and been able to see the data/do something with it.

Edited by paulkerton
  • Thanks 1
Posted
Not that I'm aware of for CSV (if there is a responses Google Sheet, you can see who has viewed that) but like I say - anyone who has accessed the form with the editable link will have been able to see the data, so downloading that data is irrelavant - it has been exposed through sharing the edit link and exposing the "Responses" tab on the form.

 

I see what you mean, apparently the DPO doesn't think this should be reported to the ICO as it was only sent to schools

Posted
I see what you mean, apparently the DPO doesn't think this should be reported to the ICO as it was only sent to schools

 

It absolutely should be. When these changes kicked in Councils around the country were very determined to say schools were not part of their organisations and were on their own.

If you don't share a DPO, then it should be reported as a breach.

Posted (edited)

1. It doesn’t matter who could download it. An unauthorised party reading it is a data breach; no download has to be involved. Someone could have taken a screenshot, a photo with their phone camera or simply copied data belonging to your students onto paper using a pen.

 

2. It must be reported to the ICO. If they don’t do it then you must. Data from your school has been potentially* breached due to this form, so I suggest you get your own DPO to report your school’s data asap.

 

*Reporting doesn’t only involve known data breaches. It also involves potential data breaches. You don’t know if your data was accessed by unauthorised parties, but it could have been; that makes it reportable to the ICO.

Edited by elsiegee40
  • Thanks 3
Posted
1. It doesn’t matter who could download it. An unauthorised party reading it is a data breach; no download has to be involved. Someone could have taken a screenshot, a photo with their phone camera or simply copied data belonging to your students onto paper using a pen.

 

2. It must be reported to the ICO. If they don’t do it then you must. Data from your school has been potentially* breached due to this form, so I suggest you get your own DPO to report your school’s data asap.

 

*Reporting doesn’t only involve known data breaches. It also involves potential data breaches. You don’t know if your data was accessed by unauthorised parties, but it could have been; that makes it reportable to the ICO.

All of the above and should be reported within 72 hours, but in this case there is no need to delay. For ICO guidance, see https://ico.org.uk/for-organisations/sme-web-hub/72-hours-how-to-respond-to-a-personal-data-breach/

Posted (edited)

By your school's policy who is responsible for reporting breaches? This is their problem. Put it in writing to them and leave it well alone.

 

 

 

I've edited this post from how it may appear on the homepage. I kind of misread a couple of replies here. Initially I also wrote: "If they don't do it you must" I would advise that you call your union for support before bypassing your DPO and going against what the LA DPO has advised.

 

I now realise the the "you" meant "your employer", so the call your union bit is unnecessary, however you are aware of the breach and may disagree with the DPO's assessment, so it is probably worth bouncing this off your Union for advice in case things come unstuck later.

Edited by psydii
Posted

Did your school put any data up there? If so, it is also your breach as you were sharing data with the LA as another controller (I don't know the purpose of the form but so far it sounds like a data gathering exercise by the LA for something ... don't really need to know what, only whether it was for their benefit or not).

 

Did you do any checks to see if it was a secure area?

Was it checked against any DSA you may have in place, or legislation/regulation/instruction meaning you have to share the data?

 

See .... lots of reasons why you can kick up a fuss.

 

It might not be reportable, depending on the personal data involved and the risks (if any) to the individuals. I don't think the LA can acertain this fully and so they should be discussing it with schools to see what the impact is ... and quickly.

  • Thanks 3
Posted

Better to report it as a breach and it not be needed, then fail to report it and it actually should've been, as far as I see it.

It's a safeguarding issue as much as anything else.

Posted

I just thought I'd give abit more context, the form is sent to all schools its a de-registration form from what I understand its used when a child leaves the schools the admin uses the form to fill in the child's details, why they are leaving the school and contact information for the parents etc this also includes the child's full name, dob, parents details

 

I spoke with the ICO and they informed me that it depends on the organisation if they want to report it or not, they say they have to prove that the information leak will not cause harm to the individual

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...