Jump to content

Recommended Posts

Posted

So bit of an odd one.

 

Just had a member of staff come to me saying she got an email "accidentally" forwarded to her from a member of staff at another school.

 

This email had pupil details including attendance, medical details and other personal information, none of which was encrypted. I refused to look at the email contents but did check the mail headers to confirm it was a legit email and not some weird phishing scam.

 

The member of staff phoned the school that the email came from and informed them what had happened. They replied that they had a member of staff with the same name as them. The domains are totally different though and my member of staff says they have never had any contact with the person that sent the email so no idea how it got to them.

 

They also seemed to blow it off as not that big a deal.

 

I'm not sure what we should be doing from here (if anything)? Given that it was sent to one of our schools email addresses and not a personal one and the nature of the information in the email I would assume we are legally obligated to report it to somewhere?

Posted

Start with your own DPO and see where that takes you?

 

You can have your actions documented and show that you did what was required, if questions are asked.

  • Thanks 1
Posted

I'd ensure the email was deleted completely then email the person that sent it, copy in their office at or head at address to say what you received, what you have done and advise that they should report the data breach in line with their policies and procedures.

 

I don't think there is a requirement for you to do any more than that.

  • Thanks 1
Posted
The member of staff phoned the school that the email came from and informed them what had happened. They replied that they had a member of staff with the same name as them.

 

Isn't that breach number 2, confirming the name of an employee?

 

I'd ensure the email was deleted completely then email the person that sent it, copy in their office at or head at address to say what you received, what you have done and advise that they should report the data breach in line with their policies and procedures.

 

I don't think there is a requirement for you to do any more than that.

 

Agreed, I think that's all you need to do. You could report it directly to the ICO or find out who their DPO is, but that might not be good for ongoing relations with the other school.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...