Jump to content

Recommended Posts

Posted

Just wanted you check with the edubrains if I have to take action in this scenario:

 

Sent secure census XML to LA for them to upload to DfE. Asked for some of the reports from COLLECT to be returned to me via the same secure file exchange system.

 

Instead of the reports I received my census XML and those of 6 other schools in the LA.

 

I reported the mistake to the LA. Am I under any obligation of reporting the breach to the other schools, my schools DPO, or the ICO.

 

I feel I have done my part and anything else is shit stirring. On the other hand I would like to know if I was the other school and what action has been taken.

Posted
Just my view, I would have suggested you passed the situation to your DPO in the first instance and let them decide what action to take. Given where you are now, report to your DPO and the step you have taken and await further guidance.
  • Thanks 1
Posted
I second the above. Report to your school's DPO & they can be the one to determine the next stage of action. You're right that you'd want to know if your data has been mishandled. With any luck the LA & your DPO should share your view & fulfil their due diligence to disclose to the other parties.
Posted
I disagree. Your DPO can advise, but it isn't your data which has been breached and you didn't breach it, therefore it isn't really your/your DPO's issue. Report it to the LA (or ICO if you want, but I sense you don't since you describe telling the other schools as shit stirring), and it is then their responsibility to report to the other schools. If you have a friendly relationship with any of the other schools, maybe tell them but you're not obliged to do so.
Posted
OP doesn't say which census data but if it includes children's data there is a safe-guarding risk and that's everyone's responsibility so personally I wouldn't be comfortable leaving the issue with the LA only. So on reflection, and depending on the data content, it may be good practice to report to the DSL as well as the DPO.
Posted

When we had our LA breach pupil data our DPO had us contact the ICO.

 

At the time the ICO said the LA should do the reporting, but we were welcome to offically bring it to the ICO's attention if we felt the LA weren't taking the necessary steps.

  • Thanks 2
Posted
At the time the ICO said the LA should do the reporting, but we were welcome to offically bring it to the ICO's attention if we felt the LA weren't taking the necessary steps.

 

That's a good point. Person at the LA might go "oh shit, I'll get in trouble for that" and not tell anyone, especially if that email wasn't an isolated incident. Going through ICO at least ensures appropriate steps are taken.

Posted

Don't forget that as part of your data sharing obligations, you need to make sure that data you share with another data controller is dealt with securely.

I'm sure your DPO would like to remind the LA about that and ask for what the remedial plan is to sort this issue out?

Just an idea.

Posted

Thanks all.

 

I've reported it up the chain and the school is contacting the LA for confirmation that they've informed the other schools and the ICO.

 

Someone mentioned it depended on what data it was above...it was the full census XML file that gets uploaded to collect for the DfE to see - so pretty much a lot of sensitive info.

  • 5 months later...
Posted
Quite a while since the last post. But to see how things turned out, did you ever hear back from the LA or from ICO? I'm particularly keen to understand if ICO sent advisory notes, but realise they might not get to you.
Posted

If I was the LA - I probably would not have reported it. If it did report, it would generally get triaged by the ICO investigations team. I was previously at the ICO, and I would probably triage it at the lowest risk rating (P4 rating)

 

You can view the rating system on the FOI reply below, its at page 48.

 

https://ico.org.uk/media/about-the-ico/disclosure-log/4018514/investigations-manual-final-disclosure-redacted-3.pdf

 

The data was sent via secure transfer, and therefore protected in transit. Whilst the school received other pupils data, I would take into consideration it was received and viewed by a trusted professional. On balance, I would have trust the school deleted the data and would not further use the data in a malicious or negligent manner.

 

Presuming the ICO followed that same trail of thought, the breach report would be marked as P4 and either closed or closed with advice around double checking data before it is sent. The ICO may have asked some follow up questions to determine the P rating, such as whether the school who received the incorrect data had actually deleted it. They may have even just put that as part of its closure advice.

 

There is nothing within the original post that would make me feel it would justify a higher P rating, and therefore require a full investigation or warrant any regulation action.

  • Thanks 1
Posted

Interesting - even more interesting the manual was published following a FOI request!

 

On the rating, wouldn't the special category data within the census mean it gets a P3 as described in the table on page 43?

Posted (edited)
Interesting - even more interesting the manual was published following a FOI request!

 

On the rating, wouldn't the special category data within the census mean it gets a P3 as described in the table on page 43?

 

It’s quite possible a case office could assign it as P3 and I wouldn’t particular object - It isn’t an exact science and the P rating scale is for guidance, the case officer will apply their own judgment assisted by the scale.

 

For myself, the fact the data was exposed to a professional working within a school, who will be DBS checked etc, I would apply a P4, not withstanding the breach included special category data.

 

To be honest, the way you handle a P3 and P4 would be pretty much the same, if not exactly the same. It’s the P1 and P2H cases where you want to be spending most of your time and resources.

Edited by rom1984
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...