gh5000 Posted October 26, 2022 Posted October 26, 2022 Just wanted you check with the edubrains if I have to take action in this scenario: Sent secure census XML to LA for them to upload to DfE. Asked for some of the reports from COLLECT to be returned to me via the same secure file exchange system. Instead of the reports I received my census XML and those of 6 other schools in the LA. I reported the mistake to the LA. Am I under any obligation of reporting the breach to the other schools, my schools DPO, or the ICO. I feel I have done my part and anything else is shit stirring. On the other hand I would like to know if I was the other school and what action has been taken.
Ditto Posted October 26, 2022 Posted October 26, 2022 Just my view, I would have suggested you passed the situation to your DPO in the first instance and let them decide what action to take. Given where you are now, report to your DPO and the step you have taken and await further guidance. 1
Tom_M Posted October 27, 2022 Posted October 27, 2022 I second the above. Report to your school's DPO & they can be the one to determine the next stage of action. You're right that you'd want to know if your data has been mishandled. With any luck the LA & your DPO should share your view & fulfil their due diligence to disclose to the other parties.
enjay Posted October 27, 2022 Posted October 27, 2022 I disagree. Your DPO can advise, but it isn't your data which has been breached and you didn't breach it, therefore it isn't really your/your DPO's issue. Report it to the LA (or ICO if you want, but I sense you don't since you describe telling the other schools as shit stirring), and it is then their responsibility to report to the other schools. If you have a friendly relationship with any of the other schools, maybe tell them but you're not obliged to do so.
Ditto Posted October 27, 2022 Posted October 27, 2022 OP doesn't say which census data but if it includes children's data there is a safe-guarding risk and that's everyone's responsibility so personally I wouldn't be comfortable leaving the issue with the LA only. So on reflection, and depending on the data content, it may be good practice to report to the DSL as well as the DPO.
andy_b Posted October 27, 2022 Posted October 27, 2022 When we had our LA breach pupil data our DPO had us contact the ICO. At the time the ICO said the LA should do the reporting, but we were welcome to offically bring it to the ICO's attention if we felt the LA weren't taking the necessary steps. 2
enjay Posted October 27, 2022 Posted October 27, 2022 At the time the ICO said the LA should do the reporting, but we were welcome to offically bring it to the ICO's attention if we felt the LA weren't taking the necessary steps. That's a good point. Person at the LA might go "oh shit, I'll get in trouble for that" and not tell anyone, especially if that email wasn't an isolated incident. Going through ICO at least ensures appropriate steps are taken.
GrumbleDook Posted November 2, 2022 Posted November 2, 2022 Don't forget that as part of your data sharing obligations, you need to make sure that data you share with another data controller is dealt with securely. I'm sure your DPO would like to remind the LA about that and ask for what the remedial plan is to sort this issue out? Just an idea.
gh5000 Posted November 2, 2022 Author Posted November 2, 2022 Thanks all. I've reported it up the chain and the school is contacting the LA for confirmation that they've informed the other schools and the ICO. Someone mentioned it depended on what data it was above...it was the full census XML file that gets uploaded to collect for the DfE to see - so pretty much a lot of sensitive info.
Ditto Posted April 24, 2023 Posted April 24, 2023 Quite a while since the last post. But to see how things turned out, did you ever hear back from the LA or from ICO? I'm particularly keen to understand if ICO sent advisory notes, but realise they might not get to you.
rom1984 Posted April 24, 2023 Posted April 24, 2023 If I was the LA - I probably would not have reported it. If it did report, it would generally get triaged by the ICO investigations team. I was previously at the ICO, and I would probably triage it at the lowest risk rating (P4 rating) You can view the rating system on the FOI reply below, its at page 48. https://ico.org.uk/media/about-the-ico/disclosure-log/4018514/investigations-manual-final-disclosure-redacted-3.pdf The data was sent via secure transfer, and therefore protected in transit. Whilst the school received other pupils data, I would take into consideration it was received and viewed by a trusted professional. On balance, I would have trust the school deleted the data and would not further use the data in a malicious or negligent manner. Presuming the ICO followed that same trail of thought, the breach report would be marked as P4 and either closed or closed with advice around double checking data before it is sent. The ICO may have asked some follow up questions to determine the P rating, such as whether the school who received the incorrect data had actually deleted it. They may have even just put that as part of its closure advice. There is nothing within the original post that would make me feel it would justify a higher P rating, and therefore require a full investigation or warrant any regulation action. 1
Ditto Posted April 24, 2023 Posted April 24, 2023 Interesting - even more interesting the manual was published following a FOI request! On the rating, wouldn't the special category data within the census mean it gets a P3 as described in the table on page 43?
rom1984 Posted April 24, 2023 Posted April 24, 2023 (edited) Interesting - even more interesting the manual was published following a FOI request! On the rating, wouldn't the special category data within the census mean it gets a P3 as described in the table on page 43? It’s quite possible a case office could assign it as P3 and I wouldn’t particular object - It isn’t an exact science and the P rating scale is for guidance, the case officer will apply their own judgment assisted by the scale. For myself, the fact the data was exposed to a professional working within a school, who will be DBS checked etc, I would apply a P4, not withstanding the breach included special category data. To be honest, the way you handle a P3 and P4 would be pretty much the same, if not exactly the same. It’s the P1 and P2H cases where you want to be spending most of your time and resources. Edited April 24, 2023 by rom1984 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now