Popular Post sigma Posted November 6, 2022 Popular Post Posted November 6, 2022 https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/11/department-for-education-warned-after-gambling-companies-benefit-from-learning-records-database/ An ICO investigation found that the DfE’s poor due diligence meant a database of pupils’ learning records was ultimately used by Trust Systems Software UK Ltd (trading as Trustopia), an employment screening firm, to check whether people opening online gambling accounts were 18. The DfE has overall responsibility for the learning records service database (LRS), which provides a record of pupil’s qualifications that education providers can access. The ICO found the DfE continued to grant Trustopia access to the database when it advised the Department that it was the new trading name for Edududes Ltd, which had been a training provider. Trustopia was in fact a screening company and used the database for age verification, a service they offered to companies including GB Group, which helped gambling companies confirm customers were over 18. This data sharing meant the information was not being used for its original purpose. This is against data protection law. John Edwards, UK Information Commissioner, said: “No-one needs persuading that a database of pupils’ learning records being used to help gambling companies is unacceptable. Our investigation found that the processes put in place by the Department for Education were woeful. Data was being misused, and the Department was unaware there was even a problem until a national newspaper informed them. “We all have an absolute right to expect that our central government departments treat the data they hold on us with the utmost respect and security. Even more so when it comes to the information of 28 million children. “This was a serious breach of the law, and one that would have warranted a £10 million fine in this specific case. I have taken the decision not to issue that fine, as any money paid in fines is returned to government, and so the impact would have been minimal. But that should not detract from how serious the errors we have highlighted were, nor how urgently they needed addressing by the Department for Education.” 5
Roberto Posted November 6, 2022 Posted November 6, 2022 Absolutely abysmal performance by the DfE here.
titch Posted November 6, 2022 Posted November 6, 2022 Shocking. Anyone got a list of the other 2800 companies the DfE was giving access to? Likely the data has come from schools so we are still the owners then DFE processors? Does these leave us open to any kind of backlash? Does anyone have a data impact assessment for the DFE? The worse thing here isn't the breach itself it's that everyone at the DfE thought this was OK?
titch Posted November 6, 2022 Posted November 6, 2022 Answered my own question I think.... https://www.gov.uk/government/publications/dfe-external-data-shares Think we can get some kind of SSO going on so the kids don't forget their Betfair logins now? Maybe Wonde can help? 4
junz Posted November 6, 2022 Posted November 6, 2022 https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/11/department-for-education-warned-after-gambling-companies-benefit-from-learning-records-database/ as any money paid in fines is returned to government, Wouldn't the above apply to schools as well?! 1
titch Posted November 6, 2022 Posted November 6, 2022 Helpful to know we are exempt from fines as well.
jthompson Posted November 6, 2022 Posted November 6, 2022 Does it say anywhere in that article which lawyers the DfE used in this matter? It's just that I've been selling access to data to a predatory industry, and I totally don't wanna go to jail.
titch Posted November 6, 2022 Posted November 6, 2022 You should be able to get legal aid, paid for by the government, to pay the government for the government fine.
junz Posted November 6, 2022 Posted November 6, 2022 Seems like they are making up rules as they go along.
GrumbleDook Posted November 7, 2022 Posted November 7, 2022 Whilst it may seem strange, and a tad annoying, that there is no fine after yet another issue with the DfE and that flippin' database, by not applying the fine the ICO team involved get far more leverage for change and improvements. As for schools, other than for failure to pay the registration fee, no school has been fined (or at least no report has ever been published showing a fine and no FOI request has shown a fine either). It is not that schools will never be fined, more a case of telling you that you would have been fined £X and that is how much you now need to internally invest instead ... oh, and we will be watching and you have to explain everything to us on a regular basis. And that model *is* something that has been applied to schools and trusts. There could also be a serious flood of complaints and legal actions by parents on behalf of their children or those adults who have been affected by this (i.e. folk still in the database who have now left school, etc.), but there needs to be clear evidence of distress. Ambulance chasing firms have already been circling. What does it mean for schools though? You may get more questions about what data you give the LA and the various Govt departments, including the Education Department of your country (remember, it is the DfE that this is against, not the equivalents in NI, Wales or Scotland), and you might even have things like attempts to withdraw consent to send data to LA/DfE or objections raised about it. Speak to your DPO about making sure you have a clear message already for children and parents, and can point to the requirements (legal obligations/Public Task) on returns, make sure the details are in your RoPA and even complete a risk assessment if needed.
DrCheese Posted November 7, 2022 Posted November 7, 2022 I can understand the logic here, but if the ICO levy'd such a fine against a private organisation whoever within that organisation screwed up badly enough to cause a £10million fine would likely be sacked. Questions would be asked at board level as well. The risk here is that there's no incentive for accountability. Just a "ah well, don't do it again"
enjay Posted November 7, 2022 Posted November 7, 2022 (edited) "The ICO found the DfE continued to grant Trustopia access to the database when it advised the Department that it was the new trading name for Edududes Ltd, which had been a training provider." Let me check I've got this right. A company contacted DfE and said "hey, we're the new name for XYZ Ltd who you share data with, can we have all that data again please?" and the DfE said "hey, nice name. Here ya go" without checking the validity of the claim? Edited November 7, 2022 by enjay
jthompson Posted November 7, 2022 Posted November 7, 2022 Seemingly so, although the company contacted DfE, not ICO (I'm sure that was just a typo).
enjay Posted November 7, 2022 Posted November 7, 2022 Seemingly so, although the company contacted DfE, not ICO (I'm sure that was just a typo). Indeed. I've edited my post.
GrumbleDook Posted November 7, 2022 Posted November 7, 2022 I can understand the logic here, but if the ICO levy'd such a fine against a private organisation whoever within that organisation screwed up badly enough to cause a £10million fine would likely be sacked. Questions would be asked at board level as well. The risk here is that there's no incentive for accountability. Just a "ah well, don't do it again" The people who are there now may not have been the people originally involved, and those there now may be firefighting and dealing with politics! One of the problems with Data Sharing Agreements is that the processes involved need to be tight, the oversight needs to be there and there is a huge chunk of training involved. We all know how much effort has gone into schools around Safeguarding ... and we still get gaps. We also don't know what has gone on internally either. Maybe some future FOI might enlighten us, but right now they are probably just trying to deal with things. And remember that the size of the fine will take into account any ongoing issues that have previously been complained about. Saying that, I wouldn't want the job of trying to manage this and the folk who are there, are good and trying to improve things ... and some of the improvements may be in spite of the political upheaval and shenanigans that have gone on over the last 12 years! To be frank ... this is almost ready to go into the politics area ...
enjay Posted November 7, 2022 Posted November 7, 2022 One of the problems with Data Sharing Agreements is that the processes involved need to be tight, the oversight needs to be there and there is a huge chunk of training involved. We all know how much effort has gone into schools around Safeguarding ... and we still get gaps. The issue isn't just with the data sharing agreement, but also that a company can just say "hi there, I'm allowed this data" and be given it. We have financial processes which state any change of bank details must be confirmed verbally by the company, that would have solved that particular breach. That said, since DfE then revoked access from another 2600 companies, it seems like this was a good hole to find.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now