Jump to content

Recommended Posts

Posted

Shocking. Anyone got a list of the other 2800 companies the DfE was giving access to?

 

Likely the data has come from schools so we are still the owners then DFE processors? Does these leave us open to any kind of backlash? Does anyone have a data impact assessment for the DFE?

 

The worse thing here isn't the breach itself it's that everyone at the DfE thought this was OK?

Posted
Does it say anywhere in that article which lawyers the DfE used in this matter? It's just that I've been selling access to data to a predatory industry, and I totally don't wanna go to jail.
Posted

Whilst it may seem strange, and a tad annoying, that there is no fine after yet another issue with the DfE and that flippin' database, by not applying the fine the ICO team involved get far more leverage for change and improvements. As for schools, other than for failure to pay the registration fee, no school has been fined (or at least no report has ever been published showing a fine and no FOI request has shown a fine either). It is not that schools will never be fined, more a case of telling you that you would have been fined £X and that is how much you now need to internally invest instead ... oh, and we will be watching and you have to explain everything to us on a regular basis.

And that model *is* something that has been applied to schools and trusts.

 

There could also be a serious flood of complaints and legal actions by parents on behalf of their children or those adults who have been affected by this (i.e. folk still in the database who have now left school, etc.), but there needs to be clear evidence of distress. Ambulance chasing firms have already been circling.

 

What does it mean for schools though? You may get more questions about what data you give the LA and the various Govt departments, including the Education Department of your country (remember, it is the DfE that this is against, not the equivalents in NI, Wales or Scotland), and you might even have things like attempts to withdraw consent to send data to LA/DfE or objections raised about it. Speak to your DPO about making sure you have a clear message already for children and parents, and can point to the requirements (legal obligations/Public Task) on returns, make sure the details are in your RoPA and even complete a risk assessment if needed.

Posted

I can understand the logic here, but if the ICO levy'd such a fine against a private organisation whoever within that organisation screwed up badly enough to cause a £10million fine would likely be sacked. Questions would be asked at board level as well.

The risk here is that there's no incentive for accountability. Just a "ah well, don't do it again"

Posted (edited)

"The ICO found the DfE continued to grant Trustopia access to the database when it advised the Department that it was the new trading name for Edududes Ltd, which had been a training provider."

 

Let me check I've got this right. A company contacted DfE and said "hey, we're the new name for XYZ Ltd who you share data with, can we have all that data again please?" and the DfE said "hey, nice name. Here ya go" without checking the validity of the claim?

Edited by enjay
Posted
I can understand the logic here, but if the ICO levy'd such a fine against a private organisation whoever within that organisation screwed up badly enough to cause a £10million fine would likely be sacked. Questions would be asked at board level as well.

The risk here is that there's no incentive for accountability. Just a "ah well, don't do it again"

 

The people who are there now may not have been the people originally involved, and those there now may be firefighting and dealing with politics!

 

One of the problems with Data Sharing Agreements is that the processes involved need to be tight, the oversight needs to be there and there is a huge chunk of training involved. We all know how much effort has gone into schools around Safeguarding ... and we still get gaps.

 

We also don't know what has gone on internally either. Maybe some future FOI might enlighten us, but right now they are probably just trying to deal with things. And remember that the size of the fine will take into account any ongoing issues that have previously been complained about. Saying that, I wouldn't want the job of trying to manage this and the folk who are there, are good and trying to improve things ... and some of the improvements may be in spite of the political upheaval and shenanigans that have gone on over the last 12 years! To be frank ... this is almost ready to go into the politics area ...

Posted
One of the problems with Data Sharing Agreements is that the processes involved need to be tight, the oversight needs to be there and there is a huge chunk of training involved. We all know how much effort has gone into schools around Safeguarding ... and we still get gaps.

 

The issue isn't just with the data sharing agreement, but also that a company can just say "hi there, I'm allowed this data" and be given it. We have financial processes which state any change of bank details must be confirmed verbally by the company, that would have solved that particular breach. That said, since DfE then revoked access from another 2600 companies, it seems like this was a good hole to find.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...