Jump to content

Recommended Posts

Posted
I'll happily tell ClassCharts what we saw and notify the schools in question directly, but not if that incriminates me or the parents who (hypothetically...) sent me screen shots.

But did they (your parents) click through, or just screenshot the first page?

 

My parents only screenshot the first page with the homework summary (etc) and the Head's announcements - you can see my screenshot in my earlier post - so I've no concerns about them taking a screenshot in order to contact me to report the issue.

 

Maybe I could/should ask them to delete the screenshot from their end, but at the end of the day all they've seen so far is a name and a school - in this one particular instance.

Posted
I can't say I know definitely but I think intent would go a long way, here. If the Parents have only emailed you then there is only the intent to inform not be malicious. There is also the fact that the parents haven't done anything to get access, they have been given access by ClassCharts. I think any company that pursue a Computer Misuse Act against a school and parents when their system was spewing out data would be looked upon dimly. I know we would drop them in an instant if that happened.
Posted
But did they (your parents) click through, or just screenshot the first page?

 

Fair point. I'm not familiar with the view of ClassCharts, but you're right - all the screen-shots I have been sent are of the "Dashboard" home page.

 

Interesting to note when looking at these that they show siblings, not two random students, and don't show the correct child at all.

Posted
Which brings us back to my earlier question about Computer Misuse Act. If I open the app for my kid's school and see 5 other kids in 5 other schools, I know I'm not meant to see that information. So, am I breaking any laws by clicking through to that data and screenshotting it? It's like if you sent me an email intended for someone else - if during the first paragraph I realise it's not for me and reply so, that's fine, but I shouldn't carry on reading the whole email and any attachments and then notify you.

 

I'll happily tell ClassCharts what we saw and notify the schools in question directly, but not if that incriminates me or the parents who (hypothetically...) sent me screen shots.

 

It's a valid question and one that sadly means some even more serious safeguarding concerns aren't reported for similiar concerns with other acts of law. In practice, I have been assured that the law enforcers take a reasonable approach and won't pursue anyone without good reason. In this instance, there may be a technical breach of the law, but I very much doubt it would stand up in court as it wouldn't meet the target for realistic prospect of prosecution, so Crown Prosecution wouldn't be interested, besides I can't see it being in the public interest. What I'd like to see is the legal regulations are updated to provide unequivocal protection for school and other relevant staff from prosecution for reporting issues like this.

 

In the specific case you are talking about, continued unauthorised access of the data is unlikely to lead to prosecution, but I would say unwise - if the level of access become excessive, the chances of getting in to hot water obviously increase. It's worth noting even without a prosecution, consequences could still come home to roost, such as dismissal for gross misconduct. Certainly passing any of that information would not be sensible, so your strategy of not continuing beyond the point of realising you are accessing unauthorised data is highly likely to keep you out of trouble.

Posted

So as best I can tell, there are no documented changes on the latest version. However, I see one diffference of note (ignoring the un-capitilising of a word in the previous version - no pedants here :rolleyes:) and that is as follows:

 

Changes2.JPG

 

I however note that 'Pendo' is documented as being added as of 31/10/2022. Thanks again to web.archiveorg, it shows the update to the list didn't happen.

 

To conclude, all-in-all nothing but some version control updates.

 

As a side note, I note that TES retain the right to update these policies and it's the schools job to check them - see Section 8. Now, that's a list of 15 third parties that TES might be sharing your pupils data with. Hands up who:

 

a) has a DPIA document for Classcharts use

b) considered and documented the list of third parties and OK'd those

c) constanly check the TES site in case the DPIA needs updating.

 

It would be interesting to know the number of Classchart schools, and the number that answer 'Yes' for question a)

 

In mathematical terms, I expect the sequence of numbers thereafter are best described as a curve of exponential decay!

  • Thanks 1
Posted

It is worth mentioning that the Privacy Notice/Privacy Policy on a website for a company is usually just that, their notice to you what they do as a company, running their business. This is not a contract or agreement.

The Data Processing Agreement is where the relationship between the school (data controller) and ClassCharts (data processor) is set out.

  • Thanks 2
Posted
Looks like a copy of their template DPA can be found yonder: https://www.edukey.co.uk/wp-content/uploads/Edukey_DPA.pdf

Section 4 covers it all and uses the wording 'without delay' more than once. So, if you know a school whose data is breached, they should have been notified 'without delay'.

 

I've been on the receiving end of this process and whilst I know it's stressful at their end, it is this end too and extremely time consuming and therefore costly.

 

We were notified with a 'assume all data breached' at the outset, but eventually it was concluded, that with near certainity, no data was lost. The lack of information was always the hardest position, as we had to balance undue stress for notifiying vulnerable people unnecessay against then finding out from a third party im an uncontrolled manner. So please, TES/Classcharts, tell us what you know now, and update us as you proceed.

Posted
Thank you for your patience on this and we are sorry it has taken some time to respond.

 

Yesterday we were made aware that a small number of customers were experiencing data issues when using Class Charts, following a product update.

 

We took immediate action to resolve the issue, but there was a very short period yesterday morning when a small number of parent or teacher users could be served up with the incorrect information.

 

Once resolved, we started investigations to understand how this could happen, who had been affected, and safeguard against anything similar in the future. There is no evidence of a malicious attack or data breach.

 

We take any kind of instance like this, no matter how limited, with the utmost seriousness. We wanted to get to a point in our investigations to assure you that we have taken steps to limit the impact and take remedial action with our systems.

We are very sorry that this occurred, and we sincerely apologise for any concern and inconvenience caused.

 

Kind regards

Class Charts

 

A breach has occurred.

  • Thanks 4
Posted
Section 4 covers it all and uses the wording 'without delay' more than once. So, if you know a school whose data is breached, they should have been notified 'without delay'.

 

They might not know which schools had their data shared to other parents and which didn't.

 

On closer inspection of some of the screen shots I've been given, we have some instances where the students at the top attend School 1 but the announcements come from School 2! In each instance where there is more than one child included, they're siblings... but not necessarily at the same school which is interesting, it seems like Parent A got mixed with Parent B when they logged in.

 

Has anyone had direction from their DPO about what we should say to parents at this stage?

Posted

The bit that has me concerned is this:

provisionmapclasscharts.PNG

I'm not sure if this exposes anything in Provision Map to parents, but we have no reason to suspect that the type of error that occurred for Parent accounts could not happen to staff accounts... and if it did there would be significantly more Sensitive data at risk.

 

TES/Edukey will need to go into some detail about their back end architecture and data security models/boundaries to put my fears to rest.

Posted

Yes I had that email saying "There is no evidence of a malicious attack or data breach."

 

The fact that they appear to be trying to back pedal and cover this data breech up is worrying given the amount of data schools trust them with. They also don't appear to have notified the ICO judging by their language. I'll leave the rest up to my DPO.

Posted (edited)

What is a personal data breach?

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This means that a breach is more than just losing personal data.

Source: https://ico.org.uk/for-organisations/law-enforcement/guide-to-le-processing/personal-data-breaches/#:~:text=A%20personal%20data%20breach%20means,than%20just%20losing%20personal%20data.

 

"a small number of parent or teacher users could be served up with the incorrect information" sounds like a data breach considering the nature of the incorrect information.

Edited by WShippin
Posted

Either the Edugeeks who have messaged here to say they have been told parents saw another child's info instead of their own have been misinformed, or TES just lied about a data breach. If anyone here has been sent hard evidence, screenshots, etc, you probably should work with your DPO to report this to ICO.

 

It'd be nice to know for sure if we've got a definite breach of student info.

Posted (edited)

 

Has anyone had direction from their DPO about what we should say to parents at this stage?

 

Not yet. For most schools I am expecting the advice to be "...there was a breach at a national provider, for a period of xx minutes parents logging on may have seen details belonging to another child, most likely from another school. We understand that nationally the number of individuals whose data was exposed is very small. Unfortunately due to the nature of the system failure the provider has not been able to be sure whose data specially was exposed, except in cases where that individual breach was reported them. The provider has begun the process of notifying any individual whose data they know to have been leaked. At this time we do not believe any data belonging to our students, parents or staff has been exposed. We apologise etc etc."

Edited by psydii
  • Thanks 1
Posted
What is a personal data breach?

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This means that a breach is more than just losing personal data.

Source: https://ico.org.uk/for-organisations/law-enforcement/guide-to-le-processing/personal-data-breaches/#:~:text=A%20personal%20data%20breach%20means,than%20just%20losing%20personal%20data.

 

"a small number of parent or teacher users could be served up with the incorrect information" sounds like a data breach considering the nature of the incorrect information.

 

They are trying to walk a line. The DPO-in-us-all know this was a data breach, but the public perception of data breaches is the massive dumping of entire data sets into the open, which this most certainly was not. They didn't leak *everyones* data, they just leaked data of one or two individuals per parent that logged on while the faulty code was running.

 

Yes its still a data breach, and it is bad because it shows there isn't the segregation of data that we naively expected, but it isn't ICO fine inducingly awful, and they probably wont have to make and insurance claim to cover the costs of putting it right. Communicating that is challenging, and perhaps they ought to have put a caveat such as no "evidence of... mass data breach") to avoid this criticism.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...