Jump to content

Recommended Posts

Posted

Our DPO (Veritau) has advised us:

 

Class Charts act as a data processor for the school therefore they must inform the school of any data breaches suffered and provide details of the impact. My advice would be to contact Class Charts directly and ask them to confirm whether any of your school’s data has been compromised due to this breach. If so, they should confirm how many individuals this has affected and what data was made visible.

We have sent such an email to Class Charts support, TES help and The DPO Centre (TES's outsourced DPO).

 

Will report back if I hear anything.

  • Thanks 2
Posted

I've had an email from CC stating "There is no evidence of a malicious attack or data breach."

 

I cannot see how they can possibly treat this as anything other than a data breach.

Posted
This is part of the issue, we can't tell unless someone contacts the school to let us know they have seen our data or ClassCharts lets us know. I have less than full confidence we will be told anything, so we will never know if our data was kept secure or our data was left open and we just haven't been told about it. Having been shafted by one company already in this fashion I am getting a bit fed up with Education companies playing fast and loose with GDPR, and data security. Our SLT currently do not want to open ClassCharts back up to our parents, and I agree with them but also realise that actually this does nothing to protect them.

 

We had two other schools ring us to say their parents had seen data of our students/pupils as they recognised the school logo and contacted us to make us aware. I am reporting to the ICO as yet I've not had anything from ClassCharts following regarding the breach despite two emails and a phone call requesting a written response.

Posted
We had two other schools ring us to say their parents had seen data of our students/pupils as they recognised the school logo and contacted us to make us aware. I am reporting to the ICO as yet I've not had anything from ClassCharts following regarding the breach despite two emails and a phone call requesting a written response.

I will be taking the same action. Truly appalling response from ClassCharts.

  • Thanks 1
Posted

One of our schools used to use classcharts. wonder if they actually delete all data ,

 

we do use their parents evening system though

 

Are they at Bett to get clobbered.!? [emoji23]

  • Thanks 2
Posted

Straight up example of why this can be an issue.

 

Child A has moved schools due to legal complications regarding a relative. There are restraining and contact orders in place. Relative must not know the whereabouts of Child A at any point.

 

Relative has a child at another school. Relative logs in to see their child's data on ClassCharts, yet they are presented with other childrens information. Including Child A.

Relative is now aware of Child A's location.

 

It's tenuous, but it's a good example of why this can be a MAJOR issue and should be treated as such.

  • Thanks 2
Posted
They didn't leak *everyones* data, they just leaked data of one or two individuals per parent that logged on while the faulty code was running.

 

Agreed. I was told one parent got 5 students every time, but all the screenshots I've seen show one or two pupils, and when there are two they are siblings so I suspect Parent A got given Parent B's access. Logging out and back in would have then given them Parent C's access.

Posted
Still not had any official confirmation from classcharts that this issue is resolved, so I rang them and was told that I had to email them requesting that they email me the confirmation, how are they getting away with this? They are taking the proverbial
Posted
Please, if you're a school affected by this, make a report to the ICO. Shouldn't take more than a couple of minutes and may force them to start taking things seriously and do better for any future issues.
  • Thanks 2
Posted
Still not had any official confirmation from classcharts that this issue is resolved

 

I got the same email others have posted on here (the one which denies a data breach, despite our screenshots to the contrary), but that was in response to a ticket I raised with them when we spotted the problem. It looks like they're replied to schools who emailed them but made no other statement.

 

Our DPO advised us to contact the ICO directly, which we've done. I think the DPO is also reporting on the collective behalf of their other schools too.

Posted
Agreed. I was told one parent got 5 students every time, but all the screenshots I've seen show one or two pupils, and when there are two they are siblings so I suspect Parent A got given Parent B's access. Logging out and back in would have then given them Parent C's access.

 

classic caching issue, steam had one a fair few christmasses ago

Posted

I asked for explicit confirmation that they were not treating the issue as a data breach and received the following:

 

We will always aim to act quickly and would rather do more than less. It is important to be clear, however, that there was not a Data Breach. As it was not a data breach, it is not a reportable incident under the requirements of the ICO.

Despite very early actions to notify all our customers through in-product messaging, we removed that message as our investigations revealed it was inaccurate as per the above, the issue was caused by a product update which was then swiftly removed.

We then took the decision to hold on any further communications until we were absolutely sure what we could say.

  • Thanks 4
Posted
I've had an email from CC stating "There is no evidence of a malicious attack or data breach."

 

I cannot see how they can possibly treat this as anything other than a data breach.

 

I can't comment on this specifically but reading the thread, I wonder if their definition of a data breach is theft of data by a malicious third party.

Posted
I can't comment on this specifically but reading the thread, I wonder if their definition of a data breach is theft of data by a malicious third party.

 

I suspect the same. Of course that's not the ICO's definition of a data breach!

Posted

Might it be worth pointing classcharts to something like this:

 

from: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/

 

"A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data.

 

Example

Personal data breaches can include:

 

  • access by an unauthorised third party;
  • deliberate or accidental action (or inaction) by a controller or processor;
  • sending personal data to an incorrect recipient;
  • computing devices containing personal data being lost or stolen;
  • alteration of personal data without permission; and
  • loss of availability of personal data."

  • Thanks 1
Posted

The daft thing is, if they report it to ICO, things will blow over quickly, especially given how short a period the issue was live and how quickly resolved. So maybe we can say they end up in tepid water.

 

A carefully worded email should be sent to schools, who can then pass on details as they see fit. That should be possible even if they don't know each actual breach details. Beyond that, they might get a ICO might advise that steps should be taken on preventing the issue in the future.

 

By going in to denial, when a cluster of schools in the meantime notify ICO of the issue, then they are likely to end up in steaming hot water!

  • Thanks 2
Posted

It's evident many IT professionals on here know a lot more about data breaches than Class Charts do

 

Imagine logging into your banking and seeing someone else's balance (hopefully better than your own!), address, contact details etc

 

Complete sloped shoulder approach is infuriating

Posted
The daft thing is, if they report it to ICO, things will blow over quickly, especially given how short a period the issue was live and how quickly resolved. So maybe we can say they end up in tepid water.

 

A carefully worded email should be sent to schools, who can then pass on details as they see fit. That should be possible even if they don't know each actual breach details. Beyond that, they might get a ICO might advise that steps should be taken on preventing the issue in the future.

 

By going in to denial, when a cluster of schools in the meantime notify ICO of the issue, then they are likely to end up in steaming hot water!

 

Yup, a mature approach to incident management like this is to accept that the incident has happened and that the best course of action is to be honest about it and conduct a proper 'lessons learned' process and be honest about disclosing what went wrong and actions taken to ensure it can't happen again. The reputational damage from trying to wriggle out of it is always worse than the reputational damage from just holding your hands up and admitting to the problem.

  • Thanks 3
Posted
Yup, a mature approach to incident management like this is to accept that the incident has happened and that the best course of action is to be honest about it and conduct a proper 'lessons learned' process and be honest about disclosing what went wrong and actions taken to ensure it can't happen again. The reputational damage from trying to wriggle out of it is always worse than the reputational damage from just holding your hands up and admitting to the problem.

 

... 110%

Posted
Yup, a mature approach to incident management like this is to accept that the incident has happened and that the best course of action is to be honest about it and conduct a proper 'lessons learned' process and be honest about disclosing what went wrong and actions taken to ensure it can't happen again. The reputational damage from trying to wriggle out of it is always worse than the reputational damage from just holding your hands up and admitting to the problem.

 

120%

 

Not just for security incidents, all types of IT change benefits from postmortem culture. There's an interesting article here: https://sre.google/sre-book/postmortem-culture/

Posted (edited)
120%

 

Not just for security incidents, all types of IT change benefits from postmortem culture. There's an interesting article here: https://sre.google/sre-book/postmortem-culture/

 

We avoid the term ‘post mortem’ as that suggests looking for faults, but we do carry out a change management process that includes a post-change review. It’s a great habit to build as it’s also good to capture what went especially well after a successful event, so you can do it again next time. The amount of extra work and time when an event was successful but unremarkable is negligible with our system, the payoff when things aren’t quite so smooth is fantastic.

Edited by Roberto
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...