Jump to content

Recommended Posts

Posted

Last week Class Charts had an IT issue in which the incorrect student record was presented to parents.

 

We had it reported by 3 parents that got information from students not in our schools, it was a random student from elsewhere in the country. It was confirmed at the time it was a wider issue not just affecting my trust.

 

We have chased Class Charts and we have been told that the issue is resolved (great) and it was only for a short period (also great) but that they don't consider it a data breach and its not reportable.

 

The message we got was clearly a stock answer and they refused to release further information.

 

The below is the reply from their "DPO team"

 

We carried out a full technical investigation after we experienced problems from the product update on Monday. I’d like to assure you, this was rolled back and fixed urgently to ensure that the cases of incorrect information being displayed were minimised. Our technical team have ensured any future updates and enhancements cannot cause similar issues.

 

Through all investigations we strictly follow ICO guidance. In line with this, what we experienced is not classed as a data breach, nor is it classed as a reportable incident. I understand the concern and why you have questioned this, but we take this very seriously and always act to ensure full compliance.

 

Due to the nature of the information available, we can not provide further detail on top of what has already been provided. I appreciate that this is frustrating when you are trying to gather the most precise information you can. This is not from us not wanting to provide further detail, but us not being able to provide further detail.

 

I am so sorry that you have had to continue to chase to get the answers you have, and that the whole experience has been far from what you would expect of our service.

 

Also due to the fact they don't consider this a breach I doubt they will sent anything out about it (we had to chase to get any information and we were one of the sites to report it)

 

Myself and my DPO think that given the full name of the student, School they attend positive and negative points, detentions as well as announcements from the school were all visible this would definitely class as a breach.

 

What are your thoughts on this.

Posted (edited)

Think you just have to gauge the reaction from the thread at the time (https://www.edugeek.net/forums/mis-systems/236405-classcharts-gdpr-security-issue.html) to get an idea what the hive mind here thinks.

 

You are not alone in your thoughts of the incident.

 

EDIT: I do find the paragraph where they say:

Due to the nature of the information available, we can not provide further detail on top of what has already been provided. I appreciate that this is frustrating when you are trying to gather the most precise information you can. This is not from us not wanting to provide further detail, but us not being able to provide further detail.

Interesting. The incident was serious so we can't comment but not so serious as to count it as a data breach.

 

I hope the ICO respond.

Edited by TechMonkey
  • Thanks 1
Posted
we had to chase to get any information and we were one of the sites to report it

 

I also reported it, and I've had that follow-up you posted. I got one last Wednesday (?) with different wording, but the same sentiment. It included "a small number of parent or teacher users could be served up with the incorrect information" and "There is no evidence of a malicious attack or data breach.". Unless they're claiming the information served up wasn't real data, I don't see how it couldn't have been a breach.

Posted

It doesn't matter how much they try and bury their heads in the sand - it was a breech clear and simple - unauthorised people access unauthorised personal data - that's always going to be a breech. So whilst classcharts appear to be saying that if it wasn't a mass data hack, it wasn't a breech, that shows their own staff's lack of understanding about data protection which is probably why this all happened in the first place.

 

The ICO appears to disagree with Classchart's interpretation of the term data breech.

 

https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/

 

"A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data."

  • Thanks 1
Posted

I get the feeling that TES believe that a breach can only occur if it's malicious.

 

That isn't the case, and it was quite clearly a breach. I hope schools have complained to the ICO, because the attitude of TES has not been great.

  • Thanks 2
Posted

One of the examples on the above linked ico page under the subheading "what is a personal data breach" is

sending personal data to an incorrect recipient

 

It's hard to see how the ICO's guidance could be clearer, or how anyone who has read even the smallest part of it could claim that what has occurred with classcharts was not a Data Breach. Unfortunately that kind of only leaves the possibility that either Classcharts have not bothered to familiarise themselves with the ICO's guidance at the most basic level, which is quite terrifying, or they're simply being dishonest with themselves and their customers.

 

If a breach has occurred, but is unlikely to pose a risk to people's rights and freedoms then it doesn't have to be reported to the ICO, but the decision and rationale should be documented. So if they deemed it low risk, they might not have to report it to the ICO, however a Data Processor (which they most definitely are) is obligated to report a breach to the organisations it is contracted to. By contacting schools with Classcharts and specifically saying it was not a breach, then Classcharts have clearly not reported the breach to their customer organisations as they are obligated to do so.

 

You know when you were little and your mam would tell you it wasn't what you'd done that was getting you into trouble, it was the lying about it afterwards...

Posted
a Data Processor (which they most definitely are) is obligated to report a breach to the organisations it is contracted to.

 

I wonder if they're playing on the fact they don't know which schools'/students' records were actually shown to another person, therefore they can't contact those schools to say it happened.

Posted
I wonder if they're playing on the fact they don't know which schools'/students' records were actually shown to another person, therefore they can't contact those schools to say it happened.

But they do for some (a number of our parents reported individual breaches to us and we reported them to classcharts).

 

It would be prudent to presume the number of individuals whose data has been breached is equal to the number of parents polling the system in the "15 minute" window.

 

This is a figure unknown to us on the outside, but based on anecdata a reasonable guess would be less than 5 breaches per 2000 students.

Posted

My DPO reported it to the ICO on the phone and the short version from that call is below;

 

 

The very helpful lady on the phone said that it was the decision of Classcharts as to whether they felt that this met the reporting threshold, having considered the risk as a result of the breach. Providing they felt that this could be justified, they just log it and keep a detailed record. Of course, if anyone is adversely affected as a result of this, then of course this would put the spotlight on Classcharts and they would then have a responsibility to evidence their justification for not reporting the breach etc.

 

Seams a little weird but guess there's not much to be done with it.

  • 4 weeks later...
Posted
My DPO reported it to the ICO on the phone and the short version from that call is below;

 

 

The very helpful lady on the phone said that it was the decision of Classcharts as to whether they felt that this met the reporting threshold, having considered the risk as a result of the breach. Providing they felt that this could be justified, they just log it and keep a detailed record. Of course, if anyone is adversely affected as a result of this, then of course this would put the spotlight on Classcharts and they would then have a responsibility to evidence their justification for not reporting the breach etc.

 

Seams a little weird but guess there's not much to be done with it.

 

Not sure the ICO is right on that. It's ultimately the Data Controllers responsibility and is liable for a breach. TES are just the processor acting on the school's behalf.

 

We're just completing a DPIA for one of TES other products and I have to say I'm not filled with confidence in them!

  • Thanks 1
Posted
My DPO reported it to the ICO on the phone and the short version from that call is below;

 

 

The very helpful lady on the phone said that it was the decision of Classcharts as to whether they felt that this met the reporting threshold, having considered the risk as a result of the breach. Providing they felt that this could be justified, they just log it and keep a detailed record. Of course, if anyone is adversely affected as a result of this, then of course this would put the spotlight on Classcharts and they would then have a responsibility to evidence their justification for not reporting the breach etc.

 

Seams a little weird but guess there's not much to be done with it.

 

Erm .... no.

I've avoided stepping in on these discussions for a range of reasons but the above needs calling out.

1 - It needs to be made clear to the ICO that Classcharts are the Data Processor and not the Data Controller

2 - This is because the Data Processor *cannot* make a full assessment about the risks to individuals who may be affected *as they do not know enough about any context*.

3 - If Classcharts are saying there is no risk, then they need to be challenged on that as to how they have reached that conclusion without discussing it in detail with *all* the Data Controllers affected.

 

If ICO is saying it is Classcharts' decision then I would ring back for a second, third and fourth opinion as this differs greatly to advice I and others have had in the past.

I would also suggest that you contact ClassCharts to get them to make the ICO understand the relationships in this.

  • Thanks 1
Posted

You seem to be missing the point slightly me old Grumbles.

 

Classcharts are purposefully playing down the data breech, ignoring that is was a data breech, pretending it wasn't a data breech.

 

Its not us you need to explain the above too - it's classcharts (or the ICO!).

Posted
You seem to be missing the point slightly me old Grumbles.

 

Classcharts are purposefully playing down the data breech, ignoring that is was a data breech, pretending it wasn't a data breech.

 

Its not us you need to explain the above too - it's classcharts (or the ICO!).

 

ClassCharts are a data processor acting under a contract to a data controller (school). The data controller is responsible for investigating and deciding whether it is a breach and whether it is reportable or not. The processor is legally obliged to assist the school and provide evidence for any investigation. It isn’t within their purview to decide that it’s not a breach.

  • Thanks 1
Posted
ClassCharts are a data processor acting under a contract to a data controller (school). The data controller is responsible for investigating and deciding whether it is a breach and whether it is reportable or not. The processor is legally obliged to assist the school and provide evidence for any investigation. It isn’t within their purview to decide that it’s not a breach.

 

But it is within their purview to at least report it to the data controller as a breech or potential breech right? Not pretend it's not a breech and everything's fine and don't worry we don't know how many parents saw other pupils data and we don't even know if any of your pupils data was compromised - but just don't worry there's the carpet brush it under there...?

 

The data processor has to take responsibility for it's own policies procedures and and breeches.

Posted
But it is within their purview to at least report it to the data controller as a breech or potential breech right?

 

Yes they have to report it to the Data Controller, not to the ICO. The Data Controller then has a duty to investigate and report to the ICO. It isn't for ClassCharts to tell the ICO it was or wasn't a breach.

 

The school's who know they've had this issue should be investigating and reporting it if deemed they need to. It's the schools who should be taking action not complaining that ClassCharts have just said it's not a breach.

  • Thanks 1
Posted
Am I misunderstanding something here, are people saying it is up to Classcharts to decide what is a breach and what isn't? No matter how serious it might actually be? So if our school gets hit with ransomware but I manage to hush it up I can just say "I didn't feel it met the threshold of a breach" and absolutely nothing would happen to us ?????????
Posted
Am I misunderstanding something here, are people saying it is up to Classcharts to decide what is a breach and what isn't? No matter how serious it might actually be? So if our school gets hit with ransomware but I manage to hush it up I can just say "I didn't feel it met the threshold of a breach" and absolutely nothing would happen to us ?????????

 

I think the answer is "sort of"! You don't have to report every incident to ICO, but you do need to document the incident and be prepared to justify why you didn't contact ICO. If ICO disagree with you about it not meeting the threshold, then stuff can happen to you.

 

In this instance, ClassCharts are leaning heavily on being the processor not controller, therefore it isn't there data which was leaked therefore they don't need to do anything. If that is valid, it's mad because it relies on us knowing the incident happened in the first place, which we legitimately might not.

Posted
In this instance, ClassCharts are leaning heavily on being the processor not controller, therefore it isn't there data which was leaked therefore they don't need to do anything. If that is valid, it's mad because it relies on us knowing the incident happened in the first place, which we legitimately might not.

Presumably Cloud providers such as Arbour/Bromcom would have the same excuse, or Microsoft/Google for that matter if their systems were breached. it does seem a bit crazy that the school would end up on the receiving end of any fine for choosing a provider who suffered a breach. Or am I misunderstanding? that classcharts still could be liable, but one of their customers must report it to ICO for the ICO to investigate?

Posted
If that is valid, it's mad because it relies on us knowing the incident happened in the first place, which we legitimately might not.

 

Or legitimately might not think it was a breach (in spite of it clearly fitting the criteria on the ICO's website) because Classcharts told everyone that it wasn't a breach?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...