Jump to content

Recommended Posts

Posted
Presumably Cloud providers such as Arbour/Bromcom would have the same excuse, or Microsoft/Google for that matter if their systems were breached. it does seem a bit crazy that the school would end up on the receiving end of any fine for choosing a provider who suffered a breach.

 

I think schools are highly unlikely to get fined based on the actions of their data processors, as long as the data processor had all the right things in their privacy and data handling policies, the school had done their DPIA, etc.

 

Or am I misunderstanding? that classcharts still could be liable, but one of their customers must report it to ICO for the ICO to investigate?

 

That's my understanding. A school as data controller must report "their" breach to ICO, who would then investigate. If ICO find the breach was caused by ClassCharts doing an avoidably stupid thing, there could be repercussions for ClassCharts. I think! It might all come down to our DPIAs and why we shared data with a processor who might do the aforementioned Stupid Thing. Like a lot of GDPR things, I think it will only become clear once someone has actually tested it in court.

Posted

Data Processors need to inform data controllers of the breach.

Class charts have done this and so it is the responsibility of the data controller to assess the implications, choose to report to the ICO or not, choose to report to data subjects or not.

It is moot as to whether ClassCharts decide whether it is reportable at this point.

The disturbing thing is that someone in the ICO is feeding back that it *is* up to ClassCharts.

As for notifying schools, data processors will have commitments within the DPA to notify the data controller. This should be something you check during due diligence.

Posted
Data Processors need to inform data controllers of the breach.

Class charts have done this

 

Have they? Hands up anyone who has been contacted by ClassCharts and informed their data was leaked...

Posted
Data Processors need to inform data controllers of the breach.

Class charts have done this and so it is the responsibility of the data controller to assess the implications, choose to report to the ICO or not, choose to report to data subjects or not.

.

 

Have they? Have they really?

 

What do you call this then:

 

"There is no evidence of a malicious attack or data breach."

Posted

We were never contacted by classcharts about this, they never reported anything to us. We contacted them and their reply was:-

 

"We can tell you that the impact was very limited and related to a product update which was swiftly removed. The vast majority of schools were not impacted. However, I’m sorry to say that we do have a small group of schools which we cannot completely discount and your school may have been part of it. There is a possibility that some limited data could have been incorrectly displayed during the period on Monday before being quickly reversed. We are sorry that we are unable to provide further detail around this."

 

We are unable to investigate what happened or assess the implications, Classcharts is a closed box we can't look in and they can't (or won't) provide any details to us.

Posted
The vast majority of schools were not impacted. However, I’m sorry to say that we do have a small group of schools which we cannot completely discount

 

I wonder what gives them the confidence or even ability to say most schools weren't impacted, other it being unlikely that bucket-loads of parents would have opened ClassCharts during the 30-minute window of opportunity.

Posted
Clearly given the multiple pages of the thread on here, all schools were impacted the only ones we know about were the ones that noticed / had parents ring in a report it etc. What they mean is "The vast majority of schools [did not notice that they were] impacted"
  • Thanks 1
Posted
Clearly given the multiple pages of the thread on here, all schools were impacted the only ones we know about were the ones that noticed / had parents ring in a report it etc. What they mean is "The vast majority of schools [did not notice that they were] impacted"

 

I suspect that's the case. We notified those schools we knew about due to parents providing screen shots, but I'm sure our parents saw data from other schools too, and it would therefore be reasonable to assume one of your parents could have seen data on one of our students.

 

How many of you have told your parents what happened? We decided not to since we don't know someone saw data they shouldn't have (aka, the ClassCharts defence!), so thought it would cause unnecessary concern, but our DPO did inform the ICO.

  • 3 months later...
Posted (edited)
Apologies I posted this on the other section about classcharts but - just had a call about a parent who had viewed their daughter Maggie Thatcher, but got a completely different pupil Christopher Thatcher instead - there has never been a Christopher Thatcher on roll here - I haven't looked fully into this yet as I'm dealing with a diff issue but does anyone know if this has reared its ugly head again? - EDIT - disregard it miscommunication no issue on Classcharts end. Edited by mikes

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...