The ICO are investigating a school in Hampstead following the discovery of a data breach of 400 students. The spreadsheet had been publically available for 18 months and included student names, their parent’s names, home address, phone numbers and email addresses.
The data had been derived from a mail shot and had accidentally been placed in a shared area; consequently leaving students and their parents vulnerable to unwanted contact and worse as the type of information available could easily be used for fraudulent criminal activity.
The ICO are currently investigating correct action to take, of which a penalty up to £500,000 could be awarded. In addition to a fine by the ICO, failing to comply with the Data Protection Act could result in the school having to pay compensation to the individuals involved, a reduction in Ofsted ratings and having to cope with damaging media attention.
Information security is paramount in schools owing to the substantial amount of personal information they hold, which could cause serious distress if exposed. It is imperative that schools spend time training staff and ensuring proper security procedures are in place for protection of data. This includes storing data in an encrypted format and ensuring regular change of passwords.
http://www.redstor.com/blog/index.php/2014/01/data-breach-of-400-pupil-records-at-school/






