DfE

DfE apologises to academy finance staff over data blunder

Contact details for staff at an academy finance professionals event were accidentally shared with other attendees

Contact details for staff at an academy finance professionals event were accidentally shared with other attendees

19 Nov 2021, 18:03

More from this author

grade
Exclusive

The Department for Education has apologised after a group of academy finance staff’s details were compromised in a data breach.

More than 850 staff working in trust finance had signed up a virtual event next week, where the DfE will advise attendees on funding levels, the pupil premium, the national funding formula and other topics. Education and Skills Funding Agency interim CEO John Edwards is due to speak at the event.

But attendees received an email on Thursday revealing officials had discovered the calendar invitation “enables people to see the email address of other participants”.

The invite was “immediately cancelled” and officials asked guests to remove the meeting from calendars.

The email also revealed “one incident” saw an attendee add the invite into their calendar, only to trigger a new meeting invitation to everyone else.

“At this stage, we do not know what has allowed this to happen, but we have logged this formally as a ‘data breach’ and would like to sincerely apologise to everyone for the confusion and inconvenience this has caused,” the DfE told attendees.

Organisers confirmed the event would still go ahead as planned. Officials said they had taken immediate action, sent out no further calendar invites and the DfE’s data protection office would review the case and decide whether to refer it to the Information Commissioner’s Office.

Duty to report some data breaches

A spokesperson for the ICO said on Friday morning it had not received a breach report from the DfE, though added that not all breaches had to be reported.

“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms.

“If an organisation decides that a breach doesn’t need to be reported they should keep their own record of it, and be able to explain why it wasn’t reported if necessary.”

Pete Woodward, co-founder of Securious, a cyber-security specialist which works with schools, noted “accidents happen”, but said it could suggest a need for better staff understanding and training in the tech they use.

“If users have seen each others’ emails – hopefully that’s not going to result in someone dying, but it is an incident that could cause concern. The bottom line is to learn from it.”

‘Increased risk’ since remote learning shift

Woodward said it was “obvious” such incidents would happen more widely in the sector given the surge in remote learning and tech use during Covid.

The shift meant lots of staff previously unfamiliar with certain software had faced a “steep learning curve”.

“Schools have a lot of children’s sensitive information – so understanding how you share and secure that is key.”

A government survey published earlier this year found 36 per cent of primary schools and 58 per cent of secondaries had identified breaches or attacks in the past year.

The DfE’s 2019-20 annual report said progress had been made on cyber-security, with an “ongoing co-ordinated programme of work to strengthen controls”.

It recorded three “protected personal data-related incidents” at the department in the year which it reported to the ICO, up from two in the two previous years.

The Department for Education has been approached for comment.

Latest education roles from

Chief Financial Officer – Lighthouse Learning Trust

Chief Financial Officer – Lighthouse Learning Trust

FEA

Chief Financial and Operations Officer

Chief Financial and Operations Officer

Tenax Schools Trust

Managers (FE)

Managers (FE)

Click

Executive Director of Finance – Moulton College

Executive Director of Finance – Moulton College

FEA

Sponsored posts

Sponsored post

IncludEd Conference: Get Inclusion Ready

As we all clamber to make sense of the new Ofsted framework, it can be hard to know where...

SWAdvertorial
Sponsored post

Helping every learner use AI responsibly

AI didn’t wait to be invited into the classroom. It burst in mid-lesson. Across UK schools, pupils are already...

SWAdvertorial
Sponsored post

Retire Early, Live Fully: What Teachers Need to Consider First

Specialist Financial Adviser, William Adams, from Wesleyan Financial Services discusses what teachers should be considering when it comes to...

SWAdvertorial
Sponsored post

AI Safety: From DfE Guidance to Classroom Confidence

Darren Coxon, edtech consultant and AI education specialist, working with The National College, explores the DfE’s expectations for AI...

SWAdvertorial

More from this theme

DfE

DfE regions group leader John Edwards to be council CEO

Senior civil servant to become chief executive of Rotherham council

Lydia Chantler-Hicks
DfE

DfE West Midlands regional director to retire

Andrew Warren to depart the DfE after five years

Jack Dyson
DfE

DfE worried about board ‘diversity’ over Collins appointment

Unearthed emails reveal civil servants' concerns non-exec board was 'all white men of a similar age'

Jack Dyson

Your thoughts

Leave a Reply

Your email address will not be published. Required fields are marked *