Schools

DfE apologises to academy finance staff over data blunder

Contact details for staff at an academy finance professionals event were accidentally shared with other attendees

Contact details for staff at an academy finance professionals event were accidentally shared with other attendees

19 Nov 2021, 18:03

More from this author

grade
Exclusive

The Department for Education has apologised after a group of academy finance staff’s details were compromised in a data breach.

More than 850 staff working in trust finance had signed up a virtual event next week, where the DfE will advise attendees on funding levels, the pupil premium, the national funding formula and other topics. Education and Skills Funding Agency interim CEO John Edwards is due to speak at the event.

But attendees received an email on Thursday revealing officials had discovered the calendar invitation “enables people to see the email address of other participants”.

The invite was “immediately cancelled” and officials asked guests to remove the meeting from calendars.

The email also revealed “one incident” saw an attendee add the invite into their calendar, only to trigger a new meeting invitation to everyone else.

“At this stage, we do not know what has allowed this to happen, but we have logged this formally as a ‘data breach’ and would like to sincerely apologise to everyone for the confusion and inconvenience this has caused,” the DfE told attendees.

Organisers confirmed the event would still go ahead as planned. Officials said they had taken immediate action, sent out no further calendar invites and the DfE’s data protection office would review the case and decide whether to refer it to the Information Commissioner’s Office.

Duty to report some data breaches

A spokesperson for the ICO said on Friday morning it had not received a breach report from the DfE, though added that not all breaches had to be reported.

“Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms.

“If an organisation decides that a breach doesn’t need to be reported they should keep their own record of it, and be able to explain why it wasn’t reported if necessary.”

Pete Woodward, co-founder of Securious, a cyber-security specialist which works with schools, noted “accidents happen”, but said it could suggest a need for better staff understanding and training in the tech they use.

“If users have seen each others’ emails – hopefully that’s not going to result in someone dying, but it is an incident that could cause concern. The bottom line is to learn from it.”

‘Increased risk’ since remote learning shift

Woodward said it was “obvious” such incidents would happen more widely in the sector given the surge in remote learning and tech use during Covid.

The shift meant lots of staff previously unfamiliar with certain software had faced a “steep learning curve”.

“Schools have a lot of children’s sensitive information – so understanding how you share and secure that is key.”

A government survey published earlier this year found 36 per cent of primary schools and 58 per cent of secondaries had identified breaches or attacks in the past year.

The DfE’s 2019-20 annual report said progress had been made on cyber-security, with an “ongoing co-ordinated programme of work to strengthen controls”.

It recorded three “protected personal data-related incidents” at the department in the year which it reported to the ICO, up from two in the two previous years.

The Department for Education has been approached for comment.

Latest education roles from

Head of Computing

Head of Computing

Lift Greensward

Head of English

Head of English

Lift Ryde

Head of Faculty

Head of Faculty

FEA

Business Development Manager 

Business Development Manager 

EducationScape

Sponsored posts

Sponsored post

CPD Workshops Announced For Inspiring Leadership Conference

Looking for an education event which offers access to a comprehensive range of CPD-accredited workshops?

SWAdvertorial
Sponsored post

CPD Accreditation Among New Developments For The Inspiring Leadership Conference

As this year’s Inspiring Leadership Conference approaches, we highlight fives new initiatives and the core activities that make this...

SWAdvertorial
Sponsored post

Equity and agency for a changing world – how six core skills are transforming inclusive education

There is a familiar thread running through current government policy, curriculum reviews and public debate about education. We are...

SWAdvertorial
Sponsored post

Equitas: ASDAN’s new digital platform putting skills at the heart of learning

As schools and colleges continue to navigate increasingly complex learning needs, the demand for flexible, skills-focused provision has never...

SWAdvertorial

More from this theme

Schools

£900k scheme offers ‘equal access to chess in schools’

Between 350 and 450 schools across all nine regions of the UK will take part

Esmé Kenney
Schools

Three primary free schools to go ahead after appeals

Meanwhile six cancelled special free school projects have been appealed

Samantha Booth
Schools

Cuts to Prevent staff considered by Kent as funding reduced

Reform-run Kent council tells schools it may lose their Prevent education officer posts

Lydia Chantler-Hicks
Schools

Academies lobby pension fund chiefs over ‘unfair’ extra payments 

West Yorkshire academy chains believe they are paying millions more than local authority schools

Jack Dyson

Your thoughts

Leave a Reply

Your email address will not be published. Required fields are marked *