Data Leak Exposes Sensitive Information of Thousands in London Borough
By Netvora Tech News
A London borough has been found to have leaked sensitive information of thousands of people, including nearly 2,400 children, through an Excel spreadsheet. The data was released in response to a Freedom of Information request and was made available on the borough's website and WhatDoTheyKnow.com.
Data Leak Discovery
The data leak was discovered in November 2023, more than two years after the information was initially released. The spreadsheet contained 35 hidden sheets, with information on over 6,500 individuals. The data included details on children in care, as well as 96 unaccompanied asylum-seeking children. The information was classified as sensitive and was made available without adequate protection.
Investigation and Findings
The UK's Information Commissioner's Office (ICO) launched an investigation into the data leak and found several breaches of data protection regulations. The investigation revealed that there were no written guidelines for the safe use of Excel spreadsheets when responding to Freedom of Information requests. Additionally, there was no specific training on the safe use of Excel spreadsheets for Freedom of Information requests.
The investigation also found that council employees were not instructed on how to check for hidden data, and there were no adequate technical and organizational measures in place to prevent sensitive information from being released. Furthermore, the ICO's best practices for safe data sharing, published in 2018, were not implemented.
Consequences and Response
The ICO has issued a reprimand to the London borough, taking into account the measures the council has taken since the incident and the lack of evidence of misuse. The council has implemented new measures to prevent similar data breaches in the future.
Conclusion
The data leak highlights the importance of adequate data protection measures, particularly when responding to Freedom of Information requests. The incident serves as a reminder to public bodies to prioritize data security and ensure that sensitive information is handled appropriately.
- The data leak exposed sensitive information of thousands of people, including nearly 2,400 children.
- The information was released without adequate protection and was made available on the borough's website and WhatDoTheyKnow.com.
- The ICO investigation found several breaches of data protection regulations, including lack of written guidelines, training, and adequate technical and organizational measures.
- The council has implemented new measures to prevent similar data breaches in the future.
Comments (0)
Leave a comment