Feeds

ICO: Education ministry BROKE the Data Protection Act

But we have decided not to do anything about it

Mobile application security vulnerability report

Exclusive The Department for Education broke the Data Protection Act after it exposed the email addresses, unencrypted passwords and sensitive answers of members of the public who filled in an online form about parental controls on the net, The Register can reveal.

However - despite the breach - the Information Commissioner's Office has decided that no further action needed to be taken against the DfE.

The watchdog said in a statement to El Reg:

We have contacted the Department for Education (DfE) over a temporary security flaw that was found on their website. The flaw related to a consultation taking place over the course of Thursday 28 and Friday 29 June. The flaw was resolved the following day but resulted in a limited amount of personal information being compromised.

Following our enquiries we have found that the DfE did breach the Data Protection Act. However, as the personal information compromised was not sensitive and any distress caused is likely to have been minimal, we have decided that no further enforcement action is required at this time.

We will be keeping a record of this incident and may revisit it again if further compliance issues come to our attention.

In June this year, the DfE released a 10-week public consultation document on parental controls that offered three scenarios to better "protect" children browsing the web.

The following day, we revealed that Tory MP Michael Gove's departmental website was suffering from a deeply embarrassing security flaw, which we notified the ICO about.

It followed readers contacting us about having their details exposed by the consultation site.

Since then, that section of the DfE's website has arguably been about as useful as a chocolate teapot by forcing any British citizens wishing to share their views on a variety of consultations relating to education policy in the UK to do so via a Microsoft Word document that they have to download, fill in and upload again.

Which is a total faff for taxpayers who are repeatedly being swamped with suggestions that the government is now stamping its authority over being "digital by default." But then, the Cabinet Office's Web2.0 whalesong clearly hasn't reached Gove's team yet.

Your correspondent can't help but wonder if the DfE is sweatily waiting for Directgov's rebranded, restaffed, relocated empire to fix its sorry website. The plans are certainly there for GOV.UK developers to prettify government department sites and group all of them under one single domain at some point between now and 2014, with costs for that project being taken from the existing £4.6m pot, apparently. ®

Update: A DfE spokesman declined to respond to The Register's questions about when its consultation site might be fixed. It's understood that all live consultations were exposed to the security flaw before the department took the system down – which was only after we informed the DfE of the glitch.

Gove's department said in a statement: "We took the site down as soon as we were made aware of a potential breach of the Data Protection Act and informed those who might have been affected immediately. The problem was detected very quickly so only a very small number of people were affected.

"We have taken all necessary steps to ensure that this will not happen again."

Bridging the IT gap between rising business demands and ageing tools

More from The Register

next story
Adam Afriyie MP: Smart meters are NOT so smart
Mega-costly gas 'n' 'leccy totting-up tech not worth it - Tory MP
'Blow it up': Plods pop round for chat with Commonwealth Games tweeter
You'd better not be talking about the council's housing plans
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
Just TWO climate committee MPs contradict IPCC: The two with SCIENCE degrees
'Greenhouse effect is real, but as for the rest of it ...'
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.