Commissioner reveals private information of thousands of students released by school

Sensitive data was accidentally exposed to the public for 36 hours

Commissioner reveals private information of thousands of students released by school

Cyber

By Lyle Adriano

A report from the Saskatchewan information and privacy commissioner’s office has determined that a school unintentionally leaked the private information of some 2,841 students last year.

The Chinook School Division, which has over 6,000 students in total, revealed that the privacy breach occurred on January 28, 2020. It also attributed the breach to “human error” after an IT worker unintentionally transferred computer code containing the student files from a private account to a public account.

The information exposed by the breach included students’ names, ID numbers, phone numbers, grades, and parent email addresses.

The office of privacy commissioner Ron Kruzeniski determined that none of the files were downloaded, and the school division confirmed that the data was accessed by only three visitors.

CBC News reported that the breach was first discovered by a search bot that was crawling the internet. It was after the bot found the data that the school division’s IT department was notified, and the privacy settings of the files were changed.

Following the discovery of the breach, the Chinook School Division notified two parents whose email addresses were found by the bot – but no other parents or students were alerted. When asked why it did not notify the rest of the individuals whose data were potentially accessed, the school division maintained that a mass notification was not necessary since only one outside organization had accessed the information – a position Kruzeniski has criticized.

"The school division did not provide appropriate notification of this breach," the privacy commissioner said, adding that the school division could have put a notice of the breach on its website, post notices in public offices, or even release a media advisory or advertisement.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!