What
Inappropriate disclosure of sensitive personal data.
How much
Unknown.
Why
An email with an attachment containing sensitive personal data was inadvertently sent to lower-sixth form students rather than their tutors. The email was only intended to contain a link to the attachment.
Regulator
ICO
Regulatory action
Undertaking issued to ensure that any documents containing personal data relating to students will only be provided to staff on a “need to know” basis and will not, in any event, be transmitted via email unless encrypted.
Reason for action
Although efforts were made to delete or recall the email, some students had already saved or forwarded the attachment and some media publicity resulted.
When
06 December 2011.
Links
View PDF of the Godalming College Undertaking (Via ICO Website)
View PDF of the Godalming College Undertaking (Breach Watch Archive)