Israel's Education Ministry Penalized for Sensitive Data Leak of Special Needs Students
Translated & summarized from Channel 13 by baba
Israel's Privacy Protection Authority found the Ministry of Education violated privacy laws after sensitive personal and medical data on 21,000 special needs students was leaked online. The ministry created an unprotected digital form containing the data, which was then distributed to unauthorized individuals. The authority cited failures in data security, permissions management, and encryption, rejecting the ministry's claims of exemption due to international certification.
The story in 5 lines · by baba
- Israel's Ministry of Education violated privacy laws by leaking sensitive data of 21,000 special needs students.
- The data leak included personal and medical information and was distributed via an unprotected online link.
- The Privacy Protection Authority found the ministry failed in data security, permissions, and encryption.
- The ministry's international ISO certification did not exempt it from Israeli privacy regulations.
- The breach is considered a severe violation of the law protecting minors' sensitive information.
Israel's Privacy Protection Authority (PPA) has concluded an administrative oversight process against the Ministry of Education, determining that the ministry violated privacy protection laws and information security regulations. This follows a significant leak of sensitive personal and medical data concerning approximately 21,000 special needs students from the Haredi sector.
The oversight process was initiated in March 2025 after media reports revealed that the data had been distributed online to unauthorized parties. An investigation found that in May 2024, ministry employees created a digital form to streamline student placements. This form generated a data file containing identifying details, addresses, religious affiliation, and specific medical information about the students' disabilities.
Crucially, the file and form were accessible via an open link without any password protection and were sent to educational institution personnel. The PPA determined the ministry failed in managing permissions, system operation, and data encryption. It also lacked essential documentation like a database definition, an information security procedure, or a valid risk assessment.
The ministry's claim that its certification to the international standard ISO/IEC 27001 exempted it from regulatory compliance was rejected. The PPA emphasized that this constitutes a severe breach of Section 17 of the Privacy Protection Law, highlighting the obligation of public bodies to safeguard sensitive data belonging to minors.
