Privacy Authority Finds Education Ministry Violated Law in Sensitive Data Leak
Translated & summarized from Bizportal by baba
Israel's Privacy Protection Authority has ruled that the Ministry of Education violated privacy and security laws in a sensitive data leak affecting 21,000 special education students. The breach involved personal and medical information due to improperly secured digital forms and data files. The authority identified multiple security deficiencies, including issues with permissions, encryption, and lack of proper documentation. The ministry's claim of exemption due to international certification was rejected.
The story in 6 lines · by baba
- The Privacy Protection Authority found the Education Ministry violated privacy and security laws in a data leak.
- Sensitive data on 21,000 special education students in the ultra-Orthodox sector was compromised.
- The leak involved personal, educational, and detailed medical information about minors.
- The ministry failed to properly secure digital forms and data files, leading to unauthorized access.
- The PPA cited deficiencies in permission management, encryption, and lack of required security documentation.
- The ministry's claim of exemption via ISO certification was rejected by the authority.
Israel's Privacy Protection Authority (PPA) has determined that the Ministry of Education violated the Privacy Protection Law and information security regulations in a leak of sensitive data concerning 21,000 special education students in the ultra-Orthodox sector. This marks the first time the PPA has issued such a ruling against a government ministry, involving particularly sensitive medical information about minors.
The PPA has not yet taken any enforcement actions against the ministry or those responsible for the breach. The investigation was initiated in March 2025 following media reports about the data leak and its dissemination online. The leaked information, extracted from a ministry system, included identifying details, residency and educational information, religious affiliation, and specific medical details about the students' disabilities.
According to the PPA's findings, in May 2024, ministry employees created a digital form to streamline the placement process for these students. To do this, they exported data from a ministry system into a file linked to the form, intended for educational institutions to fill out. The ministry claimed this data file was a 'back-end' file linked to the form for querying information.
However, the PPA found that the form was set to open access for anyone with the link, and the data file was also accessible without a password, allowing viewing and downloading by anyone possessing the link. Links to the form were sent to relevant personnel in ultra-Orthodox educational institutions via organizational and private email addresses.
The Ministry of Education suggested the leak likely resulted from a specific error in setting permissions, which allowed an external party to use search mechanisms to find the data file after clicking a link, ultimately leading to unauthorized individuals obtaining the information.
The PPA noted that the ministry's database contains sensitive information on over 100,000 individuals, requiring a high level of security. The authority identified several deficiencies, including issues with permission management, system operation, and data encryption, as the information was transferred via an open link without encryption. The ministry also lacked a database definition document, an information security procedure, and a risk assessment for the system at the time of the incident.
The Ministry of Education argued that its ISO/IEC 27001 certification exempted it from certain regulations, but the PPA rejected this, stating that international certification alone does not grant an exemption and the ministry had not met the required conditions.
