Privacy Authority Finds Ministry of Education Mishandled Sensitive Data of 21,000 Special Education Students
Translated & summarized from Kipa by baba
Israel's Privacy Protection Authority found the Ministry of Education violated privacy laws concerning 21,000 special education students in the Haredi sector. Sensitive personal and medical data was leaked due to unsecured links and poor access management. The ministry's claim of a "specific malfunction" was rejected, and numerous security deficiencies were identified. The ministry is confirmed to have breached privacy protection laws and information security regulations.
The story in 6 lines · by baba
- 21,000 special education students' sensitive data was mishandled by the Ministry of Education.
- The Privacy Protection Authority found the ministry violated privacy laws.
- Data included personal details and specific medical information about disabilities.
- The leak occurred through unsecured links sent to educational officials.
- The ministry cited a "specific malfunction" but faced criticism for multiple security lapses.
- The ministry's ISO certification did not exempt it from privacy regulations.
Israel's Privacy Protection Authority has determined that the Ministry of Education violated privacy laws by mishandling sensitive personal and medical information of approximately 21,000 special education students in the Haredi sector. The authority's administrative review, initiated in March 2025 following media reports of a data leak, found that the ministry failed to secure data extracted from one of its systems. This data, intended for a digital form to streamline placement processes, included identifying details, residency and study information, religious affiliation, and specific disability information.
According to the findings, the form and its data file were accessible via open links without password protection or authorization. In May 2024, the link was sent to educational officials in the Haredi sector via organizational and private email addresses. By March 2025, it became apparent that the data had reached unauthorized individuals and was widely disseminated.
The Ministry of Education claimed a "specific malfunction in the authorization settings" likely allowed an external party to find the data file. However, the Privacy Authority identified numerous deficiencies, including poor access management, unencrypted data transfer, lack of a database definition document, absence of an information security procedure, and a missing risk assessment.
The authority rejected the ministry's argument that its ISO/IEC 27001 certification exempted it from certain regulations, stating that international certification does not automatically grant exemption. The review concluded that the Ministry of Education breached Section 17 of the Privacy Protection Law and several regulations concerning information security.
