Israel's Education Ministry Violated Privacy Law, Leaking Sensitive Data of Special Needs Students
Translated & summarized from i24NEWS by baba
Israel's Privacy Protection Authority found the Ministry of Education violated privacy laws after sensitive personal and medical data of about 21,000 special needs students was leaked online. The ministry failed to adequately secure the data, breaching privacy regulations. The leak occurred in March 2025 after a digital form created in May 2024 with open permissions allowed unauthorized access to the sensitive information. The authority classified the incident as a severe security breach.
The story in 5 lines · by baba
- Israel's Ministry of Education violated privacy laws by leaking sensitive data of 21,000 special needs students.
- The leak involved personal and medical information, including details about students' disabilities.
- The data was accessed via a digital form with open permissions created in May 2024.
- The Privacy Protection Authority initiated an oversight process in March 2025 after the leak was reported.
- The ministry failed to meet required data security standards, leading to a severe security incident.
Israel's Privacy Protection Authority has concluded an administrative oversight process against the Ministry of Education, finding that the ministry violated privacy laws by leaking sensitive personal and medical information of approximately 21,000 special needs students from the ultra-Orthodox sector. The authority determined that the ministry failed to secure the data adequately, breaching Section 17 of the Privacy Protection Law and related regulations.
The oversight process was initiated in March 2025 following media reports that the sensitive data had been leaked and distributed online to unauthorized parties. The investigation revealed that the leaked information was extracted from a ministry system and included identifying details, residency and education information, religious affiliation, and medical data detailing the students' disabilities.
According to the findings, in May 2024, ministry employees sought to create a digital form to streamline the placement of these students. To do this, they extracted data from a ministry system, creating a file with sensitive information on the 21,000 students. This file was linked to a form intended for educational institutions to fill out. The ministry claimed this file was meant to be a "behind-the-scenes" document, accessible only for querying information. However, the form was set with open permissions, allowing anyone with the link to access and forward it. The data file itself was also linked openly, unprotected by a password, allowing anyone with the link to view and download it.
In May 2024, a link to the form was sent to relevant personnel in ultra-Orthodox educational institutions via both organizational and private email addresses. By March 2025, it became known that the data file, containing the sensitive personal information of the 21,000 students, had been leaked to unauthorized individuals and widely disseminated. The Ministry of Education suggested that a specific error in the form's permission settings likely allowed an external party to use search mechanisms to locate the data file after clicking a link.
The Privacy Protection Authority stated that the ministry's database, from which the information was extracted, contains sensitive data on over 100,000 individuals, thus requiring a high level of security. The authority deemed the use and transfer of this data to unauthorized parties a severe security incident. The oversight process uncovered deficiencies in the Ministry of Education's compliance with data security regulations.
