Privacy Authority Rules Ministry of Education Violated Law in Special Needs Student Data Leak
Translated & summarized from Mako by baba
Israel's Privacy Protection Authority ruled the Ministry of Education violated privacy laws in a data leak of 21,000 Haredi special needs students. An unauthorized employee extracted sensitive medical and personal data, which was then shared via an open, unencrypted link. The leak caused distress to families concerned about social stigma and marriage prospects, leading to a civil lawsuit.
The story in 5 lines · by baba
- The Privacy Protection Authority found the Ministry of Education violated the law in a data leak of 21,000 special needs students.
- Sensitive medical and personal data was extracted by an unauthorized employee and shared via an open, unencrypted link.
- The leak exposed diagnoses like autism and Down syndrome, causing fear of social stigma and impacting marriage prospects in the Haredi community.
- Parents have filed a civil lawsuit against the Ministry of Education seeking compensation for the data breach.
- The Authority rejected the Ministry's defense that a certification exempted them from Israeli privacy regulations.
Israel's Privacy Protection Authority has determined that the Ministry of Education fundamentally failed and violated numerous sections of the Privacy Protection Law and data security regulations in a significant data leak concerning approximately 21,000 Haredi (ultra-Orthodox) special needs students. The findings, released Thursday following an N12 investigation, reveal a chain of failures including an unauthorized employee extracting data, the file being distributed via an unencrypted, password-free open link, and its subsequent spread within the community.
The leak, which occurred in May 2024, involved sensitive medical and personal information such as diagnoses of autism, Down syndrome, and other disabilities. The data was compiled into an Excel file containing full names, ID numbers, addresses, and detailed medical information. This file was linked to an online form sent to educational institutions, but the link was carelessly configured as completely open, requiring no identification, username, or password. The link was also sent to private email addresses, not just secure organizational ones, and the information was transmitted unencrypted over the internet.
Parents of children with special needs discovered the sensitive data circulating in groups and online, causing significant distress. For families in the Haredi sector, the exposure of medical information raised serious concerns about potential harm to their children's prospects for marriage and social standing, as well as that of their siblings. The Privacy Authority rejected the Ministry's claims of a "localized error in permission settings," stating that the information had indeed leaked and reached unauthorized individuals.
The Authority emphasized that public bodies have a duty to ensure the security of personal data, especially sensitive information concerning minors. The Ministry of Education argued that its ISO 27001 certification exempted it from Israeli regulations, a claim the Authority dismissed. Because the incident predates a recent amendment allowing for heavy fines, sanctions were imposed under older legislation. Affected parents have filed a civil lawsuit against the Ministry of Education seeking compensation.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Left 1Centre 6Right 1Haredi 1Other 5
