Privacy Authority Rules Ministry of Education Violated Law in Special Needs Student Data Leak
Translated & summarized from N12 by baba
Israel's Privacy Protection Authority ruled that the Ministry of Education violated privacy laws in a data leak affecting 21,000 Haredi special needs students. An unauthorized employee extracted sensitive medical and personal data, which was then distributed via an unencrypted, open link. The leak has caused significant distress to families concerned about social stigma and marriage prospects. Parents have filed a civil lawsuit against the Ministry seeking damages.
The story in 5 lines · by baba
- The Privacy Protection Authority found the Ministry of Education violated privacy laws in a data leak.
- Sensitive data of 21,000 Haredi special needs students was exposed via an unencrypted, open link.
- An unauthorized employee extracted the data, which included medical diagnoses.
- The leak has caused fear of social stigma and damaged marriage prospects in the Haredi community.
- Parents have filed a civil lawsuit against the Ministry of Education seeking compensation.
Israel's Privacy Protection Authority has determined that the Ministry of Education fundamentally failed and violated numerous sections of the Privacy Protection Law and data security regulations in a significant data leak concerning approximately 21,000 Haredi (ultra-Orthodox) special needs students. The findings, released Thursday following an N12 investigation, reveal a chain of failures including an unauthorized employee extracting data, the file being distributed via an unencrypted, password-free open link, and its subsequent spread within the community.
The leak exposed sensitive medical and personal information, including diagnoses of autism, Down syndrome, and other disabilities. For families in the Haredi sector, this disclosure raised serious concerns about potential damage to their children's and their siblings' prospects for marriage and social standing. The Privacy Authority rejected the Ministry's claims, labeling it a "severe security incident."
According to the investigation, the breach originated in May 2024 when ministry employees sought to streamline the placement process for special needs students in the Haredi district. An Excel file containing full names, ID numbers, addresses, educational institutions, and detailed medical information was created. This file was linked to an online digital form, but the link was negligently set as completely open, requiring no identification, username, or password. The link was also sent to private email addresses, not just secure organizational ones, and the data was transmitted unencrypted over the internet.
Further investigation revealed that the employee who extracted the database was not authorized to access such information. The Ministry of Education claimed it was a "localized error in permission settings" that allowed external parties to find the file through search engines. However, the Privacy Authority refuted these explanations, confirming the data had indeed leaked and reached unauthorized individuals.
The Privacy Authority emphasized that public bodies have a duty to ensure the security of personal data, especially sensitive information concerning minors. The Ministry of Education's claim of adhering to the international standard ISO 27001 did not exempt it from Israeli regulations. As the incident occurred before stricter penalties were enacted, sanctions were applied under the old law. Parents of affected students have filed a civil lawsuit against the Ministry of Education seeking compensation, citing a severe breach of trust.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Left 1Centre 6Right 1Haredi 1Other 5
