Israel's Education Ministry Violated Privacy Laws in Data Leak
Translated & summarized from Kikar HaShabbat by baba
Israel's Privacy Protection Authority found the Ministry of Education violated privacy laws after sensitive medical and personal data on 21,000 Haredi special education students was leaked. The breach occurred around May 2024 when a digital form and linked data file were left with open, unprotected links. The ministry cited a "specific, isolated error" in permissions, but the authority ruled it a severe security incident affecting a database of over 100,000 people.
The story in 5 lines · by baba
- Israel's Privacy Protection Authority ruled the Education Ministry violated privacy laws due to a data leak.
- Sensitive medical and personal data of 21,000 Haredi special education students was compromised.
- The leak occurred around May 2024 due to unprotected digital forms and data files.
- The compromised database contained sensitive information on over 100,000 individuals.
- The Ministry of Education cited a "specific, isolated error" in permissions for the breach.
Israel's Privacy Protection Authority has determined that the Ministry of Education violated privacy protection laws and data security regulations following a leak of sensitive personal and medical information concerning approximately 21,000 special education students from the Haredi sector. The authority's findings, released on Thursday, came after an administrative review initiated due to reports of the data breach and its spread online.
According to the authority, the leaked data was extracted from a Ministry of Education system and included identifying details, residency and educational information, religious affiliation, and medical data pertaining to the students' disabilities. The review process began in March 2025, after it became known that unauthorized parties had accessed the data file. The authority's findings focused on an incident that occurred around May 2024.
Ministry of Education employees had sought to create a digital form to aid in the placement of Haredi special education students. To this end, a data file was generated from the ministry's system and linked to the form intended for educational institutions. However, both the form and the data file were configured with open links, lacking access restrictions or password protection. Anyone with a link to the file could view and download its contents, and the link to the form could even be forwarded.
The Ministry of Education stated that a specific, isolated error in the permissions for one of the forms likely allowed an external party to locate the file through search mechanisms. The authority determined that the database from which the information was extracted contains sensitive details on over 100,000 individuals, thus requiring a high level of security. It was also concluded that the use and transfer of this data to unauthorized parties constituted a severe security incident.
Among the deficiencies identified by the authority were that the data was produced by an employee not authorized to access the system, the file was transferred without encryption, and the ministry lacked required database definition documents and a data security procedure at the time of the incident. Furthermore, the ministry had not conducted a risk assessment for the system within the required timeframe. The Ministry of Education argued during the review that its certification to the international standard ISO/IEC 27001 exempted it from certain regulatory provisions, but the authority rejected this, clarifying that certification alone does not absolve compliance with legal requirements. In conclusion, the authority determined that the ministry had violated Section 17 of the law and various regulations concerning database management and security.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Left 1Centre 6Right 1Haredi 1Other 5
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
