The UK Department for Education (DfE) has been formally reprimanded by the Information Commissioner’s Office (ICO) after due diligence failings related to the database used by the DfE to store pupils’ qualifications.
The DfE utilises the Learning Records Service (LRS) Database to store all their pupils’ learning records, including personal details such as full names, dates of birth, genders and grades achieved.
The LRS contains email addresses and nationalities for some of the listed students and keeps the data for 66 years before deletion.
The Breach
Due to poor due diligence regarding critical data protection, the DfE allowed a company called ‘Trust Systems Software UK‘ access to the LRS.
The company, trading as ‘Trustopia‘ then used the database to sell its services as a screening firm to gambling companies, amongst other clients. Student data was used by the gambling companies to check whether users opening online gambling accounts were 18 or over, according to the ICO.
This constitutes prolonged misuse of the personal information of up to 28 million children.
At the time of the breach, 12,600 organisations had access to the LRS database. Most of these were schools, colleges, and other higher education institutions, granted access so they can verify a number of functions including the academic qualifications of potential students.
Regarding the data breach, John Edwards, the current information commissioner, has stated:
“No one needs persuading that a database of pupils’ learning records being used to help gambling companies is unacceptable“.
“Our investigation found that the processes put in place by the Department for Education were woeful. Data was being misused, and the department was unaware there was even a problem until a national newspaper informed them“.
Trustopia had access to the LRS from September 2018 to January 2020 and carried out age verification searches on 22,000 pupils during that time.
The ICO’s response
The ICO started its investigation after receiving a breach report from the DfE about unauthorised access to the LRS database. The DfE had only become aware of the breach from an expose in a national Sunday newspaper.
Regarding the incident, the ICO stated that the department “failed in its obligations to use and share children’s data fairly, lawfully and transparently“. The regulator also added that the DfE failed to prevent unauthorised access to children’s data, have proper oversight of the data, or stop the data being used for reasons not compatible with the provision of educational services.
Typically, a data breach of this nature would incur a £10 million fine, which IC John Edwards was keen to enforce.
However, a piece of current ICO legislation has refrained them from imposing the fine. This legislation, implemented in June 2022, has revised the organisation’s approach when dealing with public authorities, such as the Department of Education.
In practice, this means that public authorities will see an increased use of the ICO’s wider powers, including warnings, reprimands and enforcement, and fines will only be used in exceptional cases.
This does not mean that the ICO will never fine public authorities. The regulator fully intends to hold the government accountable for the same information security standards that private and charitable sector organisations are held to.
However, these fines will often be reduced, such as the £78,400 penalty issued to Tavistock and Portman NHS Foundation Trust.
The ICO acknowledges that since the incident, the DfE has removed access to the LRS database for 2,600 organisations and has strengthened its registration process.
The DFE has now implemented regular checks for excessive searches on the database and proactively de-registers organisations that no longer use it.







