Planer

  • Home
  • About
  • Privacy
  • Contact Me
Home I was wrong about the DfE & ICO

I was wrong about the DfE & ICO

Ever since Labour came to power there have been endless headlines about “two-tier justice”. But the reality is that we’ve had not just two-tier justice but an entirely two-track system of tech regulation, for far longer.

Back in 2023 I drafted a piece about a huge data and cyber failure at the DfE that should have attracted a £10m fine from the ICO. How much did the DfE end up paying? A big fat zero, but they did get a stern reprimand.

I’d forgotten what should have been a major edtech story until one of my readers got in touch and shared the details of the case. In a combination of déjà vu and a senior moment, I dug out my original draft, remembered why I hadn’t published it (legal advice), and decided to update it. Here it is.

The campaigner at the centre of this is Jen Persson, Director of the privacy group defenddigitalme, who has spent years trying to prise loose what the DfE does with the identifying records of more than 28 million learners. Having made plenty of FOI requests myself over 20 years, I wasn’t surprised by the ICO’s grudging response to her enquiries, which included the line that disclosure, “risks harming the relationship that we have with the DfE and may prejudice our ability to exercise our regulatory function with the DfE in future”. Eventually the official conceded the public-interest threshold was met, then redacted or withheld a great deal anyway.

The breach itself

The database in question is the DfE’s Learning Records Service (LRS), which holds the records of up to 28 million pupils and learners aged 14 and over; name, date of birth, gender, and their learning and training achievements. This data is retained for 66 years. The DfE has overall responsibility for it as data controller, though it is operated through its executive agency, the Education and Skills Funding Agency (ESFA). The LRS is only supposed to be accessed for educational purposes.

However, in January 2020 The Sunday Times revealed that an employment-screening firm, Trust Systems Software UK Ltd, trading as Trustopia, had been using the database to run age-verification checks for GB Group, a listed “digital identity” specialist, whose own gambling-company clients wanted to confirm punters were over 18. The ICO found Trustopia had access from September 2018 to January 2020 and ran searches on around 22,000 learners, of which more than 20,000 queries were for age verification. Tellingly, the DfE only discovered the breach when the newspaper told them.

The mechanism matters, and it leads somewhere. Trustopia obtained LRS access by assuming the trading name of Edududes Ltd, a former training provider that had held legitimate access. The DfE waved the change through. Trustopia, the ICO noted drily, had never provided any government-funded educational training at all.

At the time of the breach, 12,600 organisations had LRS access. Since then the DfE has revoked access from 2,600 of them, which still leaves roughly 10,000 third parties with their digital tentacles in learner data.

The DfE was thumped and then let off

The ICO’s verdict was withering. Commissioner John Edwards said: “No-one needs persuading that a database of pupils’ learning records being used to help gambling companies is unacceptable. Our investigation found that the processes put in place by the Department for Education were woeful.” The reprimand found breaches of Article 5(1)(a) (lawfulness, fairness and transparency) and Article 5(1)(f) (integrity and confidentiality) of the UK GDPR, and described “prolonged misuse” of children’s data.

None of this came from nowhere. The ICO’s earlier 2020 compulsory audit of the DfE, itself triggered after defenddigitalme submitted a 118-page case bundle in 2019, found the department couldn’t provide assurance that its data processing complied with the law, and issued 139 recommendations, more than 60% of them high priority or urgent.

So what did the DfE pay? Nothing. The ICO had assessed an appropriate penalty of £10,030,000, a fine it said would have been “effective, proportionate and dissuasive”. Instead it issued a reprimand, under the revised approach to public-sector enforcement announced by Edwards in June 2022 as part of the ICO’s three-year ICO25 plan. His reasoning: any fine paid by a government department simply returns to government, so the impact “would be minimal”.

No action was taken against Trust Systems Software UK, its subsidiaries or its directors. The relevant companies were placed into liquidation in May and August 2022, before the reprimand landed.

This is the two-tier problem

Strip away the detail and you’re left with this: a private company and a public body can commit functionally identical breaches and face wildly different consequences. British Airways was fined £20m (cut down from an intended £183m) for a data breach. The DfE got a strongly-worded letter.

The ICO’s logic, that fining a public body is just taxpayers’ money moving around, would, taken to its conclusion, mean you’d never fine any public body for anything. Yet courts and other regulators do so routinely. A fine creates a line in the department’s accounts, attracts Public Accounts Committee and NAO scrutiny, and gives Permanent Secretaries and their officials a concrete reason to fund data protection properly. A reprimand does none of that. Given the volume and continuous nature of public-sector breaches, the evidence is that officials don’t fear reprimands, and the softer approach plainly isn’t working.

It’s worth being precise about scope here, because the DfE’s failures are not confined to the LRS. In early 2022 the department launched a daily attendance-data collection trial, telling schools the ICO had been consulted on its DPIA. FOI material later obtained by defenddigitalme showed that, when processing began, there was no completed DPIA and no genuine prior consultation; and that the ICO had asked the DfE to pause the high-risk collection, which it declined to do. Different project, same institutional reflex.

Given the scale of failure the ICO identified, you have to wonder how many of the remaining 10,000 LRS-connected organisations, let alone the department’s thousands of other contracts, would survive the kind of due diligence that’s routine in the private sector.

What I now think

In my more recent piece I argued that the DfE and ICO should work together more closely. Having gone back over the LRS fiasco, the entrenchment of two-tier regulation, and the widening gap between how the public and private sectors are policed, I’ve changed my mind.

Closer cooperation between regulator and regulated is part of the problem, not the solution. What’s actually needed is an independent anti-corruption and standards body for central government, and were one to exist (integrity in central government currently sits, unconvincingly, with the Cabinet Office), I’d ask it to look hard at the ICO’s public-sector (four-year trial) approach. In the meantime, the Conservatives, Reform and Labour all owe the public a straight answer on whether they’ll keep running the failed experiment of two-track data and tech regulation.

Finally, hats off and three cheers for Jen Persson and DigitalDefendMe.

Sources: Guardian · Schools Week · ICO revised public-sector approach · defenddigitalme 

Jul 1, 2026Richard Taylor
2 months ago EducationDfE, digitaldefendme, Education and Skills Funding Agency, Edududes Ltd, ESFA, GDPR, ICO, Jen Persson, John Edwards, Learning Records Service, LRS, Trust Systems Software, Trustopia0
Richard Taylor
The meow of a toothless tiger$1m or your money back

Leave a Reply Cancel reply

Archives
  • July 2026 (4)
  • June 2026 (2)
  • May 2026 (4)
  • March 2026 (2)
  • January 2026 (1)
  • September 2025 (3)
  • July 2025 (2)
  • June 2025 (1)
  • May 2025 (2)
  • March 2025 (1)
  • February 2025 (2)
  • January 2025 (2)
  • December 2024 (1)
  • September 2024 (2)
  • June 2024 (1)
  • May 2024 (1)
  • April 2024 (1)
  • February 2024 (1)
  • January 2024 (1)
  • December 2023 (1)
  • October 2023 (1)
  • September 2023 (1)
  • August 2023 (1)
  • June 2023 (1)
  • May 2023 (1)
  • February 2023 (1)
  • December 2022 (1)
  • November 2022 (1)
  • September 2022 (1)
  • July 2022 (2)
  • June 2022 (2)
  • April 2022 (1)
  • March 2022 (2)
  • February 2022 (1)
  • September 2021 (2)
  • August 2021 (2)
  • July 2021 (1)
  • June 2021 (1)
  • May 2021 (2)
  • March 2021 (1)
  • January 2021 (2)
  • November 2020 (1)
  • October 2020 (2)
  • July 2020 (1)
  • June 2020 (1)
  • April 2020 (1)
  • January 2020 (2)
  • November 2019 (1)
  • September 2019 (1)
  • July 2019 (1)
  • June 2019 (2)
  • May 2019 (1)
  • March 2019 (1)
  • January 2019 (1)
  • May 2018 (1)
  • June 2017 (1)
  • May 2017 (2)
  • April 2017 (1)
  • March 2017 (1)
  • February 2017 (4)
  • January 2017 (1)
  • December 2016 (1)
  • November 2016 (2)
  • May 2016 (4)
  • April 2016 (1)
  • February 2016 (1)
  • January 2016 (1)
  • January 2015 (1)
  • May 2014 (2)
  • April 2014 (1)
  • March 2014 (2)
  • February 2014 (5)
  • October 2013 (1)
  • September 2013 (2)
  • August 2013 (1)
  • July 2013 (1)
  • June 2013 (2)
  • May 2013 (4)
  • April 2013 (2)
  • February 2013 (3)
  • January 2013 (3)
  • September 2012 (2)
  • August 2012 (2)
  • April 2012 (1)
  • February 2012 (3)
  • November 2011 (1)
  • October 2011 (2)
  • September 2011 (5)
  • August 2011 (5)
  • July 2011 (2)
  • June 2011 (2)
  • May 2011 (1)
2014 © Media Taylor