Ever since Labour came to power there have been endless headlines about “two-tier justice”. But the reality is that we’ve had not just two-tier justice but an entirely two-track system of tech regulation, for far longer.
Back in 2023 I drafted a piece about a huge data and cyber failure at the DfE that should have attracted a £10m fine from the ICO. How much did the DfE end up paying? A big fat zero, but they did get a stern reprimand.
I’d forgotten what should have been a major edtech story until one of my readers got in touch and shared the details of the case. In a combination of déjà vu and a senior moment, I dug out my original draft, remembered why I hadn’t published it (legal advice), and decided to update it. Here it is.
The campaigner at the centre of this is Jen Persson, Director of the privacy group defenddigitalme, who has spent years trying to prise loose what the DfE does with the identifying records of more than 28 million learners. Having made plenty of FOI requests myself over 20 years, I wasn’t surprised by the ICO’s grudging response to her enquiries, which included the line that disclosure, “risks harming the relationship that we have with the DfE and may prejudice our ability to exercise our regulatory function with the DfE in future”. Eventually the official conceded the public-interest threshold was met, then redacted or withheld a great deal anyway.
The breach itself
The database in question is the DfE’s Learning Records Service (LRS), which holds the records of up to 28 million pupils and learners aged 14 and over; name, date of birth, gender, and their learning and training achievements. This data is retained for 66 years. The DfE has overall responsibility for it as data controller, though it is operated through its executive agency, the Education and Skills Funding Agency (ESFA). The LRS is only supposed to be accessed for educational purposes.
However, in January 2020 The Sunday Times revealed that an employment-screening firm, Trust Systems Software UK Ltd, trading as Trustopia, had been using the database to run age-verification checks for GB Group, a listed “digital identity” specialist, whose own gambling-company clients wanted to confirm punters were over 18. The ICO found Trustopia had access from September 2018 to January 2020 and ran searches on around 22,000 learners, of which more than 20,000 queries were for age verification. Tellingly, the DfE only discovered the breach when the newspaper told them.
The mechanism matters, and it leads somewhere. Trustopia obtained LRS access by assuming the trading name of Edududes Ltd, a former training provider that had held legitimate access. The DfE waved the change through. Trustopia, the ICO noted drily, had never provided any government-funded educational training at all.
At the time of the breach, 12,600 organisations had LRS access. Since then the DfE has revoked access from 2,600 of them, which still leaves roughly 10,000 third parties with their digital tentacles in learner data.
The DfE was thumped and then let off
The ICO’s verdict was withering. Commissioner John Edwards said: “No-one needs persuading that a database of pupils’ learning records being used to help gambling companies is unacceptable. Our investigation found that the processes put in place by the Department for Education were woeful.” The reprimand found breaches of Article 5(1)(a) (lawfulness, fairness and transparency) and Article 5(1)(f) (integrity and confidentiality) of the UK GDPR, and described “prolonged misuse” of children’s data.
None of this came from nowhere. The ICO’s earlier 2020 compulsory audit of the DfE, itself triggered after defenddigitalme submitted a 118-page case bundle in 2019, found the department couldn’t provide assurance that its data processing complied with the law, and issued 139 recommendations, more than 60% of them high priority or urgent.
So what did the DfE pay? Nothing. The ICO had assessed an appropriate penalty of £10,030,000, a fine it said would have been “effective, proportionate and dissuasive”. Instead it issued a reprimand, under the revised approach to public-sector enforcement announced by Edwards in June 2022 as part of the ICO’s three-year ICO25 plan. His reasoning: any fine paid by a government department simply returns to government, so the impact “would be minimal”.
No action was taken against Trust Systems Software UK, its subsidiaries or its directors. The relevant companies were placed into liquidation in May and August 2022, before the reprimand landed.
This is the two-tier problem
Strip away the detail and you’re left with this: a private company and a public body can commit functionally identical breaches and face wildly different consequences. British Airways was fined £20m (cut down from an intended £183m) for a data breach. The DfE got a strongly-worded letter.
The ICO’s logic, that fining a public body is just taxpayers’ money moving around, would, taken to its conclusion, mean you’d never fine any public body for anything. Yet courts and other regulators do so routinely. A fine creates a line in the department’s accounts, attracts Public Accounts Committee and NAO scrutiny, and gives Permanent Secretaries and their officials a concrete reason to fund data protection properly. A reprimand does none of that. Given the volume and continuous nature of public-sector breaches, the evidence is that officials don’t fear reprimands, and the softer approach plainly isn’t working.
It’s worth being precise about scope here, because the DfE’s failures are not confined to the LRS. In early 2022 the department launched a daily attendance-data collection trial, telling schools the ICO had been consulted on its DPIA. FOI material later obtained by defenddigitalme showed that, when processing began, there was no completed DPIA and no genuine prior consultation; and that the ICO had asked the DfE to pause the high-risk collection, which it declined to do. Different project, same institutional reflex.
Given the scale of failure the ICO identified, you have to wonder how many of the remaining 10,000 LRS-connected organisations, let alone the department’s thousands of other contracts, would survive the kind of due diligence that’s routine in the private sector.
What I now think
In my more recent piece I argued that the DfE and ICO should work together more closely. Having gone back over the LRS fiasco, the entrenchment of two-tier regulation, and the widening gap between how the public and private sectors are policed, I’ve changed my mind.
Closer cooperation between regulator and regulated is part of the problem, not the solution. What’s actually needed is an independent anti-corruption and standards body for central government, and were one to exist (integrity in central government currently sits, unconvincingly, with the Cabinet Office), I’d ask it to look hard at the ICO’s public-sector (four-year trial) approach. In the meantime, the Conservatives, Reform and Labour all owe the public a straight answer on whether they’ll keep running the failed experiment of two-track data and tech regulation.
Finally, hats off and three cheers for Jen Persson and DigitalDefendMe.
Sources: Guardian · Schools Week · ICO revised public-sector approach · defenddigitalme

Leave a Reply