Friday, October 9, 2026Moscow
Society

Leaked data in the Ministry of Education

Israel’s Office of Privacy has found the Ministry of Education guilty of serious breaches of personal data protection law after leaking information on 21,000 students, demanding immediate reforms and stressing that international certification does not exempt from national requirements

Published
Leaked data in the Ministry of Education

In early October 2026, Israel’s Office of Privacy Protection completed an administrative investigation into the Ministry of Education after a massive leak of personal and medical data of approximately 21,000 special education students from the haredi sector.

Sensitive information — including names, ID numbers, dates of birth, health status, and religious group affiliation — became available to outsiders through an open Internet link sent outside the ministry. The regulator revealed a number of gross violations: the lack of encryption and access control, the transfer of data by an employee without current authority, as well as the lack of mandatory documents to determine the database, approved procedures for information security and risk analysis. The agency described the incident as a “serious security event” and recalled that the responsibility for protecting the information lies with the owner of the database under section 17 of the Privacy Protection Act [gov.il].

The regulator paid special attention to the Ministry’s attempt to justify the presence of the ISO/IEC 27001 certificate, stressing that international certification does not exempt from the need to fully comply with national requirements. “Certification can only be taken into account if all the conditions established by Israeli law are met,” the statement said. A similar position is enshrined in Europe: the French CNIL and the British ICO have repeatedly stressed that ISO/IEC 27001 is only an additional measure that does not replace the implementation of all the requirements of the GDPR and national laws [CNIL], [ICO].

Among the prescribed measures are the development and approval of internal procedures for information security, conducting a full risk analysis for all systems, restricting access to sensitive information only for authorized employees, as well as the introduction of encryption and access control technologies for data transmission and storage. The Ministry of Education, in turn, expressed regret over the incident, announced the start of an internal review and promised to cooperate with the regulator to eliminate violations and prevent similar cases in the future.

Lawyers and cybersecurity experts note that since the entry into force of Amendment No. 13 to the Privacy Protection Act (August 2025), the regulator has received significantly expanded powers to impose administrative fines and conduct investigations against public authorities and private companies. The amount of fines can reach millions of shekels, and the incident with the Ministry of Education was the first major case of applying new sanctions to the state structure, which, according to experts, sets a precedent for the whole sphere.

International experience confirms that similar incidents occur in other countries, and the reaction of regulators is becoming more severe. In the United States at the end of 2024, a breach of the PowerSchool platform leaked the data of tens of thousands of students, including information about special educational needs. Authorities initiated investigations, schools notified parents, and the company stepped up cybersecurity measures, citing FERPA and COPPA [TechTarget], [EdWeek] requirements. In the UK in 2025, ICOs imposed fines on schools and IT contractors after leaking data from more than 10,000 pupils, including medical information, and mandated mandatory encryption and regular audits. In France, a similar incident with a regional education platform affected some 8,000 pupils and staff, the CNIL investigated and imposed an administrative fine, highlighting the importance of protecting the data of minors.

Key conclusion: In all cases, the regulators recognized the incidents as serious violations, demanded the immediate elimination of deficiencies, the introduction of new procedures and technical measures, and stressed that the availability of international certificates does not exempt from national obligations.

Summary table of international incidents

Country/Region Date/Platform Leakage Scale Data type (special categories) Regulator reaction (measures, links)

Israel Ministry of Education, 2026 21,000 students Children, medical data, special needs Investigation, orders, possible fines, reference to the Law on Protection of Privacy

USA PowerSchool, 12.2024 Tens of thousands of records Children, special needs Investigations, notifications, links to FERPA/COPPA

UK School IP, 2025 > 10,000 entries Children, ICO medical data: investigations, fines, references to GDPR

France Regional Platform, 2025 ~8,000 entries Children, CNIL medical opinion: investigation, fine, references to GDPR

In conclusion, the data breach at the Israeli Ministry of Education was not only a test for the national data protection system, but also part of a global trend of tightening control and sanctions in the field of information security. Experts predict that after this case, departments and companies will be forced to reconsider their approaches to data management, and the regulator will continue to strengthen supervision and apply new tools of influence provided for by Amendment No. 13. In the coming months, new guidelines are expected to be published and possibly the first major fines that will be imposed on citizens.

Source: Московский комсомолец ↗

Share

More on This Story

IV International Conference on Forensic Expert Activities in Minsk
SocietyIV International Conference on Forensic Expert Activities in Minsk

The IV International Scientific and Practical Conference “The Role and Importance of Forensic Expertise and Forensic Expertise in Ensuring National Security” has started in Minsk.

Виктория Даревская
In Minsk are looking for a missing 41-year-old man
SocietyIn Minsk are looking for a missing 41-year-old man

Wanted 41-year-old Alexander Narkevich, who 29 September left home and ceased to communicate, according to the correspondent of the Ministry.

Яна Романчик
Folk signs: what not to do Volgograd September 26, on the day of Kornilov
SocietyFolk signs: what not to do Volgograd September 26, on the day of Kornilov

On September 26, believers remember the Hieromartyr Cornelius Sotnik, who was one of the first pagans to convert to Christianity. In the people, the holiday is called Cornelius Day or simply Cornelius

МК
The EIA Briefing

Keep reading, every morning.

The stories that matter, chosen by our editors and in your inbox before 7 a.m. — every weekday.

No spam. Unsubscribe anytime.