Hazard

Reprimands · Central government

Department for Education

No fineReprimands
Root cause Children's data Processing children's personal data without age assurance, parental consent or a lawful basis — the ICO's most active enforcement front against large platforms.

What happened

The DfE permitted third party access to the LRS database outside of the DfE and subsequent processing took place of some of that personal data (including children) for the purposes of age verification, without appropriate control or oversight. The investigation has found that therefore the personal data on the LRS database was processed in an insecure manner and for purposes that were not initially intended. Furthermore, the DfE failed to be transparent about that processing.

Summarised from the notice published by the ICO on 2 November 2022. Read the original notice — it is the authoritative version.