Outcomes - Selected Case Summaries
Categories
Government E-services website
Informal Resolution | 15 November 2019
A government ministry notified us of a data breach involving an e-services website. Two members of their staff were using the website and one noticed that he could see the personal data of the other person. The website was taken offline and an investigation launched into how the breach had occurred. It was discovered that there had been an error in implementing certain global attributes on the web page, which had caused the breach. Further testing was undertaken to ensure that this problem would not arise in the future.
After verifying the steps undertaken to prevent a repeat of this incident, there seemed to be no prejudice to the rights of the individuals involved, and the case was closed without a formal enforcement notice.