Shanraq.org Shanraq.org
Data of 4,096 people exposed on school websites: Why deleting the files is not enough
Opinion

Data of 4,096 people exposed on school websites: Why deleting the files is not enough

Prosecutors in Semey found documents on 31 school websites containing data about 3,752 employees and 344 minors. Names, national identification numbers, birth dates, addresses, and phone numbers were exposed. This column explains why removal only closes the public link, what system owners should investigate, and how to prevent a repeat.

The Abai Region prosecutor’s office says official websites of 31 schools made documents containing personal data about 4,096 people publicly available. The files covered 3,752 employees and 344 minors.

The disclosed fields included names, individual identification numbers, dates of birth, home addresses, and phone numbers. This combination links a person to official identifiers and their location, so the incident should not be treated as a minor page-formatting mistake.

Removing the link is only the first step

The files should be restricted and removed from public access immediately. But an online copy may remain in a search cache, archive, visitor download, or forwarded message.

The site owner should determine how long the material was available, which files were exposed, what data categories they contained, and what access logs show. Without that, the impact cannot be assessed and notification decisions cannot be made responsibly.

The central question is how publication was approved

When the same problem appears across dozens of institutions, the review should go beyond individual carelessness. Reporting templates, publication requirements, staff roles, permissions, and review procedures all need examination.

A common failure is uploading an original spreadsheet or scan instead of a prepared public version. If safety depends entirely on one person noticing every sensitive field, the system will eventually fail again.

Measures that actually reduce risk

Schools and site operators need a short mandatory pre-publication route:

  1. define why the document must be public;
  2. remove fields the reader does not need;
  3. inspect hidden sheets, metadata, and attachments;
  4. require a second-person review;
  5. limit publication rights and log every action;
  6. scan the site regularly for identification numbers, phone numbers, and other patterns.

Automated detection cannot replace human review, but it can stop a file containing 12-digit identification numbers before it reaches the internet.

Why children’s data needs special care

A child does not choose the school information system or control its settings. Addresses, phone numbers, and birth dates can be used for social engineering aimed at children or their parents.

Public accountability can usually be achieved through aggregated school data. Reporting enrollment, procurement, or staffing generally does not require publishing a child’s identifiers.

What should be reported publicly

The official statement confirms that a violation was found. To rebuild trust, a final report without further personal data should state the exposure period, remediation, a contact route for affected people, and the process changes introduced.

The job is not complete when 31 sets of files are deleted. It is complete when the same kind of document cannot be published again without redaction and review.

This is an opinion column. Incident facts come from the prosecutor’s statement; recommendations and conclusions are editorial analysis.

Source

If you have found a mistake or a typo in this article, tell us about it

Comments (0)

No comments yet. Be the first.