ICO to investigate University of York breach
The University of York admits to a data breach, leading to the ICO investigating further.


The Information Commissioner's Office (ICO) will be making enquiries into a data breach at the University of York, it was revealed today.
Over 17,000 students had their personal data leaked on a section of the university's website, a number of reports indicated, but a statement from the institution indicated just 148 individual records had been accessed.
IT PRO asked the university why there was such a significant discrepancy between the two figures, but it declined to comment.
Information published included student addresses, phone numbers, dates of birth and A-level results.
The university could face punishment from the ICO, which confirmed to IT PRO it is looking into the situation.
"We will be making enquiries into the circumstances of this alleged breach of the Data Protection Act before deciding what action, if any, needs to be taken," an ICO spokesperson said.
The ICO has the power to fine any organisation up to 500,000 if they are found to have breached the act.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The university said it took immediate action to rectify the problem and said it will contact the relevant people involved.
"We will contact these individuals over the next 24 hours to inform them and to discuss this matter," said Dr David Duncan, registrar at the University of York.
"We are also investigating all procedures and management systems and will undertake a thorough review of our data security arrangements."
Aziz Maakaroun, business development director at vulnerability management specialist Outpost24, said the breach was embarrassing for the university.
"By reporting this breach to the Information Commissioner's Office, and by launching a full and immediate investigation into how it occurred in the first place, the university is clearly taking the right steps to remedy the situation," Maakaroun said.
"However, you can't help but think that this is like locking the stable door after the horse has bolted."
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
TikTok to open first European data centre in Ireland
News The move could signify a desire to shift its operations away from the US as well as secure its position in the European market
By Sabina Weston
-
MPs in a muddle over GDPR and storing voters' personal data
News Labour MP Chris Bryant says his staff were told to delete constituents' data
By Bobby Hellard
-
Trump resort will not be charged for breaching data laws
News Presidential hopeful's Scottish golf course failed to register under the Data Protection Act for four years
By Adam Shepherd
-
Banks urged to share data but warned over security
News Experts voice concern over security of open API recommendations
By Rene Millman
-
EU centralises European open data through one portal
News Open Data Portal will enable public sector bodies to share information
By Rene Millman
-
Experts question sheer scale of data storage required by Snooper's Charter
News Who will foot bill for physical infrastructure to house UK's browsing histories?
By Jane McCallion
-
Snapchat's T&Cs update could put user data at risk
News Kaspersky said giving the service permission to share pictures with third parties could lead to a serious breach of privacy
By Clare Hopping
-
Transport Systems Catapult launches data sources catalogue
News Intelligent Mobility Data Index could push forward smart transport innovation in the UK
By Caroline Preece