Report: betting companies had access to a UK Department for Education database with records of 28M children, after a third-party gave access without permission
Charlie Osborne / ZDNet : Tweets: @libertyhq , @dannyjpalmer , @damiancollins , @ineqegroup , and @carolecadwalla Tweets: Liberty / @libertyhq : This data was collected from students by trusted education staff for educational purposes. Betting firms got their hands on it. And Department for Education says 12,000 organisations had access to the Learning Records Service. Questions need answering. https://www.thetimes.co.uk/... Danny Palmer / @dannyjpalmer : Bold move for a minister to claim that a massive dataset can't be lost or stolen or altered. Just the other day it was reported that data about children stored by the Department for Education was handed over to a third-party without permission... https://www.zdnet.com/... https://twitter.com/... Damian Collins / @damiancollins : This is an appalling data breach and should be investigated by @ICOnews I'd like @CommonsCMS to look at this as well. Why can't we use public data for age verification on social media and online games, but betting firms can use it to target school kids. https://www.thetimes.co.uk/... @ineqegroup : Names, ages, and physical addresses were allegedly included in the data breach. The publication labeled the incident as “one of the biggest breaches of [UK] government data . https://www.zdnet.com/... Carole Cadwalladr / @carolecadwalla : Shocking story by @KenzaBryan. Govt data on schoolchildren passed to betting firms as numbers of young people gambling skyrocket. Hope @iconews investigating https://www.thetimes.co.uk/...
Context & Ripple Effects
This 2020 report sits at the start of an accountability arc that ran for years: Liberty and MPs including Damian Collins and Carole Cadwalladr pressed the Department for Education over how a database collected by school staff for educational purposes reached betting firms, after a third party granted access without permission. The department's own figure — 12,000 organisations with access to the Learning Records Service — turned one leak into a question about systemic access control.
The story also foreshadowed a wider reckoning over children's data held by institutions: US investigators later found ransomware groups publishing schoolchildren's records, and Illuminate Education's breach exposed over a million students.
First-order effects
- The Department for Education faces immediate pressure to explain how a third party could grant betting companies access to records of 28 million children, and to audit which of the 12,000 organisations on the Learning Records Service actually needed it.
- Campaigners including Liberty gain a concrete case showing data collected under educational trust was repurposed for commercial targeting.
Second-order effects
- Regulatory follow-through materialised: the ICO's later reprimand of the department over the Trustopia employment-screening access showed the same access-control failure recurring across multiple third parties, not a one-off.
- Other government departments holding large citizen datasets come under the same scrutiny, as the Legal Aid Agency breach later demonstrated how broadly such stores can be exposed.
Third-order effects
- If the pattern holds, centralised education and public-sector databases shift from open multi-organisation sharing toward tightly scoped, audited access — with regulators treating broad standing access itself as the violation rather than any single misuse.
- The episode feeds a structural argument, echoed by the adtech privacy reckoning around IAB Europe's GDPR framework, that commercial reuse of data gathered for one purpose is becoming legally and politically untenable.
The trend: Government-held datasets on citizens — especially children — are moving from permissive multi-party access toward enforced purpose limits, with regulators and campaigners closing the gap between why data was collected and who ends up using it.