The UK's ICO reprimands the Department for Education for giving employment screening company Trustopia access to data on up to 28M children from 2018-2020
Context & Ripple Effects
The reprimand closes the loop on a story first reported in January 2020, when betting companies were found to have accessed the same Department for Education database covering 28 million children through an unauthorized third party. Trustopia, an employment screening firm, is another commercial recipient of that learning-records data, and the ICO's action — a reprimand rather than a fine — covers access from 2018 to 2020.
The regulator's choice of instrument matters: where it later moved to monetary penalties against platforms under its children's-data agenda, including the £12.7M TikTok fine and enforcement tied to the Age Appropriate Design Code, the Department for Education receives only censure — a gap between how the ICO treats state data custodians versus private platforms.
First-order effects
- The Department for Education must account publicly for how a national children's database was shared with an employment screening company without adequate safeguards, putting its third-party data-sharing contracts under immediate scrutiny.
- Trustopia's access ends and its screening business loses a government-sourced data pipeline, forcing it to source verification data commercially.
Second-order effects
- Other UK government departments holding large citizen datasets face pressure to audit which third parties hold copies, since the betting-firm episode showed unauthorized onward access was already happening downstream.
- Commercial background-checking and identity-verification firms lose the assumption that public-sector records are available as an input, raising their compliance costs.
Third-order effects
- If the ICO keeps pairing reprimands for state custodians with fines for private platforms, the structural question becomes whether government data holders need statutory duties as strict as those the Age Appropriate Design Code imposes on companies handling children's data.
The trend: Children's data protection is hardening across both private platforms and government databases, with the ICO escalating from design codes to fines while its treatment of state custodians lags behind.