The Education Ministry violated Israel’s privacy law and data-security regulations after sensitive personal and medical information about approximately 21,000 special education students reached unauthorized people, the Justice Ministry’s Privacy Protection Authority said Thursday.

The students were registered in the ministry’s ultra-Orthodox (haredi) education district. The exposed information included identifying details, home and school information, religious affiliation, and medical information specifying each student’s disability, according to the authority.

The finding followed an administrative review by the privacy regulator. The authority classified the leak as a serious security incident, but its announcement did not specify a fine or say whether further enforcement action would follow.

The authority opened its review in March 2025 after the leak was reported in the media and the information was found to have circulated online. Its investigation traced the file’s creation to around May 2024, when Education Ministry employees sought to build a digital form to streamline the placement of special education students in the haredi sector.

The employees extracted information from a ministry system and created a file containing the students’ sensitive data. They then connected it to a form that educational institutions could use to enter information.

View of an empty classroom at a school in Givatayim, during a teacher's strike, on May 6, 2025.
View of an empty classroom at a school in Givatayim, during a teacher's strike, on May 6, 2025. (credit: MIRIAM ALSTER/FLASH90)

Data reached members of public, unauthorized individuals

The Education Ministry told the authority that the data file was intended to work behind the scenes, allowing the form to retrieve information from it. In practice, however, both the form and the underlying file were set so that anyone with the link could access them. The file was not password-protected and could be viewed or downloaded, while the link itself could be forwarded to others.

The link was sent in May 2024 to relevant staff at haredi educational institutions through both official and private email accounts. The authority found that the data ultimately reached members of the public and other people who were not authorized to receive it.

The ministry argued that the leak was probably caused by an isolated error in the permission settings for one of the forms. According to its account, the error allowed an outside user to search for and locate the data file after opening a link.

The authority nevertheless found wider failures in the ministry’s handling of the system. The information had been extracted by an employee who was not included on the current list of people authorized to use it. The ministry had also failed to maintain a required description of the database, a compliant information-security policy, and a current security risk assessment.

The regulator also found failures in the way access permissions were managed, the system was operated, and the data were transmitted. Sending the information through an open link without accepted encryption measures violated the rules governing the transfer of information over the internet, it said.

The ministry database contains sensitive information about more than 100,000 people and is therefore subject to a high level of security requirements under the regulations, according to the authority.

The ministry argued during the review that its certification is under international information-security standards, which exempt it from some of the regulations. The authority rejected that argument, saying certification under an international standard does not by itself replace compliance with Israeli privacy rules.

Files contained records on 21,439 children

It concluded that the ministry violated Section 17 of the Protection of Privacy Law, which makes the owner of a database responsible for securing the information it holds, as well as several provisions of the data-security regulations.

When the leak was first reported in March 2025, N12 said the file contained records on 21,439 children, including names, identification numbers, dates of birth, addresses, and medical information. Parents said the disclosure had exposed private diagnoses within their communities and could affect their children and families in haredi social and matchmaking circles.

Because the incident occurred before Amendment 13 to the Protection of Privacy Law took effect, the authority said it conducted the review under the law and enforcement powers in force at the time.