DP-01: Mobile Guardian, Singapore

Data Breach · East Asia · Singapore · 2024

What Happened

On 17 April 2024, Mobile Guardian — a device management application widely used by Singapore MOE schools — suffered an unauthorised access breach. Names and email addresses of parents and staff from 127 schools were compromised. This illustrates the data risk schools take when sharing student and parent PII with any external organisation without adequate verification of their data security posture.

Outcome

127 schools affected; PDPA notification required; reputational damage

Quality Gaps Identified

  1. Schools shared sensitive parent and staff data with a third-party vendor without adequate prior verification of that vendor's security posture
  2. No standardised due diligence framework existed for vetting external organisations handling school data
  3. Schools routinely share student medical, dietary, SEND, and passport data with trip providers — data of at least equivalent sensitivity

TripTrust Quality Indicator Analysis

QI 6e requires trip providers to evidence their data protection policy, breach notification procedure, and compliance with applicable legislation (GDPR/PDPA) before schools share any student data with them.

Quality Indicators Referenced

QI 6e QI 6f

Primary Sources