DP-01: Mobile Guardian, Singapore
Data Breach · East Asia · Singapore · 2024
What Happened
On 17 April 2024, Mobile Guardian — a device management application widely used by Singapore MOE schools — suffered an unauthorised access breach. Names and email addresses of parents and staff from 127 schools were compromised. This illustrates the data risk schools take when sharing student and parent PII with any external organisation without adequate verification of their data security posture.
Outcome
127 schools affected; PDPA notification required; reputational damage
Quality Gaps Identified
- Schools shared sensitive parent and staff data with a third-party vendor without adequate prior verification of that vendor's security posture
- No standardised due diligence framework existed for vetting external organisations handling school data
- Schools routinely share student medical, dietary, SEND, and passport data with trip providers — data of at least equivalent sensitivity
TripTrust Quality Indicator Analysis
QI 6e requires trip providers to evidence their data protection policy, breach notification procedure, and compliance with applicable legislation (GDPR/PDPA) before schools share any student data with them.
Quality Indicators Referenced
QI 6e QI 6f