Case study: Security and privacy of online forms
This case study outlines the information and security implications of when a Victorian Public Sector Organisation’s (agency) online complaint form was not configured and/or tested correctly.
The incident involved the agency’s online complaint form accidently leaking data from one complainant’s completed form to a subsequent user’s new form.
The incident was identified not through an active audit or detection program, but when an individual was presented with a pre-populated online complaint form. This pre-population inadvertently disclosed personal information from somebody else’s complaint form, a disclosure which was inconsistent with the Information Privacy Principles and public sector information obligations.
This case study identifies how the leak occurred, how it was fixed, and lessons for public sector organisations who use any type of online form to collect personal or sensitive information from their stakeholders.