Bromcom
On a school or workplace learning platform, the institution bought the system and you were never the customer, so deletion is its call and a request to the vendor is usually sent back to it. The main record stays long after you have gone, with no period named.
Reported incidents
Pupils' and staff sign-in emails taken from a school software service
2026-09-25Affected Legacy single sign-on registration service (CommunicationServer)
Bromcom, which supplies the management information system used by many UK schools, says an unauthorised party took staff and pupil registration data from its legacy single sign-on service, used to link Microsoft or Google accounts to a school. Some functions could be called without checking who was asking. Suspicious activity began on 24 August 2026 and most of the data was taken between 3 and 7 September. The data includes email addresses, some of them pupils' personal addresses, sign-in provider, sign-in dates and school identifiers. Bromcom says passwords and sign-in tokens were not taken and parents were not affected.
People affected typically ask Bromcom to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.