History of spreadsheets
The first spreadsheet computer programme for personal computers was released 45 years ago. This programme was named “VisiCalc” and allowed data sorting and storing in tabular rows and columns, playing a significant role in opening up spreadsheet use to business users. The app sold over 700,000 copies and commanded 85% of the spreadsheet software market (The Rise and Fall of VisiCalc: How the First Spreadsheet Software Drove the PC Revolution – History Tools) by 1982. The app did not include charts and graphs that you see in spreadsheet software’s of today.
VisiCalc was joined in the spreadsheet market in the early 80’s, with “Lotus 1-2-3” giving them a run for their money. The Lotus application introduced charts and graphs and had support for macros giving capabilities to automate mundane, repetitive tasks (Jan. 26, 1983: Spreadsheet as Easy as 1-2-3 | WIRED). This software began to dominate the market, unseating VisiCalc and taking the number one spot.
It may shock you that the spreadsheet powerhouse of today, Microsoft Excel, did not immediately take the world by storm when it was released in 1985 with Lotus still excelling in the market. It wasn’t until Excel was introduced on Windows computers that its popularity began to soar, becoming the dominant spreadsheet software in the mid-1990’s (Microsoft Excel | Description & History | Britannica). There have been many new versions with new features since then, with improvements to chart making, data sharing, formula writing and much more.
There are alternative spreadsheet software’s out there today such as Google Sheets, Apple Numbers and Tableau but most people’s and businesses default is Microsoft Excel – will there be a software that can knock it off its perch?
Spreadsheet data leaks
Using spreadsheets has many benefits but should you impose restrictions on what data is allowed to be stored in them or improve security of your workbooks? There has been many a time that data from Excel spreadsheets has been leaked, with it often containing sensitive or personal data.
Cambridge University Hospitals accidentally leaked information about patients on maternity and cancer wards on two separate occasions after responding to Freedom of Information (FOI) requests.
The first leak occurred in 2020 after a spreadsheet with data provided for a FOI request via the “What Do They Know” website. The data related to over 20,000 patients booked for maternity care between January 2016 and December 2019 and included names and hospital numbers of patients but didn’t include their home addresses or dates of birth. The personal data was not immediately visible in the spreadsheet but it could be seen via a pivot table.
In another case in 2021, the data of over 300 cancer patients on clinical trials was sent as part of a FOI response to Wilmington PLC. The data included their names, hospital numbers and some medical information but again, did not include home addresses or dates of birth.
Since the leaks, a dedicated helpline was set up for patients who are concerned about their data and the trust confirmed they informed the ICO about both data breaches.
Back in 2023, the PSNI received two FOI requests from the same person which came from the What Do They Know website. The requests were for information about the number of officers at each rank and number of staff at each grade. The information was downloaded from the PSNI’s HR system and included personal data relating to all employees. When the file was uploaded to What Do They Know, a hidden worksheet was discovered which contained personal details for all employees. Data included surname, location of post, contract type, gender and staff number.
As a result of this breach, the PSNI have been fined £750,000. However, this breach has not just had a financial impact, with many officers and staff from the PSNI feeling anxiety and fear over their occupations being exposed and shows that these types of breaches can have a much wider impact than financial and reputational.
The Kensington and Chelsea Council received three FOI requests in 2017 requesting statistics on how many empty properties were in the borough. Responding to the request, a member of the council produced a pivot table that contained a list of named owners against the addresses of empty properties in the borough. Disclosing this information could have caused the information to be exploited by criminals. Instead, a list was created of the number of empty properties that was pasted into a new spreadsheet. However, journalists that received the spreadsheet discovered that double-clicking on any cell revealed the identities of the owners of the properties and published details. Another journalist published the entire spreadsheet on an online blog.
Again, this breach exposed individuals’ personal information and led to individuals being visited at their home addresses by journalists. The council was fined £120,000 by the ICO too, stating they had failed to take reasonable steps to prevent a data breach from occurring.
Tips and Resources
Below are some tips and resources to help protect data that is held in spreadsheets.
ICO Guidance
After a number of high-profile data leaks involving spreadsheets, the ICO produced guidance and checklists to assist with spreadsheets. You can find these below:
- “How to disclose information safely” PDF – How to disclose information safely (ico.org.uk)
- Advisory note – Information Commissioner’s Office – Advisory note to public authorities | ICO
- Safe disclosure of information checklist – disclosure-checklist-v1_0.docx (live.com)
Remove Data
It is important to remove data that is not relevant to requests or the project required. This is especially the case when it concerns personal and sensitive data. Ensure that you double and triple check that there are no hidden columns, rows or worksheets that may contain data that you do not want disclosed. You could always get a second pair of eyes to look over the spreadsheet too to see if they can spot anything you may have missed.
Protect your spreadsheets
You can password protect your spreadsheets to restrict unauthorised access. Check out Microsoft’s guide to password protecting your spreadsheet here. Ensure that any password you use is memorable as Microsoft cannot recover forgotten passwords, meaning you will be locked out of the spreadsheet.
Even though the file will be password-protected, it may not always be secure to distribute the file if it contains personal or sensitive information. There will still be a risk that the spreadsheet and/or password to that spreadsheet will fall into the hands of an unintended user.
