Skip to main content
Emerging ThreatsData Breaches

NRW FoI blunder exposes 2,000 staff diversity records

A calm office setting with desks, chairs, and paperwork in the background.

"We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected," Natural Resources Wales said in a disclosure statement after confirming that a spreadsheet containing staff diversity data had been "inadvertently disclosed."

Natural Resources Wales confirms an "inadvertently disclosed" spreadsheet affecting around 2,000 people

Natural Resources Wales (NRW) confirmed on Friday that diversity data belonging to current and former employees who worked at the regulator between April 2013 and March 2018 was exposed after a spreadsheet was published on a website. The organisation initially did not identify the site, explain how the sensitive data came to be posted there, or say how many people were affected; it later told The Register that around 2,000 people were affected.

NRW said the information had been released in 2021 as part of a response to a request under the Freedom of Information Act 2000. The organisation described the disclosure as inadvertent and apologised to those affected.

The categories of information that were exposed

According to NRW, the exposed material may have included a range of equality monitoring details: ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities and other "equality monitoring information." NRW noted that not every category applied to every affected employee.

NRW also acknowledged that some of those details constitute special category personal data and are therefore subject to additional protections under the UK GDPR.

Steps NRW says it has taken: removal, ICO notification, deletion and an internal review

NRW said it took immediate steps to contain the incident once it became aware of the disclosure. The organisation reported the breach to the Information Commissioner's Office (ICO), removed the information from the website, and obtained confirmation that the material had been permanently deleted.

NRW added it had "undertaken a full investigation and are continuing to review our processes and controls to help prevent a recurrence." The regulator encouraged affected individuals to "remain vigilant for any unexpected communications and to report any concerns." NRW also said it was not aware of any evidence that the information had been misused.

The Register's follow-up: questions about discovery and duration online

The Register asked NRW how it discovered the breach and why it went unnoticed for years. Those questions were included in a follow-up to NRW's disclosure; the statement released by NRW did not set out how the spreadsheet came to be posted or precisely how long the data remained accessible online beyond the note that the information had been released in 2021 as part of an FoI response.

What this means for affected employees, privacy teams, and the Information Commissioner's Office

  • Affected employees: NRW's own statement urged vigilance for "unexpected communications" and to report concerns, reflecting the immediate practical risk individuals face when sensitive equality monitoring data is exposed.
  • Privacy and security teams at public bodies: NRW said it is reviewing processes and controls and has launched a full investigation — a signal that operational and publication procedures for FoI responses will be focal points for remediation.
  • The Information Commissioner's Office: NRW reported the incident to the ICO and secured confirmation of permanent deletion, putting the ICO in a position to assess the breach and any regulatory consequences under the UK GDPR and data-protection regimes.

NRW's actions — removal of the file, notification to the ICO, confirmation of deletion and an internal investigation — are the concrete steps the organisation has disclosed. The Register's questions about how the spreadsheet was posted and why it went unnoticed for years frame the next lines of inquiry. For roughly 2,000 current and former staff whose equality monitoring information may have been exposed, the immediate concern is the potential misuse of sensitive personal data and the practical steps they should take to monitor and report any suspicious contact.

Original story: The Register