Welsh environment regulator’s FoI blunder exposes diversity data of 2,000 staff

← Back to the feed

Welsh environment regulator’s FoI blunder exposes diversity data of 2,000 staff

The Register · 1 hour ago

Natural Resources Wales (NRW), the Welsh government-sponsored environmental regulator, has admitted that sensitive diversity data belonging to around 2,000 current and former employees was accidentally published on a website. The breach stems from a spreadsheet released in 2021 in response to a Freedom of Information request, meaning the data sat exposed online for roughly five years before coming to light. NRW has not explained how the error occurred or why it went undetected for so long, raising questions about the regulator's data-handling controls given it is itself a public body subject to FoI obligations.

The exposed spreadsheet covered staff who worked at NRW between April 2013 and March 2018, and may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities and other equality monitoring information, some of which counts as special category data under UK GDPR. NRW says it has reported the incident to the Information Commissioner's Office, removed the spreadsheet, confirmed its permanent deletion, and found no evidence of misuse so far, while urging affected individuals to stay alert for suspicious contact.

  • NRW exposed diversity data of ~2,000 staff via a 2021 FoI response.
  • Breach went unnoticed on a website for around five years.
  • ICO notified; NRW says no evidence of misuse found yet.

Environment Science

Read the full article at the source →