Welsh Environment Regulator Exposes Staff Diversity Data in FoI Blunder
Natural Resources Wales inadvertently disclosed sensitive diversity data for approximately 2,000 current and former employees online, prompting an apology and investigation.

Natural Resources Wales (NRW), the environmental regulator for Wales, has admitted to a significant data breach resulting from a Freedom of Information (FoI) request blunder. The organization inadvertently published a spreadsheet containing sensitive diversity monitoring information for around 2,000 current and former employees online. The data, which covers the period from April 2013 to March 2018, may include details on ethnicity, disability, religion, sexual orientation, and other personal characteristics.
NRW confirmed the incident on Friday, stating that the information was "inadvertently disclosed" in a spreadsheet published on a website. While the organization did not initially specify the website or the exact number of affected individuals, it later clarified to The Register that approximately 2,000 people were impacted. The data was reportedly released in 2021 as part of a response to an FoI request.
The exposed "equality monitoring information" could encompass a range of sensitive personal details. These include, but are not limited to, ethnicity, disability status, religion or belief, sexual orientation, ability to speak Welsh, and caring responsibilities. NRW noted that not all categories applied to every individual whose data was compromised. Crucially, some of this information constitutes special category personal data under the UK General Data Protection Regulation (UK GDPR), which mandates stricter protections.
In response to the breach, NRW issued a sincere apology, acknowledging the potential concern and uncertainty the incident may cause to those affected. The organization stated that immediate steps were taken upon becoming aware of the issue to contain the incident and investigate the circumstances surrounding the disclosure. This included reporting the breach to the Information Commissioner's Office (ICO), the UK's data protection regulator.
NRW also confirmed that the compromised data was promptly removed from the website where it was published. Furthermore, the organization stated it had received confirmation that the data had been permanently deleted. A full investigation has been undertaken, and NRW is currently reviewing its internal processes and controls to identify and implement measures aimed at preventing similar incidents from occurring in the future.
While NRW stated that it is not aware of any evidence suggesting the information has been misused, it has advised affected individuals to remain vigilant. The regulator encouraged employees to watch out for any unexpected communications and to report any concerns they may have to the appropriate channels.
The incident highlights a recurring problem where sensitive personal data is inadvertently exposed through FoI requests or similar public disclosures. The delay between the data's release in 2021 and its discovery raises questions about NRW's data handling and review processes, which the organization is now actively examining to prevent future recurrences.