Post

Welsh Environment Regulator's FoI Blunder Exposes Diversity Data of 2,000 Staff

Welsh Environment Regulator's FoI Blunder Exposes Diversity Data of 2,000 Staff

Welsh Environment Regulator’s FoI Blunder Exposes Diversity Data of 2,000 Staff

Natural Resources Wales (NRW) has revealed that diversity data belonging to approximately 2,000 current and former employees, who worked at the environmental regulator between April 2013 and March 2018, was exposed due to a classic Freedom of Information (FoI) blunder. The Welsh government-sponsored body confirmed on Friday that the information was “inadvertently disclosed” in a spreadsheet published on a website. NRW stated that around 2,000 individuals were affected and noted that the information was released in 2021 as part of a response to a request under the Freedom of Information Act 2000.

The exposed information may have included details such as ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other “equality monitoring information.” However, not every category applied to each affected employee. Some of these details constitute special category personal data and are subject to additional protections under the UK GDPR.

NRW expressed its sincere apologies for the incident, acknowledging the concern and uncertainty it may cause to those affected. “As soon as we became aware of the issue, we took immediate steps to contain the incident and investigate the circumstances surrounding the disclosure,” NRW stated in its disclosure. The organization reported the breach to the Information Commissioner’s Office (ICO), removed the information from the website, and confirmed that it had been permanently deleted. NRW added, “We have undertaken a full investigation and are continuing to review our processes and controls to help prevent a recurrence.”

The Register inquired how NRW discovered the breach and why it went unnoticed for years. The organization responded, “We were alerted to the issue by a member of the public on 23 August 2026.” While there is no evidence that the information has been misused, NRW encourages individuals to remain vigilant for any unexpected communications and to report any concerns.

Read full article

This post is licensed under CC BY 4.0 by the author.