As cited
Copy frozen at (site build).
regulatory
Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff
Natural Resources Wales exposed diversity monitoring data for approximately 2,000 current and former employees through an inadvertently published spreadsheet in 2021. The dataset, covering workers from April 2013 to March 2018, contained sensitive information including ethnicity, disability status, religion, sexual orientation, and caring responsibilities. The organization discovered the exposure on August 23, 2026, after a member of the public flagged it, then notified the Information Commissioner's Office and removed the files.
Why it matters: Organizations managing employment records should review their Freedom of Information Act disclosure processes to prevent accidental publication of protected personal data; this incident demonstrates how special category data under UK GDPR can remain exposed for years without detection.
- Source published
- First seen by Cybersecurity Tracker