CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6584

As cited

Copy frozen at (site build).

regulatory

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Natural Resources Wales exposed diversity monitoring data for approximately 2,000 current and former employees through an inadvertently published spreadsheet in 2021. The dataset, covering workers from April 2013 to March 2018, contained sensitive information including ethnicity, disability status, religion, sexual orientation, and caring responsibilities. The organization discovered the exposure on August 23, 2026, after a member of the public flagged it, then notified the Information Commissioner's Office and removed the files.

Why it matters: Organizations managing employment records should review their Freedom of Information Act disclosure processes to prevent accidental publication of protected personal data; this incident demonstrates how special category data under UK GDPR can remain exposed for years without detection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary