AuraTracer智迹闻
中文

EVENT DOSSIER

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

2026-09-07 19:04 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
3mentions
SummaryAI generated

Natural Resources Wales acknowledged that there were FoI errors in the spreadsheet it released regarding diversity data of 2,000 employees, resulting in the accidental disclosure of sensitive personal information protected by UK GDPR, including race, disability status, and religious beliefs. The data was released in 2021 in response to a request under the Freedom of Information Act. The agency has removed the relevant content from its website and confirmed its permanent deletion, while also reporting the breach to the Information Commissioner’s Office. The organization stated that it will conduct a thorough investigation and review of its processes to prevent such incidents from happening again. No evidence of data misuse has been found so far, but affected individuals are reminded to remain vigilant. The issue was not discovered until August 23, 2026, by a member of the public.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
Information Commissioner's OfficeNatural Resources WalesWelsh government

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Information Commissione…1Information Commissione…1Natural Resources Wales…1

SignalsSIGNALS

Keyword heat
  • Natural Resources Wales1
  • Welsh government1
  • Information Commissioner's Office1

All reports (1)SOURCES

T The Register en 2026-09-07 19:04

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Natural Resources Wales admitted that the spreadsheet it released containing data on the diversity of 2,000 employees contained FoI errors, resulting in the accidental disclosure of sensitive personal information. The data included categories such as race, disability status, and religious beliefs, which are protected by the UK General Data Protection Regulations (UK GDPR). This information was released in 2021 in response to requests under the Freedom of Information Act 2000. The agency has removed the content from its website and confirmed that it will be permanently deleted, and has also reported the breach to the Information Commissioner’s Office (ICO). The agency stated that it will conduct a thorough investigation and review of its processes to prevent such incidents from happening again. No evidence of data misuse has been found so far, but affected individuals are reminded to remain vigilant. The issue was not discovered until August 23, 2026, by a member of the public.