Article 787H7 Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

by
from www.theregister.com - Articles on (#787H7)
Story ImageNatural Resources Wales (NRW) says diversity data belonging to around 2,000 current and former employees who worked at the environmental regulator between April 2013 and March 2018 was exposed in a classic Freedom of Information (FoI) blunder. The Welsh government-sponsored body confirmed on Friday the information was "inadvertently disclosed" in a spreadsheet published on a website. Its statement did not identify the site, explain how the sensitive data came to be posted there, or say how many people were affected. NRW subsequently told The Register that around 2,000 people were affected and said it had released the information in 2021 as part of a response to a request under the Freedom of Information Act 2000. The exposed information may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other "equality monitoring information," although not every category applied to each affected employee. Some of these details constitute special category personal data and are subject to additional protections under the UK GDPR. "We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected," NRW said in its disclosure statement. "As soon as we became aware of the issue, we took immediate steps to contain the incident and investigate the circumstances surrounding the disclosure." The organization said it reported the breach to the Information Commissioner's Office (ICO), removed the information from the website, and obtained confirmation that it had been permanently deleted. "We have undertaken a full investigation and are continuing to review our processes and controls to help prevent a recurrence," NRW added. "While we are not aware of any evidence that the information has been misused, we encourage individuals to remain vigilant for any unexpected communications and to report any concerns." The Register asked NRW how it discovered the breach and why it went unnoticed for years. It told us: "We were alerted to the issue by a member of the public on 23 August 2026." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments