TechNewsReel
Live

Natural Resources Wales leaks sensitive diversity data of former and current staff

The Welsh environment regulator inadvertently published a spreadsheet containing protected personal details of employees from a five-year period.

TechNewsReel Newsroom · September 7, 2026

Natural Resources Wales (NRW) has admitted to a significant data breach after inadvertently publishing a spreadsheet containing sensitive diversity information on its website. The leak exposes protected personal characteristics of employees who worked for the regulator between April 2013 and March 2018.

According to reports from The Register and Nation.Cymru, the exposed dataset included highly sensitive categories, including ethnicity, religion, sexual orientation, and disability status. The spreadsheet also contained information regarding employees' caring responsibilities and their ability to speak the Welsh language. While the breach affected a specific cohort of staff from the 2013-2018 period, the incident only came to light in September 2026. NRW has stated that there is currently no evidence that the leaked information has been misused.

Governance and Redaction Failures

This incident highlights a critical failure in data governance and the redaction process within the public sector. The breach occurred because sensitive personal information was not properly stripped from a document before it was made available to the public. Such errors are a recurring challenge for public bodies that must balance transparency requirements with strict data protection mandates. In this case, the failure to audit published documents meant that sensitive employee data remained accessible for an extended period before the error was identified and addressed.

Legal and Industry Implications

Because the leak involves diversity data, it falls under the "special category" of personal data protected by strict regulations, including the General Data Protection Regulation (GDPR). Under these laws, data concerning health, ethnicity, and sexual orientation requires higher levels of protection due to the potential for discrimination or harm if exposed. The gap between the period the data was collected (ending in 2018) and the current acknowledgment in 2026 raises serious questions about NRW's internal auditing capabilities and its ability to monitor the data it hosts publicly.

Next Steps for the Regulator

NRW must now determine the full extent of the exposure and notify the affected individuals who worked for the organization during the 2013-2018 window. Observers will be watching to see if the Information Commissioner's Office (ICO) launches a formal investigation into the regulator's data handling practices. It remains to be confirmed exactly how long the spreadsheet was live on the website and whether any third-party archives captured the data before it was removed.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.