Natural Resources Wales (NRW), a Welsh environmental regulator, exposed diversity data for 2,000 staff members through a Freedom of Information (FoI) request error five years ago but only disclosed the incident publicly in September 2026. The agency claims it found no evidence the data was misused since the 2021 disclosure.
Diversity Spreadsheet Published in Error with FoI Response
The breach occurred when NRW published a spreadsheet containing sensitive employee diversity information in error as part of a Freedom of Information response. FoI systems are designed to release government data to the public upon request, subject to privacy and security redactions. The NRW error bypassed redaction controls, releasing protected employee data directly into the public domain.
Employee diversity data can include race, ethnicity, sexual orientation, disability status, and religious beliefs—all protected characteristics under UK data protection law. Employers collect this information for equal opportunity monitoring and regulatory compliance reporting, but it must be aggregated and anonymized before public disclosure.
The spreadsheet’s publication made individually identifiable diversity data available to anyone who accessed the FoI response, whether through the original requester, public records archives, or downstream sharing.
Five-Year Disclosure Delay Raises Breach Detection and Notification Questions
The incident occurred in 2021, but NRW did not disclose it publicly until September 2026—a five-year delay. This timeline raises questions about the agency’s breach detection capabilities, internal incident response procedures, and compliance with UK data protection notification requirements.
UK law requires organizations to notify the Information Commissioner’s Office (ICO) of personal data breaches within 72 hours of becoming aware of them. If NRW discovered the breach in 2021 but delayed public disclosure until 2026, that suggests either the breach went undetected for five years or the agency reported it to regulators but did not inform affected employees or the public.
NRW stated it found no evidence the data was misused since 2021. However, absence of detected misuse is not the same as proof the data was not accessed, copied, or retained by third parties. Diversity data posted in a public FoI response could have been indexed by search engines, archived by data brokers, or copied by individuals with no immediate malicious intent but who retain the data for future use.
Ongoing Risk for 2,000 NRW Employees Despite No Detected Misuse
Even if the data has not been actively misused, its availability creates ongoing identity theft and discrimination risks for the 2,000 affected employees. Diversity characteristics combined with employment details and names enable targeted harassment, discriminatory hiring decisions by future employers who obtain the data, or identity theft schemes that exploit protected characteristics.
The five-year exposure window means the data has been available for a significant period. Any individual or organization that accessed the FoI response between 2021 and 2026 could still retain copies, making it impossible to fully contain the breach through removal or redaction now.
NRW disclosed the incident and stated no evidence of data misuse was found. The five-year delay between the breach and public disclosure may trigger regulatory scrutiny from the UK Information Commissioner’s Office, which enforces data protection breach notification requirements and can impose fines for non-compliance.
FoI Error Points to Process Failures in Public Data Release Controls
Freedom of Information systems are designed to balance public transparency with privacy protection. Requests for government data trigger a review process where officials redact sensitive personal information before releasing documents. The NRW error indicates this redaction process failed for a spreadsheet containing 2,000 employees’ diversity data.
Process failures of this type typically stem from human error—an official attaching the wrong file version or releasing an unredacted draft. However, systemic failures can also cause these breaches: inadequate training on data protection requirements, insufficient review steps before release, or technical systems that do not flag sensitive data before publication.
The scale—2,000 employee records—suggests the spreadsheet was a comprehensive organizational diversity report. Organizations collect diversity data to monitor equal opportunity compliance, but this data is highly sensitive because it reveals protected characteristics that individuals have a right to keep private.
