What happened
Natural Resources Wales (NRW), the Welsh government sponsored environmental regulator, has confirmed a data breach affecting diversity records of around 2,000 current and former employees who worked there between April 2013 and March 2018. The data was "inadvertently disclosed" in a spreadsheet published on a website as part of a response to a Freedom of Information request back in 2021, and the organization only learned of the exposure on August 23, 2026, when a member of the public alerted it.
The spreadsheet may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability and caring responsibilities, along with other "equality monitoring information". Not every category applied to every person. Because some of those details are special category personal data under the UK GDPR, they carry extra protections, which makes their exposure a more serious matter than a routine records leak.
NRW says it has reported the breach to the Information Commissioner's Office, removed the information from the website, and obtained confirmation that it has been permanently deleted. It says it has found no evidence the data was misused and is reviewing its processes and controls to prevent a recurrence, while encouraging affected people to stay vigilant for unexpected communications.
Why this is a GRC story
This incident sits at the collision point of two obligations every public body carries: transparency under freedom of information law, and protection of personal data under privacy law. An FoI response is a governance artifact. It goes out through a process designed for disclosure, which means the checks that normally apply to a data release, redaction review, retention limits and access control, can be the weakest exactly where sensitive data is most likely to slip through.
The five year gap between the 2021 release and the 2026 discovery is the detail GRC teams should sit with. The failure was not only in the original disclosure decision. It was in the absence of any monitoring that would have caught the exposure earlier. A control that only reacts to a tip from the public is not a control, it is a hope. Processes should include periodic checks of what has actually been published, especially for responses that combined FoI material with HR data.
There is also a lesson about special category data in everyday files. Diversity and equality monitoring spreadsheets look like ordinary HR paperwork, but under the UK GDPR they are in the highest risk class. Anyone who assembles FoI responses should be trained to spot that kind of data before a release, not after a five year exposure comes to light.
What to watch
Watch what the ICO does with this referral. NRW is a public body, so the regulator's options include enforcement action if it finds systemic shortcomings rather than a one-off error. Watch also whether other public bodies start auditing their own historical FoI releases for similarly sensitive spreadsheets. This kind of incident tends to prompt a quiet wave of retrospective review across the sector.
Attribution: Analysis based on The Register's reporting and related public reporting. This article is original commentary, not a repost of the source material.
