Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff
- ID
- 22073
- Status
- summarized
- Published
- 07 Sep 2026, 7:04 PM
- Fetched
- 07 Sep 2026, 7:40 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/07/welsh-environment-regulators-foi-blunder-exposes-diversity-data-of-2000-staff/5294748
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 07 Sep 2026, 7:41 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Natural Resources Wales (NRW) disclosed that diversity data for around 2,000 current and former employees (April 2013–March 2018) was accidentally published in a spreadsheet released under a 2021 Freedom of Information request. The exposed data included special category personal data under UK GDPR such as ethnicity, disability status, religion, sexual orientation, and Welsh language ability. NRW says it found no evidence of misuse and has reported the breach to the ICO.
Why it matters
A concrete reminder that FoI and open-data release pipelines need automated PII redaction before publication—this breach went unnoticed for roughly five years. Builders handling government or regulated data should ensure spreadsheets are screened for special category fields before any external release, not rely on manual review.
Discussion angle
How hard is it to build a lightweight pre-release PII scanner for spreadsheets, and why do so many government FoI leaks still come down to someone manually exporting a raw sheet?