AI Weekly Malaysia

Back to items Summaries

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

ID
22073
Status
summarized
Published
07 Sep 2026, 7:04 PM
Fetched
07 Sep 2026, 7:40 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/07/welsh-environment-regulators-foi-blunder-exposes-diversity-data-of-2000-staff/5294748
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
3.5
Created
07 Sep 2026, 7:41 PM
Tags
Audience
developerssaas_startup_founders

What happened

Natural Resources Wales (NRW) disclosed that diversity data for around 2,000 current and former employees (April 2013–March 2018) was accidentally published in a spreadsheet released under a 2021 Freedom of Information request. The exposed data included special category personal data under UK GDPR such as ethnicity, disability status, religion, sexual orientation, and Welsh language ability. NRW says it found no evidence of misuse and has reported the breach to the ICO.

Why it matters

A concrete reminder that FoI and open-data release pipelines need automated PII redaction before publication—this breach went unnoticed for roughly five years. Builders handling government or regulated data should ensure spreadsheets are screened for special category fields before any external release, not rely on manual review.

Discussion angle

How hard is it to build a lightweight pre-release PII scanner for spreadsheets, and why do so many government FoI leaks still come down to someone manually exporting a raw sheet?

Top