Natural Resources Wales (NRW) has confirmed a breach involving a spreadsheet that inadvertently exposed sensitive data on current and former staff. The spreadsheet, covering employees from April 2013 to March 2018, was unintentionally published online and contained detailed diversity information. Data points potentially disclosed include ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other equality monitoring metrics. Not all categories applied to every individual.
The error was discovered during an internal review into the spreadsheet’s publication. Once identified, NRW removed the file from its website, ceased access, secured confirmation that the exposed file was permanently deleted, and examined all published content for similar risks.
NRW has reported the incident to the UK Information Commissioner’s Office, following statutory requirements for personal data breaches. While technical specifics—such as how the file was uploaded or which parts of the website were involved—haven’t been disclosed, the organization acknowledged the data qualifies as very sensitive owing to traits employees would not expect to be made public.
Risks & Advice for Affected Individuals
There’s currently no evidence suggesting misuse of the disclosed data, but staff are urged to stay alert. Personal and diversity information can feed into more convincing phishing or impersonation attempts, such as pretend HR outreach or fake benefit schemes. Affected employees who haven’t yet been contacted by NRW can reach out via the email address the organization provided for inquiries.
Broader Lessons from the Breach
This case underscores how easily sensitive information can be exposed when files that contain hidden tabs, metadata, or unintentional columns are published without rigorous review. Standard safeguards—such as data classification, access controls, content scanning, and a formal approval workflow—are critical in preventing mishaps like this. NRW said it has completed a full internal investigation and is reviewing its processes to avoid similar incidents in the future.
This exposure represents one more reminder that even trusted public bodies are vulnerable when handling personal data. The unintended release of personal diversity metrics from a reputable organization highlights the need for stronger oversight in document handling and release procedures. As digital transparency grows, so does the responsibility to protect individuals’ private characteristics—especially when those are used for equality monitoring or sensitive HR purposes. What follows should be a careful audit of policies, better technical guardrails, and proactive communication with potentially affected individuals to rebuild trust and mitigate harm.