If you worked for Natural Resources Wales at any point in its first five years, some of the most sensitive information it held about you may have been exposed.
The environment body is warning current and former employees that a spreadsheet containing staff diversity information was “inadvertently disclosed”, in a statement published on its website on Friday.
The breach covers anyone employed by NRW between April 2013 and March 2018, a window that opens on the day the organisation was created.
NRW is the largest Welsh Government sponsored body, employing around 1,900 staff across Wales in roles from flood defence to forestry, so the five-year window is likely to take in thousands of past and present employees.
The information may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities and other equality monitoring information, NRW said, though not every category applied to every individual.
That list sits in the tier data protection law guards most closely. Details such as ethnicity, religion, health and sexual orientation are classed as special category data because of the harm their misuse can cause.
Deleted, and reported to the ICO
NRW said that as soon as it became aware of the issue, it moved to contain it: the information was removed from the website where it had been published, and the body obtained confirmation it had been permanently deleted.
It has also reviewed other published information for similar risks, and reported itself to the Information Commissioner’s Office.
“We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected,” the body said.
A full investigation has been carried out, according to NRW, and its processes and controls are still being reviewed to prevent a recurrence.
What the statement does not say is how many people are affected, how long the spreadsheet was publicly visible, or how the mistake came to be made.
What affected staff should do
NRW says it is not aware of any evidence that the information has been misused.
It is urging those affected to remain vigilant for any unexpected communications, and to report any concerns.
Anyone who believes they may have been affected and has not received direct correspondence should contact peopledata@cyfoethnaturiolcymru.gov.uk.
What the ICO could do about it
Under UK data protection law, organisations must report serious personal data breaches to the ICO within 72 hours of becoming aware of them, and must tell the people affected without undue delay where there is a high risk to them.
The watchdog can fine organisations up to £17.5m for the most serious breaches. But since 2022 it has taken a deliberately lighter approach to public bodies, preferring reprimands and reduced penalties so that fines do not divert public money from services.
The closest comparison is the Police Service of Northern Ireland, which published a spreadsheet containing details of all 9,483 of its officers and staff in a freedom of information response in 2023. The ICO fined it £750,000 in 2024, and said the penalty would have been £5.6m without the public sector discount.
The Ministry of Defence was fined £350,000 the year before, after an email blunder exposed the details of 265 Afghan nationals who had worked with UK forces, a penalty the ICO halved under the same approach.
Anyone unhappy with how their personal data has been handled can also complain directly to the watchdog.
Discover more from Swansea Bay News
Subscribe to get the latest posts sent to your email.

