Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018.
An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was identified and rectified.
Natural Resources Wales Data Breach
According to NRW’s breach notification, the leaked spreadsheet may have contained special-category personal data collected for workforce diversity and equality monitoring.
The potentially exposed information included employees’ ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other equality-monitoring data. NRW emphasized that not every category of data applied to every affected individual.
While the organization has not disclosed the specific number of individuals involved, the sensitive nature of the information raises significant privacy concerns, as diversity-related records can reveal critical aspects of a person’s identity, health, beliefs, and personal circumstances. NRW stated, “Not all categories of data applied to every individual.”
Upon becoming aware of the accidental disclosure, NRW took immediate action. This included removing the spreadsheet from the website where it had been published and ensuring that the information was permanently deleted.
The organization also reviewed other published information to identify and mitigate related exposure risks. As required by law, NRW reported the incident to the UK Information Commissioner’s Office (ICO).
The agency has completed a full investigation and continues to assess its internal processes and controls to minimize the risk of a similar incident in the future. NRW remarked, “While we are not aware of any evidence that the information has been misused, we encourage individuals to remain vigilant for any unexpected communications and to report any concerns.”
Sensitive employee datasets can be targeted for social engineering, as they may help attackers craft convincing phishing emails, impersonation attempts, or targeted scams.
Individuals affected by the breach should be cautious of unsolicited messages that reference their employment history, personal characteristics, Welsh-language information, or diversity-related topics.
NRW has apologized to the affected employees, recognizing the concern and uncertainty caused by the incident. The organization is contacting those believed to be affected directly.
Former or current NRW employees who worked for the organization between April 2013 and March 2018 and believe they may be affected but have not received correspondence are encouraged to contact NRW at [email protected].
This incident underscores the risks of publishing workforce spreadsheets. It highlights the importance of implementing data minimization, access controls, and document review procedures before making files publicly accessible.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

