NRW employee diversity spreadsheet exposed online
Natural Resources Wales says it accidentally published an employee diversity spreadsheet online. The spreadsheet may have exposed sensitive personal information, including ethnicity, disability status, religion or belief, sexual orientation and Welsh-language ability.
- Report priority
- Medium
- Involves
- Current and former Natural Resources Wales employees
What is known
- NRW said a spreadsheet containing workforce diversity and equality-monitoring data was accidentally published online, making the information accessible until it identified and removed the file.
- GBHackers describes an accidental disclosure rather than a cyberattack.
- It doesn't report how long the file was available, what led to its publication or whether anyone downloaded it.
What to do
First, determine whether you fall within the employment period above. Then check for correspondence from NRW about the incident. If you haven't received anything, contact [NRW's people-data team](mailto:peopledata@cyfoethnaturiolcymru.gov.uk), state that you worked there during that period and ask whether your record was included. No letter doesn't establish that you were unaffected.
Be cautious with unexpected messages referring to your NRW employment, personal characteristics or Welsh-language information, and report concerns to [NRW's people-data team](mailto:peopledata@cyfoethnaturiolcymru.gov.uk).
Reported details
This was reported as an accidental public disclosure of workforce equality-monitoring data, not a system intrusion. Potentially exposed categories included ethnicity, disability status, religion or belief, sexual orientation, Welsh-language ability and caring responsibilities. According to GBHackers, NRW said it wasn't aware of evidence that the information had been misused and had notified the UK Information Commissioner's Office.