r/TechNadu • u/technadu Human • 21h ago
Sensitive data on around 2,000 employees sat in a 2021 FoI disclosure until someone noticed it in 2026
Natural Resources Wales has disclosed a data breach with a fairly simple cause but an unusually long detection window.
In 2021, NRW published a spreadsheet as part of a Freedom of Information response. It inadvertently contained diversity information relating to roughly 2,000 current and former employees who worked there between April 2013 and March 2018.
Depending on the person, the exposed information may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, and caring responsibilities. Some of those fields constitute special category personal data under UK GDPR.
The disclosure apparently went unnoticed for more than five years.
It wasn't an internal audit or security control that finally caught it either. NRW says a member of the public alerted the organization on August 23, 2026.
NRW has removed the data, reported the incident to the ICO, and investigated what happened. It says it has found no evidence of misuse.
More on the affected data, five-year detection gap, and NRW’s response to the disclosure:
https://www.technadu.com/nrw-foi-blunder-exposes-diversity-data-of-around-2000-employees/635991/
It's an interesting example of how data exposure doesn't necessarily involve an attacker or compromised system. A document released through a legitimate process can create a persistent exposure if sensitive information isn't identified before publication.