Cover Wales
Back to The NationThe Nation · Data protection

A Natural Resources Wales spreadsheet that may have listed staff ethnicity, religion and sexual orientation was published by mistake, and NRW has reported itself to the regulator

NRW is the arm's length statutory body behind flood warnings, forests, fisheries and river pollution checks in Wales. Its notice of 4 September says a spreadsheet of employee diversity records was disclosed by mistake and taken down from a website, covering people it employed between April 2013 and March 2018. NRW has published no figure for how many that is. Anyone who thinks they may be affected and has had no letter can email peopledata@cyfoethnaturiolcymru.gov.uk, NRW's Welsh-language address.

Christine Jones · · updated

Warning Forest Operations Sign, Natural Resources Wales. Photo: Gary Rogers, CC BY-SA 2.0, via Geograph (geograph.org.uk/photo/5351740) and Wikimedia Commons

Where this sits

5 checked facts

  1. Is this normal?

    • NRW says the breach hits people it employed between April 2013 and March 2018. It does not say how many, or how long the file was online.

      naturalresources.wales

  2. How does it compare?

    • NRW's own accounts record exactly one case reported to the ICO in each of the last three years: 2023-24, 2024-25 and 2025-26.

      cdn.cyfoethnaturiol.cymru

    • The window opens the month NRW took on staff: its accounts date the transfer of Environment Agency Wales employees to 1 April 2013.

      cdn.cyfoethnaturiol.cymru

  3. Who can change it?

    • Three of the six categories NRW names, ethnicity, religion or belief and sexual orientation, sit on the ICO's own list of special category data.

      ico.org.uk

    • The ICO's public sector approach, published 11 November 2025, fines public bodies only in the most egregious cases and reaches for reprimands first.

      ico.org.uk

Every line above was checked against the source named beside it before this piece was published.

Natural Resources Wales published a notice on 4 September saying a spreadsheet of employee information was “inadvertently disclosed”, and that it has reported itself to the Information Commissioner's Office, the UK regulator an organisation must tell about certain personal data breaches. The breach reaches people NRW employed between April 2013 and March 2018, in NRW's words “individuals employed by NRW during the period”. Nobody has published how many that is, and it cannot be read off any staff count: a five-year window takes in everyone who joined and everyone who left across it. NRW says it is “not aware of any evidence that the information has been misused”, and asks people to “remain vigilant for any unexpected communications and to report any concerns”. It has written directly to some of those affected without saying how many, and tells anyone who believes they may be affected and has had no letter to contact peopledata@cyfoethnaturiolcymru.gov.uk.

What NRW says was disclosed

NRW says the data may have included diversity monitoring covering ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities and, in its own words, “other equality monitoring information”. NRW adds that not all categories applied to every individual. Three of the six it names are special category data on the ICO's list, the tier UK GDPR gives extra protection: ethnicity, religion or belief and sexual orientation. Disability may qualify, in the ICO's wording, in so far as it may reveal information about a person's health. Welsh language ability and caring responsibilities do not. The window opens in the month NRW took over operations: the same accounts date the transfer of Environment Agency Wales employees to 1 April 2013.

What NRW will not say

NRW says it acted as soon as it became aware, which included “removing the information from the website where it had been published” and obtaining confirmation of permanent deletion, and reporting the matter to the ICO. It does not say whose website that was. It does not give the number of people affected, or how long the file was available. And it does not say when it became aware, or when it reported. Those last two matter, because the duty runs to 72 hours from becoming aware, where feasible, and without either date nobody outside NRW can say whether it was met. NRW employed 2,492 people at 31 March 2026, but that is today's headcount rather than the affected group, and no single year's staff count stands in for one either. NRW's own accounts from inside the window record 1,925 full time equivalent employees at 31 March 2015 and 2,048 people at 31 March 2017, snapshots of a workforce that changed across all five years. NRW publishes no count of the affected group, and none of these figures is one.

How this compares with NRW's own record

NRW's accounts log one case reported to the ICO in each of the three years to March 2026, and describe the most recent as a precautionary incident where “no data was accessed and no further action was required”. This one is not that: NRW does not call it precautionary and does not say the file went unread. NRW's year ends on 31 March, so a report made after that date falls in 2026-27 and is not counted in the run of three. NRW has not said when it reported.

What happens to NRW now

What happens next is largely the ICO's call, and on the regulator's own published policy that is unlikely to mean a fine. Under the public sector approach the ICO published on 11 November 2025, it reaches for warnings, reprimands and enforcement notices, “with fines only issued in the most egregious cases”, a threshold measured on harm, on intent or negligence, and on previous infringements. NRW appears nowhere on the ICO's published enforcement register, which held 222 entries when Cover read it. Two Welsh public bodies do appear: South Wales Police, reprimanded in August 2022 and served an enforcement notice in October 2025, and the Welsh Language Commissioner, reprimanded in January 2022. None of those three actions is a fine. That register lists action the ICO has taken and published, not every breach reported to it, so it is not a clean sheet. The ICO has published nothing on this case, and neither the Welsh Government nor the Senedd, the Welsh Parliament, had done so a day after the notice went up. NRW's statement names nobody, and its apology reads: “We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected.”

Corrected at 00:25 on Sunday 6 September. An earlier version of this piece said the only Welsh public body on the ICO's enforcement register was South Wales Police. The Welsh Language Commissioner is also on it, reprimanded in January 2022. The earlier version also said the breach window opened in the month NRW first took on staff; NRW was established in 2012 and appointed staff before April 2013, which is the month it took over operations. This version adds the contact address NRW gave for anyone who thinks they are affected. Corrected again at 09:05 on Sunday 6 September, after a review desk read. An earlier version offered NRW's 1,925 full time equivalent staff at 31 March 2015 as “a closer measure” of the affected group; a single-date snapshot cannot measure a five-year population, and it was also a full time equivalent count set against a headcount. This version says plainly that no figure for the affected group exists. A published verification note also said no NRW annual report for the window was on its site; the 2013-14, 2014-15 and 2016-17 reports all are.

ShareWhatsAppX

Comments

  • No replies yet. Be the first.