Welsh Environmental Agency Reveals Breach of Employee Diversity Records
Natural Resources Wales (NRW) confirmed a personal data breach that exposed sensitive diversity‑monitoring information belonging to both former and current staff members employed between April 2013 and March 2018.
The compromised data set includes details used for internal equity reporting, such as ethnicity, gender and other demographic markers. An internal audit uncovered the breach during a routine security review, prompting NRW to launch an investigation to determine how the information was accessed and why it was not adequately protected.
Under the UK General Data Protection Regulation, the exposure of such personal characteristics can constitute a serious violation, potentially leading to regulatory action and fines. NRW has indicated that it will inform all individuals whose records were affected and advise them on steps to mitigate any risk of misuse.
The incident arrives at a time when public bodies across Wales are under heightened scrutiny to demonstrate progress on inclusion and representation. Critics argue that the handling of sensitive HR data must match the importance placed on diversity goals, and the breach raises questions about the robustness of cybersecurity practices within government agencies.
NRW says it is cooperating with the Information Commissioner's Office, reviewing its data‑handling policies, and implementing additional safeguards to prevent future incidents. The agency will also provide updates to staff and the public as the investigation proceeds.
Comments (0)
Be the first to comment.
Join the discussion