Skip to content
theregister·

🔒NRW Exposed Diversity Data of 2,000 Employees

Sensitive Employee Data Leaked Online

TL;DR

NRW inadvertently published sensitive employee data online, exposing details like ethnicity and disability status for around 2,000 people. The breach occurred in 2021 but affected data from 2013 to 2018.

NRW accidentally published sensitive employee data online, including ethnicity, disability status, and religious beliefs for around 2,000 current and former employees. The data was part of a Freedom of Information request response and was online from April 2013 to March 2018. NRW has since apologized and taken steps to ensure the data was permanently deleted. This incident highlights the importance of data protection and the risks associated with FOI requests. NRW is reviewing its processes to prevent future breaches.

NRW Exposed Diversity Data of 2,000 Employees — theregister

Key Points

1

NRW inadvertently published sensitive employee data online, affecting 2,000 people.

2

The data was published as part of a Freedom of Information request response.

3

The data was online from April 2013 to March 2018.

4

NRW has since taken steps to ensure the data was permanently deleted.

5

NRW is reviewing its processes to prevent future breaches.

Why It Matters

If you're handling sensitive data in compliance with UK GDPR, this breach highlights the risks of FOI requests and the importance of robust data protection measures. NRW's incident shows the potential for data exposure even years after the initial request, emphasizing the need for continuous monitoring and review of data handling practices.

NRWFreedom of Informationdata-breachGDPRemployee-data

Frequently Asked Questions

Why does this matter?

If you're handling sensitive data in compliance with UK GDPR, this breach highlights the risks of FOI requests and the importance of robust data protection measures. NRW's incident shows the potential for data exposure even years after the initial request, emphasizing the need for continuous monitoring and review of data handling practices.

What happened?

NRW inadvertently published sensitive employee data online, exposing details like ethnicity and disability status for around 2,000 people. The breach occurred in 2021 but affected data from 2013 to 2018.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,463 builders reading daily.

Also get