Statement : Notice of personal data breach affecting former and current employees
We are informing former and current employees of a personal data breach involving employee diversity information.
The breach affected individuals employed by NRW during the period April 2013 – March 2018.
Following an investigation, we identified that a spreadsheet containing employee information was inadvertently disclosed.
The information may have included personal data relating to diversity monitoring, such as ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities and other equality monitoring information. Not all categories of data applied to every individual.
We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected.
As soon as we became aware of the issue, we took immediate steps to contain the incident and investigate the circumstances surrounding the disclosure.
This included removing the information from the website where it had been published, obtaining confirmation that it had been permanently deleted, reviewing related published information to identify and address any similar risks, and reporting the matter to the Information Commissioner's Office (ICO) in line with our legal obligations.
We have undertaken a full investigation and are continuing to review our processes and controls to help prevent a recurrence.
While we are not aware of any evidence that the information has been misused, we encourage individuals to remain vigilant for any unexpected communications and to report any concerns.
Anyone who believes they may have been affected, and who has not received direct correspondence should contact peopledata@cyfoethnaturiolcymru.gov.uk