Security

Getting ready for the New Zealand Privacy Act 2020

Share this post:

Author: John Martin, Senior Security Architect, IBM Cloud and Cognitive Software, New Zealand

Are you ready for the New Zealand Privacy Act 2020 to come into effect on 1st December 2020? There’s a lot to consider as the clock ticks down and your organisation’s ability to comply is critical if you want to avoid some of the hefty fines involved.

As you align your security strategy with your business, here are some key areas to consider as you prepare:

Reporting privacy breaches immediately

It will be mandatory for businesses to immediately report serious privacy breaches, particularly where a data breach poses a risk of harm; for example, when leaked personal information is used in identity theft or accidentally published online.

The cost of a data breach and the speed at which the breach is identified and contained can be mitigated with a combination of risk assessment, the right security solutions and processes, and partnership with a security provider that can reduce complexity.

If you’re unsure a breach has been committed by your organisation, The Office of the Privacy Commissioner (OPC) has launched NotifyUs. This online tool enables businesses and organisations to assess whether notification of a breach is required.

Who does the new Privacy Act affect?

The new Act will affect all organisations that collect, store and use personal information about their employees and/or customers. This means if someone requests personal information held by a business, the business cannot destroy the information to avoid providing it. The Privacy Commissioner can issue compliance notices to require an organisation to do something or stop doing something. The penalty for not doing so may range from NZ $2,000 to $10,000. 

Complaints to the Human Rights Tribunal

An NZ $10,000 fine could on the face of it appear relatively low, but there is a sting in the tail. The Office of the Privacy Commissioner can make an official complaint to the Human Rights Tribunal, which may take a bit longer to go to court and be heard. But this has a maximum penalty of NZ $230,000 and all the publicity that will go with it.

Overseas organisations

Overseas organisations are also affected if they do business within New Zealand, so if you’re using service providers based overseas, it is your responsibility to ensure they are meeting the New Zealand Privacy laws. This includes businesses such as IBM, AWS, Google and many others. This is similar to the European Union’s General Data Processing Regulations or GDPR.

 Appointing a privacy officer

You will need to appoint at least one privacy officer, who is required to have a general understanding of the Act and deal with issues as they arise. The Privacy Commissioner outlines the role requirements as:

  • “be familiar with the privacy principles in the Privacy Act
  • work to make sure the organisation complies with the Privacy Act
  • deal with any complaints from the organisation’s clients about possible privacy breaches
  • deal with requests for access to personal information, or correction of personal information
  • act as the organisation’s liaison with the Office of the Privacy Commissioner.”

Christina Montgomery is IBM’s Chief Privacy Officer and an IBM Vice President.  As Chief Privacy Officer, Christina oversees IBM’s privacy program, compliance and strategy on a global basis, and directs all aspects of IBM’s privacy policies.  She also chairs IBM’s AI Ethics Board, a multi-disciplinary team responsible for the governance and decision-making process for AI ethics policies and practices. On IBM’s response to privacy, Christina has said: “We recognise our obligation to protect privacy while fostering innovation and competitiveness.”

Data versus information

There are some interesting aspects within this new Privacy Act; for instance, they do not talk about “data” they refer to “information”. There was an interesting High Court case in New Zealand, which stated that information is not confined to the written word, but embraces any knowledge however gained or held and, in some circumstances, can extend to the information contained in the mind of an individual.

It will also be an offence to mislead an agency in a way that affects someone else’s information and to destroy documents containing personal information if a request has been made for it.

Make sure you’re prepared

Remember the Privacy Act affects all organisations that collect, store and use personal information about their employees and/or customers. 

My advice for those who are not sure how to comply with the New Zealand Privacy Act 2020, is to make sure you:

It pays to be prepared.

Building a custom security plan that is both industry-specific and aligned to your security maturity demands a partner with the expertise and resources to help you as you navigate the new privacy act.

You must put in place appropriate controls to protect your data, wherever it exists and all the information that you use to run your organisation. To help you build a foundation of trust with your customers and employees you can learn more about the IBM Security Services team here.

References:

[1] https://www.privacy.org.nz/

[2] https://www.privacy.org.nz/further-resources/online-privacy-training-free/

[3] https://www.privacy.org.nz/privacy-act-2020/resources/

More stories

Getting ready for the New Zealand Privacy Act 2020

Author: John Martin, Senior Security Architect, IBM Cloud and Cognitive Software, New Zealand Are you ready for the New Zealand Privacy Act 2020 to come into effect on 1st December 2020? There’s a lot to consider as the clock ticks down and your organisation’s ability to comply is critical if you want to avoid some […]

Continue reading

How hackers are exploiting COVID-19

Remote working coupled with uncertainty around coronavirus gives hackers leverage into critical data. The Morrison government’s $1.34b investment in bolstering the country’s cybersecurity defences should be taken as a wake-up call to corporate Australia, according to industry experts. While COVID-19 has been a cause for pause for much of the world, for sophisticated cybercriminals it […]

Continue reading

The rising cost of a data breach in 2020

By Stephen Burmester, Asia Pacific Lead – X-Force Incident Response and Intelligence Services (IRIS) Increased remote working and digital footprints have accelerated the importance of cybersecurity in today’s business world. While the cost and risk of a cybersecurity breach are increasing year-on-year, there are measures companies can take to minimise the threat. Although breaches remain […]

Continue reading