IT Brief New Zealand logo
Technology news for New Zealand's largest enterprises
Partner content
Story image

Are you ready for a more privacy-focused New Zealand?

By Sara Barker
Tue 1 Dec 2020
FYI, this story is more than a year old

New Zealand’s new Privacy Act is now in effect, with significant changes that affect every organisation that operates in New Zealand, physically and/or virtually.

The Privacy Act 2020 supersedes the Privacy Act 1993 and brings New Zealand in closer alignment with Australia’s Notifiable Data Breaches (NDB) Act 2018, and the European Union’s General Data Protection Regulations (GDPR) 2018.

“The new Privacy Act provides a modernised framework to better protect New Zealanders’ privacy rights in today’s environment,” says Privacy Commissioner John Edwards.

One critical introduction in the Privacy Act 2020 is the requirement for mandatory breach reporting in certain circumstances.

If organisations experience a privacy breach that could cause serious harm, they must notify the Privacy Commissioner and anyone affected by the breach.

Serious harm could include the risk of data being published on the internet or elsewhere, or the risk of identity theft. This could happen if a cyber attack, such as a ransomware attack, hits a business and data is compromised.

If a breach that could be considered to have caused serious harm is not reported, organisations risk fines of up to $10,000 per breach. 

Other changes put a focus on ensuring that organisations, both in New Zealand and offshore, must protect New Zealanders’ data. For example, tech firms like Google and Facebook must also abide by the Privacy Act.

MinterEllisonRuddWatts senior associate June Hardacre says the Act will change how organisations do business.

"It's a matter of when, not if, cyber threats end up impacting every business. At the same time, New Zealanders are now more empowered than ever and value their privacy. People are prepared to act if they believe their privacy has been breached."

Organisations that are found to be in breach of the Privacy Act could face fines of up to $10,000 per breach.

The 13 Privacy Principles in the Privacy Act 2020 include:

  1. You can only collect personal information if it is for a lawful purpose and the information is necessary for that purpose. You should not require identifying information if it is not necessary for your purpose.
  2. You should generally collect personal information directly from the person it is about (there are exceptions)
  3. When you collect personal information, you must take reasonable steps to make sure that the person knows why it’s being collected; who will receive it; whether giving it is compulsory or voluntary; and what will happen if they don’t give you the information
  4. You may only collect personal information in ways that are lawful, fair and not unreasonably intrusive
  5. You must make sure that there are reasonable security safeguards in place to prevent loss, misuse or disclosure of personal information, including limits on employee access to other people’s information
  6. People have a right to ask you for access to their personal information. In most cases, you have to promptly give them their information
  7. A person has a right to ask an organisation or business to correct their information if they think it is wrong
  8. Before using or disclosing personal information, you must take reasonable steps to check it is accurate, complete, relevant, up to date and not misleading
  9. You must not keep personal information for longer than is necessary
  10. You can generally only use personal information for the purpose you collected it
  11. You may only disclose personal information in limited circumstances
  12. You can only send personal information to someone overseas if the information will be adequately protected (i.e. the personal information is subject to privacy safeguards that are similar to those in New Zealand). However, this rule does not apply to a cloud or service provider storing or processing information on behalf of an agency if that cloud or service provider does not use or disclose that information
  13. Generally, you may only assign unique identifiers (for example driver’s license numbers or IRD numbers) where it is necessary for operational functions.

These changes are just the tip of the iceberg. It is imperative that businesses take the time to understand The Privacy Act 2020 and uphold the law. This is why organisations and employees should take the time to learn about the Act and how it will change the way we all deal with data.

Mimecast provides business training and awareness to help organisations understand their obligations under the new Act, and what it means for them.

Mimecast Australia and New Zealand country manager Nick Lennon says that the Act has an impact on all data-driven companies with any operations in New Zealand.  It’s as much of a change for offshore businesses as it is for homegrown ones.

“The Act makes it very clear that offshore companies can no longer claim that New Zealand privacy laws don’t apply to them," says Lennon.

"With the Privacy Act 2020 coming into force, knowledge is power. No organisation should risk being caught unaware by this important legislation."

Mimecast can assist with training and awareness, as well as preparing, assessing, upskilling and having the right plans in place.

Learn more about Mimecast’s awareness and training programmes here.

Related stories
Top stories
Story image
Data ownership
Brands must reclaim trust by empowering data ownership
According to Twilio's new State of Personalisation Report 2022, 62% of consumers expect personalisation from brands, and yet only 40% trust brands to use their data responsibly and keep it safe.
Story image
Stock security features inadequate in face of rising risk
"Organisations must proactively find ways of identifying unseen vulnerabilities and should take a diligent, holistic approach to cybersecurity."
Story image
Video: 10 Minute IT Jams - An update from CrowdStrike
Scott Jarkoff joins us today to discuss current trends in the cyber threat landscape, and the reporting work CrowdStrike is doing to prevent further cyber harm.
Story image
Forescout reveals top vulnerabilities impacting OT vendors
Forescout’s Vedere Labs has disclosed OT: ICEFALL, naming 56 vulnerabilities affecting devices from 10 operational technology vendors.
Story image
TO THE NEW unveils A/NZ Managed Services for Microsoft Azure
TO THE NEW has released Managed Services for Microsoft Azure to meet the growing demand in the A/NZ market and globally.
Story image
Internet of Things
Global 5G subscriptions to top one billion by the end of 2022
Global 5G subscriptions are predicted to pass the one billion milestone by the end of 2022, according to a new report.
Story image
Significant security concerns resulting from open source software ubiquity
"The risk is real, and the industry must work closely together in order to move away from poor open source or software supply chain security practices."
Story image
Video: 10 Minute IT Jams - An update from Tricentis
Tricentis provides software testing automation, and software quality assurance products for enterprise software.
Story image
Enable launches free Wi-Fi in Christchurch city centre
Fibre broadband provider, Enable, and the Christchurch City Council have launched their new Christchurch Free Wi-Fi service in the central city. 
Story image
Dark web
Cybercrime in Aotearoa: How does New Zealand law define it?
‘Cybercrime’ is a term we hear all the time, but what exactly is it, and how does New Zealand define it in legal terms?
Story image
NOWPayments launches new service to analyse cryptocurrency fees
NOWPayments has launched a new network fee optimisation solution that analyses current network fees and picks the most profitable option out of the client's payout wallets.
Story image
Internet of Things
Domino's Pizza: A blueprint for secure enterprise IoT deployment
Increasingly, organisations are embracing smart technologies to underpin innovations that can enhance safety and productivity in every part of our lives, from industrial systems, utilities, and building management to various forms of business enablement.
Story image
Threat actors ramp up their social engineering attacks
As people get better at identifying potential threats in their inbox, threat actors must evolve their methods. Their new M.O? Social engineering.
Story image
Microsoft expands APAC Enabler Mentorship Program
"Mentors are the key to success for every professional. A good mentor is a coach, a guide, as well as a vocal advocate."
Story image
How TruSens air purifiers can create healthier workspaces
The pandemic has heightened our awareness of our own and others’ health, and made us all much more conscious of the environments we work in.
Story image
Online identity theft is rising in NZ - here’s what to do about it
It may start with a few stolen details online, but it could end with thousands of dollars missing or worse, a reputation down the drain.
Story image
Forrester names Talend Leader in enterprise data fabric
Forrester has named Talend a leader among enterprise data fabric providers in the Forrester Wave: Enterprise Data Fabric, Q2 2022 report.
Story image
Digital Transformation
Cybersecurity priorities for digital leaders navigating digital transformation
In recent years, Asia-Pacific has especially been a hotspot for cyberattacks, and as we continue into 2022, it’s evident that the problem is becoming more significant.
Story image
Honeywell launches new carbon energy management software for buildings
The new Carbon & Energy Management service allows building owners to track and optimise energy performance against carbon reduction goals, down to a device or asset level.
Story image
The link between cybersecurity, extremist threat and misinformation online in Aotearoa
Long story short, it's often the case that misinformation, threat and extremism link closely to cybersecurity issues and cyber harm.
Story image
Ready for anything with the PagerDuty Operations Cloud
In a world of digital everything, teams face increasing complexity. Ever-growing dependencies across systems and processes put customer and employee experience, not to mention revenue, at risk.
Story image
Network Security
Netskope announces zero trust network access updates
Customers can now apply zero trust principles across a range of hybrid work security needs, including SaaS, IaaS, private applications, and endpoint devices.
Story image
Trend Micro
5G network projects driven by improving security and privacy
Trend Micro's new study reveals the prospect of improved security and privacy capabilities are the main motivations behind private 5G wireless network projects.
Story image
Industry-first comprehensive risk-based API security enhances protection
Application Programming Interfaces (APIs) have become a crucial part of operating web and mobile application businesses and are causing significant economic growth in the digital sector.
Story image
Amazon Web Services / AWS
Zscaler, AWS accelerate onramp to the cloud with zero trust
Zscaler has announced an extension to its relationship with Amazon Web Services, as well as innovations built on Zscaler's Zero Trust architecture.
Story image
Ingram Micro launches vendor-backed security program
Ingram Micro has unveiled a new program intended to give resellers the effective offerings their customers need to stay safe in the evolving threat landscape.
Story image
Hybrid workforce
Why hybrid working is here to stay and how to ace it
Citrix's new report reveals hybrid workers are more productive and engaged at work than their office and completely remote counterparts.
Story image
Vulnerable APIs costing businesses billions every year
Large companies are particularly vulnerable to the security risks associated with exposed or unprotected APIs as they accelerate digital transformation.  
Story image
How to achieve your monthly recurring revenue goals
Monthly recurring revenue (MRR) is the ultimate goal, the most important issue on which anyone in the IT channel should focus.
Story image
Volpara, Microsoft project to detect cardiovascular issues
Volpara Health Technologies is working with Microsoft on a research and development project to speed up creating a product that detects and quantifies breast arterial calcifications (BACs).
Story image
Overcoming hybrid and multi-cloud challenges to drive innovation
Driven by improvements in technology, financial services companies have advanced both internal and external systems and processes, with the likes of digitisation, personalisation and risk management redefining the industry.
Story image
New Relic
How to tackle the great brain drain in the tech industry
Attracting and retaining tech talent in Australia and New Zealand is becoming increasingly challenging, with the 2022 Hays Salary Guide showing a startling 91% of employers facing a skills shortage.
Story image
Cyclone selected as NZ MOE software licensing partner
Following a recent Request for Proposal (RFP), Christchurch-based company Cyclone Computer Company Ltd (Cyclone) has been selected as The Ministry of Education’s software licensing partner.
Story image
Consumers want personalisation, but don't trust brands with their data
Customers expect personalisation during every brand interaction but they don't trust brands to keep their personal data secure and to use it responsibly. 
Story image
The best ways to attract young talent during labour shortages
New research from Citrix reveals hybrid working and ventures into the metaverse are top of mind for Gen Z workers.
Story image
F5 Networks
Telstra, F5 team up to bolster services and solutions
“This partnership demonstrates our ongoing investment into APAC as we continue delivering high value services and solutions to our partners and customers."
Story image
Artificial Intelligence
Accenture shares the benefits of supply chain visibility
It's clear that gaining better visibility into the supply chain will help organisations avoid excess costs, inefficiencies, and complexity to ultimately improve their bottom line.
Story image
Why is NZ lagging behind the world in cybersecurity?
A recent report by TUANZ has revealed that we are ranked 56th in the world when it comes to cybersecurity - a look into why we're so behind and what needs to be done.
Story image
Global investment in data centers more than doubled in 2021
DLA Piper's latest global survey finds the total investment in data center infrastructure worldwide rose from USD $24.4 billion in 2020 to USD $53.8 billion in 2021.
Story image
Robust digital warehouse management crucial in Asia-Pacific
Thanks to a network of “cloud” stores, grocery and food delivery providers such as Foodpanda can arrange for these commonly requested items to get packed up and sent over in almost no time.
Story image
Unknown connections: How safe is public WiFi in Aotearoa?
If it's not your own household WiFi, then who has control of your data and is your connection actually safe?
Story image
Employers look to hire inexperienced coders due to skills shortage
"Even inexperienced workers without prior qualifications or experience had managed to pivot to new roles in coding as long as they are willing to upskill."
Story image
Gartner's top recommendations for security leaders
"Leaders now recognise that major disruption is only one crisis away. We can’t control it, but we can evolve our thinking, philosophy, program and architecture.”
Story image
How Airwallex helps businesses achieve globalisation success
As markets continue to shift, businesses need to be able to provide the same quality of service for customers regardless of where they are located around the world.