Articles
Your Work Email Is Not Your Personal Inbox
Most of us have probably done it at some point. Used our work email address for something that has absolutely nothing to do with work. A recent case from the Office of the Privacy Commissioner is a useful reminder that where personal information is stored can matter just as much as what the information is about.
The 13, 13½ or 14 Privacy Principles?
There are few things New Zealand privacy professionals enjoy more than a good academic debate. For years, life was beautifully simple. The Privacy Act had 13 Information Privacy Principles (IPPs). We called them "the 13 IPPs" and everyone knew what we meant.
Then along came IPP 3A.
What Your Website Knows About Your Customers
Tracking pixels have become a standard part of digital marketing, but many organisations don't understand what information they're collecting or where it's going. Here's what the OAIC's latest guidance means for businesses and why privacy should be treated as a business decision, not just a technical one.
The Myth of “Private” Facebook Groups
Recently a Facebook group that was informal, member-driven, and private became the subject of a legal ruling under the Privacy Act 2020. The case involving the “Bad Tenants, New Zealand (Landlords Only)” group, and the $7,500 award against its administrator for failing to comply with a privacy request.
Controller or Processor: Decide Early
Somewhere between the first line of code and the first paying customer, there is a quiet decision every SaaS builder makes, whether privacy is something you will design, or something you will retrofit. Most choose the latter, not out of neglect, but out of urgency to get to market.
When you build a SaaS product, you are not just creating features. You are defining relationships.
Policies Alone Don’t Provide Protection
During our work we often hear a familiar reassurance: “We have a policy for that.” It sounds comforting and responsible. But a recent decision from the Office of the Privacy Commissioner (PBN3791), involving something as ordinary as a lost USB stick, is a sharp reminder that policies alone don’t protect anything. What is required to mitigate the risk is a combination of controls, readiness, and culture.
Reading Between the Privacy Lines
When organisations see a rise in access, correction, deletion, or opt-out requests, the first instinct is to consider how to streamline the Privacy Request Process. This is important, but they’re rarely the sole solution.
Scaling Privacy Risk Management with Microsoft Tools
For many organisations, the privacy assessment process including Privacy Impact Assessments (PIAs) is recognised as an essential part of managing risk, yet the reality of how it is often carried out tells a different story.
Automating the privacy assessment process does not require new, expensive technology or a complete overhaul of systems. In fact, the building blocks for an effective, automated approach already exist within most organisations.
When Good Intentions Meet Hidden Risk
More and more organisations are encouraging their people to contribute beyond their day jobs including joining charity boards, helping professional associations, or volunteering in community roles. It’s a positive trend that builds capability, networks, and a sense of purpose. But there’s a quiet privacy risk that often goes unnoticed.
Employee Privacy Across the Tasman
Privacy law in Australia and New Zealand both aim to protect individuals’ rights over their personal information, but the way each country defines and regulates that information reveals some important differences, especially when it comes to how employee personal information is treated.
The Hidden Privacy Risks of Technology Pilots
Piloting new technology is exciting. It’s a chance to explore innovation, test ideas quickly, and see how emerging tools might transform the way we work. Whether it’s an AI solution, a new analytics platform, or a digital service prototype, pilots feel like safe spaces to experiment. But there’s a growing issue that’s easy to overlook in the rush to innovate: privacy.
The Loneliness of Being the Only Privacy Person
In many organisations, the responsibility for privacy rests with just one person. That single privacy person is expected to be the responder to breaches, the handler of privacy requests, the privacy by design specialist, the reviewer of vendor arrangements and the trainer of staff, all at once. It’s a role that sits at the heart of trust and compliance, but it is also one that can feel incredibly lonely.
The Privacy Act: No Free Pass for Charities and Societies
When most people think about the Privacy Act 2020, they picture government agencies, and big corporates. But here’s the truth: it applies just as much to your local sports club, a neighbourhood charity, or a professional society as it does to corporates. Being a not-for-profit doesn’t mean you’re exempt.
The Pitfall of Cataloguing Without Context
In the rush to show progress on privacy, many organisations begin by building data catalogues of personal information. They invest in tools, run workshops, and inventory every system, every database, every field. On the surface, this feels like progress: “we’ve mapped our personal information.” But the truth is, without context, cataloguing is a dead end.
Privacy Policy vs. Privacy Statement - Why the Difference Matters in NZ
Scroll through many organisations’ websites in New Zealand and you’ll find a link to something called a “Privacy Policy.” Nine times out of ten, though the content isn’t a policy at all it’s a privacy statement. And while the difference might seem like splitting hairs, in practice it reveals a lot about how seriously an organisation takes privacy and the level of privacy maturity.
"But I Outsourced That!" – Why You’re Still on The Hook Under The Privacy Act
Think outsourcing means you’ve handed over the responsibility for personal information? Think again.
Under the Privacy Act, even if you outsource operations to a third party, your organisation remains accountable for the personal information they access and manage on your behalf.
Are They a Controller or a Processor?
Understanding the relationship between the parties is especially important when it comes to indirect collection — that is, receiving personal information from a third party rather than directly from the individual.
Who Should Be Your Privacy Officer?
Did you know that every organisation in New Zealand is required by law to have a Privacy Officer? That includes businesses of all sizes, public agencies, and not-for-profits — no one is exempt.