Articles

Collection, Governance, Privacy Request Caroline carver Collection, Governance, Privacy Request Caroline carver

Your Work Email Is Not Your Personal Inbox

Most of us have probably done it at some point. Used our work email address for something that has absolutely nothing to do with work. A recent case from the Office of the Privacy Commissioner is a useful reminder that where personal information is stored can matter just as much as what the information is about.

Read More
GDPR, Governance Caroline carver GDPR, Governance Caroline carver

Controller or Processor: Decide Early

Somewhere between the first line of code and the first paying customer, there is a quiet decision every SaaS builder makes, whether privacy is something you will design, or something you will retrofit. Most choose the latter, not out of neglect, but out of urgency to get to market.

When you build a SaaS product, you are not just creating features. You are defining relationships.

Read More
Governance Caroline carver Governance Caroline carver

Policies Alone Don’t Provide Protection

During our work we often hear a familiar reassurance: “We have a policy for that.” It sounds comforting and responsible. But a recent decision from the Office of the Privacy Commissioner (PBN3791), involving something as ordinary as a lost USB stick, is a sharp reminder that policies alone don’t protect anything. What is required to mitigate the risk is a combination of controls, readiness, and culture.

Read More
Governance Caroline carver Governance Caroline carver

Scaling Privacy Risk Management with Microsoft Tools

For many organisations, the privacy assessment process including Privacy Impact Assessments (PIAs) is recognised as an essential part of managing risk, yet the reality of how it is often carried out tells a different story.

Automating the privacy assessment process does not require new, expensive technology or a complete overhaul of systems. In fact, the building blocks for an effective, automated approach already exist within most organisations.

Read More
Governance, Third Parties, Privacy Request Caroline carver Governance, Third Parties, Privacy Request Caroline carver

When Good Intentions Meet Hidden Risk

More and more organisations are encouraging their people to contribute beyond their day jobs including joining charity boards, helping professional associations, or volunteering in community roles. It’s a positive trend that builds capability, networks, and a sense of purpose. But there’s a quiet privacy risk that often goes unnoticed.

Read More
Disclosure, Third Parties, Governance Caroline carver Disclosure, Third Parties, Governance Caroline carver

The Hidden Privacy Risks of Technology Pilots

Piloting new technology is exciting. It’s a chance to explore innovation, test ideas quickly, and see how emerging tools might transform the way we work. Whether it’s an AI solution, a new analytics platform, or a digital service prototype, pilots feel like safe spaces to experiment. But there’s a growing issue that’s easy to overlook in the rush to innovate: privacy.

Read More
Governance, New Zealand Caroline carver Governance, New Zealand Caroline carver

The Loneliness of Being the Only Privacy Person

In many organisations, the responsibility for privacy rests with just one person. That single privacy person is expected to be the responder to breaches, the handler of privacy requests, the privacy by design specialist, the reviewer of vendor arrangements and the trainer of staff, all at once. It’s a role that sits at the heart of trust and compliance, but it is also one that can feel incredibly lonely.

Read More
Governance Caroline carver Governance Caroline carver

The Pitfall of Cataloguing Without Context

In the rush to show progress on privacy, many organisations begin by building data catalogues of personal information. They invest in tools, run workshops, and inventory every system, every database, every field. On the surface, this feels like progress: “we’ve mapped our personal information.” But the truth is, without context, cataloguing is a dead end.

Read More
Governance, Notice, New Zealand Caroline carver Governance, Notice, New Zealand Caroline carver

Privacy Policy vs. Privacy Statement - Why the Difference Matters in NZ

Scroll through many organisations’ websites in New Zealand and you’ll find a link to something called a “Privacy Policy.” Nine times out of ten, though the content isn’t a policy at all it’s a privacy statement. And while the difference might seem like splitting hairs, in practice it reveals a lot about how seriously an organisation takes privacy and the level of privacy maturity.

Read More