Articles
The 13, 13½ or 14 Privacy Principles?
There are few things New Zealand privacy professionals enjoy more than a good academic debate. For years, life was beautifully simple. The Privacy Act had 13 Information Privacy Principles (IPPs). We called them "the 13 IPPs" and everyone knew what we meant.
Then along came IPP 3A.
Employee Privacy Across the Tasman
Privacy law in Australia and New Zealand both aim to protect individuals’ rights over their personal information, but the way each country defines and regulates that information reveals some important differences, especially when it comes to how employee personal information is treated.
Privacy Breach vs Breach of the Privacy Act
When something goes wrong with personal information two phrases get tossed around a lot: privacy breach and breach of the Privacy Act. They sound similar, and they often get blurred together in day-to-day conversations. But they mean very different things and confusing them can lead to the wrong response by an organisation.
The Loneliness of Being the Only Privacy Person
In many organisations, the responsibility for privacy rests with just one person. That single privacy person is expected to be the responder to breaches, the handler of privacy requests, the privacy by design specialist, the reviewer of vendor arrangements and the trainer of staff, all at once. It’s a role that sits at the heart of trust and compliance, but it is also one that can feel incredibly lonely.
IPP 3A Clears Third Reading: The Time to Act is Now
Last week Parliament passed the Privacy Amendment Bill through its third reading, confirming the introduction of a new Information Privacy Principle IPP 3A focused on indirect collection. This isn’t a change that can be left until the week before commencement. The work must start now.
The Privacy Act: No Free Pass for Charities and Societies
When most people think about the Privacy Act 2020, they picture government agencies, and big corporates. But here’s the truth: it applies just as much to your local sports club, a neighbourhood charity, or a professional society as it does to corporates. Being a not-for-profit doesn’t mean you’re exempt.
Privacy Policy vs. Privacy Statement - Why the Difference Matters in NZ
Scroll through many organisations’ websites in New Zealand and you’ll find a link to something called a “Privacy Policy.” Nine times out of ten, though the content isn’t a policy at all it’s a privacy statement. And while the difference might seem like splitting hairs, in practice it reveals a lot about how seriously an organisation takes privacy and the level of privacy maturity.
Facial Recognition in New Zealand Retail: Innovation and Trust
Walk into a New Zealand supermarket today and it’s no longer unusual to see CCTV cameras silently watching over the aisles. Increasingly though, those cameras aren’t just recording, they may also be recognising individuals. Facial recognition technology (FRT) is shifting from futuristic possibility to everyday reality in retail.
The Biometric Code is Out!! – Is Your Organisation Ready?
The Biometric Processing Privacy Code has now been issued. It will come into force in two tranches:
3 November 2025 – for biometric processing that starts after 3 November 2025
3 August 2026 – for biometric processing already in use on or before 3 November 2025
Who Should Be Your Privacy Officer?
Did you know that every organisation in New Zealand is required by law to have a Privacy Officer? That includes businesses of all sizes, public agencies, and not-for-profits — no one is exempt.