Privacy by Design Starts Earlier Than You Think

There is a point in most technology projects where someone asks about the privacy risks. Sometimes it is during procurement. Sometimes when the contract is being drafted. Sometimes it is the day before go live.

The Compliance Notice (20260923-HealthNZ-Compliance-Notice-HNZ-CN-02-2026a-A1220605.pdf) issued by the Privacy Commissioner to Health New Zealand – Te Whatu Ora following the Manage My Health cyber security breach is a useful reminder of why the timing matters.

Privacy by design isn't about checking privacy at some point during a project, it is about making privacy part of the decisions that shape the project in the first place.

On 31 December 2025, a cyber security breach affected the Manage My Health patient portal. Around 99,416 people were affected, with approximately 91% being Health NZ patients in Northland. Following its inquiry, the Privacy Commissioner found that Health NZ had failed to comply with Rule 5(1)(b) of the Health Information Privacy Code 2020. This rule requires a health agency, when giving health information to another person in connection with providing a service, to do everything reasonably within its power to prevent unauthorised use or disclosure.

The Commissioner identified deficiencies in Health NZ's organisational controls in relation to privacy both before and during the project. Findings included

  • Health NZ had not conducted sufficient due diligence before engaging Manage My Health;

  • There were problems with the quality of the privacy risk assessments;

  • Health NZ did not sufficiently understand how the system would manage the information it provided;

  • Key technical issues were not identified;

  • The project relied too heavily on the provider's own assessments of security and privacy rather than Health NZ forming its own independent view; and

  • The project's steering group did not include direct privacy or security representation; and

  • The contractual arrangements also lacked appropriate protections for patient information.

Overall privacy wasn't sufficiently embedded in the design and governance of the project.

Privacy by design isn't just about building secure software. It starts much earlier, with understanding the information involved, assessing potential providers independently and making privacy part of procurement and design decisions.

The Compliance Notice issued makes that expectation clear. Health NZ must independently assess potential providers, involve privacy expertise at the design stage and undertake a PIA that examines how information flows between Health NZ and its provider. Importantly, the PIA isn't a one-off exercise. It must be reviewed as the project develops, when its scope changes and annually once operational.

Privacy also needs a seat at the governance table. Future project governance must include privacy and technical security expertise, rather than bringing them in after key decisions have already been made. Otherwise, privacy by design quickly becomes privacy by retrofit.

The same applies to contracts. Privacy and security obligations need to be clear, extend to relevant subcontractors and provide mechanisms for ongoing assurance and audit. A supplier's certifications, questionnaires and assurances can support due diligence, but they aren't a substitute for an organisation forming its own view of the risks.

There is a useful question organisations can ask themselves after reading this Compliance Notice:

If we were starting our most important digital project again tomorrow, at what point would privacy become involved?

If the answer is "when we do the PIA", look earlier.

Privacy should be part of the decisions that shape a project from requirements and supplier selection through to information flows, contracts and governance. And once the system is live, someone needs to make sure the assumptions and safeguards remain valid.

At ThreeBlackCats, we help organisations embed privacy into those decisions. That can include better PIAs, supplier due diligence, privacy requirements for procurement and contracts, information-flow mapping, and practical privacy governance and assurance. The aim isn't more paperwork. It's better decisions, made earlier.

Because the lesson from the Health NZ Compliance Notice is that privacy problems don't begin with a breach. Problems can start much earlier when a supplier is selected, a system is designed, a contract is signed, or everyone assumes someone else has checked. Privacy by design is about making sure those moments don't get missed.

Next
Next

Your Work Email Is Not Your Personal Inbox