Privacy FAQs
Privacy is often understood at a high level, but the complexities often arise when moving into the detail. These are common questions we hear from organisations navigating their obligations.
General
-
Personal information is information about an identifiable individual. It can cover anything, in any format: spoken, written, stored digitally, captured by CCTV, or measured in biometric scans.
Personal information includes obvious direct identifiers like a name or phone number, but it also covers indirect identifiers including a mix of details that, when combined, point to a single person.
If a person can reasonably be identified from the information, it is likely covered.
Care should be taken to not interchange the term PII as they are not the same.
-
Customers increasingly expect organisations to handle personal information responsibly. Strong privacy practices demonstrate accountability, transparency, and respect for individuals' information.
Organisations with effective privacy programmes are often better positioned to build trust, strengthen relationships, and protect their reputation in the event of a privacy incident.
-
If you collect personal information, you are required to have a clear and accessible privacy statement explaining:
What you collect
Why you collect it
How it is used and shared
How individuals can access or correct their information.
Be aware a privacy statement is different from a privacy policy.
-
It is best practice to have a privacy policy but is not required legislatively.
A privacy policy is an organisation’s internal document that sets out how personal information is to be handled inside your organisation, who carries which responsibilities, and what practices and safeguards are in place, such as when is a privacy assessment required. It’s the document your staff refer to when managing personal information to ensure they comply with your organisation's requirements.
Be aware a privacy statement is different from a privacy policy.
-
A privacy consultant can assist organisations to assess the seriousness of a privacy breach, determine whether notification is required, manage regulatory obligations, communicate with affected individuals, and strengthen controls to reduce future risks.
Privacy by Design
-
A Privacy Impact Assessment is a structured process that helps identify privacy risks and opportunities before a project is implemented. It enables organisations to address privacy concerns early, improve stakeholder trust, and demonstrate accountability.
-
A Privacy Impact Assessment should be considered whenever a project involves collecting, using, storing, sharing, or changing the way personal information is handled. PIAs are particularly valuable for new technology projects, digital transformations, AI initiatives, customer databases, and information-sharing arrangements.
-
Digital transformation projects often involve new technologies, new ways of collecting information, and changes to business processes. Privacy consulting helps organisations identify risks early, integrate privacy considerations into project planning, and ensure compliance with legal and regulatory requirements.
Embedding privacy into project design can reduce delays, improve stakeholder confidence, and support successful implementation.
New Zealand Privacy Act 2020
-
Yes. The Privacy Act applies to organisations of all sizes, including small businesses, sole traders, and not-for-profits, if they collect or use personal information.
-
The Privacy Act 2020 gives the Privacy Commissioner a range of compliance and enforcement powers. Depending on the circumstances, organisations may face investigations, compliance notices, reputational damage, legal costs, and financial penalties.
-
The Office of the Privacy Commissioner has a selection of knowledge articles available.
The Office of the Privacy Commissioner has recently changed the way it responds to public enquiries and will no longer provide 1:1 advice to organisations unless there is a statutory requirement to do so. Organisations are expected to rely on their internal Privacy Officer capability to answer privacy questions and manage compliance. ThreeBlackCats are here to help.
Privacy Officers
-
A Privacy Officer helps an organisation comply with privacy legislation and promotes good privacy practices. Responsibilities often include:
Managing privacy enquiries and complaints
Supporting privacy breach response
Providing privacy advice to staff
Monitoring privacy compliance
Reviewing policies and procedures
Assisting with Privacy Impact Assessments
Promoting privacy awareness and training
Every organisation in New Zealand is required to have at least one Privacy Officer.
-
Every organisation in New Zealand is required by law to have a Privacy Officer? That includes businesses of all sizes, public agencies, and not-for-profits — no one is exempt.
-
An external Privacy Officer is a privacy specialist who performs the role of Privacy Officer for your organisation without being an employee. This can be a cost-effective solution for small and medium-sized organisations that need privacy expertise but do not require a full-time privacy professional.
-
An external Privacy Officer provides independent expertise and practical support without the cost of employing a full-time privacy specialist. Benefits can include:
Access to specialist privacy knowledge
Independent advice and assurance
Reduced compliance risk
Support for privacy incidents and breaches
Assistance with Privacy Impact Assessments
Ongoing guidance as privacy requirements evolve
Many organisations use external Privacy Officers to strengthen their privacy capability while maintaining flexibility.