Legislation leads to greater transparency

Reports of privacy breaches have doubled following the introduction of the Privacy Act 2020.

Legislation leads to greater transparencyLegislation leads to greater transparency
Category
Insight | Tech
Insight
|
Tech
Published Date
25
May 2021
Reading Time

Reports of privacy breaches have doubled following the introduction of the Privacy Act 2020.

Part 6 of the Privacy Act 2020 introduced a mandatory obligation to report privacy breaches to the Privacy Commissioner and the affected individual(s) where the breach is likely to cause serious harm. Failing to report these breaches is a criminal offence, with potential liability up to $10,000 (NZD) for offending. As a result of this obligation, reports of serious privacy breaches have doubled since the Privacy Act came into effect on 1 December 2020.

Only those breaches that are likely to cause serious harm must be reported. The Privacy Act outlines that in considering serious harm you should look at;

  • action taken by the agency to reduce the harm;
  • whether the personal information is sensitive;
  • the nature of the harm that may be caused to the affected individual;
  • whether an organisation or person has obtained personal information from the breach;
  • whether the personal information is protected by security measures;
  • and any other factors that your organisation thinks may mitigate or aggravate the risk of harm.

More than half of the breaches reported to the Office of the Privacy Commission (OPC) involved emotional harm and approximately one third involved the risk of identity theft or emotional harm. The OPC has outlined that organisations are being proactive in reporting serious breaches with over 50% being reported within 5 days of the breach, and 65% of organisations notifying individuals of the breach at the same time as notifying the Privacy Office.

At the In-house Lawyers Association of New Zealand (ILANZ) conference last week, the Privacy Commissioner, John Edwards, highlighted that the penalties associated with failing to notify the Privacy commissioner of a breach seems to have motivated people to over-report breaches, including some that may not have been necessary. Mr Edwards, suggested agencies should consider whether in some cases informing individuals of a potential privacy breach may distress those individuals, causing them more harm than good, if there is no real risk of onward transmission or misuse of their personal information.

What does this mean?

Mandatory requirements within the Privacy Act have had a direct impact on these statistics. Training and education during the past 6 months by the Privacy Commission to raise awareness has also contributed to the increase.

Whilst the number of significant breaches may be skewed by over-reporting, increased reporting illustrates that more New Zealand organisations are taking privacy matters and their obligations seriously. Increased media attention (such as the prevalence of articles related to the security of personal information in the COVID-tracing app) also means businesses can’t pretend they’re unaware of their legal obligations or afford not to respond to customer queries or concerns. Like their European counterparts under GDPR, New Zealand consumers are becoming increasingly curious and cautious about how their personal information is treated.

Taking these elements together, the drastic increase in privacy breach reporting in the past six months shouldn’t come as a surprise, but that doesn’t make it less nerve-wracking if you are facing an incident.

What should you do if you have a potential privacy breach?

1) Take a breath.
2) Pause and consider whether there is real risk of serious harm.
3) Consider the spread of the breach and the risk of personal information being accessed. For example;

  • Has the email only been sent to one person and you have retrieved it or had them delete it before they have opened it?
  • Was the personal information securely locked or encrypted meaning the person who accidentally received it can't access it?
  • Did the email sent to the wrong person really contain personal information?

4) Communicate with your internal team about managing this breach and what action can be taken to mitigate the risk of serious harm.
5) Triage and develop the best way to manage the breach and consider the potential risk of serious harm.
6) If you feel that there is a genuine risk of serious harm from the breach, notify the OPC using its NotifyUs tool , and the affected individual as soon as possible.

Useful Resources

  • Click here for the article by the Privacy on the reporting statistics.
  • Check out useful resources on OPC's eLearning site.
  • Click here for more on the Privacy Act.
  • Click here to read more from Andrew Dentice on Modernising the Act.

If you and your organisation would like help on ensuring that your privacy policy is up to date or if you have any privacy related queries, get in touch.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore.

There are no services for this current insight. Take a look at our services page for more information on our different offerings.
Previous Article
Next Article

Consultation opens on New Zealand's payment services regulation

Modern slavery regulation on the way – Is your business ready?

From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business

Space Law in New Zealand — Signals from the ground

Cyber security changes flagged for New Zealand

The four Cs of successful fintech partnerships

New rule 3A introduced to the Biometric Processing Privacy Code

IPP3A is nearly in force – What agencies need to know

OPC shifts public enquiries online – What agencies should do now

AI as a confidante? Legal privilege and the ever-increasing use of AI

New Therapeutic and Health Advertising Code – What you need to know

Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia

Consumer law update 2025

Open banking launches in New Zealand

Is fair something to fear? The Government announces beefed-up Fair Trading Act

Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta

Open banking almost live

Why New Zealand businesses should care about the EU Data Act

Product labelling changes flagged for New Zealand

Biometric Processing Privacy Code 2025 introduced to New Zealand

Open banking regulations released for consultation

Ten tips for buy-side M&A success

A recipe for disaster – Is caramel a copyright work?

Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)

Important changes made to the Privacy Act

New Zealand may ban social media for young users

Customer and Product Data Act update – Open banking officially on the way

Tips from the trenches – Your AI policy cheat sheet

Significant regulatory reform proposed for New Zealand media

Security guidance released for emerging tech companies

Customer and Product Data Bill – Select Committee reports back

Consumer law update 2024

New Zealand’s Artist Resale Royalty is ready to go

The shape of coffee – “Moccona” vs “Vittoria”

New Zealand’s Copyright Act gets a sense of humour

WIPO’s traditional knowledge treaty is adopted

Doing business in the Middle East

AI and advertising – What producers need to know

Seven contract clauses every freelancer needs

Baby Reindeer – When truth is stranger than fiction?

Our comments on the Biometric Processing Privacy Code

Therapeutic Products Act to be repealed this year

Is End-to-End to end?

Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement

Lawyers and Generative AI – New NZ Law Society guidance released

Facing the future – A biometrics code of practice for New Zealand?

Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?

Five Eyes release the Five Principles to Secure Innovation

The copyright conundrum with generative AI

Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools

Political advertising on social media: sludge or copyright quagmire?

Privacy Amendment Bill introduced to Parliament

New Data Privacy Framework: Meta gets a lifeline

The long and winding road to royalties

Implications of the Supreme Court’s “new debt” approach in Mainzeal

EU gets closer to AI laws

UK Supreme Court puts Quincecare ‘duty’ back in its box

A Deep Dive into The Customer and Product Data Bill

Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data

New NZ-UK Free Trade Agreement signals tech, media and IP law changes

Ditch the fax! Tips for building a tech-savvy law firm

The Incorporated Societies Act 2022 – what you need to know for your society

Common myths about copyright online

Artificial artist, or artificial plagiarist?

Big boost to gaming

Is your product “AI powered”?

The latest on New Zealand’s Consumer Data Right

Space Law in New Zealand

You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law

Open Banking is coming – through the Consumer Data Right

Massive SEC Fines for Companies Using Text and Instant Messaging

One Act to Rule Them All

A Legal Guide to Kicking SaaS

Potential changes to the Privacy Act 2020

NZ's Social Media "Code of Practice" Launched

Are you being unfair?

A new Companies Office levy is one step closer

Has Paramount Pictures gone maverick?

From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners

Retail Payment System Act 2022 now in force

Paying the price for getting privacy wrong

Can AI be an inventor?

Finfluencer Crackdown

TIN Fintech Insights Report Launch

Britain seeks to regulate 'Big Tech'

Disclosure of personal information - how to, not don't do

The Spice May Flow, But The Copyright Doesn’t

Sound Recording Ownership (Taylor's Version)

The Lowdown (and Lockdown) on Summer Clerkships

Building Blocks of Trust

Firm News | Legal Rankings

Buy Now, Regulate Soon

Ten simple things

Funding the Future

Cyber Security for Start-ups

Fit for purchase

The Screen Industry Workers Bill

Other articles you
might like

Consultation opens on New Zealand's payment services regulation
26
May 2026

New Zealand is consulting on reforms to its payment services regulatory framework, with submissions closing 3 July 2026.

Andrew Dentice

Andrew Dentice

Partner

Kyra Vince

Kyra Vince

Special Counsel – Knowledge

The four Cs of successful fintech partnerships
2
April 2026

Negotiating a fintech partnership agreement is not a zero sum game.

Andrew Dentice

Andrew Dentice

Partner

New rule 3A introduced to the Biometric Processing Privacy Code
1
April 2026

New rule 3A means individuals must be notified about indirect collection under the Biometric Processing Privacy Code 2025.

Kyra Vince

Kyra Vince

Special Counsel – Knowledge

Anchali Anandanayagam

Anchali Anandanayagam

Partner