New Privacy Act comes into force in December

The Privacy Act has now been passed and will become law on 1 December 2020. It will repeal and replace the current Privacy Act 1993, and will update the law to reflect the continually-evolving needs of the digital age.


Why new legislation?

Your personal information is stored in many places by organisations such as businesses, government agencies, healthcare providers, financial institutions, social network platforms and telecommunications companies (called ‘agencies’ in the new legislation).

Technology has enabled large quantities of personal information to be stored, retrieved, used and disclosed; the current law does not address how your personal data can be properly protected. The new legislation aims to provide more protection of personal and sensitive information.


Key changes

The changes relate to both agencies and individuals. Major features are:

  1. Reporting data breaches: if an agency has a privacy breach posing a risk of serious harm to people, it must notify the people affected and the Privacy Commissioner
  2. Compliance notices: the Privacy Commissioner will be able to issue compliance notices to an agency to require it to do something or stop doing something, to comply with privacy law
  3. Decisions on access requests: if a complaint is made about being unable to access certain information, the Privacy Commissioner will make a decision on the complaint. However, this decision can be appealed to the Human Rights Review Tribunal
  4. Strengthening overseas connections: at least one permitted category must be satisfied for an agency to disclose information to an overseas agency. In terms of cloud storage, this isn’t considered a disclosure for the purposes of the privacy principles, but the
  5. disclosing agency is responsible for the cloud storage provider’s compliance with the Act, and
  6. New criminal offences: these include misleading an agency to obtain access to another person’s information and destruction of documents by an agency which has been asked to provide information by the person entitled to it. The level of fines has been raised to a maximum of $10,000.


What is a privacy breach?

A privacy breach occurs when someone collects, uses, stores or discloses personal information contrary to the privacy principles, such as accessing personal information without permission, failing to comply with the request for specific information or not using your contact details for the purpose for which they were collected.

An example of a privacy breach could be when an unauthorised person accesses your personal information, such as your banking details, and your credit card is used unlawfully.

In business, a breach could occur when an agency incorrectly disposes of confidential documents containing personal information, and that data becomes public.


Privacy laws are important

The recent COVID requirements, where for example, information was provided to a restaurant when dining out, have highlighted the importance of privacy laws. We, as individuals, have become more aware that we entrust others with our private data and, as a result, we have an increased awareness of compliance with privacy legislation in New Zealand.


Disclaimer: All the information published in Fineprint is true and accurate to the best of the author’s knowledge. It should not be substituted for legal advice. No liability is assumed by the authors or publisher for losses suffered by any person or organisation relying directly or indirectly on this newsletter. Views expressed are the views of the authors individually and do not necessarily reflect the view of this firm. Articles appearing in Fineprint may be reproduced with prior approval from the editor and credit being given to the source. 

Content Copyright © NZ LAW Limited, 2020. Editor Adrienne Olsen, e.  p. 029 286 3650