{"id":16176,"date":"2026-03-31T10:24:06","date_gmt":"2026-03-30T21:24:06","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=16176"},"modified":"2026-03-31T10:24:06","modified_gmt":"2026-03-30T21:24:06","slug":"could-you-get-into-trouble-with-the-law-if-you-lose-a-usb-stick","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=16176","title":{"rendered":"Could you get into trouble with the law if you lose a USB stick?"},"content":{"rendered":"\n[et_pb_section fb_built=&#8221;1&#8243; theme_builder_area=&#8221;post_content&#8221; _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221;][et_pb_row _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; type=&#8221;4_4&#8243; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<p>&nbsp;<\/p>\n<div>\n<h2>A lost USB stick can be a notifiable privacy breach.<\/h2>\n<h3>Here\u2019s why that matters<\/h3>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">It sounds old school, but USB sticks are still floating around plenty of NZ businesses.\u00a0 A recent <strong>draft decision note from the Office of the Privacy Commissioner<\/strong> is a timely reminder that losing one isn\u2019t just inconvenient.\u00a0 It can cross the line into a <em>notifiable privacy breach<\/em>.<\/div>\n<\/div>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; column_structure=&#8221;1_2,1_2&#8243;][et_pb_column _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; type=&#8221;1_2&#8243; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<h3><span style=\"color: #222222; font-family: Montserrat, Helvetica, Arial, Lucida, sans-serif; font-size: 16px; font-weight: bold; text-transform: uppercase;\">Why a lost USB can be a big problem<\/span><\/h3>\n<div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">In the decision note, the Privacy Commissioner considered a situation where a USB stick containing personal information was lost and never recovered.<\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\"><\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">Because the organisation <strong>couldn\u2019t be confident the data was protected or inaccessible<\/strong>, the loss created a real risk of harm to the people involved. That\u2019s what tipped it into <em>notifiable breach<\/em> territory.<\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\"><strong><\/strong><\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\"><strong>If personal information goes missing and you can\u2019t rule out misuse, you may have an obligation to notify both the Privacy Commissioner and affected individuals.<\/strong><\/div>\n<\/div>[\/et_pb_text][\/et_pb_column][et_pb_column _builder_version=&quot;4.27.6&quot; _module_preset=&quot;default&quot; type=&quot;1_2&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2026\/03\/RobotDropsUSB400.png&quot; _builder_version=&quot;4.27.6&quot; _module_preset=&quot;default&quot; theme_builder_area=&quot;post_content&quot; title_text=&quot;RobotDropsUSB400&quot; border_radii=&quot;on|10px|10px|10px|10px&quot; border_color_all=&quot;#222222&quot; border_width_all=&quot;1px&quot; box_shadow_style=&quot;preset1&quot; hover_enabled=&quot;0&quot; sticky_enabled=&quot;0&quot;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&quot;4.27.6&quot; _module_preset=&quot;default&quot; theme_builder_area=&quot;post_content&quot; column_structure=&quot;1_2,1_2&quot;][et_pb_column _builder_version=&quot;4.27.6&quot; _module_preset=&quot;default&quot; type=&quot;1_2&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.6&quot; _module_preset=&quot;default&quot; theme_builder_area=&quot;post_content&quot; hover_enabled=&quot;0&quot; sticky_enabled=&quot;0&quot;]<div>\n<h3>It\u2019s not about the USB \u2014 it\u2019s about risk<\/h3>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">This isn\u2019t a story about outdated tech. It\u2019s about <strong>risk management<\/strong>.<\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">When regulators assess a breach, they look at things like:<\/div>\n<ul>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">What type of personal information was involved<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Whether it was encrypted or otherwise protected<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Who could realistically access it<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Whether the organisation could contain or recover the data<\/li>\n<\/ul>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">If the answers aren\u2019t clear, the risk goes up.<\/div>\n<\/div>[\/et_pb_text][\/et_pb_column][et_pb_column _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; type=&#8221;1_2&#8243; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<div>\n<h3><span style=\"font-size: 16px;\">What this means for NZ businesses<\/span><\/h3>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">For many organisations, the biggest exposure isn\u2019t hackers.\u00a0 It\u2019s everyday behaviour and legacy practices that haven\u2019t been revisited in years.<\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">Think:<\/div>\n<ul>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Data copied \u201cjust in case\u201d<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Files taken home to finish work<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">Portable storage with no encryption<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\">No clear policy on what\u2019s allowed (or not)<\/li>\n<\/ul>\n<\/div>\n<p>&nbsp;<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; type=&#8221;4_4&#8243; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<div>\n<h3><span style=\"font-size: 16px;\">Practical steps to reduce your risk<\/span><\/h3>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">You don\u2019t need to ban productivity to improve privacy. A business\u2011first IT approach helps you protect data <em>and<\/em> keep work flowing.<\/div>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">A few good starting points:<\/div>\n<ul>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\"><strong>Reduce reliance on portable storage<\/strong> by using secure cloud platforms<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\"><strong>Encrypt anything that leaves your environment<\/strong><\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\"><strong>Set clear policies<\/strong> around personal data handling<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\"><strong>Train staff<\/strong> on what to do (and what not to do)<\/li>\n<li class=\"___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf\"><strong>Review how incidents are detected and reported<\/strong><\/li>\n<\/ul>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">This is proactive IT \u2014 identifying issues early, before they become problems.<\/div>\n<\/div>\n<p>&nbsp;<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; theme_builder_area=&#8221;post_content&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<div>\n<h3><span style=\"font-size: 16px;\">Making IT simple \u2014 and safer<\/span><\/h3>\n<div class=\"paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol\">Privacy compliance isn\u2019t about ticking boxes. It\u2019s about protecting people, trust, and your reputation.\u00a0\u00a0If you\u2019re unsure how personal data moves through your business, or whether your current setup would stand up to scrutiny, we\u2019re happy to help.<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; A lost USB stick can be a notifiable privacy breach. Here\u2019s why that matters It sounds old school, but USB sticks are still floating around plenty of NZ businesses.\u00a0 A recent draft decision note from the Office of the Privacy Commissioner is a timely reminder that losing one isn\u2019t just inconvenient.\u00a0 It can cross [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":16177,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-16176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/16176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16176"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/16176\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}