{"id":3487,"date":"2019-04-18T09:27:16","date_gmt":"2019-04-17T21:27:16","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=3487"},"modified":"2019-04-18T09:27:16","modified_gmt":"2019-04-17T21:27:16","slug":"updated-privacy-laws-coming-to-nz","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=3487","title":{"rendered":"Updated Privacy Laws coming to NZ"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;3.22&#8243;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;3.25&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.25&#8243; custom_padding=&#8221;|||&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.9.2&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; hover_enabled=&#8221;0&#8243; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3527  alignright\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2019\/05\/private-300x200.jpg\" alt=\"\" width=\"458\" height=\"305\" \/><\/p>\n<p>Overshadowed by overseas privacy law changes like GDPR, our own NZ Privacy legislation has flown a little under the radar. But rest assured, changes are coming here as well.<\/p>\n<p>The last change in NZ Law was 1993, and it was world-leading at the time. Then in 2011, the Law Commission suggested an update, and that\u2019s where we are now. The expectation is that the bill will become law mid-2019, with the key aim to ensure we can be confident that our personal information \u2013 online or elsewhere \u2013 is safe and treated\u00a0well.<\/p>\n<h2>Notifiable Breaches<\/h2>\n<p>The key change, like the Australian Notifiable Breaches legislation, is to require a notification in the event of a data breach. There is a trigger for this \u2013 the breach must pass a certain threshold, and if it does, the agency holding the data must let the impacted individual know, and notify the Privacy Commission . There are a couple of exceptions to this, but nothing significant.<\/p>\n<p>You must notify if the breach may cause (or the potential risk) of:<\/p>\n<ul>\n<li>loss, detriment, damage, or injury to the individual;<\/li>\n<li>adversely affect the rights, benefits, privileges, obligations, or interests of the individual; or<\/li>\n<li>result in significant humiliation, loss of dignity, or injury to the feelings of the individual<\/li>\n<\/ul>\n<p>That of course raises the question as to what \u2018potential risk\u2019 is and how on earth you can decide that. But with a $10,000 potential fine, this will be significant for any business, especially a small business.<\/p>\n<h2>Mandatory Demands<\/h2>\n<p>There are legal scenarios, presumably a warrant or similar, that require you to hand over information to law enforcement authorities that may include information about individuals that would fall under the act. If you find yourself in this position, you must only hand over exactly what is required and nothing extra, otherwise this too would be a breach.<\/p>\n<p>The bill is currently at it\u2019s second reading \u2013 so some of the points above are subject to the select committee and may yet change. One example is the limit of the fines for non-compliance with the Privacy Commissioner reported to be trying to increase these to a maximum of $100,000. You can learn more on the <a href=\"https:\/\/www.parliament.nz\/en\/pb\/bills-and-laws\/bills-proposed-laws\/document\/BILL_77618\/privacy-bill\" target=\"_blank\" rel=\"noopener\">parliamentary website<\/a>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overshadowed by overseas privacy law changes like GDPR, our own NZ Privacy legislation has flown a little under the radar. But rest assured, changes are coming here as well. The last change in NZ Law was 1993, and it was world-leading at the time. Then in 2011, the Law Commission suggested an update, and that\u2019s [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":3489,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<img class=\"wp-image-3527  alignright\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2019\/05\/private-300x200.jpg\" alt=\"\" width=\"458\" height=\"305\" \/>\n\nOvershadowed by overseas privacy law changes like GDPR, our own NZ Privacy legislation has flown a little under the radar. But rest assured, changes are coming here as well.\n\nThe last change in NZ Law was 1993, and it was world-leading at the time. Then in 2011, the Law Commission suggested an update, and that\u2019s where we are now. The expectation is that the bill will become law mid-2019, with the key aim to ensure we can be confident that our personal information \u2013 online or elsewhere \u2013 is safe and treated\u00a0well.\n\n[header2 text=\"Notifiable Breaches\" align=\"left\" color=\"#336A40\" margintop=\"\"]\n\nThe key change, like the Australian Notifiable Breaches legislation, is to require a notification in the event of a data breach. There is a trigger for this \u2013 the breach must pass a certain threshold, and if it does, the agency holding the data must let the impacted individual know, and notify the Privacy Commission . There are a couple of exceptions to this, but nothing significant.\n\nYou must notify if the breach may cause (or the potential risk) of:\n<ul>\n \t<li>loss, detriment, damage, or injury to the individual;<\/li>\n \t<li>adversely affect the rights, benefits, privileges, obligations, or interests of the individual; or<\/li>\n \t<li>result in significant humiliation, loss of dignity, or injury to the feelings of the individual<\/li>\n<\/ul>\nThat of course raises the question as to what \u2018potential risk\u2019 is and how on earth you can decide that. But with a $10,000 potential fine, this will be significant for any business, especially a small business.\n\n[header2 text=\"Mandatory Demands\" align=\"left\" color=\"#336A40\" margintop=\"\"]\n\nThere are legal scenarios, presumably a warrant or similar, that require you to hand over information to law enforcement authorities that may include information about individuals that would fall under the act. If you find yourself in this position, you must only hand over exactly what is required and nothing extra, otherwise this too would be a breach.\n\nThe bill is currently at it\u2019s second reading \u2013 so some of the points above are subject to the select committee and may yet change. One example is the limit of the fines for non-compliance with the Privacy Commissioner reported to be trying to increase these to a maximum of $100,000. You can learn more on the [wow_colorme]<a href=\"http:\/\/-https:\/\/www.parliament.nz\/en\/pb\/bills-and-laws\/bills-proposed-laws\/document\/BILL_77618\/privacy-bill\" target=\"_blank\" rel=\"noopener\">parliamentary website<\/a>.[\/wow_colorme]","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-3487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/3487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3487"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/3487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}