{"id":8705,"date":"2022-02-08T15:46:52","date_gmt":"2022-02-08T02:46:52","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=8705"},"modified":"2022-02-08T15:46:52","modified_gmt":"2022-02-08T02:46:52","slug":"does-your-firm-have-an-appropriate-data-privacy-policy","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=8705","title":{"rendered":"Does your firm have an appropriate Data Privacy Policy?"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Data Privacy is now a hot topic in <\/strong><strong style=\"font-size: 26px;\">NZ.<\/strong><\/h2>\n<p><strong><\/strong><\/p>\n<p><strong>As a law firm, you will be more aware of the legislation than us, but we have been astonished that not every firm seems to understand the ramifications for their own work product.<\/strong><\/p>\n<p>You will know what is driving our concern:<strong><\/strong><\/p>\n<p><strong>1. The GDPR<\/strong> (General Data Protection Regulation) which came into effect in Europe in May 2018. This introduced strict regulations on what private information is, how to get consent from users, how to deal with breaches, and when personal information must be deleted. The fines for not complying were large; \u20ac20 million or up to 4% of the annual worldwide turnover. Although\u00a0it is a\u00a0European regulation, it applies to any company that stores personal information for EU citizens so potentially impacts all companies world-wide.<\/p>\n<p><strong>2. Updates to the Australian Privacy Act<\/strong>, which makes data breach notification compulsory as of February 2018. This means that if an individual\u2019s personal information is leaked and likely to result in serious harm the company is required by law to notify the individual(s). Again, the fines for not complying were increased to up to\u00a0AU$2 million.<\/p>\n<p><strong>3. <a href=\"https:\/\/new.kinetics.co.nz\/privacy-act-2020-are-you-ready-for-dec-1st\/\">The New Zealand Privacy Act\u00a0<\/a><\/strong>changes in 2020, introducing mandatory reporting requirements and tougher fines.<\/p>\n<p>Updated privacy regulations aim primarily to give <strong>control to citizens of their personal data.<\/strong> It means that citizens are more aware of how their personal data will be stored, used and shared.<\/p>\n<p>We <strong>recommend that a data privacy policy is created<\/strong> based on best practice and research performed across the industry. Staff should be trained on the privacy policy and it should be included in the staff induction process.<\/p>\n<h2>Does your practice have a data privacy policy?<\/h2>\n<p><strong>How to create your own:<\/strong><\/p>\n<p>To create a data privacy policy the following areas and questions need to be answered:<\/p>\n<ul>\n<li><strong>What<\/strong> data do we hold?<\/li>\n<li>We don\u2019t tend to delete data \u2013 <strong>why<\/strong> do we hold it?<\/li>\n<li><strong>When<\/strong>, if at all, should we purge it?\u00a0 Why?<\/li>\n<li>If someone asks us, what is our process on <strong>checking<\/strong> that they are who they say they are?<\/li>\n<li>How would we know if it were <strong>stolen or leaked<\/strong>? Who would we notify?<\/li>\n<li>What is our <strong>obligation<\/strong> to the clients and their staff?\u00a0 Is it different?<\/li>\n<li>Who do we <strong>notify?<\/strong><\/li>\n<\/ul>\n<p>\u00a0You can use this <a href=\"https:\/\/www.privacy.org.nz\/tools\/privacy-statement-generator\/\">generator<\/a> to help create your own, but we recommend a more thorough approach<\/p>\n<p>\u00a0<strong>To get started, <\/strong><strong>we recommend a <\/strong><strong><a href=\"https:\/\/new.kinetics.co.nz\/flightplan\/\">Kinetics &#8220;FlightPlan&#8221;<\/a><\/strong><strong><\/strong><strong>\u00a0to explore these ideas, and many other aspects to help us make sure that your IT isn&#8217;t just running well, but the way you use your IT matches your business needs.<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Data Privacy is now a hot topic in NZ. As a law firm, you will be more aware of the legislation than us, but we have been astonished that not every firm seems to understand the ramifications for their own work product. You will know what is driving our concern: 1. The GDPR (General [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[9],"tags":[],"class_list":["post-8705","post","type-post","status-publish","format-standard","hentry","category-legal-firms"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/8705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8705"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/8705\/revisions"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}