Privacy Act 2020

Purpose
 

The Privacy Act provides a framework for protecting an individual’s right to privacy of personal information, including the right of an individual to access their personal information and request a correction of any information the individual believes is inaccurate, while recognising that other rights and interests may at times also need to be taken into account.

It gives effect to internationally recognised privacy obligations and standards in relation to the privacy of personal information.

Definitions
 

“Agency” means any person or body of persons, whether corporate or unincorporated, and whether in the public or the private sector; and for the avoidance of doubt, includes a Department of Government.

“Individual” means a natural person other than a deceased natural person.

“Personal Information” means information about an identifiable individual; and includes information contained in any register of deaths.

Information Privacy Principles (IPP)
 

The Privacy Act establishes the following 13 Information Privacy Principles:

  • IPP 1: Personal information may only be collected where it is lawful and necessary (Purpose of Collection).
  • IPP 2: Personal information must be collected directly from the individual concerned (Source of Personal Information).
  • IPP 3: When collecting the information the agency must make the individual aware of the fact that the information is being collected, the purpose of collection and the rights of access and correction (Collection of Information from Subject).
  • IPP 4: The information must not be collected by unlawful means or means that are unfair or intrude unreasonably upon the personal affairs of the individual (Manner of Collection).
  • IPP 5: The information must be protected against loss and unauthorised access, use, modification or disclosure (Storage and Security).
  • IPP 6: An individual is entitled to obtain confirmation that an agency holds personal information about them and to have access to that information (Access to Information).
  • IPP 7: An individual is entitled to request correction of the personal information held concerning them (Correction of Personal Information).
  • IPP 8: An agency must not use or disclose personal information without taking reasonable steps to ensure that it is accurate, up-to-date, complete, relevant and not misleading (Accuracy of Information).
  • IPP 9: An agency must not keep information for longer than is required (Keep information no longer than necessary).
  • IPP 10: An agency must not use information for any purpose other than that for which it was collected (Limits on Use).
  • IPP 11: An agency that holds personal information must not disclose that information to any other person, body or agency unless there are reasonable grounds (Limits on Disclosure).
  • IPP 12: An agency may disclose personal information to a foreign person or entity in limited circumstances (Disclosure outside NZ)
  • IPP 13: An agency may assign a unique identifier to an individual for use in its operations only if that is necessary to enable the agency to carry out its functions efficiently (Unique Identifiers). 

Note that:

  • IPPs 1 to 4 do not apply to personal information collected before 1 July 1993.
  • IPP 13(1) to (4)(a) does not apply to unique identifiers assigned before 1 July 1993.
  • IPPs 1 to 3 and 4(b) do not apply to an agency if that agency is an individual; and is collecting personal information solely for the purposes of, or in connection with, the individual’s personal or domestic affairs.

  • IPPs 5 to 12 do not apply to an agency if that agency is an individual; and is holding personal information that was collected by a lawful means solely for the purposes of, or in connection with, the individual’s personal or domestic affairs.
  • IPPs 2, 3, and 4(b) do not apply to personal information collected by an intelligence and security agency.
  • IPPs 6 and 7 do not apply in respect of certain information such as personal information during transmission by post, personal delivery, or electronic means; or personal information that is contained in any correspondence or communication between an agency and certain persons such as an Ombudsman, the Commissioner, or personal information held by the Auditor-General, submissions made to a government inquiry and so on (please refer to full Act).
  • The Commissioner may authorise collection, use, storage, or disclosure of personal information otherwise in breach of IPP 2 or IPPs 9 to 12. 

Exceptions to Access Principles
 

An agency (including any employer) holding personal information must allow the individual access to that information. Information must be made available to the individual in the way he/she prefers (inspection, copy, excerpt, summary etc).

Exceptions include:

  • Protection of the individual as a reason for refusing access if disclosure of the information would be likely to pose a serious threat to the life, health, or safety of any individual, or to public health or public safety; or create a significant likelihood of serious harassment of an individual; or include disclosure of information about another person who is the victim of an offence or alleged offence; and would be caused significant distress, loss of dignity, or injury to feelings by the disclosure of the information.
  • Evaluative material as reason for refusing access to personal information.
  • Security, defence, international relations as reason for refusing access to personal information.
  • Trade secret as a reason for refusal.
  • Other reasons such as the information requested does not exist or, despite reasonable efforts to locate it, cannot be found; or the disclosure of the information would involve the unwarranted disclosure of the affairs of another individual; or a deceased person; or the disclosure of the information would be likely to prejudice the maintenance of the law by any public sector agency, including the prevention, investigation, and detection of offences; and the right to a fair trial; or the disclosure of the information would breach legal professional privilege; or disclosure of the information and so on.
  • Agency may impose conditions instead of refusing access to personal information.
  • Withholding personal information contained in a document, such as by dedacting same
  • On certain grounds, an agency may neither confirm nor deny that it holds the personal information, or some of the personal information, requested.

Privacy Officer
 

The Act requires the appointment of at least one Privacy Officer in every “agency” (which includes an employer). Duties will include:

  • Encouraging compliance with the Privacy Principles.
  • Dealing with requests for information under the Act.
  • Working with the Privacy Commissioner in relation to investigations.
  • Promoting the Act.

An agency should put in place privacy management processes:

  • Implement systems and procedures covering how information will be collected, stored, used and disclosed. The privacy officer should be responsible for implementing the policy and regularly reviewing and updating it.
  • Implement an internal data access process so privacy requests can be actioned within 20 working days.
  • Ensure this is matched with the data access arrangements you have with your data service provider, especially if it is an overseas provider. 

Mandatory Reporting of Serious Breaches
 
  • An agency is responsible for any privacy breach committed by anyone that it engages for the collection, storage, use or disclosure of personal information undertaken by the agency. This is known as the “data lifecycle”.
  • A privacy breach that poses a risk of serious harm to an affected individual must be notified to the Privacy Commissioner and to the affected individual as soon as practical after the agency becomes aware of the breach.
  • An agency should implement processes for immediate privacy breach reporting such as putting in place a privacy breach handling process to enable timely management of a privacy breach, including steps to contain the breach, a framework to assist in determining whether the breach must be notified to the Privacy Commissioner and to affected individuals, and steps to capture learnings for future breach mitigation. All contractors, agents and commercial partners of the agency that are engaged or involved in any part of the “data lifecycle” must be required to immediately notify the agency of a privacy breach so action can be taken to contain the breach and assess if the breach must be notified. 


Greater Controls on Sharing Information Overseas
  • If an agency needs to share personal information with overseas agencies, that may only be done if person concerned consents to their information being passed on; and overseas entity receiving the personal information will protect the data in a way that is consistent with New Zealand privacy laws.

Employee Rights
  • To have the protection of the Act’s privacy principles. An employer may collect personal information only for a lawful purpose connected with the employer’s business.
  • To have requests from an employer, or prospective employer, for personal information addressed directly to the employee himself/herself unless:

    • The information is publicly available.
    • The employee has authorised collection from someone else.
    • The employee’s interests would not be prejudiced by non-compliance.
    • Non-compliance is necessary for law and order purposes, for the purpose of enforcing a fine, for the protection of public revenue or for the conduct of any court proceedings.
    • Compliance would prejudice the purpose of collection.
    • Compliance is not reasonably practicable in the particular circumstances.
    • The information will not be used in a way which identifies the individual or will be used only for statistical or research purposes.
    • Collection (in limited circumstances) has been authorised by the Privacy Commissioner.
  • To be made aware that personal information is being collected, the reason why, who it is for and whether it is required or authorised by law (and the particular law which applies). If the information’s collection is authorised by law, the employee must be told whether it has to be provided or whether its provision is voluntary. An employee must also be told what, if any, consequences there will be if the information is not provided and that he or she has a right to see and correct the information. Collection must not be by unlawful, unfair, or unreasonably intrusive means.
  • To receive confirmation (where information can be readily retrieved), that an employer is holding personal information and to have access to it.
  • To request the correction of any information held and, if it is not corrected, to have attached to the information a statement of the correction sought (with anyone else affected also informed, if practicable, of any action taken).
  • To be given reasonable assistance when seeking access to personal information, including help in complying with the Act’s requirements.
  • To have an information request (where the employer does not hold the information sought) transferred within ten working days to someone believed by the person dealing with the request to hold it and be told of the transfer.
  • To be told within 20 days of making a request whether the request will be granted, the way in which it will be granted and whether there will be any charge (which may be payable in advance).
  • To be allowed, where the information sought is contained in a document, to inspect the document, or be provided with a copy of the document, or be allowed to see any visual material, hear any recorded material or have a written transcript of any codified material or of anything written in shorthand.
  • To have information contained in any document provided in the manner requested, unless compliance would impair efficient administration, be contrary to any of the employer’s legal duties in respect to the document, prejudice national security, defence, international relations, or commercial position, disclose trade secrets or have any other adverse effect identified in the Act.
  • To be told, if any information is not provided in the way requested, the reason why not and to be given, where these are asked for, the grounds supporting that reason; and also to be told of the right to make a complaint concerning the response received (unless to do so would prejudice interests protected by the Act).
  • To be given, where any document provided contains deletions, the reason for withholding this information and, where these are asked for, the grounds supporting that reason; and to be told of the right to make a complaint concerning the response received.
  • To be told, where an information privacy request is refused, why it has been refused, and to be told of the right to make a complaint concerning the response received.

Employer Rights
 

An employer may disclose personal information only where there are reasonable grounds for believing that:

  • The disclosure of the information is one of the purposes for which the information was obtained or is directly related to that purpose.
  • The source of the information is a publication which is publicly available.
  • Disclosure is to the employee concerned or authorised by the employee.
  • Non-compliance is necessary for law and order purposes, or for the enforcement of a law imposing a pecuniary penalty, to protect the public revenue or for the conduct of proceedings before any court or tribunal.
  • Disclosure is necessary to prevent a serious or imminent threat to public health and safety or the life or health of the employee or some other individual.
  • Disclosure is necessary to facilitate the sale or other disposition of a business, as a going concern.
  • The information is to be used in a way which does not identify the individual, including for statistical and research purposes.
  • Disclosure has been authorised by the Privacy Commissioner.

Employer Obligations
 
  • To ensure any personal information held is reasonably protected against loss, unauthorised access, and, except with the employer’s authority, against use, modification, or disclosure, and against any other misuse. If the information must be given to someone who is providing a service to the employer, the employer must do everything reasonably possible to prevent unauthorised use or disclosure.
  • To use personal information only if steps have been taken to ensure that, having regard to the intended use, the information is up to date, complete, relevant and not misleading.
  • To inform an employee (if this is reasonably practicable) both when, at the employee’s request or on the employer’s own initiative, personal information has been corrected and when the employer is not willing to correct personal information and a statement provided by the employee has been attached. Whenever a request for a correction is received, the employer must tell the employee what action has been taken as a result.
  • To keep personal information only as long as it is needed for those purposes for which it may lawfully be used.
  • To use personal information only for the purpose for which it was obtained unless there are reasonable grounds for believing that:

    • The information-source is a publicly available publication.
    • The use of information about an employee for another purpose other than that authorised by the employee.
    • Non-compliance is necessary for law and order purposes, for the enforcement of a law imposing a pecuniary penalty, to protect the public revenue, or for the conduct of any court or tribunal proceedings.
  • To release personal information where required to do so by the provisions of an Act of Parliament.
  • To allow access to easily retrievable information only if satisfied about the identity of the person making the request, making sure that the information in question goes only to the employee for whom it is intended or to that employee’s agent.
  • To ensure that any agent appointed by an employee has been properly authorised to obtain the information, preferably by means of a written authority.
  • To tell the employee, where an information privacy request is refused, the reason for refusal, unless to do so would be likely to prejudice national security, commercial position etc. In this case a written reply neither confirming nor denying the existence of the information requested may be provided.

To access the complete Act click here

Back to Employment Legislation