Our website uses cookies to give you the best experience and for us to analyse our site usage. If you continue to use our site, we will take it you are OK about this. Click on More for information about the cookies on our site and what you can do to opt out.

We respect your Do Not Track preference.

ANZ’s practical guide to protecting privacy Colin Trotter
16 December 2014

new anz logo

ANZ’s privacy and data protection manager Hannah Johnston was a recent guest speaker at our last Technology and Privacy Forum for 2014 and she gave a comprehensive overview about what the bank – New Zealand’s third largest employer after its merger with the National Bank – was doing to protect customer privacy.

Hannah had just broken a foot while kite surfing, so it was ‘above and beyond’ to still make herself available for the presentation despite wearing a moon boot and handling crutches.

Her topic to an audience of over 70 people at the National Library meeting venue last month was ANZ’s practical approach to privacy compliance. Hannah joined ANZ in 2011 in the Risk Division and has worked in a variety of compliance and regulatory roles, so she was well versed in the subject.

Her presentation told the story of ANZ’s review of disclosure incidents and the new training programme it has developed to help reduce the number of incidents. A startling finding of ANZ’s review was that 90 percent of incidents resulted from human error, nine percent were systems issues, and one percent occurred where data was not de-identified.

Hannah played us some of the ANZ staff training ‘A day in the life’ videos that the bank commissioned as part of their new privacy programme. The video focuses on four situations – sending information to the wrong person, sending mail for more than one person in the same envelope, disclosing information over the phone to the wrong person and showing account information on a computer screen to someone other than the account holder.

The videos have a humorous angle and I can imagine they were a hit with staff, given our Technology and Privacy Forum audience clearly enjoyed what it saw of them.

ANZ’s package of measures to improve staff privacy practice includes the videos, 15 minute face-to-face training sessions and a takeaway bookmark. On the technology side, ANZ also has security and privacy features available for staff to use. These include privacy screens, email encryption, and recommendations that staff turn off auto-complete, impose an email send delay, and use secure information exchange techniques such as encryption.

Since its new training programme went live earlier this year, ANZ has seen a spike in incident reporting and faster handling of those incidents. The next step will be for the bank to consider making some of its employee guidance mandatory.

The presentation was a top effort by Hannah and we wish her a speedy recovery. If you want to see the slides that accompanied her presentation, you can find them here.

4 comments

, ,

Back

Comments

  • Unfortunately your 'here' does not take you to the slides that accompanied Hannah's presentation. Is there any chance we could see these?

    Posted by Shelley, 17/12/2014 12:54pm (3 years ago)

    Post Reply

    The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.

  • Hi Shelley,
    Hannah's presentation can be found here:
    https://privacy.org.nz/news-and-publications/speeches-and-presentations/previous-t-p-forum-presentations/
    Thanks for your interest,
    Charles

    Posted by OPC, 17/12/2014 4:31pm (3 years ago)

    Post Reply

    The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.

  • That video ‘A day in the life’ was great. I wonder if anyone else knows a good video for training staff around whats appropriate behaviour for leaving voice mail messages? Or perhaps we could ask the ANZ nicely to share their video?

    Posted by Gareth Foster, 05/03/2015 9:14am (2 years ago)

    Post Reply

    The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.

  • Hi Gareth,
    we'll ask Hannah to see if it can be made available. We were impressed and enjoyed it too.
    Thanks for the suggestion.
    Colin

    Posted by OPC, 05/03/2015 9:40am (2 years ago)

    Post Reply

    The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.

Post your comment

The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.

Latest Blog Entries