Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

Can I tell the cops? A guide for health professionals Richard Stephen
7 July 2017 at 11:32

In their job, health professionals have to look after some of the most intimate details of their patients’ lives. This is a great responsibility, and patients trust and expect doctors, nurses and others to not just tell anyone. This obligation is recognised in the Health Information Privacy Code.

Tribunal finds confusion over request led to delay Annabel Fordham
14 June 2017 at 11:58

Mr Brooks was an active Taekwondo competitor and a long-time member of the Taekwondo Union of New Zealand (TUNZ). He represented New Zealand in the 2005 World Championships and the 2006 Commonwealth Championships.

Should agencies leave no stone unturned? Charles Mabbett
10 May 2017 at 09:31

Organisations sometimes get it wrong when they respond to a person’s request for their personal information. Information is sometimes lost, displaced or accidentally deleted. A recent privacy case dealt with by the Human Rights Review Tribunal considers when an organisation can call it quits when it comes to searching for personal information in responding to an access request.

Breach Case 3: Catches win matches Neil Sanson
7 April 2017 at 10:39

A recent data breach provided an example of how it is sometimes possible to catch a breach as it is happening and avert potential harm.

How to make information available – some tips for agencies Lynley Cahill
4 April 2017 at 14:32

We live in an age where agencies collect and hold a lot of information about us. When we then request access to that information, this places demands on the time and resources of agencies to meet their obligations under the Privacy Act. Agencies sometimes feel a bit overwhelmed when responding to requests for personal information -  especially where a high volume of information is held.

Hager and Westpac - A bit more context, information and clarification Sam Grover
22 March 2017 at 09:50

There has been a significant amount of media coverage about our investigation into Westpac bank disclosing journalist Nicky Hager’s bank account information to Police in 2014. In the course of that reporting, some misconceptions have emerged. Because of the interest in the case, and the potential implications for future practice, we have noted some points of clarification and context below.

What to do in a phishing attack Neil Sanson,
20 March 2017 at 14:42

A recent data breach involved a deliberate email phishing attack on an organisation. The email looked like it came from the chief executive and requested a copy of the membership list (names and email addresses).

Sir Bruce Houlton Slane Charles Mabbett
8 January 2017 at 09:50

Sir Bruce Houlton Slane KNZM, CBE, LLB practiced law in New Zealand for almost 50 years, including 11 years as the country’s first Privacy Commissioner.