Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
The Information Matching Agreements finalised under the Privacy Act 1993 continue in force under the Privacy Act 2020 (Schedule 1, section 11) |
The Privacy Commissioner has a regulatory role to monitor the use of information matching by government departments. (The term ‘data matching’ is commonly used in other countries.)
Part 7 sub-part 4 and Schedule 6 of the Privacy Act provide a set of rules dealing with the supervision and operation of authorised information matching programmes.
Information matching provisions are authorised by statute and these are listed in Schedule 5 of the Privacy Act 2020. Our list of the information matching provisions and the matching programmes operated under those provisions provides links to descriptions and annual reports of the results of all operating information matches can be found here. Our comments on proposed legislation authorizing information matches, and the 5-yearly reviews of each information matching provision can be found here.
A person's privacy can be affected by information matching when agencies are:
If unchecked, information or data matching would seriously undermine people's trust in government. To address the risks, the Privacy Act regulates the practice of information matching in the public sector. It does this by having the following controls put in place:
Operating programmes: Detailed descriptions and annual reports of the results of all operating authorized information matches.
Information Matching Reports and Reviews: The Commissioner's comments on proposed legislation authorizing information matches, and other reports on information matching programmes.
Part 7 of the Privacy Act regulates the operation of government information matching to minimise the privacy risks and maintain public confidence in the fair handling of data. The Privacy Commissioner oversees compliance with the controls in Part 7.
In response to the growth and changing nature of authorised information matching programmes, the compliance audit approach to reporting has been developed. The audit approach assesses compliance with the Privacy Act information matching controls in two parts:
The Privacy Act requires that the Commissioner review the operation of each information matching provision every five years. In these reviews under section 184 the Commissioner recommends whether a provision should continue, be amended or be cancelled. These updates are included in each year’s Annual Report, which can be found here.