The Manage My Health inquiry: what every New Zealand organisation should take from it
New Zealand's largest health data breach. What the Privacy Commissioner's inquiry means for any organisation that holds or shares personal information.
Get in touch Guidance on data breaches, serious-harm assessments, information security, identity checks and the responsibilities attached to sensitive data.
Need advice rather than general information?
Data breach & incident response adviceNew Zealand's largest health data breach. What the Privacy Commissioner's inquiry means for any organisation that holds or shares personal information.
How NZ businesses should assess whether a privacy breach is notifiable under the Privacy Act 2020. Practical guidance on the serious harm test.
CJEU rules pseudonymised data may be anonymous in some contexts. What this means for New Zealand privacy law, AI, and contractual safeguards.
Weak ID checks are not just a privacy gap, they are a business risk
A finance business recently found itself under scrutiny after a fraud incident exposed significant gaps in its privacy practices, including a failure to notify the Privacy Commissioner as required under the Privacy Act.A caller pretending to be a customer was able to mislead staff, access the customer’s account, and make unauthorised changes and transactions. Not once, but multiple times. Even though the customer raised repeated concerns that someone was accessing and using their personal inform