Gordon Campbell | Parliament TV | Parliament Today | News Video | Crime | Employers | Housing | Immigration | Legal | Local Govt. | Maori | Welfare | Unions | Youth | Search

 

Playing a short game on the privacy bill

Playing a short game on the privacy bill

14 March 2019 | BRIEF COUNSEL


The select committee has played safe on the Privacy Bill, recommending only modest changes.

While this will make for an easy transition in the short term, it may also mean further reform is needed in a few years' time.

In particular, the Bill falls well short of the European Union (EU) General Data Protection Regulation (GDPR), which sets the standard for EU engagement – an outcome that could create compliance costs for some New Zealand businesses.

Key amendments

Raising the threshold for privacy breach notification

An agency would only need to notify the Privacy Commissioner and affected individuals of a privacy breach where it is reasonable to believe the breach is likely to cause “serious harm”.

This is a higher threshold than originally proposed, responds to concerns raised by submitters, and aligns New Zealand with Australian and European law.

Cross-border reach

The Bill would apply to all New Zealand agencies collecting personal information (regardless of where it is collected or held), overseas agencies that collect personal information in the course of carrying on business in New Zealand, and non-resident individuals who collect personal information while in New Zealand.

Additional requirements when sending data offshore

The Bill requires an agency disclosing personal information to a “foreign person or entity” to meet one of six grounds the effect of which is to provide safeguards comparable to those in New Zealand.

While the intention of this change is laudable, the provisions (including the definition of “foreign person or entity”) may create added complexity without a clear need for change.

That said, the Bill has been amended to clarify that “disclosure” does not include sending information to a cloud service provider or other party that holds the information solely as agent.

Agencies not to collect identifying information unless necessary

The Bill would expand IPP 1 (collection for lawful and necessary purposes) to prohibit collection of “identifying information” if not necessary for the purposes for which the information is being collected.

We understand that this change is intended to nudge agencies towards allowing individuals to interact anonymously with them, but what counts as “identifying information” is unclear, and in any case it will be a rare occurrence where an agency is unable to find at least some purpose (however speculative) that justifies collection.

Removal of the Public Register Principles

The public register privacy principles have been removed as recommended by both the Law Commission and the Privacy Commissioner. This is on the basis that appropriate protections are better addressed by the legislation that governs use and public access to the applicable register.

Changes the Privacy Commissioner wanted but did not get

The Privacy Commissioner argued for a number of changes which the committee has not delivered. Principal among these were a power to seek civil penalties, rights of erasure for individuals (sometimes referred to as “a right to be forgotten”), data portability, and transparency for algorithmic decisions.

The Ministry of Justice departmental report indicates further reform along these lines may be needed to maintain EU adequacy.

The Privacy Commissioner issued a statement saying that the Bill “addresses some of the most pressing aspects of the modern digital economy” but that he would continue to make the case for more civil enforcement powers and “other modernising reforms to ensure that New Zealand’s privacy framework is robust, fit-for-purpose and comparable to those of its trading partners”.

Implications of the Bill for business

For most businesses, the two most noteworthy features of the Bill are the requirement to notify privacy breaches to the Privacy Commissioner and affected individuals (now subject to a higher threshold before notification is required), and the obligation to ensure safeguards are in place when sending data offshore.

Both these features will require businesses to put in place new processes in order to comply, although the burden is likely to be modest, especially for those organisations that already have good privacy practices embedded in their operations.

The Bill is proposed to come into force on 1 March 2020.

Our thanks to David Smith for writing this Brief Counsel.


© Scoop Media

 
 
 
Parliament Headlines | Politics Headlines | Regional Headlines

Commerce Commission: Retail Fuel "Not As Competitive As It Could Be"

The Commission has outlined some options it considers could improve competition. There are two broad sets of options it thinks may have the potential to help create a competitive wholesale market. These are:

• Greater contractual freedom to make it easier for resellers to switch between suppliers; and
• Enabling wider participation in the majors’ joint infrastructure, notably the shared terminals and supporting logistics involved in their borrow-and-loan system.
Further options, including improving the transparency of premium petrol prices, are discussed in the draft report. More>>

 

Promises: Independent Election Policy Costing Unit A Step Closer

The creation of an entity to provide political parties with independent and non-partisan policy costings is a step closer today, according to Finance Minister Grant Robertson and Associate Finance Minister James Shaw. More>>

ALSO:

School's In: Primary And Intermediate Principals Accept New Offer

Primary and intermediate school principals have voted to accept a new settlement from the Ministry of Education, which includes entrenched pay parity with secondary principals. More>>

ALSO:

IPCA On 'Rawshark' Investigation: Multiple Police Failings In Hager Searches Confirmed

The Independent Police Conduct Authority has found that the Police's unlawful search of Nicky Hager's property in October 2014 resulted from an unwitting neglect of duty and did not amount to misconduct by any individual officer... More>>

ALSO:

Broadcasting Standards: Decisions On Coverage Of Mosque Attacks

The Authority upheld one of these complaints, finding that the use of extensive excerpts from the alleged attacker’s livestream video on Sky News New Zealand had the potential to cause significant distress to audiences in New Zealand, and particularly to the family and friends of victims, and the wider Muslim community. More>>

PM's Post-Cab: Bad Mail

Cabinet was updated on the process around prisoners sending mail, following the accused Christchurch gunman sending letters that "should have been stopped". All mail of "high concern prisoners" will now be checked by a specialist team and a changes to the legal criteria for witholding mail are expecting to go to a cabinet committee in this parliamentary session. More>>

Welfare: Ongoing Drug-Test Sanctions Contradicts Govt’s Rhetoric

Reports that two-thirds of beneficiaries who fail drug tests are still having their benefit sanctioned contradicts the Government’s so-called health approach to drugs. More>>

ALSO:

Welfare: More Measures To Help Those Facing Homelessness

Ministers have announced $54 million in Government funding for initiatives which will support at-risk individuals and whānau to stay in their existing tenancies. The funding will also provide additional wrap around services. More>>

ALSO:

Corrections: New Strategy On Māori Reoffending And imprisonment

Authentic co-design with Māori, incorporating a Te Ao Māori worldview, and greater connectedness with whānau are key elements of Hōkai Rangi, Corrections’ new departmental strategy designed to address the long-term challenge of Māori reoffending and imprisonment. More>>

ALSO:

 
 
 
 
 

LATEST HEADLINES

  • PARLIAMENT
  • POLITICS
  • REGIONAL
 
 

InfoPages News Channels