Data Security for NZ Businesses: What to Protect and How

Data security is the set of safeguards that keep the information your business holds from being lost, altered, misused or seen by people who should not see it. That covers personal information, and also the commercial and operational records you need to keep trading. For personal information the legal standard is set by the Privacy Act 2020, and the wording matters: safeguards that are reasonable in the circumstances. Not best practice, not the most you could buy.

Most data security advice starts with a list of tools. This starts with the law. In New Zealand the obligation came first, the tools are only how you meet it, and knowing which is which saves a great deal of money.

Principle 5 of the Privacy Act 2020 says that an agency holding personal information must protect it, by such security safeguards as are reasonable in the circumstances, against loss, against access, use, modification or disclosure the agency did not authorise, and against other misuse.

Read that phrase again. Reasonable in the circumstances. That phrase is the whole test, and it does more work than most owners realise.

It means there is no fixed shopping list. What is reasonable for a two person consultancy holding email addresses is not what is reasonable for a medical practice holding clinical notes, and the law expects you to have thought about which one you are.

That is good news for a smaller business. It makes proportionate data security a defensible position and not a compromise, provided somebody has worked out what you hold and protected it accordingly. Without that, the test has no anchor and neither do you.

There is a second reason to start here. Clients, insurers and procurement teams increasingly ask what your data security arrangements are, and the answer they want is evidence that the safeguards are in place and suited to what you hold, not a product name.

This guide covers what the obligation actually says, how to judge what is reasonable for your business, what to protect in practice, and where New Zealand businesses most often fall short.

What Does Data Security Mean Under the Privacy Act?

It means protecting personal information with safeguards proportionate to the risk. Principle 5 of the Privacy Act 2020 sets three things you must protect against: loss, unauthorised access or use or modification or disclosure, and other misuse.

Notice what the Act does not say. It names no technology, no certification and no minimum spend. Data security under New Zealand law is judged on whether the safeguards suit what you hold, not on what you bought. A written record helps you explain the approach you took. It does not make inadequate protection reasonable, and a breach does not by itself establish that every safeguard was unreasonable.

The word agency covers almost everyone. It is not limited to government. It takes in sole traders, clubs, charities and companies of any size, so a business holding a single spreadsheet of customer contact details is already inside the obligation and usually does not know it.

Personal information is broader than most people assume as well. It is any information about an identifiable person. That takes in staff records, customer email addresses, the CCTV footage at the door, and the running notes somebody keeps in a shared inbox.

It also takes in information you never deliberately collected. A CV emailed in by a candidate who was never hired is personal information, and so is the delivery address on an invoice from four years ago.

The starting point is knowing what you hold, and how long that takes depends on how many systems and records are involved. Nearly every data security conversation should start there and very few do. Our guide to Privacy Act compliance covers the wider obligations that sit alongside this one.

What Data Does Your Business Actually Hold?

Almost certainly more than you would list from memory, and in more places. The exercise that makes data security tractable is writing it down, because you cannot apply a proportionate safeguard to something you have not identified.

Data security inventory showing four listed systems beside five unlisted places personal information also sits

Start with the obvious systems: the finance package, the customer database, the job or practice management system, payroll. Then add the ones nobody thinks of as systems at all. Shared mailboxes, the sales spreadsheet living on somebody’s desktop, the folder of scanned identity documents from an onboarding process three years ago, and whatever remains in the archive nobody has opened since the last office move.

For each one, record more than the system name. Six fields make an inventory usable:

Field What to record
Information The categories held, including personal, commercial and operational data
Location and copies Systems, cloud services, paper records, devices, exports and backups
Business owner The role responsible for deciding appropriate use, access and retention
Access and sharing Who can view or change it, and where it is sent outside the business
Purpose and retention Why it is needed, any retention requirement, and the disposal arrangement
Impact What exposure, incorrect changes or loss of access would mean for people and operations

Record categories and locations rather than copying sensitive records into the inventory itself, because the inventory should reduce your data security exposure and not add to it. The impact field is the one that decides how much data security each item deserves.

Old data collects risk without anyone deciding it should. Information you no longer need still has to be protected for as long as you hold it. The simplest way to reduce a data security obligation is therefore to stop holding things you have no reason to keep, which reduces both your duty and your exposure at once. Disposal has to be coordinated across active copies, exports and backup retention, and historic copies may not all be immediately removable.

Expect the exercise to turn up at least one unwelcome discovery. A former employee whose account is still active, an export nobody deleted, a system still holding records from a business line closed two years ago. Old software and fragmented records can make the data security work substantial, so start with the main systems and the higher-risk information and fill the gaps with the people who use it.

Keep the result somewhere it will be updated, not somewhere it will be filed. An inventory that reflects last year is worse than useful, because it invites confident answers that are wrong.

What Counts as Reasonable Data Security?

There is no statutory list. There is an official New Zealand one you can borrow. The NCSC’s minimum cyber security standards, published on 30 October 2025, set out ten areas covering business-critical and externally facing systems, and they are a useful structure for reviewing foundational controls.

NCSC minimum standard The question it really asks
Risk management Have you assessed what could go wrong and written it down?
Security awareness Is training current and relevant to the actual threats?
Assets and their importance Do you know what you hold and which parts matter most?
Secure configuration of software Are new systems set up securely by default?
Patching Can you state your patch cadence and evidence it?
Multi-factor authentication Do users authenticate securely to critical systems and remote services?
Detect unusual behaviour Would you notice, and would a named person see it?
Least privilege Does everyone have only the access their role needs?
Data recovery Can the data and services you need actually be restored?
Response planning Is the plan tested, and can you reach it during an outage?

Read them as questions, not purchases. Each one asks whether something is actually in place, not whether a product has been bought. Many can be answered from settings inside software the business already pays for, so a good deal of data security costs time rather than licensing.

The standards were written under the Government Chief Information Security Officer mandate, and the NCSC says non-mandated agencies wishing to adopt them are welcome to. Nothing stops a private business using them the same way. The NCSC also states that the standards do not cover the entire cyber security spectrum, so working through them does not establish that your safeguards meet the Privacy Act. Apply them to your own data security risks alongside the privacy, sector and contractual requirements that apply to you.

Proportion runs through all ten. A firm holding health information should reach further down the list than a firm holding trade contact details. Both should be able to say why they stopped where they did, and that explanation is the part anyone reviewing you will actually want.

Where you land also shapes what an insurer will accept and what a client procurement questionnaire will ask for, so the work has a second use well beyond the Act.

One caution on reading the list. It is a set of areas, not a scoring system, and it is not an order in which a smaller business can stop early. Review all ten and prioritise the gaps by risk. A business that treats it as ten boxes to tick will end up with ten thin answers.

Who Can Reach Your Data Right Now?

Usually more people than intended, and the gap between the two is the most common data security failure we find. Access accumulates. Somebody needs a folder for a project, gets added, and nobody removes them when the project ends.

Run three data security checks and write down the answers. Who holds administrator rights, which accounts belong to people who have left, and which shared logins exist that cannot be attributed to an individual. All three can be answered in an afternoon on most systems, and the results are usually worse than expected.

Shared logins are the one worth being firm about. An account several people use cannot be tied to a person. That defeats accountability and it defeats any later attempt to reconstruct what happened. These accounts usually exist because setting up individual logins once felt like effort, and they outlive the reason.

Then look at where data leaves, not only where it lives. Exports to spreadsheets, forwarding rules quietly set on mailboxes, files synced to personal cloud accounts, and contractors who still hold access months after the contract ended.

Mailbox forwarding rules deserve their own check. Attackers favour them because they make no noise, they survive a password reset, and almost nobody looks at them.

Access is only half of it. Protect information wherever staff actually use it. Use approved sharing methods and check recipients and permissions before sending, secure the laptops and portable devices that leave the building, and keep paper records out of public view. Restrict who can change important records and keep a way to investigate or reverse an unauthorised change, because data security covers accuracy and availability as well as confidentiality. Plan recovery around the information the business needs in order to keep operating.

Multi-factor authentication belongs on everything reachable from the internet, and the exceptions list is where to look first. Most tenancies carry a handful of accounts excluded for a reason that made sense once, and an exception granted that way tends to outlive the data security reason for it. Our post on secure passwords covers the credential side in more detail.

What Happens If Data Security Fails?

Assess promptly whether there are reasonable grounds to believe the breach has caused, or is likely to cause, serious harm to anyone. If it is notifiable, the Act requires you to tell the Privacy Commissioner as soon as practicable after becoming aware of it. The Office of the Privacy Commissioner asks agencies to do that within 72 hours, even while the investigation is still open, and that is guidance on promptness rather than a statutory deadline.

Affected people have to be told as soon as practicable too, unless one of the exceptions in the Act applies. That conversation goes considerably better coming from you than reaching them another way. The businesses that manage it well are the ones who already knew what they held and where, because they can be specific instead of vague at exactly the moment vagueness does the most damage.

Losing access counts as well. The Act treats an action that prevents you reaching the information as a privacy breach, so an incident that locks up records without anyone copying them can still be notifiable. If establishing what personal information was in that system takes a week, you cannot assess it promptly, and the inventory in the previous section matters more than any single control for exactly that reason.

Keep the contact details and the response steps somewhere that survives the incident. A plan stored only on the file server is a plan you will not have access to on the day you need it.

Decide in advance who makes the notification call as well. Left undecided, it falls to whoever is most anxious at the time, and that is not a good way to make a legal judgement under pressure. What an employee or an agent knows can count as known by the business, so escalation should not wait for the privacy officer to find out personally.

Check your contractual notification duties separately. Client agreements in professional services and health frequently set their own notification windows, and those are obligations in their own right rather than something to weigh against the Act.

Does Using an IT Provider Transfer the Obligation?

No, and Principle 5 addresses this directly. Where information is given to somebody in connection with a service provided to you, the Act requires you to do everything reasonably within your power to prevent unauthorised use or disclosure of it.

Section 11 of the Act puts it beyond doubt. Information a provider holds solely for you is generally treated as held by your business rather than theirs. You can outsource the work and you cannot outsource the duty, and that is where board-level accountability sits. There is one qualification worth knowing. If the provider also uses or discloses that information for its own purposes, it is treated as holding the information too, and both organisations may then have obligations under the Act.

What a provider can do is make the obligation answerable. Who holds administrator rights, when the last access review happened, whether multi-factor authentication covers every service reachable from the internet, and what the backup retention actually is. Those are questions with documented answers, not opinions. Producing them on request is what data security looks like in practice.

Ask the provider to state in writing what they secure and what remains yours, including who handles incident escalation, what happens to your data when the agreement ends, and which subcontractors touch it along the way. Most contracts are less specific than either side assumes, and the gap tends to surface at the worst moment. A provider should also tell you promptly about incidents affecting your information, because you cannot meet your own obligations otherwise.

It is worth reading your agreement with that in mind before an incident makes it urgent. The questions to ask are narrow: who holds the administrator credentials, what is monitored, what is backed up, how long is it kept, and who is told when something looks wrong.

That list is also a reasonable summary of what our cyber security work covers, and a provider who cannot answer all five in writing is a fair thing to be uneasy about.

Where Do NZ Businesses Most Often Fall Short?

In four places, and none of them is exotic. No inventory of what is held, access that was never reviewed, a backup nobody has restored from, and a notification duty nobody has read.

Four data security gaps to check: no inventory, access never reviewed, backup never restored and notification duty unread

The inventory is the one the others rest on, because every data security decision needs it. Without it a business cannot judge what is reasonable, cannot assess a breach promptly, and cannot tell a client which of their records were affected. Each of those failures is visible to somebody who matters.

Access review is usually the least expensive item on the list and among the easiest to defer. Listing administrators and closing the accounts of people who have left removes real data security risk for very little outlay, though how long it takes depends on how many systems hold their own accounts.

Backups get bought and not tested, which produces the appearance of protection without the substance. Our guide to a data backup strategy covers the copies and the test schedule.

The fourth is the quietest. Businesses discover the notification obligation during the incident, which is the worst possible moment to read it for the first time. A technical problem becomes a legal one on the same afternoon.

How Would You Know Where You Stand?

By having somebody check your data security against what you actually hold. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand.

An IT security audit looks at who can reach your systems, what is actually configured, and where that sits against the ten standards. It is a technical review rather than a complete inventory of everything you hold, and it usually shows you where the inventory needs to start.

What we find is rarely dramatic. An inventory that has never existed, a list of administrators longer than anyone expected, and a backup nobody has restored from since the day it was set up. None of that would make a headline, and all of it would matter on the day.

Those are all fixable in ordinary time, and fixing them is most of what reasonable data security means for a business this size.

One boundary worth stating. We do not advise on the Privacy Act itself, and where a question turns on legal interpretation we will say so and point you to somebody who does.

Frequently Asked Questions

What is data security?

Data security protects information against loss, unauthorised access, alteration and misuse. It covers personal information and the commercial and operational records a business needs to keep running. In New Zealand the legal standard for personal information comes from Principle 5 of the Privacy Act 2020, which requires safeguards that are reasonable in the circumstances rather than a fixed list of technology.

Does the Privacy Act apply to small businesses?

Yes. The Act uses the word agency, which covers sole traders, clubs, charities and companies of any size. If you hold information about identifiable people, including staff and customers, the data security obligation applies. Size affects what is reasonable, not whether the duty exists.

What does reasonable in the circumstances mean?

It means safeguards suited to the information, how it is used, the risks to it and the consequences for the people involved. A firm holding health records is expected to do more than one holding business contact details. Documenting a decision helps you explain it, and it does not make inadequate protection sufficient.

What is the first step to improving data security?

Identify the main information you hold, where it is kept, who uses it and who is responsible for it. Every other decision depends on that, including whether your safeguards are proportionate and whether you could assess a breach promptly. Start with the higher-risk information and the obvious exposures while the inventory develops. How long it takes depends on the systems and records involved.

How quickly must a privacy breach be reported in NZ?

As soon as practicable after you become aware that a breach is notifiable. The Privacy Commissioner asks agencies to do that within 72 hours even while they are still investigating, which is guidance on promptness rather than a statutory deadline. Affected people have to be told as soon as practicable too, unless an exception applies. A breach is notifiable where it is reasonable to believe it has caused serious harm, or is likely to.

Does our IT provider carry the data security obligation?

No. Under section 11 of the Privacy Act, information a provider holds solely on your behalf is generally treated as held by your business. If the provider also uses or discloses it for its own purposes, both organisations may have obligations. Agree who manages security, access, incident escalation and the return or deletion of data, and expect the provider to tell you promptly about incidents affecting your information.

What are the NCSC minimum cyber security standards?

Ten areas: risk management, security awareness, assets and their importance, secure configuration of software, patching, multi-factor authentication, detect unusual behaviour, least privilege, data recovery and response planning. Published on 30 October 2025 under the Government Chief Information Security Officer mandate, they apply to business-critical and externally facing systems, and non-mandated agencies are welcome to adopt them. The NCSC notes they do not cover the entire cyber security spectrum, so they are a reference rather than a test of Privacy Act compliance.

Is encryption required for data security in New Zealand?

Principle 5 does not prescribe one technology for every situation, so encryption is not mandated by itself. It may still be necessary as part of reasonable safeguards, particularly for sensitive information on laptops and portable media that leave the building, and sector or contractual requirements can ask for it separately. Encryption does not replace access controls or safe handling.

How long should we keep personal information?

Only as long as you have a lawful purpose for it. Holding data you no longer need extends your obligation and your exposure at the same time, so disposal is a data security control and not housekeeping. Retention rules under other legislation, such as tax records, still apply. Coordinate disposal across active copies, exports and backups, because historic copies may not all be immediately removable.

Which data security gaps should we check first?

Check information stored outside your main systems, access nobody has reviewed, sharing settings, and whether the data you need can actually be restored. Confirm who responds to an incident as well. Prioritise the gaps by their likely consequences for people and for operations, rather than assuming one of them is always the largest.

Do we need a certification such as ISO 27001?

The Privacy Act does not generally require it. A client contract or a procurement process may ask for it, and certification can be a useful discipline in its own right. The obligation under the Act is reasonable safeguards, which a smaller business can meet and evidence without certifying.

How does Exodesk help with data security?

We establish what you hold, who can reach it and what is actually configured, then check that against the ten standards and fix the gaps. We do not give legal advice on the Act. Where a question is about obligations rather than systems, it belongs with your own adviser.

NEXT STEP

Could you list what personal information you hold?

Most businesses cannot, and it is the first thing the Privacy Act expects you to know. Talk to us about the information your business relies on and the systems that hold it. We can review access, configuration and recovery arrangements, and agree which data security improvements to address first.

Or start with an IT assessment.

Start typing and press Enter to search

AI in cybersecurity banner showing many arrows aimed at one unchanged locked doorCyber risk assessment banner showing a ranked risk register with graded severity markers Call Us Now