NZ Privacy Act and Cybersecurity: Reasonable Security Safeguards

Privacy Act Principle 5 requires an organisation holding personal information to protect it with security safeguards that are reasonable in the circumstances. The safeguards must protect against loss, and against access, use, modification or disclosure that is not authorised, as well as other misuse. Cybersecurity is one part of meeting that duty.

 

New Zealand’s Privacy Act 2020 requires organisations holding personal information to protect it with safeguards that are reasonable in the circumstances. Principle 5 covers loss, misuse and unauthorised access, use, alteration or disclosure. Cybersecurity is part of meeting that duty, alongside staff procedures, physical security and the way suppliers handle information.

This guide explains how to turn that duty into practical IT decisions. It focuses on security safeguards; our NZ Privacy Act compliance guide covers the wider privacy programme, including collection, notices, retention, access requests and overseas disclosure. Your privacy officer or legal adviser should confirm how the rules apply to your business.

What does Privacy Act Principle 5 require?

The Privacy Act sets out information privacy principles 1 to 13, plus IPP 3A, which deals with notifying people when their information is collected indirectly. The Privacy Commissioner confirms that IPP 3A came into force on 1 May 2026. Principle 5 is the principle that deals directly with security.

The Commissioner’s summary of Principle 5 describes it as the storage and security principle. An agency that holds personal information must make sure there are security safeguards that are reasonable in the circumstances to protect against:

  • Loss. Records, files or devices holding personal information going missing.
  • Unauthorised access, use, modification or disclosure. Someone reaching, changing or sharing information without authority.
  • Other misuse. Information being used in ways the organisation did not intend or permit.

Principle 5 also applies when you give personal information to someone in connection with a service they provide to you. In that case, the Privacy Act expects everything reasonably within your power to be done to prevent unauthorised use or disclosure of that information. This is why supplier choice and supplier settings form part of the security duty, not just your own systems.

Where does cybersecurity fit?

Cybersecurity covers the technical side: accounts, devices, email, cloud services, software updates and backups. The duty itself is wider. A filing cabinet left unlocked, a printout left on a desk or a staff member sharing records with the wrong person can all fall under Principle 5. Technical controls support the duty, but they are not the whole of it.

Installing a security tool or completing an audit does not by itself establish compliance with the Privacy Act. The Act also governs how information is collected, used, shared, retained and corrected, and those duties sit with your privacy programme rather than your IT settings.

Does health information have different rules?

Health agencies follow the Health Information Privacy Code 2020, which modifies how the principles apply to health information. Rule 5 of the code covers storage and security. If your business provides health services, check the code alongside the Privacy Act before relying on general guidance.

What makes a security safeguard reasonable?

The Privacy Act does not list specific technologies. Whether a safeguard is reasonable depends on the circumstances, so the same control can be sufficient for one organisation and inadequate for another. Useful questions to work through include:

  • How sensitive is the information? Health details, identity documents, financial information and records about children carry more potential for harm than a basic contact list.
  • How much is held, and for how long? Larger volumes and longer retention widen the impact of a breach.
  • What harm could follow? Consider identity theft, financial loss, embarrassment, discrimination or risk to someone’s safety.
  • Where and how is it held? Cloud services, laptops, shared mailboxes, paper files and supplier systems each carry different risks.
  • Who can reach it? Staff, contractors, suppliers and integrations may all have some level of access.
  • What is practical? The cost and effort of a safeguard can be weighed against the risk it reduces.

Does a small business have a lower bar?

Risk depends on the information, the likely harm and the circumstances, not the business label. A small retailer may hold staff records, identity documents, bank details for payroll or customer payment information. A small medical or legal practice may hold highly sensitive records. Size can affect what is practical, but it does not remove the Privacy Act duty.

Does a breach prove the safeguards were unreasonable?

No. A breach can happen even where reasonable safeguards were in place, and a lack of breaches does not prove the safeguards are adequate. What matters is whether the safeguards were reasonable for the risk, and whether the business reviews them as its systems, staff and information change.

Which controls protect personal information?

Start with where personal information is held and what could go wrong. The examples below are practical safeguards to consider, not a statutory checklist or a guarantee of compliance with the Privacy Act.

Examples of security safeguards to consider under Privacy Act Principle 5: accounts, devices, sharing, software, records and reporting

Risk Practical safeguard
Stolen or misused accounts MFA, appropriate permissions, separate administrator access and prompt removal of departed users.
Lost devices or unsafe sharing Device encryption, screen locks, controlled sharing links and checks before sending sensitive files.
Exploited software Supported systems, timely updates and clear ownership of unresolved vulnerabilities.
Lost or unavailable records Protected backups and restore testing matched to the importance of the information.
Incidents left unreported A clear staff reporting route, technical escalation and access to the privacy officer.

Accounts and access

Multi-factor authentication reduces the risk of account takeover when a password is stolen or guessed. It does not stop every attack, so pair it with permissions that match each role, separate administrator accounts and a reliable process for removing access when people leave. Our guide to identity and access management covers these controls in more detail.

Devices

Laptops and phones travel, so a lost or stolen device is one way personal information can leave the business. Encryption reduces the risk that information on a lost device can be read. It does not protect against someone using a compromised authorised account or an exposed key, so screen locks, sign-in controls and the ability to locate or wipe a device also matter. Mobile device management helps apply these settings consistently.

Email and file sharing

Sending information to the wrong person is one way privacy breaches happen. Check recipients before sending sensitive files, use controlled sharing links with expiry where possible, and avoid sending large personal datasets by email. Email security controls and data loss prevention rules can flag or block risky sharing.

Software and maintenance

Unsupported or unpatched software gives attackers known ways in. Keep systems on supported versions, apply updates in a timely way and give someone clear ownership of any vulnerability that cannot be fixed straight away. Vulnerability management covers how to track and prioritise that work.

Backups and recovery

Losing access to personal information can itself be a privacy breach under the Privacy Act, so backups are part of the security duty. Protect backups from the same attack that could affect live systems, and test restores so you know information can be recovered. Our guide to data backup strategy explains how to match backup frequency and retention to the importance of the information.

People and process

Mistakes and process failures can cause breaches, alongside attacks and technical weaknesses. Security awareness training helps staff recognise phishing and handle information carefully, but training works best alongside safer systems and workflows. Make it easy to report a mistake quickly, without blame, so problems are contained early.

Physical records and premises

Privacy Act Principle 5 applies to paper as well as digital information. Lock away files and printouts holding personal information, control access to offices and server rooms, and dispose of records securely when they are no longer needed.

Suppliers and cloud services

When a supplier stores or processes personal information for you, check how they protect it, who on their side can access it and how they will tell you about an incident. Cloud security settings, such as sign-in policies and sharing controls, remain your responsibility in many services. Privacy Act rules on overseas disclosure are covered in our compliance guide.

Can a cyber incident be a privacy breach without a data leak?

Yes. Under the Privacy Act, a privacy breach is not limited to stolen data. The Commissioner’s guidance on what counts as a notifiable privacy breach covers personal information that has been accessed, disclosed, altered, lost or destroyed without authorisation, including temporary loss of access.

Types of privacy breach under the Privacy Act: unauthorised access, disclosure, alteration, loss, destruction and loss of access to personal information

That means ransomware can create a privacy breach even if no records leave the business. If staff or customers cannot get to their information because it has been encrypted by an attacker, that loss of access is part of the assessment. Our guide to ransomware protection covers how to reduce that risk.

When does a breach become notifiable?

A privacy breach becomes notifiable when it is reasonable to believe it has caused serious harm to an affected person, or is likely to do so. When assessing the likelihood of serious harm, the Privacy Act requires an agency to consider:

  • Action taken. Any steps taken to reduce the risk of harm after the breach.
  • Sensitivity. Whether the personal information is sensitive in nature.
  • Nature of the harm. The kind of harm that may be caused to affected people.
  • Who has it. The person or body that has obtained or may obtain the information, if known.
  • Security measures. Whether the information is protected by a security measure, such as encryption.
  • Other matters. Any other relevant circumstances.

Security measures appear in that list, which is one reason encryption and access controls matter after an incident as well as before it.

What should happen when a privacy breach is suspected?

A clear process helps your team act quickly and record its decisions. The steps below can overlap, and updates can follow while the investigation continues.

Responding to a suspected privacy breach under the Privacy Act: identify and contain, assess serious harm, notify the Privacy Commissioner, and notify affected people

1

Identify and contain

Stop further access or loss as quickly as possible. Reset compromised accounts, isolate affected devices and recall misdirected emails where you can.

2

Assess serious harm

Work out promptly what information was involved, who is affected and whether serious harm has occurred or is likely.

3

Notify the Commissioner

As the Privacy Act requires, notify the Privacy Commissioner as soon as practicable after becoming aware that a notifiable privacy breach has occurred.

4

Notify affected people

Notify affected people as soon as practicable, or give public notice where individual notification is not reasonably practicable, subject to the exceptions and permitted delays in the Act.

What does the 72-hour guidance mean?

The Commissioner explains in How long is 72 hours? that it expects notification within 72 hours of becoming aware of a notifiable breach. This is guidance, not a statutory deadline or a waiting period. If you already know a breach is notifiable, notify as soon as practicable rather than waiting for the 72 hours to pass.

Are there exceptions to notifying affected people?

Yes. The Privacy Act sets out limited exceptions, such as where notification would be likely to endanger someone’s safety or prejudice the maintenance of the law. A delay is also permitted where notifying could create risks for the security of the information that outweigh the benefits of telling people, for as long as those risks continue. Get advice before relying on an exception.

What is the offence for failing to notify?

Under section 118 of the Privacy Act, an agency commits an offence if it fails to notify the Commissioner of a notifiable privacy breach without reasonable excuse. The offence concerns the failure to notify, not the breach itself. An incident response plan that names who assesses harm and who contacts the Commissioner helps avoid that failure.

How do you review whether safeguards remain appropriate?

Safeguards that were reasonable under the Privacy Act when introduced can fall behind as the business adds systems, staff and suppliers. Build reviews into normal routines rather than treating security as a one-off project.

  • Map the information. Keep a simple record of where personal information is held, who can reach it and which suppliers handle it.
  • Review after change. Check safeguards when you adopt a new system, change supplier, restructure teams or open a new office.
  • Test what matters. Restore from backup, check that leavers lose access and confirm that MFA covers the accounts it should.
  • Record decisions. Note what you chose, why and when it will be reviewed, so the reasoning is clear later.
  • Learn from incidents. After a near miss or breach, review which safeguard failed or was missing and what will change.

A security audit gives an independent view of technical controls and gaps. It supports your review but does not certify compliance with the Privacy Act as a whole.

Privacy Act security support from Exodesk

Exodesk helps businesses put practical security controls in place, including access management, device and cloud security, and backup and recovery. Exodesk has supported New Zealand businesses since 1989, with offices in Christchurch and Dunedin. Your privacy officer leads the wider Privacy Act programme, and we can work alongside them on the technical side.

Explore our cyber security services or contact us to discuss your systems.

Frequently Asked Questions

What does Principle 5 of the Privacy Act require?

Principle 5 requires an organisation holding personal information to have security safeguards that are reasonable in the circumstances. The safeguards must protect against loss, unauthorised access, use, modification or disclosure, and other misuse.

Does the Privacy Act list specific security controls?

No. The Privacy Act does not name technologies such as MFA or encryption. Whether a safeguard is reasonable depends on the sensitivity of the information, the likely harm and the circumstances of the business.

Do security tools make us Privacy Act compliant?

No. Security tools can support your safeguards, but the settings, coverage, staff processes and ongoing upkeep matter too. The Act also governs how information is collected, used, shared and retained. An IT review does not certify compliance with all those duties.

Can ransomware be a privacy breach without a data leak?

Yes. A privacy breach can involve losing access to personal information, even temporarily. Ransomware does not have to leak records to create a privacy issue. Assess whether serious harm has occurred or is likely, including harm caused by the information being unavailable.

What is a notifiable privacy breach?

A notifiable privacy breach is one where it is reasonable to believe serious harm has been caused to an affected person, or is likely to be. A breach can involve unauthorised access, disclosure, alteration, loss or destruction of personal information, including temporary loss of access.

Do we have 72 hours to report a privacy breach?

The Privacy Act requires notification to the Commissioner as soon as practicable after becoming aware of a notifiable breach. The Commissioner expects notification within 72 hours of becoming aware. This is guidance, not a waiting period, so notify sooner where you can.

Do we have to tell affected people about a breach?

Yes, for a notifiable breach, unless an exception applies or a delay is permitted. Where notifying each person is not reasonably practicable, public notice may be required instead. Get advice before relying on an exception.

Is every privacy breach an offence?

No. The offence in section 118 concerns failing to notify the Commissioner of a notifiable breach without reasonable excuse. A breach on its own is not that offence, although the Commissioner can still investigate how information was handled.

Does MFA stop all account attacks?

No. Multi-factor authentication reduces the risk of account takeover, but some attacks can still get around it. Combine it with appropriate permissions, monitoring and prompt removal of access when people leave.

Does encryption make stolen information safe?

Encryption reduces the risk that information on a lost device or intercepted file can be read. It does not help if an attacker uses a compromised authorised account or an exposed key. Treat it as one safeguard among several.

Does Principle 5 apply to paper records?

Yes. Privacy Act Principle 5 covers personal information in any form, including paper files, printouts and handwritten notes. Lock away physical records, control access to offices and dispose of records securely.

Are we responsible for information held by our IT or cloud provider?

When a provider holds or processes personal information on your behalf, your business remains responsible for it. Check how the provider protects the information, who can access it and how incidents will be reported to you. Our NZ Privacy Act compliance guide covers overseas disclosure rules.

How do we know whether our safeguards are still reasonable?

Review whether safeguards remain appropriate when systems, suppliers, staff or the information you hold change. Test key controls such as backups and leaver access, and record what you decided and why.

Who should lead Privacy Act compliance in a business?

Every organisation needs a privacy officer, who leads the wider privacy programme. IT staff or an IT provider can implement and maintain the technical safeguards, but they do not replace the privacy officer role.

NEXT STEP

Need help with the technical safeguards?

Exodesk helps businesses put practical security controls in place, including access management, device and cloud security, and backup and recovery. Talk to us about your systems.

Or explore our cyber security services.

Start typing and press Enter to search

Shadow IT: a magnifying glass over business apps, with unapproved tools highlightedWindows 10 end of life NZ -- flat vector showing Windows 10 countdown warning transitioning to Windows 11 Call Us Now