Privacy Act Changes
5 November 2019
Changes to the Privacy Act are currently making their way through Parliament and are expected to be passed into law before the end of the year. The changes are being made to make sure that the legislation is in line with new technology and the way that businesses now operate.
The proposed changes include:
- Mandatory reporting to the Privacy Commissioner and affected individuals of privacy breaches, where the breach has caused or is likely to cause serious harm. When considering if the breach is notifiable, consider the following:
- Is the information sensitive in nature?
- The nature of harm caused.
- Who obtained or may obtain the information as result of the breach?
- Any action taken by the agency to reduce harm.
- Whether the information is protected by security measures; and
- Any other relevant matters.
- You must also advise the Office of the Privacy Commission as soon as practicable after becoming aware of a notifiable breach either by email, phone or using their online form
- If a business receives a request for personal information, the business cannot destroy the information in order to avoid providing it.
- Where NZ businesses use overseas service providers e.g. cloud storage, the NZ business is treated as holding the personal information stored with the overseas provider, which means the NZ business remains responsible for complying with the privacy principles in respect of that information.
- Agencies will be required to take into account the vulnerability of children and young people when collecting personal information from them. In an amendment to Privacy Principle 4 (which sets out how personal information should be collected).
What you will need to do:
- Undertake training with your staff about your process to follow in the event of a serious privacy breach.
- Make sure that you and your staff are aware of how to respond to requests for personal information.
- Make sure that all personal information is stored securely and disposed securely when you have finished with it.
- If you are using an overseas based agency e.g. IT service provider for cloud computing, ask them how they are meeting NZ privacy laws. A change to the Act means that you must have reasonable grounds to believe the person overseas complies with the Privacy Act or an equivalent law safeguarding privacy.
- Appoint a Privacy Officer , this is a requirement under the Privacy Act.
- Review your Privacy Statement
- If required use the Privacy Commission on-line learning
Remember the same principles apply to your employee’s information.
Other recent articles
13 August 2026
21 years of HealthyPractice!
A lot has changed since the early days and HealthyPractice has transformed along the way to keep supporting practices in ways that are useful, practical and easy to work with. What has not changed is the heart of the service. It is still going strong. Most importantly, we would like to thank our Subscribers. Your support, feedback and trust over the past 21 years have helped shape HealthyPractice into what it is today, and we are so grateful to have been part of your journey while you have been part of ours.
16 July 2026
June on the road - Connecting with practices across New Zealand
Kia ora, We hope you are faring well, six months into 2026! At our end it’s been a busy month for the HealthyPractice team - here’s a quick snapshot of what we’ve been up to. It was great to connect face-to-face with practice owners, managers, clinicians and support teams at both the New Zealand Veterinary Association Te Pae Kīrehe Conference (NZVA) and the NZGPCME Primary Care Conference, both held in June. The MAS and HealthyPractice stand was a real hub of activity, helped along by a very popular coffee cart.
10 June 2026
Privacy updates and training
Due to recent changes, this month we wish to remind you of the update to the Privacy Act 2020 with a new principle called the Information Privacy Principle 3A (IPP3A). For practices’, the new principle means there are additional notification obligations when receiving personal information about a patient from a third party. Under IPP3A, if your practice receives patient information from another provider (such as a lab, hospital, specialist, pharmacy or ACC), you must take reasonable steps to let the patient know their information has been collected. This change applies to any information collected on or after 1st May 2026.
Join other practices already using HealthyPractice.
Register now