were exempt from this requirement, as well as most of the other IPPs.107 This amendment was sought by the Privacy Commissioner and has the effect of significantly strengthening the application of privacy rights and standards to the surveillance and information gathering activities of the intelligence and security agencies. In March 2016, Sir Michael Cullen and Dame Patsy Reddy presented the First Independent Review of Intelligence and Security to parliament (Cullen/Reddy Report).108 The review focused on the legislative framework governing the Government Communications Security Bureau (GCSB) and NZ Security and Intelligence Service (NZSIS) and their oversight regime. They concluded that there should be a single, integrated and comprehensive Act clearly setting out how and why the agencies are constituted; how their intelligence and security activities are authorised; and their oversight. 2.8 Legislative Advisory Committee Guidelines, the Chief Privacy Officer and the Government Chief Data Steward Chapter 7 of the Legislation Advisory Committee (LAC) Guidelines on Process and Content of Legislation (LAC Guidelines), directs Government officials as to their legal and ethical obligations regarding privacy and personal information when developing legislation: The Government should respect privacy interests and ensure that the collection of information about people is done in a transparent manner, where the type and amount of information collected and what is done with that information is clearly explained. Maintaining the community’s trust that government will respect privacy interests is key to the Government’s ability to collect the information it needs to provide many public services.109 The LAC Guidelines provide that if proposed legislation affects the privacy of individuals, the 107 Prior to the amendment, intelligence and security agencies were exempt from all IPPs, other than IPP 6 (regarding access to personal information which itself is a national security exemption under s 27), IPP 7 (regarding correction of personal information) and IPP 12 (which regulates the assignment and use of unique identifiers) 108 https://www.parliament.nz/resource/en-nz/51DBHOH_PAP68536_1/64eeb7436d6fd817fb382a2005988c74dabd21fe e. 109 http://www.ldac.org.nz/guidelines/lac-revised-guidelines/chapter-7/. Privacy Commissioner and the Government Chief Privacy Officer (GCPO)110 should be consulted. Ministers and their officials are required to advise Cabinet of aspects of Bills that depart from principles in the Guidelines. The Guidelines set out the following five-part set of questions that officials must apply to proposed legislation: • Is the legislation consistent with the requirements of the Privacy Act 1993 and its 12 Information Privacy Principles? • Have you complied with any relevant Code of Practice issued by the Privacy Commissioner? • Have you consulted the Privacy Commissioner, the Ministry of Justice and the GCPO? • Does the legislation require a complaints process? • Have you considered the consequences of non-compliance with the Privacy Act 1993? The Guidelines also provide that if any policy development involves personal information then a Privacy Impact Assessment (PIA) should be carried out to assess the extent of the impact and how it can be managed in the policy development process. The Office of the Privacy Commissioner has produced guidance on whether a PIA is needed; and on how to complete a PIA. According to the PIA guidance, organisations should check that the legal framework complies with the principles in the Privacy Act; identify privacy risks and how to mitigate them, and produce and then act on a PIA report.111 The LAC Guidelines can be seen, in this respect, as establishing a legislative due diligence procedure on privacy. The GCPO is also an integral component of the Government’s internal due diligence processes on privacy. Unlike the Privacy Commissioner, who as the Privacy Act ‘watchdog’ agency, is an Independent Crown Entity and therefore legally independent of the Government, the GCPO is a government official tasked with developing standards, issuing guidance and providing assurance to Government 110 The GCPO’s role is to provide expert guidance and internal advice on privacy issues to the Government: https://www.ict.govt.nz/governance-and-leadership/the-gcio-team/government-chief-privacy-officer/. 111 https://www.privacy.org.nz/assets/Files/Guidance/Privacy-Impact-Assessment-Part-2-FA.pdf 23

اختر الفقرة المستهدفة3