latter is in regularly updated Codes of Practice152
The First Independent Review of Intelligence and
Security in New Zealand similarly placed greater
transparency as a central objective of reform to
the intelligence and security sector, providing
that one of its key purposes was:
to provide transparency and accountability
through its recommendations for a “single,
integrated and comprehensive Act of Parliament
that lays out in plain English how the agencies
are constituted what their purposes are; how
all their intelligence and security activities are
authorised; and how they are overseen so as to
protect those freedoms and liberties that are
part of what we are as a nation.153
It is notable that the Privacy Act 1993 requires
procedural transparency and consultation in the
development of Approved Information Sharing
Agreements (AISAs), as well as publication and
public access following the passage of an AISA
into law.154
Transparency requirements also extend to
private sector actors. For example, the Special
Rapporteur on the right to freedom of expression
has recommended that telecommunications
companies should be transparent in how they
communicate the impact of their activities on
human rights externally, including the number
of government requests they have received for
things such as customer data, and the availability
of remedies for persons whose rights have been
breached as a result of their activities.155
4.3 Purpose Specification
The Special Rapporteur on the right to privacy has
affirmed the principle of “purpose specification”
as fundamental to ensuring that data collection
and use adheres with the right to privacy. He
notes:
Put simply, personal data should be collected,
used, stored and re-used for a specified legitimate
152 David Andersen Q.C. Independent Reviewer of Terrorism Legislation,
A Question of Trust Report of the Investigatory Powers Review (June
2015) p 253.
153 Cullen/Reddy Report, p 1.
154 Privacy Act 1993, ss 96O, 96S.
155 Report of Special Rapporteur for freedom of expression (11 May
2016) para 13
purpose or for a compatible purpose. Once the
time required for the data to be stored by that
specified purpose runs out then the data should
be deleted permanently. Re-using personal data
is not part of our privacy or data protection
DNA.156
Against this context, it is notable that the OHCHR
has expressed concern that “personal data ends
up in the same ‘bucket’ of data which can be
used and re-used for all kinds of known and
unknown purposes.”157 In addition, the Special
Rapporteur on countering terrorism has noted
that many States lack “purpose specification”
provisions that restrict information gathered for
one purpose from being used for other unrelated
governmental objectives, leading to “purpose
creep”.158 The Special Rapporteur observed:
This means that data for national security
purposes may be shared between intelligence
agencies, law enforcement agencies and other
State entities, including tax authorities, local
councils and licensing bodies. National security
and law enforcement agencies are typically
excluded from provisions of data protection
legislation that limit the sharing of personal
data. As a result, it may be difficult for individuals
to foresee when and by which State agency they
might be subjected to surveillance. This “purpose
creep” risks violating article 17 of the Covenant,
not only because relevant laws lack foreseeability,
but also because surveillance measures that
may be necessary and proportionate for one
legitimate aim may not be so for the purposes
of another.159
In New Zealand, the Privacy Act places limits
on the use of personal information that was
obtained in connection with one purpose from
being used for another purpose, unless specific
criteria are met.160 One of these criteria relates
to the activities of New Zealand’s intelligence
and security agencies and was introduced by the
enactment of the Intelligence and Security Act
2017. It provides that:
An intelligence and security agency that holds
personal information that was obtained in
156 Report of the Special Rapporteur on privacy, Joseph A. Cannataci
(24 November 2016).
157 OHCHR Report, The right to privacy in the digital age, para. 20
158 Report of Special Rapporteur on countering terrorism, para. 56
159 Ibid
160 Privacy Act 1993, Principle 10
31