of individuals residing in the EU, regardless
of the company’s location.
• Data Protection Officers: In some
circumstances data controllers or processors
must designate a Data Protection Officer
as part of their accountability programme.
This covers processing carried out by a
public authority, where core activities are
involved, monitoring data subjects on a
large scale; and where core activities consist
of processing on a large scale of special
categories of data.
• Consent: Restrictive approach to consent
requiring that it must be “freely given,
specific, informed and unambiguous.”
• Penalties: A tiered approach to penalties
is established with fines for some
infringements of up to the higher of 4%
of annual worldwide turnover and EUR20
million (e.g. breach of requirements relating
to international transfers or the basic
principles for processing, such as conditions
for consent). Civil liability is also possible
with a right to compensation.
• Data breach notification: Data controllers
must notify most data breaches to the Data
Protection Authorities within 72 hours of
awareness.
• Data subject rights: Rights of individuals
are bolstered including rights to: require
information about data being processed
about themselves; be forgotten entitling
individuals to have personal data about
them erased; correction of data which is
wrong; a right to restrict certain processing;
object to their personal data being processed
for direct marketing purposes; and to an
explanation about information based on
algorithms.
The GDPR may impact on New Zealand in two
ways. First, any public agency or business in New
Zealand that handles personal data of individuals
residing in the EU will need to ensure that their
internal data processing procedures comply.
Second, it is possible that the EU may find that
New Zealand’s data protection laws are no
longer ‘adequate’ for the transfer of European-
originated data for processing.42 The Office of
the Privacy Commissioner has indicated that they
are in regular communication with the European
Commission on this issue.43
Asia-Pacific Region
APEC Privacy Framework
The APEC Privacy Framework was developed in
light of the 1980 OECD Guidelines and applies to
all 27-member countries.44 The Framework sets
out principles and implementation guidance for
the public and private sectors who control the
collection, holding, processing, use, transfer or
disclosure of personal information. Key principles
include:
• Preventing harm: Preventing misuse of
personal information and consequent harm
to individuals.
• Notice: Individuals should know that
information is collected about them and the
purpose for which it is used.
• Collection limitation: Limited collection of
information to the purposes for which it is
collected.
• Use limitation: Limits the use of personal
information to fulfilling the purposes of the
collection.
Also included in the framework are the
principles of choice and consent, data integrity,
security safeguards, access and correction and
accountability. Progress on the implementation
of the Framework includes the application of
Information Privacy Individual Action Plans by 14
economies. New Zealand last updated its Data
Privacy Individual Action Plan, in 2011.45
Comprehensive and Progressive Agreement for the
Trans-Pacific Partnership Agreement (TPP)
42 Privacy Commissioner, Office of the Privacy Commissioner Briefing
for the Incoming Minister of Justice: Hon Andrew Little, October 2017,
para 4.14 https://privacy.org.nz/assets/Uploads/Briefing-for-Incoming-Minister-October-2017.pdf Ibid para 4.14.
43 Ibid
44 https://www.apec.org/Publications/2017/08/APEC-Privacy-Framework-(2015)
45 https://www.apec.org/Groups/Committee-on-Trade-and-Investment/
Electronic-Commerce-Steering-Group/Data-Privacy-Individual-Action-Plan.aspx
13