for agencies to report privacy breaches to the Privacy Commissioner and affected individuals if the breach has caused or risks causing harm.72 This is consistent with mandatory reporting regimes that are increasingly required in privacy legislation overseas, including in Australia, Canada and the European Union. Notification must occur as soon as practicable after an agency becomes aware of a breach, and if it is not reasonably practicable to notify affected individuals, the agency must instead give public notice of the breach. It is an offence to fail to notify the Commissioner, with a maximum penalty of $10,00073 and the Commissioner has the power to publish the identity of an agency that has notified him or her of the privacy breach, if the agency consents or if the Commissioner is satisfied that it is in the public interest to do so.74 • Compliance notices: The Commissioner’s functions are expanded under the new Bill. It allows the Commissioner to issue compliance notices that require an agency to do something, or stop doing something, in order to comply with privacy law.75 The Human Rights Review Tribunal will be able to enforce compliance notices and hear appeals.76 • Information-gathering powers: The Bill expands the Commissioner’s informationgathering powers when investigating complaints about an interference of privacy. The Commissioner can require any person to provide information or documents and can specify a time limit for providing information.77 information available in a particular way.78 2.4 Approved Information Sharing Agreements In 2013, the Privacy Act was amended to introduce Approved Information Sharing Agreements (AISAs) which are the legal mechanism that authorises the sharing of information about an individual by one government agency to another, usually for a purpose unrelated to the reason for which the information was originally collected or provided. Currently, there are seven AISAs in place.79 The Privacy Act provides for procedural safeguards in the formation of AISAs as well as continued oversight, including: • Agencies must consult the Privacy Commissioner, any person or organisation representing the interests of the people whose information will be affected and any other person that the agencies consider should be consulted.80 • The Minister must be satisfied of a number of factors including that the AISA does not unreasonably impinge on privacy and it contains adequate safeguards.81 • The Privacy Commissioner also has the power to prepare a report on any privacy matters relating to the AISA.82 • Access requests: The Commissioner is also given a new power to direct an agency to confirm whether it holds specified information about an individual, permit access to that information or to make the 72 Privacy Bill, Clause 119. Harm is defined as an action that (i) has caused, or may cause, loss, detriment, damage, or injury to the individual; or (ii) has adversely affected, or may adversely affect, the rights, benefits, privileges, obligations, or interests of the individual; or (iii) has resulted in, or may result in, significant humiliation, significant loss of dignity, or significant injury to the feelings of the individual. 73 Privacy Bill, Clause 122. 74 Ibid. Clause 123. 75 Ibid. Clause 124. 76 Ibid. Clause 130. 77 Ibid. Clause 92. 78 Ibid. Clause 96. 79 For example: Inland Revenue Department (IRD) and the Department of Internal Affairs to share information from adult passport applications with IRD for the purpose of contacting overseas-based student loan borrowers and child support liable parents who are in arrears; IRD and the New Zealand Police regarding disclosure of information for the purpose of prevention, detection, investigation or providing evidence of serious crime. 80 Privacy Act 1993, s 96O. 81 Ibid. s 96N. 82 Privacy Act 1993, s 96P. 19

Select target paragraph3