were exempt from this requirement, as well as
most of the other IPPs.107 This amendment was
sought by the Privacy Commissioner and has
the effect of significantly strengthening the
application of privacy rights and standards to the
surveillance and information gathering activities
of the intelligence and security agencies.
In March 2016, Sir Michael Cullen and Dame
Patsy Reddy presented the First Independent
Review of Intelligence and Security to parliament
(Cullen/Reddy Report).108 The review focused
on the legislative framework governing the
Government Communications Security Bureau
(GCSB) and NZ Security and Intelligence
Service (NZSIS) and their oversight regime.
They concluded that there should be a single,
integrated and comprehensive Act clearly setting
out how and why the agencies are constituted;
how their intelligence and security activities are
authorised; and their oversight.
2.8 Legislative Advisory Committee
Guidelines, the Chief Privacy Officer and the
Government Chief Data Steward
Chapter 7 of the Legislation Advisory Committee
(LAC) Guidelines on Process and Content of
Legislation (LAC Guidelines), directs Government
officials as to their legal and ethical obligations
regarding privacy and personal information when
developing legislation:
The Government should respect privacy interests
and ensure that the collection of information
about people is done in a transparent manner,
where the type and amount of information
collected and what is done with that information
is clearly explained. Maintaining the community’s
trust that government will respect privacy
interests is key to the Government’s ability to
collect the information it needs to provide many
public services.109
The LAC Guidelines provide that if proposed
legislation affects the privacy of individuals, the
107 Prior to the amendment, intelligence and security agencies were
exempt from all IPPs, other than IPP 6 (regarding access to personal
information which itself is a national security exemption under s 27),
IPP 7 (regarding correction of personal information) and IPP 12 (which
regulates the assignment and use of unique identifiers)
108 https://www.parliament.nz/resource/en-nz/51DBHOH_PAP68536_1/64eeb7436d6fd817fb382a2005988c74dabd21fe e.
109 http://www.ldac.org.nz/guidelines/lac-revised-guidelines/chapter-7/.
Privacy Commissioner and the Government Chief
Privacy Officer (GCPO)110 should be consulted.
Ministers and their officials are required to
advise Cabinet of aspects of Bills that depart
from principles in the Guidelines. The Guidelines
set out the following five-part set of questions
that officials must apply to proposed legislation:
• Is the legislation consistent with the
requirements of the Privacy Act 1993 and
its 12 Information Privacy Principles?
• Have you complied with any relevant
Code of Practice issued by the Privacy
Commissioner?
• Have
you
consulted
the
Privacy
Commissioner, the Ministry of Justice and
the GCPO?
• Does the legislation require a complaints
process?
• Have you considered the consequences of
non-compliance with the Privacy Act 1993?
The Guidelines also provide that if any policy
development involves personal information then
a Privacy Impact Assessment (PIA) should be
carried out to assess the extent of the impact and
how it can be managed in the policy development
process. The Office of the Privacy Commissioner
has produced guidance on whether a PIA is
needed; and on how to complete a PIA. According
to the PIA guidance, organisations should check
that the legal framework complies with the
principles in the Privacy Act; identify privacy
risks and how to mitigate them, and produce and
then act on a PIA report.111
The LAC Guidelines can be seen, in this respect,
as establishing a legislative due diligence
procedure on privacy. The GCPO is also an
integral component of the Government’s internal
due diligence processes on privacy. Unlike the
Privacy Commissioner, who as the Privacy Act
‘watchdog’ agency, is an Independent Crown
Entity and therefore legally independent of
the Government, the GCPO is a government
official tasked with developing standards, issuing
guidance and providing assurance to Government
110 The GCPO’s role is to provide expert guidance and internal advice
on privacy issues to the Government: https://www.ict.govt.nz/governance-and-leadership/the-gcio-team/government-chief-privacy-officer/.
111 https://www.privacy.org.nz/assets/Files/Guidance/Privacy-Impact-Assessment-Part-2-FA.pdf
23