latter is in regularly updated Codes of Practice152 The First Independent Review of Intelligence and Security in New Zealand similarly placed greater transparency as a central objective of reform to the intelligence and security sector, providing that one of its key purposes was: to provide transparency and accountability through its recommendations for a “single, integrated and comprehensive Act of Parliament that lays out in plain English how the agencies are constituted what their purposes are; how all their intelligence and security activities are authorised; and how they are overseen so as to protect those freedoms and liberties that are part of what we are as a nation.153 It is notable that the Privacy Act 1993 requires procedural transparency and consultation in the development of Approved Information Sharing Agreements (AISAs), as well as publication and public access following the passage of an AISA into law.154 Transparency requirements also extend to private sector actors. For example, the Special Rapporteur on the right to freedom of expression has recommended that telecommunications companies should be transparent in how they communicate the impact of their activities on human rights externally, including the number of government requests they have received for things such as customer data, and the availability of remedies for persons whose rights have been breached as a result of their activities.155 4.3 Purpose Specification The Special Rapporteur on the right to privacy has affirmed the principle of “purpose specification” as fundamental to ensuring that data collection and use adheres with the right to privacy. He notes: Put simply, personal data should be collected, used, stored and re-used for a specified legitimate 152 David Andersen Q.C. Independent Reviewer of Terrorism Legislation, A Question of Trust Report of the Investigatory Powers Review (June 2015) p 253. 153 Cullen/Reddy Report, p 1. 154 Privacy Act 1993, ss 96O, 96S. 155 Report of Special Rapporteur for freedom of expression (11 May 2016) para 13 purpose or for a compatible purpose. Once the time required for the data to be stored by that specified purpose runs out then the data should be deleted permanently. Re-using personal data is not part of our privacy or data protection DNA.156 Against this context, it is notable that the OHCHR has expressed concern that “personal data ends up in the same ‘bucket’ of data which can be used and re-used for all kinds of known and unknown purposes.”157 In addition, the Special Rapporteur on countering terrorism has noted that many States lack “purpose specification” provisions that restrict information gathered for one purpose from being used for other unrelated governmental objectives, leading to “purpose creep”.158 The Special Rapporteur observed: This means that data for national security purposes may be shared between intelligence agencies, law enforcement agencies and other State entities, including tax authorities, local councils and licensing bodies. National security and law enforcement agencies are typically excluded from provisions of data protection legislation that limit the sharing of personal data. As a result, it may be difficult for individuals to foresee when and by which State agency they might be subjected to surveillance. This “purpose creep” risks violating article 17 of the Covenant, not only because relevant laws lack foreseeability, but also because surveillance measures that may be necessary and proportionate for one legitimate aim may not be so for the purposes of another.159 In New Zealand, the Privacy Act places limits on the use of personal information that was obtained in connection with one purpose from being used for another purpose, unless specific criteria are met.160 One of these criteria relates to the activities of New Zealand’s intelligence and security agencies and was introduced by the enactment of the Intelligence and Security Act 2017. It provides that: An intelligence and security agency that holds personal information that was obtained in 156 Report of the Special Rapporteur on privacy, Joseph A. Cannataci (24 November 2016). 157 OHCHR Report, The right to privacy in the digital age, para. 20 158 Report of Special Rapporteur on countering terrorism, para. 56 159 Ibid 160 Privacy Act 1993, Principle 10 31

Выберите целевой абзац3