for agencies to report privacy breaches to
the Privacy Commissioner and affected
individuals if the breach has caused or
risks causing harm.72 This is consistent
with mandatory reporting regimes that are
increasingly required in privacy legislation
overseas, including in Australia, Canada
and the European Union. Notification must
occur as soon as practicable after an agency
becomes aware of a breach, and if it is not
reasonably practicable to notify affected
individuals, the agency must instead give
public notice of the breach. It is an offence
to fail to notify the Commissioner, with a
maximum penalty of $10,00073 and the
Commissioner has the power to publish the
identity of an agency that has notified him
or her of the privacy breach, if the agency
consents or if the Commissioner is satisfied
that it is in the public interest to do so.74
• Compliance notices: The Commissioner’s
functions are expanded under the new
Bill. It allows the Commissioner to issue
compliance notices that require an agency
to do something, or stop doing something,
in order to comply with privacy law.75 The
Human Rights Review Tribunal will be able
to enforce compliance notices and hear
appeals.76
• Information-gathering powers: The Bill
expands the Commissioner’s informationgathering powers when investigating
complaints about an interference of privacy.
The Commissioner can require any person
to provide information or documents
and can specify a time limit for providing
information.77
information available in a particular way.78
2.4 Approved Information Sharing
Agreements
In 2013, the Privacy Act was amended to introduce
Approved Information Sharing Agreements
(AISAs) which are the legal mechanism that
authorises the sharing of information about an
individual by one government agency to another,
usually for a purpose unrelated to the reason for
which the information was originally collected
or provided. Currently, there are seven AISAs in
place.79 The Privacy Act provides for procedural
safeguards in the formation of AISAs as well as
continued oversight, including:
• Agencies must consult the Privacy
Commissioner, any person or organisation
representing the interests of the people
whose information will be affected and any
other person that the agencies consider
should be consulted.80
• The Minister must be satisfied of a number
of factors including that the AISA does not
unreasonably impinge on privacy and it
contains adequate safeguards.81
• The Privacy Commissioner also has the
power to prepare a report on any privacy
matters relating to the AISA.82
• Access requests: The Commissioner is also
given a new power to direct an agency
to confirm whether it holds specified
information about an individual, permit
access to that information or to make the
72 Privacy Bill, Clause 119. Harm is defined as an action that (i) has
caused, or may cause, loss, detriment, damage, or injury to the individual; or (ii) has adversely affected, or may adversely affect, the rights,
benefits, privileges, obligations, or interests of the individual; or (iii) has
resulted in, or may result in, significant humiliation, significant loss of
dignity, or significant injury to the feelings of the individual.
73 Privacy Bill, Clause 122.
74 Ibid. Clause 123.
75 Ibid. Clause 124.
76 Ibid. Clause 130.
77 Ibid. Clause 92.
78 Ibid. Clause 96.
79 For example: Inland Revenue Department (IRD) and the Department
of Internal Affairs to share information from adult passport applications
with IRD for the purpose of contacting overseas-based student loan
borrowers and child support liable parents who are in arrears; IRD and
the New Zealand Police regarding disclosure of information for the
purpose of prevention, detection, investigation or providing evidence of
serious crime.
80 Privacy Act 1993, s 96O.
81 Ibid. s 96N.
82 Privacy Act 1993, s 96P.
19