Skip to content

Evidence request lists

Privacy Act 2020

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach Response

NZPRV-7
Notifiable Privacy Breach Scheme

Per Privacy Act 2020 Part 6 (Notifiable Privacy Breaches): breach notification. Requirements include (a) implement Notifiable Data Breaches scheme - if a notifiable privacy breach occurs (compromise of security or integrity of personal information likely to cause serious harm) notify Office of Privacy Commissioner + affected individuals as soon as practicable + (b) conduct breach assessment including likelihood + harm + sensitivity + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + assessment process + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting OPC reporting.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-7
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Collection

NZPRV-1
IPP 1-4 Purpose, Source, Collection from Subject, Manner of Collection

Per Information Privacy Principles (IPPs) 1-4 of Privacy Act 2020: collection principles. Requirements include (a) IPP 1 - Personal Information must be collected for a lawful purpose connected to the function or activity of the agency + must be necessary for that purpose + (b) IPP 2 - Source of Personal Information should be the individual concerned unless an exception applies + (c) IPP 3 - Collection of Information from Subject - take reasonable steps to ensure individual is aware of the fact + purpose + intended recipients + name + address of agency + consequences of not providing + right to access + correct + (d) IPP 4 - Manner of Collection must not be unlawful + unfair + unreasonably intrusive + (e) document collection sources + purposes + (f) integrate with privacy policy.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-1
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Disclosure and Cross-Border

NZPRV-5
IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)

Per IPPs 11-12 of Privacy Act 2020 + Schedule 8: disclosure + cross-border. Requirements include (a) IPP 11 - Limits on Disclosure of Personal Information - personal information should not be disclosed unless disclosure is one of the purposes for which it was collected + an exception applies + (b) IPP 12 - Disclosure of Personal Information Outside New Zealand - personal information may not be disclosed to a recipient outside NZ unless the recipient is subject to privacy laws comparable to Privacy Act 2020 + appropriate safeguards + individual consents + (c) maintain inventory of cross-border data flows + recipients + safeguards + (d) implement contractual + technical safeguards + (e) cooperate with Office of Privacy Commissioner (OPC) on transfer matters.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-5
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Governance and Enforcement

NZPRV-8
Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Per Privacy Act 2020 + OPC: governance + enforcement. Requirements include (a) appoint Privacy Officer with defined responsibilities including handling complaints + facilitating compliance + cooperating with OPC + (b) cooperate with OPC including responding to inquiries + facilitating compliance audits + (c) handle Compliance Notices and Information Privacy Principle (IPP) compliance notices issued by Privacy Commissioner + (d) operate Complaints Handling mechanism enabling complaints to agency + Office of Privacy Commissioner + (e) deliver Privacy Training and Awareness programmes including role-based content + IPPs + breach response + (f) maintain Enforcement and Penalties awareness including compliance directions + civil penalties + criminal offences + (g) integrate with broader compliance.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-8
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

High-Risk Processing

NZPRV-6
IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Per IPP 13 of Privacy Act 2020 + OPC guidance: unique identifiers + PIA. Requirements include (a) IPP 13 - Unique Identifiers - agency must not assign a unique identifier to an individual unless reasonably necessary + must not require the individual to disclose another agency's unique identifier unless reasonably necessary + (b) conduct Privacy Impact Assessments (PIA) per OPC guidance for processing with significant privacy implications + (c) implement Privacy by Design across systems + processes + procurement + (d) implement Agents and Service Providers controls including contractual safeguards + (e) maintain documented PIAs + safeguards + (f) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-6
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Individual Rights

NZPRV-3
IPP 6-8 Access, Correction, Accuracy

Per IPPs 6-8 of Privacy Act 2020: access + correction + accuracy. Requirements include (a) IPP 6 - Access to Personal Information - upon request individual is entitled to access personal information held about them + (b) IPP 7 - Correction of Personal Information - upon request agency must consider whether to correct + attach a statement of correction sought but not made + (c) IPP 8 - Accuracy of Personal Information - take reasonable steps to ensure personal information is accurate + up-to-date + complete + relevant + not misleading before use or disclosure + (d) maintain mechanism for receiving + verifying + responding within statutory timelines + (e) handle refusals consistent with the Act + (f) maintain records of requests + responses.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-3
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Retention and Use

NZPRV-4
IPP 9-10 Retention, Limits on Use

Per IPPs 9-10 of Privacy Act 2020 + agency-specific provisions: retention + use. Requirements include (a) IPP 9 - Retention of Personal Information - personal information should not be kept longer than is required for the purposes for which the information may lawfully be used + (b) IPP 10 - Limits on Use of Personal Information - personal information obtained for one purpose may only be used for that purpose unless an exception applies + (c) implement Retention and Disposal aligned to purpose + legal obligations + (d) implement use limits in systems + processes + including secondary use approvals + (e) maintain records of use + retention decisions + (f) integrate with broader records management.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-4
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial

Security

NZPRV-2
IPP 5 Storage and Security of Personal Information

Per IPP 5 of Privacy Act 2020: storage and security. Requirements include (a) IPP 5 - Storage and Security of Personal Information - agency holding personal information must ensure it is protected by reasonable security safeguards against loss + unauthorised access + use + modification + disclosure + (b) if agency provides personal information to another person for storing + processing - ensure preventive measures + (c) implement encryption + access control + activity logging where appropriate + (d) conduct regular security testing + assessment + (e) integrate with broader information security baseline + (f) maintain documented security measures aligned to OPC guidance.

Artefacts an auditor will ask for
  • NZ Privacy Act 2020 evidence for NZPRV-2
Where this commonly fails
  • Privacy Officer + breach assessment + PIA partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Privacy Act 2020 framework page.