Part 6 Notifiable privacy breaches and compliance notices

Subpart 1—Notifiable privacy breaches

117 Interpretation

(1)

In this subpart,—

affected individual, in relation to personal information that is the subject of a privacy breach,—

(a)

means the individual to whom the information relates; and

(b)

includes an individual inside or outside New Zealand; and

(c)

despite the definition of individual in section 6(1), includes a deceased person—

(i)

if a sector-specific code of practice issued under section 35 specifies that the code applies to information about deceased persons; and

(ii)

to the extent that the code of practice applies 1 or more IPPs to that information

notifiable privacy breach means a privacy breach that has caused any of the types of harm listed in section 75(2)(b) to an affected individual or individuals or there is a risk it will do so

notifiable privacy breach

(a)

means a privacy breach that it is reasonable to believe has caused serious harm to an affected individual or individuals or is likely to do so (see section 117A for factors that must be considered by an agency when assessing whether a privacy breach is likely to cause serious harm); but

(b)

does not include a privacy breach if the personal information that is the subject of the breach is held by an agency who is an individual and the information is held solely for the purposes of, or in connection with, the individual’s personal or domestic affairs

privacy breach, in relation to personal information held by an agency,—

(a)

means—

(i)

unauthorised or accidental access to, or disclosure, alteration, loss, or destruction of, the personal information; or

(ii)

an action that prevents the agency from accessing the information on either a temporary or permanent basis; and

(b)

includes any of the things listed in paragraph (a)(i) or an action under paragraph (a)(ii), whether or not it—

(i)

was caused by a person inside or outside the agency; or

(ii)

is attributable in whole or in part to any action by the agency; or

(iii)

is ongoing.

(2)

For the purposes of this subpart, the meanings of access, disclosure, and loss are not limited by the use of those words or the meanings ascribed to them elsewhere in this Act.

Compare: 1956 No 65 s 22B