Skip to Content
OPINION

Notes from the Asia-Pacific region: Outsourcing data doesn't outsource accountability

Compliance notices from New Zealand's Office of the Privacy Commissioner following two health data breaches highlight regulators' expectations for governance, risk assessments and supplier oversight.

Published

Contributors:

Daimhin Warner

CIPP/E

Country Leader, New Zealand, IAPP; Partner

Simply Privacy

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

Back in February and March this year, I wrote about two separate privacy breaches that hit New Zealand's heath tech sector — Manage My Health and MediMap. These breaches provided a real wake up call for government about the sufficiency of New Zealand's privacy regime, and the Office of the Privacy Commissioner took this opportunity to reinforce calls for change.

In the latest development, the OPC issued compliance notices to MMH and Health New Zealand. These notices provide some important lessons for privacy professionals in the health sector and beyond.

The notices follow the commissioner's inquiry into the MMH breach, which found both organizations had breached Rule 5 of the Health Information Privacy Code, but in different ways. MMH failed to have reasonable security safeguards in place, while Health NZ failed to do everything reasonably within its power to protect the information it provided to MMH as a service provider.

For privacy professionals, the Health NZ notice is particularly instructive. The commissioner identified deficiencies in Health NZ's own due diligence, privacy risk assessment, governance, contracting and ongoing assurance. The OPC found Health NZ also relied too heavily on the provider's own assessments of its privacy and security. The required actions provide us with a clear picture of the commissioner's expectations.

First, privacy needs a seat at the table early enough to make a difference. The commissioner criticized the lack of direct privacy and security representation in project governance and the absence of evidence that specialists provided advice early enough to inform the project's design. Privacy review toward the end of procurement or implementation will be too late.

Second, privacy impact assessments need to do real work. The compliance notice requires Health NZ to conduct privacy assessments during procurement and a PIA at the system and process design stage, including detailed assessment of information flows. Importantly, the PIA must then be reviewed before implementation, when the project expands and annually once implemented. This reflects the general idea that a PIA should be a living risk management process rather than a single, point-in-time assessment.

Third, supplier assurance cannot rely on questionnaires and contractual promises alone. The commissioner expects independent assessment of providers, evidence against relevant security standards and ongoing assurance that privacy and security safeguards are actually operating as intended. Contracts should support this through clear privacy and security requirements, breach notification obligations, regular assurance reporting, audit rights and escalation processes. This deeper level of due diligence will present practical challenges for many organizations, particularly in relation to the use of global platforms.

The MMH notice was targeted specifically at platform security issues that would be relevant for any tech provider. But more broadly it highlights that privacy and cybersecurity cannot operate in silos. The commissioner identified shortcomings across multifactor authentication, access management, web security, vulnerability management, system development, logging and monitoring and data loss prevention. 

Failures in these technical areas will impact overall privacy compliance, and so privacy professionals must ensure security experts are sufficiently placed across the technical and organizational security settings for any new project — whether it's an internal change or a new supplier.

As I have mentioned previously, the breaches, the inquiry report and now these compliance notices serve as a sobering reminder that outsourcing the handling of personal information does not outsource accountability. Privacy professionals do not need to become security experts, but we do need to ask the right questions, involve the right specialists and make sure there is evidence behind the assurances we receive.

Ultimately, the compliance notices provide a useful and practical indication of what the OPC considers good privacy risk management looks like in a significant digital project. Organizations would be well advised to compare those expectations against their own project governance, PIA and due diligence processes before an incident gives the regulator reason to do it for them.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Daimhin Warner

CIPP/E

Country Leader, New Zealand, IAPP; Partner

Simply Privacy