Mandatory scheme
Privacy Act 2020 — notifiable privacy breach
Privacy Act 2020 — notifiable privacy breach — mandatory scheme, New Zealand. It binds any agency within the Act's scope that experiences a privacy breach causing, or likely to cause, serious harm.
- Jurisdiction
- New Zealand
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to New Zealand. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Privacy Act 2020 (No 31)
Who it binds
Any agency within the Act's scope that experiences a privacy breach causing, or likely to cause, serious harm.
What it requires
Agencies covered by the Privacy Act 2020 must comply with the Information Privacy Principles. Where a breach has caused, or is likely to cause, serious harm, the agency must notify the Privacy Commissioner and the affected individuals as soon as practicable after becoming aware of it, using the Commissioner's own NotifyUs tool. Failing to notify is an offence; penalty amounts are not published here.
Route to the authority
Last verified:
Related records and requirements
- Privacy Act 1988 — Australian Privacy Principles (Australia) — Australia's Notifiable Data Breaches scheme requires notifying both affected individuals and the OAIC of a data breach likely to cause serious harm.
- Act on the Protection of Personal Information (APPI) compliance (Japan) — APPI Art. 26 requires reporting a data breach to the Personal Information Protection Commission (PPC) and notifying the affected individual, subject to narrow statutory exceptions.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.