Data Governance & Privacy
Knowing what sensitive data you hold, where it goes, and proving the controls around it hold up.
Almost every organisation overestimates how well it knows where its sensitive data sits. The system of record is well understood. The copies are not: the extract someone built for a report three years ago, the production dump restored into a test environment to reproduce a bug, the spreadsheet emailed to a supplier, the backup in a region nobody chose deliberately. Data protection applied only to the system of record protects a fraction of the actual exposure.
So the work starts with discovery and classification attached to real data flows rather than to a policy document. Once you know what you hold and where it moves, a privacy impact assessment against the Privacy Act 2020 becomes a concrete exercise instead of a paperwork one, and control design can be proportionate: the strongest controls on the data that would actually hurt, rather than a uniform layer that irritates everyone and protects nothing in particular.
For health information the bar is higher and more specific, which is where HISO applies, and for payment data PCI-DSS brings its own scoping discipline. In every case the aim is privacy engineered into the systems: collect less, keep it for a defined period, restrict access by default, and be able to evidence all three to a regulator or an assessor without a scramble.
You might need this if
- Nobody can say with confidence where personal information lives across the estate
- Production data has been copied into test or development environments
- A retention policy exists and nothing has ever actually been deleted
- A privacy request or a breach notification would take weeks to answer accurately
- You handle health or payment data and the scoping has never been examined
Who it's for
Organisations handling health, financial, or personal data who need privacy obligations met in the build, not bolted on after an audit finding.
How the engagement runs
- 01
Discovery and classification
Find the data, including the copies, and classify it against how much harm its exposure would cause rather than against how sensitive it feels.
- 02
Privacy impact assessment
Assess the collection, use, disclosure, and retention against the Privacy Act 2020, and where relevant HISO, identifying where practice has drifted from what was originally intended.
- 03
Control design
Proportionate controls: minimisation, retention with actual deletion, access restricted by default, and de-identification where the use case does not require the real thing.
- 04
Evidence and operationalisation
Make it routine and provable: request handling that works under time pressure, breach assessment criteria agreed in advance, and evidence a regulator would accept.
What's delivered
- Data discovery and classification, so the obligations attach to real data flows
- Privacy impact assessment aligned to the NZ Privacy Act 2020
- Control design for sensitive and regulated data sets, including health information
- Privacy engineered into systems: minimisation, retention, and access by design
- Evidence a regulator or an assessor will accept
Proof point
Led HISO audit and implementation to safeguard sensitive health information for clients in the health sector.
Common questions
- Isn't this a job for our lawyers?
- Partly, and I work alongside them rather than in place of them. Legal advice tells you what the obligation is. This work establishes what your systems actually do, which is usually the harder question and the one that determines whether the legal position holds.
- Do we need a dedicated privacy officer?
- Under the Privacy Act 2020 every agency must have a privacy officer, but for most smaller organisations that is a role someone holds alongside another job rather than a dedicated hire. What matters is that the person has the authority and the information to actually do it.
- We're small. Does the Privacy Act really apply to us?
- Yes. There is no small-business exemption in New Zealand, and the notifiable breach obligations apply regardless of size. The proportionate response differs a great deal by size; the obligation itself does not.
- What makes health information different?
- The Health Information Privacy Code sets more specific rules than the general principles, and HISO standards apply to how health information is handled and exchanged. Scope and expectations are both tighter, and the consequences of getting it wrong are more personal to the people involved.
Other services
- Risk Management & Quantitative Risk Analysis
- Digital, Cyber & Technology Risk
- Third-party & Supply Chain Risk
- AI Security, Risk & Governance
- Applied AI for Cyber
- Security Operations
- Governance, Risk & Compliance
- Secure Architecture & Zero Trust
- Secure Web Applications for SMEs
- Virtual CISO & Security Leadership
- Incident Response & Readiness
Let's talk about your security programme
Considering a vCISO, a security strategy and architecture, a SOC uplift, an AI assurance review, or a secure web build? Tell me where you are and where you need to get to.