New Zealand’s Privacy Act 2020 requires reasonable security safeguards (IPP 5) and makes breaches likely to cause serious harm notifiable to the Office of the Privacy Commissioner and affected people ‘as soon as practicable’, which OPC guidance sets at within 72 hours. No law mandates ISO 27001. Certification is the practical way to evidence the safeguards IPP 5 assumes.
New Zealand consolidated its rules in the Privacy Act 2020, which replaced the Privacy Act 1993 and is enforced by the Office of the Privacy Commissioner (OPC). Two parts of it carry the security requirements.
IPP 5 requires agencies to protect personal information with reasonable security safeguards. The provision is technology-neutral: no standard, no certificate, no control list. What counts as reasonable is established by the organisation and, following a complaint or a breach, has to be demonstrated by it.
The notifiable-breach regime (ss 112–117) turns on one test: serious harm. A privacy breach that causes, or is likely to cause, serious harm must be notified to the Office of the Privacy Commissioner and to the affected people, as soon as practicable. OPC guidance quantifies that as within 72 hours, even where the investigation is incomplete. Failing to notify the Commissioner is an offence.
| Privacy Act element | What it requires |
|---|---|
| IPP 5 | Reasonable security safeguards for personal information |
| ss 112–117 | Notify the OPC and affected people of serious-harm breaches as soon as practicable — 72 hours per OPC guidance |
| IPP 12 | Safeguards when disclosing personal information overseas (no residency rule) |
Beyond the Privacy Act, New Zealand has no dedicated general cybersecurity statute for organisations. The sector exception is TICSA — the Telecommunications (Interception Capability and Security) Act 2013 — which places network-security duties on public telecommunications network operators, including notification to the National Cyber Security Centre (NCSC). For organisations outside that sector, the Privacy Act is the principal legal requirement, and customer security questionnaires apply the commercial pressure.
ISO 27001 provides a method rather than a fixed checklist: assess risk across the 93 Annex A controls, record what applies in the Statement of Applicability, and evidence that the applicable controls operate. That documented, independently audited position is what a reasonable-safeguards case consists of when the OPC, a customer, or an insurer asks for one.
| New Zealand obligation | Where the ISMS answers it |
|---|---|
| IPP 5 reasonable safeguards | Risk assessment plus Statement of Applicability, with audit evidence the controls run |
| The serious-harm test | Logs and monitoring that can establish what was accessed and who is affected — the inputs the test requires |
| Notify as soon as practicable (72-hour guidance) | Incident management with detection in front of it, so the clock starts at a monitored alert |
| IPP 12 overseas disclosure | Supplier and transfer controls, with records of where personal information flows and what protects it there |
Accreditation is trans-Tasman. JAS-ANZ — the Joint Accreditation System of Australia and New Zealand — accredits certification bodies on both sides of the Tasman, so a certificate over a New Zealand scope carries the same accreditation weight in Sydney as in Wellington. NZ companies selling into Australia, and Australian groups with NZ operations, can run one ISMS across both countries and certify once.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a JAS-ANZ-accredited certification body rather than by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system, followed by annual surveillance audits and three-yearly recertification.
Secure60 has delivery infrastructure in New Zealand via Rackcorp, with a datacentre in-country, so log collection and monitoring can run onshore on our security platform where customers require it. Secure60 provides infrastructure rather than a local office, and the audit remains with the accredited body.
The OPC’s guidance sets the expectation at 72 hours even where the investigation is incomplete, so an incomplete picture is anticipated by the guidance rather than accepted as grounds to delay. Notification proceeds on what is known, and the investigation continues. Failing to notify the Commissioner is an offence, which makes under-notification the more expensive error.
Both points require the serious-harm test to be run early, on evidence of what was accessed and who is affected. Evidence available at hour one comes from monitoring that was running at hour zero.
Secure60 delivers the certification and operates the security behind it. For New Zealand that means an ISMS built against the Privacy Act 2020, with the logging, monitoring and incident management that make a 72-hour serious-harm assessment possible, running on Rackcorp infrastructure in-country where onshore delivery is required. The certification audit belongs to a JAS-ANZ-accredited certification body; we make sure what it samples is operating. Secure60 holds ISO 27001:2022 certification and faces the same auditors.
Is ISO 27001 legally mandatory in New Zealand?
No. The Privacy Act 2020’s IPP 5 requires reasonable security safeguards without naming a standard. A certified ISMS is the practical way to establish what your safeguards are, why they are reasonable, and that an independent auditor has seen them operating.
What does the Privacy Act require after a breach?
Where a privacy breach causes, or is likely to cause, serious harm, you must notify the Office of the Privacy Commissioner and the affected people as soon as practicable. OPC guidance sets that at within 72 hours even where the investigation is incomplete. Failing to notify the Commissioner is an offence.
Does New Zealand have a general cybersecurity law?
There is no dedicated general statute for organisations. Sector-specific duties exist: the Telecommunications (Interception Capability and Security) Act 2013 (TICSA) imposes network-security duties on public telecommunications network operators, including notifying the NCSC. For other organisations, the Privacy Act’s IPP 5 is the main legal hook.
Who performs the ISO 27001 certification audit in New Zealand?
A certification body accredited by JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified.
Does data have to stay in New Zealand?
The Privacy Act contains no residency rule. IPP 12 sets safeguards for disclosing personal information overseas, which is a controls-and-contracts question the ISMS records. Where data should sit is then driven by customer and sector expectations.
Can Secure60 deliver in New Zealand?
Yes. We have delivery infrastructure in New Zealand via Rackcorp, with a datacentre in-country, so log collection and monitoring can run onshore. We have no local offices, and we do not perform the certification audit.