Notifiable privacy breaches in New Zealand: the serious-harm test
Since December 2020, New Zealand's Privacy Act has required agencies to notify certain privacy breaches. The trigger is not every incident, it is a test: is the breach likely to cause serious harm to an affected individual? If the answer is yes, you must notify both the Office of the Privacy Commissioner and the affected people as soon as practicable after you become aware of it.
That single word, likely, is doing a lot of work, and it is where teams get into trouble. Under-report and you have committed an offence. Over-report reflexively and you erode trust and swamp your own team. The Act asks for a judgement, made quickly and recorded.
What goes into the serious-harm judgement
The Act lists factors you must weigh when deciding whether serious harm is likely. In plain terms:
- How sensitive the information is. Health, financial and identity data raise the stakes.
- What protections were in place. Strongly encrypted data that is unreadable is very different from a plain spreadsheet.
- Who has obtained the information, and whether they are likely to misuse it.
- The nature of the harm that could follow, from financial loss to physical safety or serious emotional harm.
- Any steps taken to reduce the risk after the breach, such as remote-wiping a lost device.
Failing to notify a breach that should have been notified is an offence under the Act. The serious-harm test is not a loophole to talk yourself out of reporting, it is a judgement you have to make honestly and be able to show your working on.
Why this belongs in software, not a document
A breach is the worst possible time to be inventing a process. You want the serious-harm assessment, the OPC notification, the notices to individuals and the retained record to be one rehearsed workflow, not a frantic email thread. In Compliance One the New Zealand notifiable-breach workflow runs off a pre-seeded OPC authority: you assess serious harm against the statutory factors, notify the OPC and affected individuals, and keep a complete, timestamped record. The clock starts the moment you know. The point is to already be ready when it does.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.