Menu
Facebook, AWS seek changes to New Zealand Privacy Bill

Facebook, AWS seek changes to New Zealand Privacy Bill

One local technology service provider is suggesting New Zealand needs a "right to be forgotten"

Credit: Reseller News

That responsibility should lie with the person with both the ability and the incentive to take action to protect such information, Edwards added.

Furthermore, AWS said the company supports the view of the Law Commission that that person should be the person that directs or initiates the information collection.

When AWS initiates such collection it should be responsible, the submission said, but when it is a client using its infrastructure, that responsibility should lie with the client.

"This means that while AWS manages security of the cloud, security in the cloud is the responsibility of the customer," Edwards wrote.

This is because AWS has no visibility over the data or control over the client operating systems and security systems installed on its platform.

Data breach notification isn't Facebook's only beef with the Bill however, the company also notes that Information Privacy Principle 11 includes new provisions in relation to cross-border data transfers.

"Cross-border data flows are not only a factor of increasing connectivity and globalisation but an essential component of their emergence," Facebook submitted.

"Without cross-border flows, users would only be restricted to the few services provided by their local service providers though more affordable or better services may exist from providers abroad.

"As such, cross-border flows have not only enhanced consumer choice and interest, but also cross-border investments and information flows."

Facebook is, therefore, encouraging Parliament to safeguard and facilitate the free flow of data if it decides to prescribe rules regarding the protection of personal data transferred abroad.

Chorus

Like Facebook, Chorus said it supports mandatory data breach reporting but was concerned the definition of “notifiable privacy breach” in the Bill was too wide.

"We would support amending the definition of 'notifiable privacy breach' to include a materiality threshold, similar to Australia," the company said. "A privacy breach will, in most cases, cause a degree of loss, of some description, to the individual.

"But not all privacy breaches should be notifiable. An individual may suffer more harm as a result of notification, particularly in situations where the likely harm arising from the breach is not serious."

Chorus said a definition of notifiable privacy breach that includes a materiality threshold similar to that in Australia would provide a "more appropriate notification trigger" without impacting an individual’s right to privacy.

Catalyst IT

Meanwhile, Wellington-based ICT service and cloud provider Catalyst IT said the Bill does not go far enough and needs to be aligned with the European Union's General Data Protection Regulation (GDPR), including a "right to be forgotten".

"We believe that the Bill represents a good opportunity for New Zealand to position itself as a privacy-affirming jurisdiction," the company stated.

"By enacting privacy regulation that is comprehensive, emphasises the rights of data subjects and is easily enforceable, New Zealand can present itself as a jurisdiction where privacy and data protection matter.

"The ability to trade on an internationally recognised high standard of legislative protection would represent a significant competitive advantage to New Zealand companies, especially in the information technology sector."

The company supports additional regulations suggested in a 2016 report by the Privacy Commissioner including  data portability as a consumer right; controls on the risk that individuals could be re-identified from anonymised data; increased civil penalties for non-compliance; giving the commissioner power to require agencies to demonstrate compliance.

In addition, Catalyst IT advocates two key elements of the GDPR be incorporated into New Zealand Bill: a requirement for agencies to adopt the principle of privacy by design; and the recognition of the right of data subjects to be forgotten.

"The Bill, as currently worded, is a good start," Catalyst argued. "However, without some significant changes along the lines of those proposed in this submission, it would amount to a relatively insignificant reform falling well short of the standards of privacy protection that exist in jurisdictions comparable to ours."

The full list of submissions and documents can be found here.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags FacebookAWSChorusdata breach notificationCatalyst ITprivacy.

Featured

Slideshows

The making of an MSSP: a blueprint for growth in NZ

The making of an MSSP: a blueprint for growth in NZ

Partners are actively building out security practices and services to match, yet remain challenged by a lack of guidance in the market. This exclusive Reseller News Roundtable - in association with Sophos - assessed the making of an MSSP, outlining the blueprint for growth and how partners can differentiate in New Zealand.

The making of an MSSP: a blueprint for growth in NZ
Reseller News Platinum Club celebrates leading partners in 2018

Reseller News Platinum Club celebrates leading partners in 2018

The leading players of the New Zealand channel came together to celebrate a year of achievement at the inaugural Reseller News Platinum Club lunch in Auckland. Following the Reseller News Innovation Awards, Platinum Club provides a platform to showcase the top performing partners and start-ups of the past 12 months, with more than ​​50 organisations in the spotlight.​​​

Reseller News Platinum Club celebrates leading partners in 2018
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP has honoured its leading partners in New Zealand during 2018, following 12 months of growth through the local channel. Unveiled during the fourth running of the ceremony in Auckland, the awards recognise and celebrate excellence, growth, consistency and engagement of standout Kiwi partners.

Meet the top performing HP partners in NZ
Show Comments