Overview

The Privacy Act 2020 represents New Zealand’s primary law for preserving personal information. It regulates the way any organisations, corporations, as well as government agencies should gather, store, utilise, and disclose personal information (Rustad & Koenig, 2023). The Act’s goal is to provide individuals control over their personal information while also requiring businesses to manage data ethically and publicly. The Act is based on thirteen Information Privacy Principles (IPPs). These principles direct companies on how to acquire information legally, use it exclusively for legitimate reasons, keep it secure, assure accuracy, and allow individuals to access and rectify their personal information (Farayola & Olorunfemi, 2024). The Act also mandated the reporting of major privacy violations to the Privacy Commissioner, including impacted persons.

Purpose of the Act

The Act aims to:

  • Protect individuals’ privacy.
  • Promote transparency in data handling.
  • Give individuals control over their personal information.
  • Encourage responsible information management.

Key Privacy Principles

Collection of Information

Organizations should only collect information necessary for a legitimate purpose.

Storage and Security

Personal information must be protected against unauthorized access, loss, or misuse.

Access and Correction

Individuals have the right to access and correct their personal information.

Disclosure

Information should only be shared when legally permitted.

Importance in IT

IT professionals regularly handle:

  • Customer databases
  • Employee records
  • Cloud storage systems
  • Online applications

Compliance with the Privacy Act helps prevent data breaches and protects user trust.

Māori Data Sovereignty

Māori Data Sovereignty emphasizes that Māori data should be controlled and governed by Māori communities.

Importance

  • Protects cultural identity.
  • Ensures ethical use of indigenous information.
  • Supports self-determination.

The Privacy Act is highly significant to IT professionals since many digital systems handle enormous volumes of personal data. When creating databases, websites, mobile applications, cloud systems, or programs, IT professionals must ensure that personal information is only collected, when necessary, safeguarded with proper security measures, and shared with permitted parties. Strong cybersecurity controls, encryption, access management, and protected storage techniques all help to ensure compliance with the Act (Ferguson-Lees, Brogt & Naswall, 2025). The Act aligns with the Māori data sovereignty ideals proposed by Te Mana Raraunga. Māori data sovereignty advocates for Māori ownership and control over data related to their individuals, communities, resources, and culture. Organisations handling Māori data must maintain Māori principles, involve Māori stakeholders within decision-making, and use data in ways that benefit Māori communities (Queniahan, 2024). Protecting Māori data is both a legal responsibility and an ethical commitment to upholding cultural identity, self-determination, including indigenous rights in digital environments.