Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Oceania

New Zealand: file security and audit obligations

New Zealand regulates through a principles-based Privacy Act rather than a prescriptive cyber statute, with the NZISM providing the technical control baseline for government and the agencies it supplies.

At a glance

How New Zealand regulates file security

  • 01

    Regime

    Principles-based privacy law plus a government control manual (NZISM)

  • 02

    File security

    NZISM content filtering and gateway controls; malware protection

  • 03

    Audit and evidence

    Privacy breach notification to OPC; NZISM logging and audit requirements

Overview

The regulatory picture

New Zealand does not have a SOCI-style critical infrastructure statute, so the obligations that reach file security come from two directions: privacy law that applies to everyone, and a government control manual that applies to agencies and anyone supplying them.

The Privacy Act 2020 sets thirteen Information Privacy Principles, including IPP 5, which requires reasonable security safeguards against loss, misuse and unauthorised access. It also requires notification to the Office of the Privacy Commissioner and to affected individuals where a privacy breach causes or is likely to cause serious harm. The Privacy Amendment Act 2025 received royal assent on 24 September 2025 and introduces IPP 3A, a new transparency obligation to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. IPP 3A comes into force on 1 May 2026 and applies only to personal information collected on or after that date.

The New Zealand Information Security Manual (NZISM), published by the GCSB's National Cyber Security Centre, is the control baseline for government systems. Its gateway, content filtering and malware protection sections are the file-security relevant ones, and it is routinely referenced in government procurement, which pulls suppliers into scope by contract rather than by statute.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Privacy Act 2020OPCIn forceDirect
Privacy Amendment Act 2025 (IPP 3A)OPCPartly in forceIndirect
New Zealand Information Security Manual (NZISM)NCSCIn forceDirect

OPC

Privacy Act 2020

Thirteen Information Privacy Principles. IPP 5 requires reasonable security safeguards. Notifiable privacy breaches must be reported to the OPC and to affected individuals where serious harm is caused or likely.

Why it matters for file security. Documents are where personal information accumulates without governance. Reducing the personal data held in loose files lowers IPP 5 exposure and shrinks the set of files that could produce a notifiable breach.

How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, which is a concrete IPP 5 safeguard rather than a policy statement. Storage Monitor extends the same treatment to material already at rest in Microsoft 365 and records what was processed for each tenant.

Find & RedactStorage Monitor + SM AuditGlasswall Halo

Source: OPC

OPC

Privacy Amendment Act 2025 (IPP 3A)

Adds IPP 3A, requiring agencies to take reasonable steps to notify individuals when collecting their personal information indirectly from a third party. In force 1 May 2026, applying to information collected on or after that date.

Why it matters for file security. Indirect for file security specifically, but it changes what organisations must know about personal data arriving in bulk, often as spreadsheets and document sets from third parties. Knowing what is inside inbound files becomes a compliance input.

How Glasswall addresses it. Where personal information arrives indirectly as bulk document or spreadsheet transfers, Find & Redact can strip data patterns that were never needed, reducing the volume of indirectly collected information an agency has to account for.

Find & RedactGlasswall Halo

Source: OPC

NCSC

New Zealand Information Security Manual (NZISM)

The technical control baseline for New Zealand Government information systems, covering gateways, content filtering, malware protection, logging and audit.

Why it matters for file security. The gateway and content filtering chapters govern what happens to content crossing into a government network, and the malware protection controls set the expectation for untrusted file handling. Suppliers to government are commonly held to these by contract.

How Glasswall addresses it. CDR at the gateway rebuilds inbound content to a known-good standard, which addresses the content filtering and malware protection control objectives deterministically rather than by detection tuning. The per-file verdict record feeds the NZISM logging and audit expectations and exports to SIEM. Meteor covers the on-premises and air-gapped deployments where a cloud service is not acceptable.

Content Disarm and ReconstructionICAP ClientPer-file verdict recordCross-domain and air-gapped transferGlasswall Halo / Glasswall Meteor

Source: NCSC

Latest developments

What has changed in New Zealand

Most recent first.

  1. In forceContext

    IPP 3A indirect collection transparency obligation comes into force

    IPP 3A took effect, requiring agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. It applies only to personal information collected on or after this date.

    Why it matters for file security. Organisations receiving bulk personal data from third parties, frequently as documents and spreadsheets, now have a transparency obligation attached to that intake.

    • banking
    • telco
    • healthcare
    • education

    Source: Bell Gully

  2. AmendmentContext

    Privacy Amendment Act 2025 receives royal assent

    The Privacy Amendment Act 2025 received royal assent, adding IPP 3A to the Privacy Act 2020 with a commencement date of 1 May 2026.

    Why it matters for file security. Sets the compliance clock for indirect-collection transparency, relevant to any organisation ingesting third-party personal data in document form.

    • banking
    • telco
    • healthcare
    • education

    Source: New Zealand Legislation

Scope

About this page

This page is a working reference for organisations operating in New Zealand.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in New Zealand?