Regulatory landscape ยท Oceania
New Zealand: file security and audit obligations
New Zealand regulates through a principles-based Privacy Act rather than a prescriptive cyber statute, with the NZISM providing the technical control baseline for government and the agencies it supplies.
At a glance
How New Zealand regulates file security
- 01
Regime
Principles-based privacy law plus a government control manual (NZISM)
- 02
File security
NZISM content filtering and gateway controls; malware protection
- 03
Audit and evidence
Privacy breach notification to OPC; NZISM logging and audit requirements
Overview
The regulatory picture
New Zealand does not have a SOCI-style critical infrastructure statute, so the obligations that reach file security come from two directions: privacy law that applies to everyone, and a government control manual that applies to agencies and anyone supplying them.
The Privacy Act 2020 sets thirteen Information Privacy Principles, including IPP 5, which requires reasonable security safeguards against loss, misuse and unauthorised access. It also requires notification to the Office of the Privacy Commissioner and to affected individuals where a privacy breach causes or is likely to cause serious harm. The Privacy Amendment Act 2025 received royal assent on 24 September 2025 and introduces IPP 3A, a new transparency obligation to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. IPP 3A comes into force on 1 May 2026 and applies only to personal information collected on or after that date.
The New Zealand Information Security Manual (NZISM), published by the GCSB's National Cyber Security Centre, is the control baseline for government systems. Its gateway, content filtering and malware protection sections are the file-security relevant ones, and it is routinely referenced in government procurement, which pulls suppliers into scope by contract rather than by statute.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Privacy Act 2020 | OPC | In force | Direct |
| Privacy Amendment Act 2025 (IPP 3A) | OPC | Partly in force | Indirect |
| New Zealand Information Security Manual (NZISM) | NCSC | In force | Direct |
OPC
Privacy Act 2020
Thirteen Information Privacy Principles. IPP 5 requires reasonable security safeguards. Notifiable privacy breaches must be reported to the OPC and to affected individuals where serious harm is caused or likely.
Why it matters for file security. Documents are where personal information accumulates without governance. Reducing the personal data held in loose files lowers IPP 5 exposure and shrinks the set of files that could produce a notifiable breach.
How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, which is a concrete IPP 5 safeguard rather than a policy statement. Storage Monitor extends the same treatment to material already at rest in Microsoft 365 and records what was processed for each tenant.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
OPC
Privacy Amendment Act 2025 (IPP 3A)
Adds IPP 3A, requiring agencies to take reasonable steps to notify individuals when collecting their personal information indirectly from a third party. In force 1 May 2026, applying to information collected on or after that date.
Why it matters for file security. Indirect for file security specifically, but it changes what organisations must know about personal data arriving in bulk, often as spreadsheets and document sets from third parties. Knowing what is inside inbound files becomes a compliance input.
How Glasswall addresses it. Where personal information arrives indirectly as bulk document or spreadsheet transfers, Find & Redact can strip data patterns that were never needed, reducing the volume of indirectly collected information an agency has to account for.
Find & RedactGlasswall Halo
NCSC
New Zealand Information Security Manual (NZISM)
The technical control baseline for New Zealand Government information systems, covering gateways, content filtering, malware protection, logging and audit.
Why it matters for file security. The gateway and content filtering chapters govern what happens to content crossing into a government network, and the malware protection controls set the expectation for untrusted file handling. Suppliers to government are commonly held to these by contract.
How Glasswall addresses it. CDR at the gateway rebuilds inbound content to a known-good standard, which addresses the content filtering and malware protection control objectives deterministically rather than by detection tuning. The per-file verdict record feeds the NZISM logging and audit expectations and exports to SIEM. Meteor covers the on-premises and air-gapped deployments where a cloud service is not acceptable.
Content Disarm and ReconstructionICAP ClientPer-file verdict recordCross-domain and air-gapped transferGlasswall Halo / Glasswall Meteor
Latest developments
What has changed in New Zealand
Most recent first.
-
IPP 3A indirect collection transparency obligation comes into force
IPP 3A took effect, requiring agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. It applies only to personal information collected on or after this date.
Why it matters for file security. Organisations receiving bulk personal data from third parties, frequently as documents and spreadsheets, now have a transparency obligation attached to that intake.
- banking
- telco
- healthcare
- education
-
Privacy Amendment Act 2025 receives royal assent
The Privacy Amendment Act 2025 received royal assent, adding IPP 3A to the Privacy Act 2020 with a commencement date of 1 May 2026.
Why it matters for file security. Sets the compliance clock for indirect-collection transparency, relevant to any organisation ingesting third-party personal data in document form.
- banking
- telco
- healthcare
- education
Scope
About this page
This page is a working reference for organisations operating in New Zealand.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.