Privacy, Cyber, and Data Security
Privacy, Cyber, and Data Security
Privacy, cyber security, and data governance issues are a core risk for organisations of all sizes.
Whether you are collecting personal information from customers or service users, implementing new technologies, managing employee information, responding to a security incident, or navigating a commercial transaction, understanding your privacy obligations is critical.
Our team provides practical, commercially focused advice on privacy law and data governance matters. We work with businesses, charities, not-for-profits, and other organisations to help them meet their obligations under the Privacy Act 2020, respond effectively to privacy and cyber incidents, and build policies and systems that support good information management practices.
Privacy and cyber issues rarely arise in isolation. They often involve employment, governance, commercial, technology, and reputational considerations. Our advice is tailored to the needs of each client and focused on managing risk while supporting organisational objectives.
Services we offer:
- advising on privacy compliance and obligations under the Privacy Act 2020;
- assisting clients to respond to privacy breaches, cyber incidents and other data security events, including notification obligations and engagement with the Office of the Privacy Commissioner;
- preparing, reviewing, and updating privacy policies, privacy statements, and collection notices;
- conducting privacy reviews and audits of existing practices, processes, and documentation;
- advising on information sharing, disclosure, and data retention obligations;
- supporting organisations through system changes, digital projects, and the implementation of new technologies;
- developing robust internal policies, procedures, and governance frameworks, including for the implementation and use of AI technologies in the workplace;
- advising on privacy, cyber security, and data management issues arising in commercial transactions, restructures, and governance projects; and
- delivering privacy training and workshops for boards, leadership teams and staff, either in person or online.
Useful articles from our blog:
- What you need to know about the new Information Privacy Principal 3A
- Surveillance without Safeguards: CCTV and the Privacy Act
- New legislation to allow some company directors to keep addresses private
- Outsourced, but not off the hook: who’s accountable in a third-party privacy breach?
- If it's not on Strava, it didn't happen...
- What you need to know about the Biometric Processing Privacy Code 2025
- Privacy Commissioner’s Inquiry into Facial Recognition in Retail
- A New Era for Consumer Data in New Zealand