Privacy Act and APP 11 readiness
APP 11 is the one about taking reasonable steps to protect the personal
information you hold. We work out what personal information you actually
have and where it lives — which is nearly always more places than anyone
expects — then put real access controls, encryption and retention around it.
Then we write down what we did, because "reasonable steps" you can't
demonstrate are not much use to you after the fact.
Privacy Act 2020 and IPP 5 readiness
IPP 5 is storage and security: reasonable safeguards against loss, misuse
and unauthorised access. We work out what personal information you actually
hold and where it lives — nearly always more places than anyone expects —
then put real access controls, encryption and retention around it, and
write down what we did. The Manage My Health finding turned on exactly this
principle, and on whether the safeguards could be shown to have been
adequate at the time.
A breach plan you've actually rehearsed
A breach response plan in a drawer is a document. A breach response plan
you've run as a tabletop exercise is a control. We sit your leadership team
in a room for ninety minutes with a realistic scenario and find out who
makes the call, who rings the lawyer, who talks to staff, and how long it
takes you to work out what was taken. The first run is always messy. That's
the point of doing it on a Tuesday instead of during an actual incident.
My Health Record security and access policy
If your practice connects to Australia's My Health Record you need a written
security and access policy, and it needs to match what your practice
management system is actually configured to do. We reconcile the two, which
is usually where the gap is.
Where your data sits, and what the Act actually says
This is the first question every New Zealand client asks us, so here is the
honest answer. The Privacy Commissioner's guidance is explicit that where a
provider holds information as your agent under section 11 — for safekeeping
or processing on your instructions, not for its own purposes — that is
generally not a cross-border disclosure under IPP 12. In the Commissioner's
words, "you'll be responsible for the personal information that you put in
the cloud – not the cloud service provider".
Read that carefully, because it is not the win some providers pretend. It
does not move the obligation off you. It moves it from "is this lawful" to
"is this well governed", and you stay accountable for IPP 5 either way. So
we tell you plainly where the data sits, put model contract clauses in
place using the Commissioner's own agreement builder and decision tree, and
let you make the call. Health and government clients often have onshore
hosting requirements that have nothing to do with the Privacy Act, and
those still apply.
Accreditation evidence packs
Accreditation surveyors ask for evidence, not assurances. We assemble the
technical half of the pack — access logs, backup and restore records,
patching reports, user account reviews, device encryption status — and keep
it current so the next cycle isn't a scramble.
Tracking pixels and marketing tech
The June 2026 findings over pixels on health websites should make every
practice with a booking page nervous. We audit what your site and booking
forms send to third parties, tell you in plain English what data is leaving,
and help you shut off the bits that shouldn't be. Your marketing agency
probably installed these with good intentions and no privacy review.
What your website sends, and where it goes
Every third-party script on your site is a collection point you did not
document and a recipient you did not name. Booking pages and enquiry forms
are the ones worth checking first, because what they capture is often more
sensitive than the rest of the site combined. We audit what leaves, tell you
in plain English who receives it, and help you shut off the parts that
shouldn't be there. Your marketing agency installed most of it with good
intentions and no privacy review.
Customer security questionnaires
Increasingly the privacy questions and the security questions arrive on the
same form. We answer them for you, accurately, and flag what we can't yet
answer. More on how that works on the
cyber security page.