Data Privacy Day has been internationally observed on 28 January since 2007. Its purpose is to raise awareness and promote best privacy and data protection practices. It serves as an excellent reminder of exactly how precious our data is, as well as our ethical and legal obligations as businesses to securely manage and protect it.
So, in terms of data privacy, how have we fared here in New Zealand? Why is data governance so important - what is it, and why exactly do you need it?
Warning – triggering content: It may not be your job to manage data – and you may not think you even need to care about it. But if you are a stakeholder, it’s your responsibility to make sure that your business complies with New Zealand’s privacy and data protection best practices.
This is a big topic (sorry!), so it’s in two parts.
In the
Annual Report 2024, our Privacy Commissioner (Michael Webster) had good and bad news for 2023-2024. Over that time, the Office of the Privacy Commissioner handled:
The good news? The Report says a highlight of the year was that more Kiwis were concerned about privacy than ever before – up by 16% on the previous two-year period.
There’s no sugar-coating it. Webster is worried.
He bemoans their problematic environment, with privacy breaches increasing in frequency and complexity. And he firmly attributes this to many agencies having little understanding of how to manage privacy, a lack of accountability for poor management of personal information, and insufficient prioritisation of data privacy compared with other compliance requirements.
In short, too many companies and agencies aren’t up to speed with their data governance capabilities.
And that should be a significant concern for most businesses – including you if you don’t have a data governance policy.
Why? Well, 70% of the people surveyed for the Report said they’d change service providers if they heard their provider had poor privacy and security practices. That has to hurt.
Which makes taking data privacy and data governance seriously even more critical.
Going back to basics, what exactly is data governance, and what does it mean for your business? Here you go: Data governance is a system that defines who can access, use, and change your data - and how. It’s the backbone of data privacy.
Why is this important? With data governance in place, you can ensure that your business information is secure, accurate, and available. You avoid potential fines or penalties by meeting your regulatory and industry requirements. And you’re safe in the knowledge that with clean, accurate data, you’ll make better business decisions. So, it’s a good thing.
What does data governance include?
Congratulations, AI and data governance are a great match. A warning, though – while they’ll achieve great things together in terms of helping achieve better data privacy, they’ll also present challenges that make it harder to function effectively.
AI is great for enhancing data quality as it can automate data cleansing, classification and validation – which means improved decision-making capabilities as you’ll have trustworthy data. AI can also monitor your data practices, ensuring you’re compliant with regulations and flagging potential problems before they happen.
As AI can analyse vast amounts of data, it’s ideal for identifying risks relating to data security and governance. And when you can predict potential breaches or compliance issues, you can stop them in their tracks rather than mop up the messy aftermath.
We all know that AI relies on analysing massive data sets to do its job. However, when personal data is involved, there’s always the risk that data will be served up or shared inappropriately.
Integrating AI into data governance can also expose you to new security vulnerabilities – AI systems are a hot new target for cybercriminals. So, protecting these systems adds yet another layer of complexity. Implementing AI effectively into existing data governance frameworks also requires specialised skills and knowledge – and finding these skills can be another challenge.
Then, there are the ethical dilemmas regarding accountability and responsibility posed by using AI in decision-making. Nothing is ever simple, is it?
We did warn you that this is a big (and important) topic, and we appreciate you taking the time to find out more!
So, in part two of this blog, we focus on the 13 Information Privacy Principles in our Privacy Act (2020) and what you need to do to stay on the right side of our legislation – and your customers.
Stay tuned!
40 King Street, Palmerston North
25 Bower Street, Napier
15 Purnell Street, Whanganui