The Office of the Privacy Commissioner can now issue fines of up to $10,000 for Privacy Act 2020 breaches in New Zealand. That number gets attention. But what most organisations miss is that the law doesn't just punish breaches — it rewards preparation. Specifically, it rewards organisations that took "reasonable steps" to protect personal information before the breach happened.
Staff awareness training is the most visible, auditable reasonable step you can take.
What "Reasonable Steps" Actually Means
Information Privacy Principle 5 (IPP 5) requires organisations to protect personal information against loss, unauthorised access, use, modification, or disclosure. The Privacy Commissioner assesses compliance by asking whether the organisation took steps *proportionate to the sensitivity of the information* they hold.
For most NZ businesses, the biggest risk to personal information isn't a sophisticated external attacker — it's a staff member clicking a phishing link, responding to a social engineering call, or accidentally emailing the wrong person. All three are human-layer failures that awareness training directly addresses.
When the Commissioner investigates a breach, one of the first questions is: "What training did staff receive?" If the answer is "none" or "we sent a policy document once," that's a finding against you. If you can produce training completion records for all staff covering phishing, data handling, and incident reporting, you're demonstrating reasonable steps.
The Notifiable Privacy Breach Requirement
Under the Privacy Act 2020, organisations must notify the Privacy Commissioner and affected individuals of a privacy breach that has caused, or is likely to cause, serious harm. Failure to notify carries its own penalties.
More importantly, the breach notification process itself exposes the organisation's security practices to scrutiny. The Commissioner will assess whether the breach was preventable and whether adequate controls were in place.
A documented training programme doesn't prevent you from having to notify — but it materially changes the Commissioner's assessment of whether you acted in good faith and took reasonable precautions.
What the Training Programme Should Cover
To satisfy IPP 5 as a control, your training should cover:
- Phishing and email security — the leading cause of personal data breaches in NZ (CERT NZ consistently reports this)
- Data handling and classification — staff need to know what constitutes personal information and how to handle it
- Incident reporting — staff must know what to report, to whom, and how quickly (the 72-hour window matters)
- Social engineering — phone-based and in-person manipulation that bypasses technical controls
- Access control basics — password hygiene, MFA, and not sharing credentials
This isn't a one-time exercise. The Privacy Commissioner looks for ongoing, regular training — not a single onboarding session three years ago.
Australian Privacy Act Parallel
For organisations operating in Australia, the Privacy Act 1988 (amended 2024) carries similar requirements. The Australian Information Commissioner uses comparable "reasonable steps" language, and the penalties are significantly higher — serious or repeated breaches now carry civil penalties up to AU$50 million for large organisations.
The training evidence that satisfies the NZ Privacy Commissioner translates directly to the Australian framework. If you operate in both markets, a single well-documented training programme covers both.
Building the Evidence File
When a breach occurs and the Commissioner comes knocking, you need to produce:
- Training completion records (who completed, when, what module)
- Assessment scores demonstrating comprehension
- Records of refresher training and updates
- Incident reporting logs showing staff actually used what they learned
This is exactly what cyber insurance providers also look for when assessing a claim. The documentation you build for Privacy Act compliance double-dips into your insurance risk profile.
What Happens Without Training Evidence
The Privacy Commissioner's published decisions make the pattern clear: organisations that cannot demonstrate staff training receive harsher findings. The absence of training evidence is treated as a systemic failure — not an isolated mistake.
More practically, your cyber insurer may decline or reduce a claim if they determine the breach resulted from foreseeable human error that training could have prevented. "Reasonable steps" is a legal test and an insurance test simultaneously.
SecureAZ provides NZ-localised security awareness training covering every Privacy Act 2020 risk area — with completion records and reports built for exactly this kind of compliance evidence. Start free for 45 days.
External references: