WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Wellington privacy programmes face a tension that private sector programmes elsewhere do not. Privacy practice pushes towards holding personal information no longer than it is needed. Public records obligations push the other way, requiring records to be retained and prohibiting disposal without authority.

Both apply to agencies and both reach the suppliers holding information on their behalf. A retention schedule designed purely around privacy minimisation can breach recordkeeping obligations. One designed purely around recordkeeping can leave personal information held long after any operational justification has expired.

Nathan ISO Consulting implements privacy information management systems for Wellington organisations, standalone under the 2025 revision or alongside an existing ISO 27001 certification.

Reconciling Retention With Minimisation

The reconciliation is not conceptually difficult but it is rarely done. Records with continuing value are identified, scheduled and retained under an authorised disposal framework. Personal information without that status is disposed of when its purpose is exhausted. What makes it work is that the decision is made deliberately, documented, and applied consistently rather than left to whoever administers the storage. What makes it fail is a supplier applying a commercial retention default to agency information, or an agency assuming the supplier will follow a schedule nobody has given them. We build the reconciliation explicitly, because in this city it is the single most common gap we find.

Looking for an ISO 27701 Privacy Consultant in Wellington?

Why ISO 27701 Matters for Wellington Organisations

Volume and sensitivity are the first reason. Agencies operating from Wellington hold information about a substantial proportion of the population, frequently including material people had no practical choice about providing. The consequences of mishandling it are not primarily commercial.

Supplier exposure is the second. A great deal of agency information is processed by contracted providers, and those providers carry obligations through their agreements that are more specific than anything in general commercial practice. Certification gives a supplier an assessed structure to answer from rather than negotiating what adequate looks like agency by agency.

The third reason is that the standard became independently certifiable in October 2025. An organisation whose exposure is personal information rather than broad information security can now certify against the thing that actually matters, which suits the community services, health and education providers delivering a large share of government services.

Legal and Regulatory Compliance in New Zealand

ObligationWhat It Involves
Privacy Act 2020 and the 13 Information Privacy PrinciplesRules governing how information about people may be gathered, applied, shared, kept accurate, protected and made available to them, reaching almost every organisation
IPP 3AOperative from May 2026. Where you obtain someone’s information from a third party rather than from them, you must take reasonable steps to let them know
Notifiable privacy breach obligationsTelling the Commissioner and the people affected, without undue delay, whenever a breach looks likely to cause serious harm
Public Records Act 2005Retention, accessibility and authorised disposal obligations for public records, following records held by contractors
Official Information Act 1982Requests for information, with privacy withholding grounds requiring assessment rather than blanket refusal
Biometric Processing Privacy Code 2025Binding rules on biometric information, with the transition period now closed
Health Information Privacy CodeSpecific rules for health information held by health agencies, operating alongside the Act
Cross-border disclosure under IPP 12Responsibility that follows information offshore, with the receiving party required to offer protections of a comparable standard

Agency obligations reach suppliers through contract. Where retention or disposal requirements are not specified in your agreement, that gap is worth closing before it becomes a finding for both parties.

Wellington Precincts and the Wider Region

Wellington LocationBusiness ActivityPrivacy Exposure
Thorndon and PipiteaGovernment departments, ministries, Crown entitiesPopulation-scale personal information and statutory recordkeeping duties
Lambton Quay and the CBDICT suppliers, consultancies, professional servicesAgency information processed under contract with retention obligations attached
Newtown and hospital precinctHealth services, clinical support, researchHealth information under the Act and the health information code
Kelburn and the university precinctResearch institutes, tertiary educationResearch participant data, ethics conditions and long-term retention
Te Aro and Cuba QuarterSoftware, digital services, marketing technologyProcessor obligations, indirect collection and cross-border transfer
Community and social servicesProviders delivering agency-funded servicesRecords concerning vulnerable people, with limited privacy resourcing
Porirua and KāpitiService delivery, education, community organisationsClient records held on behalf of agencies
Petone and GracefieldScientific services, laboratories, engineeringResearch and personnel information, sample-linked personal data
Wairarapa and regional deliveryHealth, education and community servicesSmall-community re-identification risk in aggregated reporting

Standalone or Combined

Independent certification arrived with the 2025 revision. Two questions usually settle which route suits.

What Do Your Agreements Name?

Read the last few agency contracts and check which certificate is specified, if any. In Wellington security is named more often, reflecting agency familiarity with the Protective Security Requirements, but privacy is increasingly named alongside it where the contract concerns personal information at scale.

Is Your Exposure Information Security or Personal Information?

Where the risk is essentially about people’s information rather than systems and intellectual property, standalone is narrower to build and lighter to maintain. Where you also hold sensitive operational material or run services where availability matters, combining makes more sense because the governance layer is constructed once.

Not sure whether standalone or combined suits your organisation?

Our Wellington Delivery Approach

Step One – Scope and Build

Everything begins by tracing the information, and in this city that tracing has to split what you hold in your own right from what you hold for an agency, since the disposal rules diverge completely. Roles are then settled activity by activity. External notices follow, along with the applicability statement, handling of access and correction requests, an incident procedure calibrated to the serious harm threshold, and a retention model that satisfies both minimisation and statutory recordkeeping instead of sacrificing one to the other.

Step Two – Assessment

Few bodies here yet carry scope for independent certification, so confirming who genuinely does precedes any recommendation, and dates get held early. Preparation tests you against the standard and your principle-level duties together in one pass, closing with a minuted review. We attend both visits.

Step Three – Keeping It Alive

The legislation has shifted twice in short order and further codes keep appearing. Periodic audits, surveillance preparation and watching for changes that touch your position remain our responsibility, as does updating the information trace whenever services, suppliers or agency arrangements move.

The Documentation You Receive

  • Information trace. Each category followed from where it came, why you may hold it, who touches it, where it sits and when it goes, with agency material kept separate from your own.
  • Retention reconciliation. A framework satisfying privacy minimisation and public records obligations together, with disposal authority documented.
  • IPP 3A assessment. Where information is collected from someone other than the individual, and what notification steps are reasonable in each case.
  • Role allocation. Whether you decide or merely act on instruction, settled for each activity and expressed in the terms the legislation itself uses.
  • Incident response. Calibrated to the serious harm threshold and the duty to report without undue delay, rather than to a borrowed hour count.
  • Access and correction handling. Processes for individual requests, including how they interact with official information obligations.

Where Wellington ISO 27701 Projects Go Wrong

  • A commercial retention default applied to agency information, disposing of records that carry statutory retention obligations
  • Retention set purely to recordkeeping requirements, leaving personal information held long after its purpose expired
  • IPP 3A overlooked, leaving indirect collection unassessed where information moves between agencies and providers
  • Breach procedures imported from European templates applying a fixed deadline New Zealand law does not set
  • Access requests and official information requests handled by separate teams with no shared view of what is held
  • Role determination declared once for the organisation rather than established per activity

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.

Send Us Your Retention Schedule

Your current retention schedule, and the disposal authority behind it, tells us more than a discovery session would. If agency information is held under a commercial default, that is the place to start.

Ready to start your ISO 27701 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Records with continuing value are retained under an authorised disposal framework; personal information without that status is disposed of when its purpose ends. The reconciliation must be deliberate and documented, because applying either rule alone breaches the other.

You can, following the 2025 revision. Anything stating otherwise refers to the superseded edition, which functioned purely as an add-on. Organisations here whose exposure is personal information often find the independent route a better match.

Operative from May 2026, it obliges you to take reasonable steps to inform people when their information reached you from a source other than themselves. That captures anyone receiving records from another agency or a commercial third party.

The duty rests with the public office, but it follows the records. Where you hold agency records, retention, accessibility and disposal requirements reach your systems through the contract, whether or not the contract says so explicitly.

No hour count is specified. Once you are aware and serious harm appears likely, the Commissioner and those affected must be told without undue delay. The 72-hour rule is European and has no application in this country.

They run under different statutes with different tests, but both require knowing what you hold and being able to retrieve it. Organisations handling them in separate teams without a shared information map routinely give inconsistent answers.

Both, in nearly every case, depending on what you are doing. Processing agency material on instruction puts you one side of the line; choosing how your own workforce or client records are used puts you the other. It is recorded per activity.

Being compliant is a legal condition; holding a certificate demonstrates a managed route toward it. Our mapping runs the controls against every principle so each duty can be traced to the place it is discharged.

Move to the schedule your certification body sets. The substance you have written mostly holds. What changes is architecture: making the applicability statement function independently and stripping out assumptions about a companion security certificate.

Independently, between fourteen and twenty-six weeks, less where security certification already exists. Tracing the information controls the pace, and anyone holding both agency-entrusted and own-account records should allow toward the longer end.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance