Wellington privacy programmes face a tension that private sector programmes elsewhere do not. Privacy practice pushes towards holding personal information no longer than it is needed. Public records obligations push the other way, requiring records to be retained and prohibiting disposal without authority.
Both apply to agencies and both reach the suppliers holding information on their behalf. A retention schedule designed purely around privacy minimisation can breach recordkeeping obligations. One designed purely around recordkeeping can leave personal information held long after any operational justification has expired.
Nathan ISO Consulting implements privacy information management systems for Wellington organisations, standalone under the 2025 revision or alongside an existing ISO 27001 certification.
Reconciling Retention With Minimisation
The reconciliation is not conceptually difficult but it is rarely done. Records with continuing value are identified, scheduled and retained under an authorised disposal framework. Personal information without that status is disposed of when its purpose is exhausted. What makes it work is that the decision is made deliberately, documented, and applied consistently rather than left to whoever administers the storage. What makes it fail is a supplier applying a commercial retention default to agency information, or an agency assuming the supplier will follow a schedule nobody has given them. We build the reconciliation explicitly, because in this city it is the single most common gap we find.
Looking for an ISO 27701 Privacy Consultant in Wellington?
Why ISO 27701 Matters for Wellington Organisations
Volume and sensitivity are the first reason. Agencies operating from Wellington hold information about a substantial proportion of the population, frequently including material people had no practical choice about providing. The consequences of mishandling it are not primarily commercial.
Supplier exposure is the second. A great deal of agency information is processed by contracted providers, and those providers carry obligations through their agreements that are more specific than anything in general commercial practice. Certification gives a supplier an assessed structure to answer from rather than negotiating what adequate looks like agency by agency.
The third reason is that the standard became independently certifiable in October 2025. An organisation whose exposure is personal information rather than broad information security can now certify against the thing that actually matters, which suits the community services, health and education providers delivering a large share of government services.
Legal and Regulatory Compliance in New Zealand
| Obligation | What It Involves |
|---|---|
| Privacy Act 2020 and the 13 Information Privacy Principles | Rules governing how information about people may be gathered, applied, shared, kept accurate, protected and made available to them, reaching almost every organisation |
| IPP 3A | Operative from May 2026. Where you obtain someone’s information from a third party rather than from them, you must take reasonable steps to let them know |
| Notifiable privacy breach obligations | Telling the Commissioner and the people affected, without undue delay, whenever a breach looks likely to cause serious harm |
| Public Records Act 2005 | Retention, accessibility and authorised disposal obligations for public records, following records held by contractors |
| Official Information Act 1982 | Requests for information, with privacy withholding grounds requiring assessment rather than blanket refusal |
| Biometric Processing Privacy Code 2025 | Binding rules on biometric information, with the transition period now closed |
| Health Information Privacy Code | Specific rules for health information held by health agencies, operating alongside the Act |
| Cross-border disclosure under IPP 12 | Responsibility that follows information offshore, with the receiving party required to offer protections of a comparable standard |
Agency obligations reach suppliers through contract. Where retention or disposal requirements are not specified in your agreement, that gap is worth closing before it becomes a finding for both parties.
Wellington Precincts and the Wider Region
| Wellington Location | Business Activity | Privacy Exposure |
|---|---|---|
| Thorndon and Pipitea | Government departments, ministries, Crown entities | Population-scale personal information and statutory recordkeeping duties |
| Lambton Quay and the CBD | ICT suppliers, consultancies, professional services | Agency information processed under contract with retention obligations attached |
| Newtown and hospital precinct | Health services, clinical support, research | Health information under the Act and the health information code |
| Kelburn and the university precinct | Research institutes, tertiary education | Research participant data, ethics conditions and long-term retention |
| Te Aro and Cuba Quarter | Software, digital services, marketing technology | Processor obligations, indirect collection and cross-border transfer |
| Community and social services | Providers delivering agency-funded services | Records concerning vulnerable people, with limited privacy resourcing |
| Porirua and Kāpiti | Service delivery, education, community organisations | Client records held on behalf of agencies |
| Petone and Gracefield | Scientific services, laboratories, engineering | Research and personnel information, sample-linked personal data |
| Wairarapa and regional delivery | Health, education and community services | Small-community re-identification risk in aggregated reporting |
Standalone or Combined
Independent certification arrived with the 2025 revision. Two questions usually settle which route suits.
Read the last few agency contracts and check which certificate is specified, if any. In Wellington security is named more often, reflecting agency familiarity with the Protective Security Requirements, but privacy is increasingly named alongside it where the contract concerns personal information at scale.
Where the risk is essentially about people’s information rather than systems and intellectual property, standalone is narrower to build and lighter to maintain. Where you also hold sensitive operational material or run services where availability matters, combining makes more sense because the governance layer is constructed once.
Not sure whether standalone or combined suits your organisation?
Our Wellington Delivery Approach
Everything begins by tracing the information, and in this city that tracing has to split what you hold in your own right from what you hold for an agency, since the disposal rules diverge completely. Roles are then settled activity by activity. External notices follow, along with the applicability statement, handling of access and correction requests, an incident procedure calibrated to the serious harm threshold, and a retention model that satisfies both minimisation and statutory recordkeeping instead of sacrificing one to the other.
Few bodies here yet carry scope for independent certification, so confirming who genuinely does precedes any recommendation, and dates get held early. Preparation tests you against the standard and your principle-level duties together in one pass, closing with a minuted review. We attend both visits.
The legislation has shifted twice in short order and further codes keep appearing. Periodic audits, surveillance preparation and watching for changes that touch your position remain our responsibility, as does updating the information trace whenever services, suppliers or agency arrangements move.
The Documentation You Receive
Where Wellington ISO 27701 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.
Send Us Your Retention Schedule
Your current retention schedule, and the disposal authority behind it, tells us more than a discovery session would. If agency information is held under a commercial default, that is the place to start.
Ready to start your ISO 27701 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Records with continuing value are retained under an authorised disposal framework; personal information without that status is disposed of when its purpose ends. The reconciliation must be deliberate and documented, because applying either rule alone breaches the other.
You can, following the 2025 revision. Anything stating otherwise refers to the superseded edition, which functioned purely as an add-on. Organisations here whose exposure is personal information often find the independent route a better match.
Operative from May 2026, it obliges you to take reasonable steps to inform people when their information reached you from a source other than themselves. That captures anyone receiving records from another agency or a commercial third party.
The duty rests with the public office, but it follows the records. Where you hold agency records, retention, accessibility and disposal requirements reach your systems through the contract, whether or not the contract says so explicitly.
No hour count is specified. Once you are aware and serious harm appears likely, the Commissioner and those affected must be told without undue delay. The 72-hour rule is European and has no application in this country.
They run under different statutes with different tests, but both require knowing what you hold and being able to retrieve it. Organisations handling them in separate teams without a shared information map routinely give inconsistent answers.
Both, in nearly every case, depending on what you are doing. Processing agency material on instruction puts you one side of the line; choosing how your own workforce or client records are used puts you the other. It is recorded per activity.
Being compliant is a legal condition; holding a certificate demonstrates a managed route toward it. Our mapping runs the controls against every principle so each duty can be traced to the place it is discharged.
Move to the schedule your certification body sets. The substance you have written mostly holds. What changes is architecture: making the applicability statement function independently and stripping out assumptions about a companion security certificate.
Independently, between fourteen and twenty-six weeks, less where security certification already exists. Tracing the information controls the pace, and anyone holding both agency-entrusted and own-account records should allow toward the longer end.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving