Guidance

Keeping personal information safe: a guide for organisations and their suppliers

The following advice is designed to help organisations implement appropriate controls when working with third party suppliers.

PUBLISHED DATE: 3 August 2026

Many organisations hold considerable amounts of information related to individuals – some of it very personal, such as medical records and financial history. 

Increasingly, it is not only the organisations collecting data who face the risk of compromise. Their third party suppliers may be an easier target if they do not implement adequate cyber security controls.

Case study

In December 2025, a significant data breach affecting a medical record platform exposed the personal information of over 99,000 New Zealanders. This is one of New Zealand’s largest known breaches of sensitive personal information. A review by the Office of the Privacy Commissioner found that threat actors had managed to steal large amounts of health information from a patient health portal using valid stolen patient credentials. The Office of the Privacy Commissioner review into the December 2025 incident found that using reasonable security safeguards could likely have prevented the compromise.

Sensitive data is attractive to cyber criminals who attempt to gain access to it in order to extort the companies responsible or the individuals concerned.

Cyber criminals do not need sophisticated techniques to compromise organisations with poor cyber security. Ensuring fundamental security controls are in place can provide a strong basis for protection from common attacks. 

Unfortunately, organisations do not always implement the appropriate controls that will keep data safe, particularly if organisations outsource data storage, processing and/ or management functions to third parties without maintaining oversight of the security controls the third party uses to protect the data. 

Data protection is the process and guidelines for ensuring information is responsibly managed and complies with privacy regulations. The New Zealand Privacy Act 2020 requires organisations to implement "reasonable security safeguards" to protect personal information against unauthorised access, loss, or disclosure.

Below is an overview of cyber security practices that should be implemented by organisations working with personal data. This guidance is intended to be used by organisations with responsibility for managing contracts with third party suppliers.

Third party supplier assurance 

Organisations are often reliant on third parties to support their day-to-day operations. As an organisation, if you transfer personal information to a third party to store and manage, or authorise them to use it for specific purposes, you need to proactively ensure they are embedding appropriate data protection measures. 

Third party suppliers should be clear on data protection and cyber security expectations and assessed against these expectations at the procurement stage and throughout the life of the contract.

Questions to consider when working with third party suppliers

It is an ongoing process to manage third party suppliers. You need to be considering cyber security right from the start (e.g. procurement) of working with a third party supplier. 

  • Scoping supplier requirements:
    • Have you considered whether potential third party suppliers might need access to sensitive data?
    • Do you have a clear understanding of the data protection and cyber security expectations that potential suppliers will need to meet given the types of data they will have access to? 
  • Cyber security contractual clauses:
    • Do you have specific contractual clauses with your supplier that establish clear data protection and cyber security expectations? For example, you could require suppliers to hold a cyber security certification or provide other evidence of appropriate cyber security practice.
  • Security governance:
    • What information do you have that suppliers’ key decision makers (e.g. the Board) sighted on and prioritising cyber risk management?
    • Are any of your suppliers' services subject to other jurisdictions’ laws regarding the collection and storage of personal data and the potential impact of this on your obligations under New Zealand law? If so, are you aware of this jurisdictional risk?
    • Do not assume suppliers are following cyber security best good practice – you must maintain strong and ongoing oversight. You are responsible for ensuring suppliers have appropriate cyber security.
  • Incident management:
    • Are your suppliers contractually obligated to provide incident reporting?
    • Are you receiving this reporting in a timely manner that enables your organisation to act fast if needed? 
  • Network protection:
    • Are your suppliers’ networks protected from potential harms of untrusted networks? Are their Cloud services properly configured and protected?
    • Do your suppliers know who has access to their networks and have processes to control privileged access (are they granting only the minimum level required)?
    • How do your suppliers secure remote networks and authenticate remote users? 
  • Data protection:
    • Do your suppliers encrypt data on portable devices? Do they securely wipe devices prior to reuse/disposal?
    • Do your suppliers have processes to detect and prevent unauthorised data transfers and to protect data in transit (e.g., through secure email or APIs)?
  • Independent assurances:
    • Do your suppliers conduct any independent security tests? If issues are uncovered through independent audits, how are these addressed?

Organisations can help lift overall cyber security in their systems by requiring suppliers to maintain effective cyber security across products and services. 

Key steps for data protection

A risk management approach can help your organisation determine appropriate cyber security for you and your suppliers. It is important to understand the data you collect and store, and the systems you use to maintain it. This knowledge puts you in a better position to identify the best way to protect personal information. 

Read more in the NCSC’s Supply Chain Cyber Security: In Safe Hands guidance. 

Some basic controls that are particularly important for protecting data include:

  • Ensuring appropriate firewall protection 
  • Encrypting data  
  • Enforcing multifactor authentication (MFA) on all systems, accounts and profiles 
  • Setting access limitations on accounts, or adhering to the principle of least privilege (limiting who is authorised to access what)
  • Enabling data loss prevention (DLP) solutions for data at rest (to help prevent personal information from getting out)

Frameworks and guidance

The NCSC provides guidance that can help organisations proactively manage their cyber security risk: 

  • NCSC Cyber Security Framework:  All organisations should have a cyber security framework. A framework facilitates a risk approach, including identifying assets, improving understanding of the context and threat environment in which those assets are used, and clarifying security responsibilities between organisations and their suppliers. The NCSC Framework is one example. Awareness and early detection enable increase your cyber security resilience before an attack, so it is important to continuously monitor your cyber security environment for vulnerabilities and emerging threats, and regularly review your suppliers’ security policies and any agreements you have with them.
  • Minimum Cyber Security Standards: The NCSC developed Cyber Security Minimum Standards for use by government agencies. Although Minimum Standards are not required by organisations across the New Zealand economy, the standards outline essential controls (such as multifactor authentication) that, when implemented appropriately, ensure your organisation has basic cyber security in place to protect against many common attacks.
  • New Zealand Information Security Manual: Refer to the New Zealand Information Security Manual (NZISM) for guidance on security controls important for data protection; including encryption (at rest and in transit), data retention, identity and access management. This advice is primarily designed for government agencies but contains information what could be helpful for all organisations across the economy who handle personal data.
  • The Protective Security Requirements (PSR) Security Governance requirements: The PSR Security Governance requirements ensure effective oversight and management of all security areas. The fifth requirement, GOV 5: Manage risks when working with others, specifically addresses the management of risks when working with suppliers. As part of a GOV 5 refresh, the PSR is developing a set of criteria that organisations can use when assessing risk in supplier contracts. The “Common Criteria for Assessing Risk” will assist organisations in ranking the risks of suppliers, determining their capability maturity and the level of supplier assurance needed.

Additional resources 

Additional guidance is available which covers a breadth of security and privacy topics, including holistic security governance and risk management: