From $10,000 to Millions: The Privacy Commissioner Asks for Teeth

Previous: CN#9 -- The $409 Million Lesson: When Deleting the Logs Costs More Than the Breach (22 June 2026)


On 4 June 2026, Privacy Commissioner Michael Webster did something unusual: he told the public, plainly, that the law he enforces is not good enough.

Eight days after releasing Phase 1 findings into the ManageMyHealth (MMH) breach, Webster issued a formal public statement calling on the Government to amend the Privacy Act so his office can impose direct financial penalties on agencies that fail to protect personal data. The current maximum criminal fine for procedural privacy offences is NZ$10,000. Webster is asking for millions.

The timing matters. Declared serious privacy breaches in New Zealand rose 43 per cent in a single year, according to the OPC's November 2025 Annual Report [1]. The MMH inquiry confirmed 99,416 patients were affected, approximately 91 per cent of them Northland hospital patients [2]. The Commissioner issued compliance notices to both ManageMyHealth Ltd and Health NZ, describing them as "the strongest tool currently available" [3].

That phrase is the article's thesis in six words. Not: the tool we chose to use. The tool currently available. The enforcement architecture is constrained by legislation, not preference, and the Commissioner is formally asking Parliament to change it.

This is not a breach story. The breach is the trigger. The subject is the accountability gap the breach exposed, the machinery already moving to address it, and what New Zealand boards need to understand before the gap closes.


The Act Does Not Contain a Penalty for the Breach Itself

The Privacy Act 2020 came into force on 1 December 2020. Its enforcement architecture was designed on a mediation-first, litigation-secondary model. That design reflected the era in which it was drafted: smaller datasets, slower breach timelines, and lower digital concentration of health information.

When a serious breach occurs today, the regulatory pathway runs as follows. A complaint is lodged with the Privacy Commissioner. The Commissioner investigates and, if warranted, issues a compliance notice. Failure to comply with a compliance notice is a criminal offence carrying a maximum fine of NZ$10,000. Where a complaint is unresolved and the Commissioner declines to investigate further, the complainant may take the matter to the Human Rights Review Tribunal (HRRT). The HRRT can award damages of up to NZ$350,000 per proceeding to an aggrieved individual [4].

Three architectural features define this pathway and explain why the Commissioner is asking for something qualitatively different.

First, the damages flow to the complainant, not to a regulator enforcing the public interest. The HRRT award compensates a victim; it does not impose a regulatory penalty on an entity whose governance failed. The financial consequence to the organisation is the award itself, paid to an individual, through a process characterised in published legal analysis as "lengthy." [4]

Second, the criminal fines in the Act are narrow. The NZ$10,000 penalty exists for procedural offences: failing to notify the Commissioner of a serious breach (section 116), failing to comply with a compliance notice (section 118), and obstructing the Commissioner (section 213) [5]. These are process failures, not substantive ones. The law attaches a financial consequence to an organisation that does not tell the Commissioner about a breach; it does not attach a financial consequence to an organisation that caused the breach in the first place.

Third -- and this is the architecture point that the Commissioner's request directly targets -- there is no financial penalty, anywhere in the current Act, for breaching an information privacy principle. The requirement to take reasonable steps to protect personal information (IPP 5) carries no financial sanction if breached. ManageMyHealth operated without mandatory multi-factor authentication on the affected module. It operated without anomaly detection capable of flagging an attacker accessing hundreds of thousands of records in patterns no legitimate user would generate [2]. Under the current Act, the regulatory financial consequence for both of those failures is zero.

The Commissioner's 4 June request is not for more investigation powers or stronger compliance notices. It is for the ability to attach a meaningful financial consequence to the failure that caused the harm, not merely to the procedural failures that followed it.

The Privacy Amendment Act 2025 (Royal Assent 23 September 2025; Part 1 commenced 1 May 2026) introduced IPP 3A, expanding transparency obligations around indirect data collection. That amendment, which this series covered in earlier editions, did not alter the penalty architecture in any respect [6].


What Australia Built After Optus and Medibank

New Zealand is not operating in a regulatory vacuum. The international enforcement benchmarks are not theoretical; they are operational and their scale is instructive.

In late 2022, Australia experienced two large-scale data breaches in rapid succession. The Optus breach affected 9.5 million current and former customers. The Medibank breach affected 9.7 million members, with health data including sensitive diagnostic codes subsequently published by the attackers. Together, those two incidents exposed data belonging to roughly 80 per cent of Australia's population [7].

The Australian Parliament passed the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 in November of that year. The reform raised the maximum penalty for serious or repeated privacy violations from A$2.2 million to whichever is greatest: A$50 million, three times the value of any benefit obtained through the breach, or 30 per cent of the entity's adjusted turnover during the relevant period [7].

The Australian Information Commissioner filed civil penalty proceedings in the Federal Court against Medibank in relation to the October 2022 breach. Those proceedings were ongoing as at June 2026. The reform is not a proposal awaiting a test case; the regulatory machinery is in motion.

The NZ Herald published analysis that, in Australia, ManageMyHealth "would now be staring down the barrel of a $60m fine" [8]. The underlying A$50 million floor, confirmed from the Office of the Australian Information Commissioner, is the minimum exposure for a large-scale health breach before the turnover-multiple test applies. The 30 per cent of adjusted turnover calculation would likely produce a higher figure. The Australian Clinical Labs precedent, a A$5.8 million penalty imposed in 2025 for health privacy violations, confirms that the reformed regime is producing outcomes at scale, not merely on paper.

The comparison with other jurisdictions reinforces the picture. The EU General Data Protection Regulation allows supervisory authorities to impose administrative fines of up to €20 million (approximately NZ$36 million) or 4 per cent of an entity's global annual turnover for the most serious violations, whichever is higher [9]. The GDPR model is direct: supervisory authorities issue fines without requiring court proceedings; appeals go to national administrative courts. South Korean regulators imposed a penalty of KRW 624.6 billion (approximately NZ$710 million) against Coupang in June 2026, driven in part by the deliberate destruction of access logs after a preservation order was issued, compounding the breach with post-breach conduct [10].

Against those benchmarks, the enforcement gap is not a matter of degree. New Zealand's maximum procedural criminal fine is approximately five thousand times smaller than Australia's penalty floor for the same class of breach. The comparison does not argue that New Zealand should adopt any single model. It establishes the factual position: the enforcement architecture that currently governs how New Zealand's Privacy Commissioner responds to a serious breach is materially and structurally weaker than the tools available to equivalent regulators in comparable jurisdictions.


Three Reform Vectors Are Already Moving

The Commissioner's 4 June request is not a lone voice asking Parliament to act from a standing start. Three distinct government processes are converging on the same question.

Action 8, Cyber Security Action Plan 2026-2027. The DPMC Cyber Security Action Plan 2026-2027, published by the Department of the Prime Minister and Cabinet, formally tasks the Ministry of Justice with advising on options to introduce a civil pecuniary penalty regime to the Privacy Act [11]. This is an active government workstream, not a proposal awaiting initiation. The Government has already identified the mechanism. The Commissioner's 4 June request is an external input to a process that the Government's own action plan initiated. The accurate framing is not that reform has been demanded and not delivered; it is that an advisory process is under way and reform requires that process to complete before a Bill can be drafted.

DPMC Critical Infrastructure Consultation. The DPMC's consultation on mandatory critical-infrastructure cyber security, which closed on 19 April 2026 and whose submissions were under analysis as at June 2026, proposes a corporate penalty of the greater of NZ$5 million or 2 per cent of turnover, plus director personal liability of up to NZ$500,000 [12]. These penalties apply to critical-infrastructure entities under a separate regime and do not directly affect the Privacy Act. However, they establish the penalty quantum that the Government has already proposed for the adjacent regulatory domain. If the health sector is designated as critical infrastructure under the proposed framework, which the DPMC's own consultation anticipates, the exposure for organisations handling sensitive health data would shift materially.

OPC Phase 2 MMH Inquiry. The Phase 2 inquiry will examine the real-world impact of the breach, authorisation practices, breach communications, data retention and deletion, notification compliance, and whether the breach caused disproportionate harm to Northland Māori [2]. No publication date had been set as at June 2026. Phase 2 findings will add political and regulatory pressure to the civil penalty question as they publish.

The Commissioner's wider reform agenda extends beyond civil penalties. His October 2025 Privacy Act turns-five statement called for a right to erasure, stronger automated decision-making protections, requirements for agencies to demonstrate compliance, and direct audit powers for his office [13]. The fining-powers request is the first item in a package and the most immediately applicable to the MMH accountability gap. For boards, understanding both the immediate question and the broader direction of travel is the relevant framing.


The Structural Argument: Deterrence Must Exist Before the Breach

The Commissioner's request is most usefully understood through the lens of how deterrence functions in regulatory design.

Under the current Act, the financial cost of a serious security failure is remediation plus reputational harm. The compliance notice the Commissioner issues requires an organisation to fix what it should have fixed before the breach. The cost of proactive compliance -- building the controls, implementing multi-factor authentication, deploying anomaly detection -- is therefore compared by boards not against the cost of the failure itself but against the cost of the failure plus a regulatory penalty. Remove the penalty and you reduce the economic case for the pre-breach investment.

This is not an analytical inference from first principles. It is a structural feature of the current enforcement architecture, confirmed by the legal design of section 116. An organisation that reports a serious breach promptly faces a compliance notice and potential HRRT referral. An organisation that reports the same breach and has adequate security controls in place faces no regulatory action at all. The financial consequence of having inadequate controls and suffering a breach -- as distinct from failing to report that breach -- is zero at the regulatory level.

The Once-Only Resilience Framework, which this series introduced in its early editions, establishes that organisations get one opportunity to build resilience before an incident. The Commissioner's argument for fining powers is the regulatory-design equivalent of that framework: the deterrent must exist before the breach, not as a corrective measure applied after the harm has already been done.

The Fiduciary Risk Exposure analysis that boards should already be applying to cybersecurity governance maps the risk to director duties under Companies Act section 137. The Commissioner's international comparators show what that exposure looks like when a civil penalty regime is in place. Under a reformed Privacy Act, the accountability chain from governance failure to financial consequence would be shorter and more certain than it is today: a breach attributable to inadequate security controls, a Commissioner-initiated civil penalty, a financial outcome measurable in millions rather than thousands.

Third-party processor liability adds a further dimension. The OPC Phase 1 report recommends amending the Privacy Act to allow direct liability for third-party providers handling personal information where reasonable security safeguards are not maintained [2]. ManageMyHealth was a third-party vendor operating the portal through which 99,416 patients' records were accessed. Under the current law, Health NZ retained primary regulatory liability; ManageMyHealth's exposure ran through contract. A civil penalty regime that reaches the party that made the security decision -- not merely the agency that contracted them -- closes a structural gap that the MMH scenario illustrated precisely.

The architecture of the Privacy Act was not designed for an era in which a third-party vendor could hold access to 1.8 million registered users' health records and suffer a credential-based breach that ran undetected for an extended period. The Commissioner is asking Parliament to repay that legislative debt.


What Boards Should Do Before the Fine Arrives

Two points follow directly from this analysis, and both are actionable before Parliament moves.

The first is that the risk already exists. Director liability under Companies Act section 137 does not wait for civil penalties to be enacted. Boards that govern organisations holding sensitive personal data have fiduciary obligations today, under the current law, and those obligations are not satisfied by delegating the governance question to compliance teams or relying on contractual assurances from vendors. The MMH breach proceeded because valid credentials were not restricted to legitimate use patterns and because anomaly detection was absent. Both are governance decisions. Neither required a sophisticated attacker to exploit.

The second is that the reform timeline is uncertain but the direction is not. The Ministry of Justice is tasked to advise. The DPMC consultation has proposed NZ$5 million penalties in the adjacent critical-infrastructure domain. The Commissioner has formally described his current enforcement tools as insufficient for the scale of harm that serious breaches can cause. Public survey evidence from March 2025 suggests three-quarters of New Zealanders would support granting the Commissioner the power to impose fines for serious privacy failures [13]. The political conditions for reform are present. The advisory process is under way. The legislative pathway from MoJ advice to Cabinet to Bill to enactment would take at minimum several months even with political consensus.

The relevant board questions are concrete.

Does the organisation have multi-factor authentication deployed on every module or interface through which personal information is accessible, including third-party vendor portals? The MMH breach operated through a module for which MFA was available but not mandatory [2].

Does the organisation have anomaly detection that covers credential-based access patterns at scale? Not just intrusion detection at the perimeter, but behavioural analytics that would flag an authenticated session accessing records in volumes and sequences that no legitimate user would generate?

What is the vendor assurance programme for third-party processors holding personal data? The OPC's third-party-processor liability recommendation points directly at organisations that have contracted out data handling and rely on contractual representations rather than independent verification [2].

Is the board receiving regular reporting on IPP 5 compliance? The information privacy principle requiring reasonable steps to protect personal data is the principle that was breached in the MMH case. It is the principle at the centre of the civil penalty debate. Boards that are not explicitly monitoring IPP 5 compliance are governing a risk they cannot see.

What is the organisation's plan for the twelve months before a civil penalty regime might be enacted? Not a plan to comply once the legislation passes. A plan to have the controls in place before the legislation passes, because the governance duty exists now.

The enforcement architecture is changing. The question for boards is whether the governance architecture is keeping pace.


The enforcement dimension that gets less attention concerns what state-aligned operations do with the data that organisations like ManageMyHealth hold. The National Cyber Security Centre (NCSC NZ) annual threat assessment, produced through New Zealand's contribution to the Five Eyes intelligence-sharing framework, consistently identifies health records and sensitive personal data as priority collection targets for state-aligned threat actors. The MMH breach required no sophisticated intrusion: an attacker on valid credentials accessed records at a scale that no anomaly detection system flagged. That pattern (credential-based, sustained, invisible to passive controls) is the approach state-aligned operations favour because access cost is low and attribution risk is manageable. An enforcement architecture that attaches no financial consequence to the controls gap that enabled that access does not alter the deterrence calculation for an entity conducting low-attribution data collection. The compliance notice addresses the technical gap. It does not change what the data was worth to take.

The privacy reform conversation has finally reached the boardroom. Who in your organisation is making sure the governance architecture arrives before the fine does?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] Office of the Privacy Commissioner. (2025, November). OPC Annual Report 2024-2025. Office of the Privacy Commissioner of New Zealand. https://www.privacy.org.nz

[2] Office of the Privacy Commissioner. (2026, May 27). Phase 1 inquiry findings: ManageMyHealth data breach. Office of the Privacy Commissioner of New Zealand. https://www.privacy.org.nz

[3] Webster, M. (2026, June 4). Privacy Commissioner calls for fining powers [Public statement]. Office of the Privacy Commissioner of New Zealand. Reported by NewsWire NZ and RNZ, 4 June 2026.

[4] Baker McKenzie. (2026). Global Data and Cyber Handbook: New Zealand entry. Baker McKenzie.

[5] Privacy Act 2020. (2020). Sections 116, 118, 213. New Zealand Parliament. https://www.legislation.govt.nz/act/public/2020/0031/latest/whole.html

[6] Privacy Amendment Act 2025. (2025). New Zealand Parliament. https://www.legislation.govt.nz

[7] Australian Parliament. (2022, November). Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. Parliament of Australia. https://www.legislation.gov.au

[8] NZ Herald Tech Insider. (2026, June). What the MMH breach would cost in Australia. NZ Herald. [Full text paywalled; headline and subject confirmed from search result metadata, 19 June 2026. Underlying A$50 million floor confirmed separately from OAIC.]

[9] European Parliament and Council. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation), Article 83. Official Journal of the European Union.

[10] Personal Information Protection Commission, Republic of Korea. (2026, June 11). PIPC penalty ruling: Coupang Inc. KRW 624.6 billion. PIPC. [Previously documented in Cyber Sunday CN#9, 17 June 2026.]

[11] Department of the Prime Minister and Cabinet. (2026). NZ Cyber Security Action Plan 2026-2027, Action 8. DPMC. https://www.dpmc.govt.nz

[12] Department of the Prime Minister and Cabinet. (2026). Critical Infrastructure Cyber Security: Discussion document. DPMC consultation (closed 19 April 2026). https://www.dpmc.govt.nz

[13] Office of the Privacy Commissioner. (2025, October). Privacy Act turns five: Reform priorities. OPC. Survey: 75% of 1,200 respondents supported Commissioner audit and fine powers (March 2025 privacy survey). https://www.privacy.org.nz

Previous
Previous

Cyber Governance: New Zealand's C2 Incidents Are Back After Five Years

Next
Next

The $409 Million Lesson: When Deleting the Logs Costs More Than the Breach