The Rule That Has Been Live Since May

New Zealand's Information Privacy Principle 3A came into force on 1 May 2026. By the first week of October it had been the law for five months and one week. This week's intelligence sweep described it instead as "rapidly approaching its enforcement date... with a shrinking window." Both statements cannot be true. The Ministry of Justice's own announcement, titled without qualification "New privacy information principle now in force," settles which one is.[1]

The same week, on 1 October, the National Cyber Security Centre and New Zealand Police jointly published an advisory. It covered North Korean IT workers obtaining remote contract work in New Zealand under false identities.[2] Its three controls are architecture, not awareness: verify identity, issue a managed device, watch for abnormal access patterns.[3] Neither instrument is new. Both were read this week as if they were.

IPP3A is not abstract. Under the Privacy Amendment Act 2025, an agency that collects personal information about someone indirectly, from any source other than that person, must take reasonable steps to tell them. Four things: that the collection happened and why, who the intended recipients are, whether it was authorised or required by law, and their own rights of access and correction. The Privacy Commissioner's own guidance lists six notifiable matters in total, and nine exceptions, from information already publicly available to cases where the person was already told by whoever collected it first.[4]

The exceptions matter less than a distinction the Commissioner's own guidance draws, using a worked example built around two fictional companies. Where a third party collects or holds information on an agency's behalf, under contract, purely for that agency's own purposes, a payroll processor or a basic IT services vendor, section 11 of the Privacy Act applies instead of IPP3A. The principal agency carries the responsibility throughout. IPP3A applies specifically where the agency later obtains information a third party collected for its own purposes: a credit bureau, a verification service, a reference check, a screening company reporting its own assessment.[4] A verification lookup or an enrichment service sits squarely inside IPP3A's reach. A feed from a contracted processor acting purely on instructions is a section 11 question instead. The mapping exercise a board needs is to classify every vendor by whether it collected this for itself or for us, not simply to list them. An organisation that has never asked that question cannot answer either half of it.

The Commissioner's own guidance makes the distinction concrete with a worked, fictional example: a business called "Swiftstart NZ" that engages a payroll provider called "Clear Consulting" to run its payroll under contract.[4] Clear Consulting is collecting employee information purely as Swiftstart's processor, for Swiftstart's own purposes, so section 11 governs that relationship and Swiftstart carries the responsibility throughout. If Swiftstart instead buys a credit check or a reference report on a job candidate from a separate company that compiled that assessment for its own commercial purposes, that is IPP3A territory. Swiftstart then has to notify the candidate. Two vendors, two different legal bases, and nothing about either arrangement looks different from a procurement spreadsheet. The difference only shows up once someone asks who the information was collected for.

Legal commentary followed the Commissioner's final guidance, published by one account in late November 2025, more than five months ahead of commencement. It describes the core recommendation in exactly those terms: a data mapping exercise, done before worrying about the notification step.[5] Nothing in the sourcing reviewed for this article indicates that any enforcement action has yet been taken under IPP3A specifically. No enforcement action yet does not mean the rule has been tested and passed. The next point worth checking is 1 November 2026, six months after commencement, specifically to see whether the Commissioner has published any enforcement activity or guidance update under the new principle. A board that has not mapped its vendors by then will be answering that question from a standing start, not from a file it already holds.

This series covered the National Cyber Security Centre's Cyber Threat Report 2026 last week. The same DPRK remote-worker case sat inside it then, described only as an attributed account with no independent corroboration beyond the agency's own page. This week's advisory takes that same case and turns it into a named control set for every organisation that might face the next one, rather than reporting something new. The NCSC and Police advisory is the domestic half of a story that started well before this week. North Korea has, on the two agencies' own published assessment, deployed thousands of highly skilled IT workers globally. They pose as remote freelancers under false identities, generating revenue for its nuclear weapon and ballistic missile programmes as a method of evading United Nations sanctions. They also obtain foreign intellectual property and steal data for ransom.[3] That is the agencies' own stated position, reported here as such and not independently assessed by this article. Workers have asked New Zealanders to let their own addresses be used for receiving mail, and their own bank accounts for receiving payments made on the worker's behalf.[3] The advisory assesses likely targets as government agencies, defence contractors, technology companies, financial institutions, large corporates and any organisation holding sensitive information or strategic technology.[3]

The three controls the advisory names are specific and small. Strengthen identity verification. Require anyone working fully remotely to use a managed corporate device rather than their own. Monitor for access patterns that do not match the role.[3] None of the three depends on a staff member noticing something odd. All three are things an organisation builds before it hires anyone.

The advisory did not arrive from nowhere. On 31 July 2026, eleven states issued a joint alert: the United States, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom.[6][7] It warned that North Korean IT workers were using false identities, proxies, location-masking tools and artificial intelligence to obtain remote work and fund the same weapons programmes. New Zealand was one of the eleven signatories. It did not read a warning that other states issued first and catch up two months later. It had already committed, at the multilateral table, to the same position its own domestic regulator set out on 1 October. The advisory is this country's own follow-through on a commitment it made in July.

A related campaign, separately attributed, sharpens the same picture without adding a second New Zealand incident. In September, Japan's National Police Agency, the FBI, the US Department of Defense's Cyber Crime Center, and agencies in Australia and Germany published a joint advisory on a scheme known as WaterPlum. It used fake job interviews and recruiter personas to infect more than 30,000 devices across over 100 countries.[8][9] The scheme stole roughly US$10.7 million in cryptocurrency, chiefly from freelance developers and blockchain specialists. New Zealand is not named as a party to that advisory, and no source reviewed for this article reports a confirmed New Zealand victim of it. Japanese and US investigators assess that WaterPlum's operators and the IT workers behind the recruitment-fraud scheme answer to the same body: the 313 General Bureau of the Munitions Industry Department. It sits under the Workers' Party's Central Committee.[8] The recruitment-fraud limb and the malware limb are two revenue streams run by the same organisation, surfacing in New Zealand and elsewhere through entirely different mechanisms.

Put the two halves of this article beside each other. A board that has mapped where its indirectly collected personal information comes from can answer the Privacy Commissioner's question: have you told the person. A board that has built identity verification, managed devices and access monitoring into its hiring process can answer the NCSC and Police's question: do you actually know who you hired. Neither question is new in October. Both have been live, in one form or another, since well before this week's coverage of them. The recruitment limb and the data governance limb are the same governance failure, read from two different regulators. Each is a live, specific obligation or control set, misread as future because nobody checked whether the organisation already met it.

This book's existing toolkit has a genuine gap here. The Kaitiakitanga Checklist asks whether an organisation has identified which datasets contain Māori data. It also asks whether the organisation is partnering with Data Iwi Leaders Groups for oversight, and whether its access controls prevent bulk exports of community health information. Those are specific, Māori-data questions. IPP3A is not a statutory version of that checklist. The two share format, not substance: a short, named list of "have we identified" questions a director has to answer. IPP3A's own notification duty quietly assumes an agency has already turned that same mechanism on itself.

The Audit of Intent has the same gap, for the second time running. This book's behavioural-detection concept monitors an already-authenticated account for anomalous patterns: unusual downloads, access that does not match normal use. It has nothing useful to say about whether an organisation has mapped where the data it holds about a person actually came from. That is a question about the moment of collection. The Audit of Intent is a tool for the moment of use. The same admission applies to the DPRK hiring case from a second angle: an identity fraud at the point of onboarding is not something a behavioural monitor, however well built, is designed to catch.

Two different gaps, surfaced from two different angles, point at the same weakness in this book's own toolkit. It is strong on watching what an already-trusted account does. It is weak on governing who gets trusted in the first place, and what gets collected about them along the way. A Fiduciary Risk Exposure style reading makes the cost concrete without inventing a new penalty tier, because IPP3A created none. The Cost of Remediation here is the data mapping exercise itself. The Potential Fine or Liability is the same ceiling this series has already established remains unmoved since 2020. The obligation is new. What happens if a board ignores it has not changed at all.

Four actions belong on the agenda before the next board meeting. None of them needs new legislation to start.

List every vendor, service and screening provider that supplies information about a person your organisation did not collect directly. Classify each one by whether it collected that information for itself, a credit bureau, a background checker, a verification service, or purely as your own processor under contract. The first group needs an IPP3A notification pathway. The second does not, because section 11 already covers it.[4] An organisation that has never drawn this line cannot say which of its vendors even needs attention.

Trace the flow for at least the highest-risk category, pre-employment screening, since it is the one this week's advisory and this week's privacy obligation both touch. Know where a candidate's verification data comes from, what the vendor does with it, and whether the person has been told.

Build the three controls the NCSC and Police named into the hiring process itself, not into a policy document nobody consults once it is signed off. Identity verification before an offer goes out. A managed corporate device for anyone fully remote. Monitoring for access patterns that do not match the role, from day one, not from the first complaint.[3]

Set a date to check both items again. Put it on a calendar rather than a risk register nobody opens. Six months after commencement is a sensible point to confirm whether the Commissioner has published anything further, and whether the organisation's own vendor list has actually been built, not merely scheduled.

Put a single question to whoever owns vendor risk: if the Privacy Commissioner asked tomorrow whether we have mapped our indirect collection, could we answer in an afternoon? Or would it take a project? The honest answer to that question is itself a governance signal. An organisation that would need a project has not yet treated 1 May as a date that already happened.

Two New Zealand government publications arrived in the same week, from two different regulators, about two different things. One was a statutory notification duty that has quietly governed every indirect data collection in the country since the first of May. The other was a security advisory about a hiring fraud this country had already committed, in writing, two months earlier, to help counter. Neither was new. Both were reported, this week, as though they were.

A board does not get to choose which regulator's question arrives first. It can choose, in advance, whether the answer is already on file or has to be improvised on the day. For IPP3A, the answer is a vendor list, correctly classified. For the hiring fraud case, it is three controls, already built. Both are available now, not after the next headline makes them unavoidable.

The open-source dimension of this sits in the mapping problem itself, not in either advisory. An organisation that wants to answer the Privacy Commissioner's question, where did this information about a person actually originate, needs to trace a field back through every system that touched it. Tooling for exactly that exists in the open-source data governance space. Apache Atlas, a metadata and lineage project under the Apache Software Foundation, lets an organisation follow a piece of data across its own systems rather than take a vendor's word for where it came from.[10] None of this is exotic engineering. It is published, inspectable and free to run before a regulator asks, rather than after. The same habit of inspectability, applied one level up, is what makes a multilateral advisory worth acting on at all: a control only earns trust once someone outside the vendor can see how it works.

The 1 October advisory is part of a wider shift in how allied states share cyber and sanctions intelligence. New Zealand's July signature sat alongside the United States, Japan, South Korea, Australia, Canada, France, Germany, Italy and the Netherlands, a grouping considerably wider than the Five Eyes partnership that more often anchors this argument. That breadth matters for sovereignty planning. New Zealand's access to allied threat intelligence increasingly runs through coalitions assembled issue by issue, not through one fixed alliance structure. A board's own threat model should expect intelligence to arrive through whichever coalition forms around a specific threat, not only through the partners it is used to naming. The domestic advisory that followed is the operational half of a commitment this country made at the multilateral table two months earlier.

When your organisation last engaged a verification service, a background checker or a reference-check vendor, could you say today whether that counted as your own collection or theirs? And who was supposed to be told?

If your board wants an independent AI and cyber risk briefing, or a review of what your vendor's assurance actually verified, message me and I will send the scope and the fixed fee.

• • •

The views expressed in this article are entirely my own, informed by morethan 30 years of professional experience in architecture, security, andtechnology leadership in New Zealand. I write as director of Te PonoLimited; the views are personal and do not represent the position of anyclient, any government agency, or the New Zealand government. My commentaryon legislation and policy is analytical, drawing on publicly availablesources and my professional expertise in architecture, security, and AIgovernance, and it is politically neutral.

• • •


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance. Through Te Pono he provides independent AI and cyber risk briefings and vendor assurance reviews to boards; contact andreas@thehambergerreport.com for the scope and fixed fee.


This article was produced with AI assistance under my direction. Research,drafting and images pass through a pipeline I built and govern: automatedgates for source verification, forbidden language and political neutrality,and my own review before anything is published. The tools include Claude,Gemini and Openart. The frameworks, arguments and editorial judgements aremine and are the same discipline I apply to the AI systems I audit forclients. AI accelerated the work; the thinking, and the responsibility forit, are mine.


[1] Ministry of Justice (New Zealand). "New privacy information principle now in force." 2026. https://www.justice.govt.nz/about/news-and-media/news/new-privacy-information-principle-in/

[2] National Cyber Security Centre (New Zealand) and New Zealand Police. "Cyber risks of Democratic People's Republic of Korea IT workers to New Zealand organisations." 1 October 2026. https://www.ncsc.govt.nz/alerts/cyber-risks-of-democratic-peoples-republic-of-korea-it-workers-to-new-zealand-organisations/

[3] RNZ. "Businesses warned over North Korean workers posing as freelancers." 1 October 2026. https://www.rnz.co.nz/news/business/1672593/businesses-warned-over-north-korean-workers-posing-as-freelancers

[4] Office of the Privacy Commissioner (New Zealand). "IPP3A." Accessed October 2026. https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/

[5] MinterEllison. "Final IPP3A guidance released." 2026. https://minterellison.co.nz/insights/final-ipp3a-guidance-released

[6] UPI. "South Korea, US, Japan joint alert: North Korea IT workers." 31 July 2026. https://www.upi.com/Top_News/World-News/2026/07/31/South-Korea-US-Japan-joint-alert-North-Korea-IT-workers/3071785518557

[7] NK News. "11 nations issue first-ever joint alert on North Korean IT worker schemes." August 2026. https://www.nknews.org/2026/08/11-nations-issue-first-ever-joint-alert-on-north-korean-it-worker-schemes/

[8] SecurityWeek. "Japan dismantles first North Korean 'laptop farm' as US and allies detail wider scheme." 2026. https://www.securityweek.com/japan-dismantles-first-north-korean-laptop-farm-as-us-and-allies-detail-wider-scheme/

[9] VOA News. "WaterPlum: fake job interviews used to steal cryptocurrency." 2026. https://www.voanews.com/a/waterplum-fake-job-interviews/8207210.html

[10] Apache Software Foundation. "Apache Atlas." Accessed October 2026. https://atlas.apache.org/

Next
Next

The Questions Are Now Addressed to the Board