1,093 Data Breach Notifications: What the Privacy Commissioner’s Numbers Show

Share Article

1,598 complaints and 1,093 breach notifications in the year to 30 June 2025. Two-thirds of closed complaints settled.

The Office of the Privacy Commissioner received approximately 1,598 privacy complaints and 1,093 data breach notifications in the year ending 30 June 2025. Of complaints closed in 2024/25, 67 percent were closed with some form of settlement.

Those numbers are worth reading carefully, because they say something about how privacy problems actually resolve.

Breaches are being notified

Over a thousand notifications in a year indicates the notifiable breach regime is functioning. Under the Privacy Act 2020, where a breach has caused or is likely to cause serious harm, an agency must notify the Privacy Commissioner and affected individuals as soon as practicable.

The failure mode is rarely the decision itself. It is that nobody in the organisation recognised an incident as a privacy breach quickly enough to make the decision at all.

Candidates that do not look like cyber incidents to the person who notices first: a lost laptop, an email sent to the wrong distribution list, a misconfigured cloud folder, a document left on a printer, and a departing employee copying a customer database.

Most complaints settle

Sixty-seven percent closing with a settlement tells you the system is oriented toward resolution rather than punishment. For a business on the receiving end of a complaint, that is useful context — engaging constructively generally produces a better outcome than defending positionally.

It also means most privacy problems are resolvable if handled reasonably at the point they surface.

Compliance notices are being used

In May 2026 the Office confirmed its intention to issue compliance notices to Manage My Health Limited and Health New Zealand for failing to protect health information, following a breach affecting Manage My Health in January 2026.

Compliance notices require an agency to do something, or stop doing something, to comply with the Act. They are a step beyond investigation and they are public.

Health information is among the most sensitive categories, which is why those cases attract the most direct response — but the underlying obligation to protect personal information with reasonable safeguards applies to every business.

What “reasonable safeguards” means practically

For most businesses:

  • Multi-factor authentication, email first. Email is the master key — it resets every other password you own.
  • Access limited to those who need it. Health and personal information should not sit in a general folder readable by any staff member.
  • Removal of access the day someone leaves.
  • Patching, particularly anything internet-facing.
  • Encryption on portable devices.
  • Retention limits — data you no longer need is data that can be breached.

Note that most ransomware now exfiltrates data before encrypting it, which makes a ransomware incident a privacy breach as well as an availability one. Assume exfiltration rather than hoping otherwise.

Know what you hold

Most businesses cannot list every system holding personal information. The inventory is longer than expected: accounting software, payroll, CRM, email, cloud storage, website and e-commerce, marketing platform, point of sale, CCTV, and spreadsheets on individual machines that nobody counts.

For each: what is held, why, who can access it, where it is stored, and how long it is kept.

Businesses doing this for the first time routinely find data they did not know they had, in systems nobody owns, accessible to people who no longer work there.

The obligation runs during the incident

Notification is required as soon as practicable after becoming aware. That runs while you are still fighting the incident, which is why the decision path should be written down beforehand — and kept somewhere not dependent on the systems that may be unavailable.

Notification can be made before the full picture is known and updated later. Waiting for complete information is a common error.

IPP 3A applies now

The Privacy Amendment Act 2025 inserted a new principle covering indirect collection, in force since 1 May 2026. Where you collect personal information from a source other than the individual — a data broker, a marketing list, a credit reporting agency, a related company — a notification obligation applies.

Businesses that buy prospect lists or enrich customer records from third-party sources now have an obligation they did not have before, and the exceptions are narrower than most assume.

The Office of the Privacy Commissioner publishes guidance, breach notification tools and privacy statement templates free at privacy.org.nz, and its material is licensed for reuse with attribution.

Figures: Office of the Privacy Commissioner Annual Report, year ending 30 June 2025; compliance notice announcements May 2026. General information only, not legal advice.

ads-2

Explore Business Topics

Whether you’re running a business, growing your career or simply staying informed, discover expert articles from New Zealand’s most important industries.

Accounting

Tax, bookkeeping, Xero, payroll and financial reporting.

Agriculture

Farming, agribusiness, horticulture, innovation and rural industry news.

Construction

Building, trades, regulations, projects and construction industry updates.

Engineering

Engineering innovation, infrastructure, manufacturing and technical expertise.

Finance

Business finance, investing, lending, insurance and economic insights.

Health

Healthcare, medical services, wellbeing, aged care and industry developments.

Law

Commercial law, employment law, property law and legal guidance.

Logistics

Supply chains, warehousing, fulfilment, freight and logistics solutions.

Property

Commercial property, real estate, investment and market trends.

Retail

Retail trends, eCommerce, customer experience and business growth.

Technology

Artificial intelligence, cybersecurity, software and digital transformation.

Transport

Road, rail, marine, aviation and transport industry developments.