Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.
We respect your Do Not Track preference.
If you find a security issue with our online systems, please tell us so that we can get it fixed. Our goal is to protect people’s privacy. That means getting vulnerabilities fixed as soon as possible. It also means encouraging people to tell us about vulnerabilities. So we want to work with anyone who tells us about vulnerabilities in our system.
As far as practicable we use components of the New Zealand Government Marketplace web platform. If the vulnerability is in the Marketplace then we will need to pass the information on to the Department of Internal Affairs. But we will not pass on your contact details without your permission.
Read Information for Whistleblowers, which also tells you how to alert a vulnerability.
Please tell us what you can of the following information without doing any further work on the vulnerability.
We acknowledge receipt as soon as possible and within 7 working days we will give you an update on the progress of our investigation.
We will look at the reported vulnerability and work with the appropriate service provider to validate the reported vulnerability. We will notify you of what that investigation found and what we decided to do.
We aim to address all vulnerabilities as quickly as possible but are reliant upon contracted suppliers.
If appropriate we will also handle this as a privacy breach and tell people whose personal information may have been disclosed. You can read about how data-related privacy breaches are handled on our website https://privacy.org.nz/responsibilities/privacybreaches We will work with you if you want to publicly disclose finding the vulnerability.
We will work with you if you want to publicly disclose finding the vulnerability.
Some types of behaviour are not reasonable research approaches. Please do not try actions that can cause harm.
Please do not share with others any vulnerability that you find until we have had the opportunity to fix the vulnerability. We don’t want others trying to exploit the vulnerability.
Please do not share any personal information obtained from the Office, because that could cause harm to others. Posting personal information could constitute a breach of the Privacy Act which we might then have to investigate.
If you act in good faith and follow this policy, then we make the following commitments to you:
If you have any queries, please contact us.
Download a copy of this policy (opens to PDF, 133KB).