Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

A blurred photo of a lawyer sitting at a desk. The focus is on a statue of the scales of justice on the right of the image. What happened

In November 2025 a legal practice notified us of a privacy breach. The incident concerned unauthorised access to an email account, identified by the agency in May 2025, which enabled an unknown third-party to access sensitive personal information about its clients. The six-month delay between when the agency became aware of the incident and when OPC and individuals were notified of the notifiable privacy breach was a key concern. 

The agency received forensic findings in May 2025 and did not appreciate that the findings also identified a privacy breach, which required assessment under the Privacy Act. That assessment would have determined whether OPC and affected individuals should be notified. The agency did not have an incident response plan to deal with privacy breaches and the individual responsible for privacy matters (the agency’s office manager) had not received adequate privacy training. As a result, the agency was not well-positioned to identify and promptly respond to the privacy breach that had happened because of the cyber security incident.

Because the legal practice had not recognised that the cyber security incident was also a privacy breach, there were delays in determining that it was also a notifiable privacy breach under the Privacy Act, which required notifying OPC and the affected individuals. 

What your organisation can learn from this incident

Organisations and businesses are required to notify OPC and affected individuals of notifiable privacy breaches as soon as practicable

Organisations and business must assess whether a privacy breach has caused or is likely to cause serious harm to the individuals whose personal information has been affected. If it does, it is a notifiable privacy breach under section 112 of the Privacy Act.

Organisations are required to notify OPC and the affected individuals of any notifiable privacy breach as soon as practicable after becoming aware that the breach has occurred. Becoming aware of a notifiable breach requires some degree of knowledge or an assessment about the risk of harm from the privacy breach. Information known by your employees or agents (third-party providers) is treated as being known by the organisation. Third-party contracts should include the requirement to inform the contracting agency about a privacy breach so that they can fulfil their obligations.

We expect that OPC is notified within 72 hours of an organisation becoming aware that a breach is notifiable. An organisation can fulfil its notification requirements to our Office and affected individuals on an incremental basis, under section 117(5) of the Privacy Act, so long as the organisation does this as soon as reasonably practicable after finding out that information. 

When there is a notifiable privacy breach, the agency is required to notify the people affected unless an exception applies. These requirements are intended to allow an affected individual to take steps to mitigate their own risk. For example, by changing relevant passwords. An affected individual may complain to OPC about an interference with their privacy if they believe that the organisation did not notify them of the privacy breach as soon as practicable.

Where it is not reasonably practicable to notify affected individuals or a group of them, public notice must be given instead.

Importance of an incident response plan

It is crucial for organisations to develop and maintain a plan to respond to privacy breaches that impact the personal information they are responsible for. They should also practice the plan. An incident response plan will enable you to respond quickly to a breach or incident, which can potentially decrease the impact on affected individuals, reduce the costs associated with dealing with a breach, and reduce the potential reputational damage to your organisation. Our free online toolkit Poupou Matatapu includes guidance about privacy breach management and creating an incident response plan. 

Part of an incident response plan includes ensuring that your agency’s appointed privacy officer can identify and respond to a privacy incident and that you have appropriate processes in place to assess whether the privacy incident requires notification to OPC and affected individuals. 

Training

Good privacy is everyone’s responsibility. As well as ensuring your privacy officer is well equipped to support your organisation, everyone in your organisation should have a basic understanding of what good privacy practice is and how to spot and escalate privacy issues including possible breaches. This can be achieved by creating a privacy training programme.

OPC has free online training covering a variety of privacy topics on our e-learning modules, which can help to build capability within your organisation.

Resources