Schedule 1, s 4
In forcePrinciple 4—Data Security
Schedule 1–The Information Privacy Principles
4 Principle 4—Data Security
4.1 An organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.
4.2 An organisation must take reasonable steps to destroy or permanently de-identify personal information if it is no longer needed for any purpose.
This Act’s bill:Explanatory memorandumSecond reading speech
Research tools for this sectionSubscription
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.