We don't know whether the most recent response to this request contains information or not – if you are Phillip Fry please sign in and let everyone know.

Role-based access controls and audit oversight

Phillip Fry made this Official Information request to Ministry of Education

This request has an unknown status. We're waiting for Phillip Fry to read a recent response and update the status.

From: Phillip Fry

Dear Ministry of Education,

Given recent public reporting on cyber incidents involving sensitive personal information in New Zealand, there is heightened public interest in understanding the safeguards in place for systems collecting children’s data.

Under the Official Information Act 1982, please provide copies of documents that describe how access to student data within the Student Monitoring, Assessment and Reporting Tool (SMART) is governed, controlled, and monitored.

In particular, I request documents that address:
The role-based access control model for SMART, including which categories of data each role is permitted to access.

Differences in data access between user groups, including teachers, principals, Ministry of Education staff, Janison staff, and any subcontractors.

Whether access to SMART data is identifiable at the individual student level or restricted to aggregated or de-identified views for each role.

Audit logging, monitoring, and review arrangements for access to SMART data, including who can view audit logs and how inappropriate access or misuse is detected and managed.

This request includes any relevant policies, access control matrices, security documentation, contractual provisions, or internal guidance relating to data access and oversight.

Yours faithfully,

Phillip Fry

Link to this

From: Enquiries National
Ministry of Education

Thank you for your email to the Ministry of Education.  
This is an auto generated response confirming your email has been received.
Please do not respond to this message.  
The Ministry of Education is closed for the holiday period between the
25^th of December and 4^th of January.
  
We will respond to your email as soon as possible on our return.   
Happy Holidays!
Tēnā koe mō tō īmēra mai ki te Tāhuhu o te Mātauranga.  
  
He urupare aunoa tēnei hei whakaatu kua tae mai tō īmēra
ki a mātou. Kaua noa e whakautu i tēnei karere.  
  
Mea ake nei ka urupare tonu atu mātou ki tō īmēra. 

  

show quoted sections

Link to this

From: Phillip Fry

Dear Ministry of Education,

For the avoidance of doubt, I am not seeking technical configuration details, encryption keys, network diagrams, or other information that could give rise to concerns under section 6(c) of the Act. I am seeking the governance policies that define how the Ministry protects student privacy. If any document is withheld, I request a summary of the protections and a redacted version of the document in question.

Yours faithfully,

Phillip Fry

Link to this

From: Enquiries National
Ministry of Education


Attachment image001.png
3K Download


[IN-CONFIDENCE - RELEASE EXTERNAL]

Kia ora Phillip,

 

Thank you for the information request below.  The Ministry will consider
and respond to your request in accordance with the Official Information
Act 1982 (the Act).

 

Under section 15(1) of the Act, we are required to make and inform you of
our decision on your request as soon as reasonably practicable and in any
case not later than 20 working days after the day on which your request is
received.  You can therefore expect to receive our decision on your
request on or before 13 February 2026.  If more than 20 working days are
needed due to the potential workload and/or consultations involved in
answering your request, we will notify you accordingly.

 

Please note, the days between 25 December – 15 January (inclusive) are not
considered to be “working days” for the purposes of calculating the 20
working day timeframe for providing a response under the Act.

 

In the interim, if you have any questions about your request, please email
[1][email address].

 

 

Ngâ mihi,

Enquiries National Team | Te Tâhuhu o te Mâtauranga | Ministry of
Education | JH
[2]education.govt.nz
We shape an education system that delivers equitable and excellent
outcomes
He mea târai e mâtou te mâtauranga kia rangatira ai, kia mana taurite ai
ôna huanga

[3]Te TD huhu o te MD tauranga

 

 

Dear Ministry of Education,

 

Given recent public reporting on cyber incidents involving sensitive
personal information in New Zealand, there is heightened public interest
in understanding the safeguards in place for systems collecting children’s
data.

 

Under the Official Information Act 1982, please provide copies of
documents that describe how access to student data within the Student
Monitoring, Assessment and Reporting Tool (SMART) is governed, controlled,
and monitored.

 

In particular, I request documents that address:

The role-based access control model for SMART, including which categories
of data each role is permitted to access.

 

Differences in data access between user groups, including teachers,
principals, Ministry of Education staff, Janison staff, and any
subcontractors.

 

Whether access to SMART data is identifiable at the individual student
level or restricted to aggregated or de-identified views for each role.

 

Audit logging, monitoring, and review arrangements for access to SMART
data, including who can view audit logs and how inappropriate access or
misuse is detected and managed.

 

This request includes any relevant policies, access control matrices,
security documentation, contractual provisions, or internal guidance
relating to data access and oversight.

 

Yours faithfully,

 

Phillip Fry

 

-------------------------------------------------------------------

 

This is an Official Information request made via the FYI website.

 

Please use this email address for all replies to this request:

[4][FOI #33483 email]

 

Is [5][Ministry of Education request email] the wrong address for Official
Information requests to Ministry of Education? If so, please contact us
using this form:

[6]https://fyi.org.nz/change_request/new?bo...

 

Disclaimer: This message and any reply that you make will be published on
the internet. Our privacy and copyright policies:

[7]https://fyi.org.nz/help/officers

 

If you find this service useful as an Official Information officer, please
ask your web manager to link to us from your organisation's OIA or LGOIMA
page.

 

 

-------------------------------------------------------------------

 

show quoted sections

Link to this

From: Phillip Fry

Dear Enquiries National,

To assist the Ministry and reduce scope, I wish to narrow my earlier request.

Please treat the request below as replacing my previous wording. It is limited to formal, authoritative documentation relied upon by the Ministry and does not seek informal correspondence or draft material.

Under the Official Information Act 1982, I request the following information relating to governance and oversight of access to student data within the Student Monitoring, Assessment and Reporting Tool (SMART):

Copies of any formal access control documentation relied upon by the Ministry for SMART, including:

role-based access control (RBAC) specifications or access matrices; and

documentation describing differences in data access between user roles (e.g. teachers, principals, Ministry staff, Janison staff, and subcontractors).

Documentation describing whether SMART data access for each role is:

identifiable at the individual student level, or

restricted to aggregated or de-identified views.

Copies of any formal policies or assurance documents describing audit logging and monitoring of access to SMART data, including:

who can view audit logs; and

how inappropriate access or misuse is detected and managed.

This request is limited to formal, authoritative documents and does not seek informal correspondence or draft material.

Yours sincerely,

Phillip Fry

Link to this

From: Enquiries National
Ministry of Education

Thank you for your email to the Ministry of Education.  
This is an auto generated response confirming your email has been received.
Please do not respond to this message.  
  
We will respond to your email as soon as possible.
Tēnā koe mō tō īmēra mai ki te Tāhuhu o te Mātauranga.     
  
He urupare aunoa tēnei hei whakaatu kua tae mai tō īmēra
ki a mātou. Kaua noa e whakautu i tēnei karere.  
  
Mea ake nei ka urupare tonu atu mātou ki tō īmēra. 

  

show quoted sections

Link to this

We don't know whether the most recent response to this request contains information or not – if you are Phillip Fry please sign in and let everyone know.

Things to do with this request

Anyone:
Ministry of Education only: