This is an HTML version of an attachment to the Official Information request 'Publication of OIA responses'.




Disposal 
In the context of information and records, disposal means 
the decision-making processes for retaining, transferring or 
destroying information and records 
Executive Sponsor 
Person appointed by The Secretary, to oversee information and 
records management at MBIE who ensures compliance with the 
Public Records Act 2005, liaise with Archives New Zealand about 
monitoring and reporting on compliance, and cooperates and 
align best practice process with his/her peers in other 
organisations. 
Information 
For the purposes of this policy, information includes 
information, data, records, and meta-data.  
In this context, information is knowledge, facts or details that 
have been created and/or obtained and managed by MBIE. 
Personal information 
Information about an identifiable, living person. 
Records 
Any information, regardless of form and format, from 
documents through to data. A record includes its metadata, 
which is also managed as a record and the records of any task 
contracted to an independent contractor. 
Records management 
Is an integrated framework of governance arrangements, 
architectures, policies, processes, systems, tools, and 
techniques that enable organisations to create and maintain 
trustworthy evidence of business activity in the form of records. 
Retention and disposal 
A records retention and disposal schedule outline show long 
schedule 
items must be kept and provides disposal guidelines for how 
items should be discarded. 
6  Policy statements 
6.1 
MBIE must have a records management framework (the Framework) as required under the Public 
Records Act 2005 and the Archives New Zealand Information and records management standard 
(the Standard) to manage and maintain full, authentic, accurate and accessible records over time. 
The Framework must include procedures, guidelines, training, and metadata creation.  
6.2 
Archives New Zealand must be advised of MBIE’s Executive Sponsor appointment. 
6.3 
Executive Sponsor responsibility must be included in his/her performance plan. 
6.4 
Our people must comply with the Framework. To support compliance, MBIE will ensure our 
people are aware of their information and records management responsibilities by providing 
training and guidance as required. 
6.5 
MBIE’s information and records storing systems must be configured to ensure appropriate 
classification and management of records, including records of any matters contracted out to 
independent parties.  
6.6 
Records must be stored for as long as they are required by legislation, and protected to prevent 
unauthorised and unlawful access, alteration, damage, loss, deletion, destruction, theft, 
vandalism, misuse, or inadvertent release, using appropriate content management systems. 
6.7 
MBIE must create, maintain, and execute a Retention and Disposal Schedule to enable records to 
be legally retained and disposed of. A register of all authorised disposals will be maintained. 
Title: 
Information and Records 
Date of Issue: 
October 2018 
Dep Sec Sponsor: 
Deputy Secretary Digital, Data & 
Management Policy 
Insights 
Version: 
1.1 
Last Review: 
December 2023 
Policy Owner: 
Chief Data Officer 
Policy Classification: 
Governance 
Next Review: 
December 2026 
Security Classification: 
Unclassified 
Page 3 of 8 





Information Management 

Supports the CDO and the MBIE Executive
Team/Manager 
Sponsor with monitoring and compliance of this
policy

Manage the disposal of all MBIE information
and records, including the transfer of records to
Archives NZ, completion of any Public Records
Act Section 23 transfers

Maintain and manage the disposal register

Maintain and manage the register of all
breaches of this policy
Protective Security Team/Manager 

Ensures that enterprise policy protects
information and records in accordance with the
all-of-government Protective Security
Requirements.
Raraunga Matihiko Māori 

Ensures that the policy gives effect to the
Team/Manager 
principles of te Tiriti o Waitangi / the Treaty of
Waitangi
Technology and Architecture 

Ensures that enterprise systems are compliant
Team/Manager 
with this policy
8  Procedures 
a. DA558 General Disposal Authority 6: Common Corporate Services Public Records
b. DA576 General Disposal Authority 7: Facilitative, Transitory, and/or Short-Term Value Records
c. DA644 MBIE Records Retention and Disposal Schedule
d. Guidance and advice on the management of information and data
9  Related MBIE policies and documents 
a. Enterprise Data Governance Policy
b. ICT Acceptable Use Policy
c. Information Gathering Policy
d. Official Information Act Requests Policy
e. Privacy Policy
f. Protective Security Policy
g. Social Media Channel Policy
10 Relevant legislation, regulations, and standards 
a. Official Information Act 1982
b. Privacy Act 2020
c. Public Records Act 2005
d. Information and Records Management Standard
Title: 
Information and Records 
Date of Issue: 
October 2018 
Dep Sec Sponsor: 
Deputy Secretary Digital, Data & 
Management Policy 
Insights 
Version: 
1.1 
Last Review: 
December 2023 
Policy Owner: 
Chief Data Officer 
Policy Classification: 
Governance 
Next Review: 
December 2026 
Security Classification: 
Unclassified 
Page 6 of 8 

e. Further relevant legislation, regulations and standards listed in Appendix 1 of this policy
11 Measures of success and compliance management 
11.1 
The Chief Data Officer will assess the effectiveness of this policy based on the following measures 
of success: 
a.
At least 90 % of our people complete the relevant learning modules e.g., Records
management 101, MAKO Workshop within 3 months of commencing work with MBIE.
b.
All business groups have information and records management procedures and processes
documented.
c.
Information and records management requirements are documented or reflected in
specifications for systems and metadata schemas.
d.
The decommissioning of systems follows the requirements for disposing of information and
records
e.
Storage solutions are compliant with the requirements of this policy
11.2 
The Chief Data Officer will monitor compliance with this policy as follows: 
a.
Maintain a central register to record breaches of the policy.
b.
Maintain a register of all approved disposals.
11.3 
Compliance information regarding the performance of this policy will be provided to the relevant 
business group and Compliance Centre of Excellence on a quarterly basis.  
12 Non-compliance 
12.1 
Failure to comply with this policy may be considered a breach of the Code of Conduct, and may 
result in the loss of access to data and/or specific IT systems by  individuals or teams.   
12.2 
Any action taken because of a breach of any of the obligations set out in this policy will be 
conducted in good faith, a fair process will be followed, and the person involved will have a full 
opportunity to respond to the concerns or allegations and have access to appropriate support, 
advice, or representation.  
Title: 
Information and Records 
Date of Issue: 
October 2018 
Dep Sec Sponsor: 
Deputy Secretary Digital, Data & 
Management Policy 
Insights 
Version: 
1.1 
Last Review: 
December 2023 
Policy Owner: 
Chief Data Officer 
Policy Classification: 
Governance 
Next Review: 
December 2026 
Security Classification: 
Unclassified 
Page 7 of 8 

Appendix 1: Information and Records Management Policy – Further 
related Legislation, regulations and standards 

a. Contract and Commercial Law Act 2017 (CCLA) section 229(2) mandates the “Authority to retain
public records in electronic (digital) form only.”
b. Companies Act 1993, states company records must be kept years for 7 years.
c. Copyright Act 1994 which protects original works, published or unpublished, in print or stored
electronically, from copying without approval from the copyright owner, unless there is a statutory
exception to such infringement.
d. Crimes Act 1961 and Summary Offences Act 1981 make it an offence to use or disclose information
without authorisation and set out penalties for the unauthorised use or disclosure of that
information.
e. Employment Relations Act 2000 requires employers to maintain wage, time, holiday and leave
records for their employees.
f.
Evidence Act 2006 governs the legal admissibility of documents and affects the form of the record
retained.
g. Financial Reporting Act 2013 defines the standards to be used in preparing financial reports and
obligations in respect of the preparation and audit of financial statements.
h. Health and Safety at Work Act 2015 requires employers to maintain a register of accidents and
incidents where staff are seriously harmed.
i.
Holidays Act 2003 states holiday and leave records must be kept for not less than 6 years.
j.
Patents Act 2013 and the Patents Regulations 2014 sets out the requirements for filing and issuing
patents.
k. Public Finance Act 1989 sets requirements for Crown Agencies in terms of financial reporting and
accountability.
l.
State Sector Act 1988 aims to promote efficiency in the State Services and other agencies; ensure
responsible management; maintain appropriate standards of integrity and conduct among
employees in the State Services and other agencies; ensure that every employer in the State
Services is a good employer; promote equal employment opportunities (EEO); and provide for the
negotiation of conditions of employment in the State Services and other agencies.
m. Tax Administration Act 1994 requires taxpayers and employers to keep records for 7 years for tax
purposes.
n. Public Service Code of Conduct, 2007
o. International Standards Organisation. Information and Documentation: Records Management (ISO
15489), 2001
p. Standards New Zealand, Information Security Risk Management Guidelines. New Zealand Standard
HB 231:2004
q. Protective Security Requirements (maintained by Government Communications and Security
Bureau, NZ Security Intelligence Service and Department of the Prime Minister and Cabinet)
Title: 
Information and Records 
Date of Issue: 
October 2018 
Dep Sec Sponsor: 
Deputy Secretary Digital, Data & 
Management Policy 
Insights 
Version: 
1.1 
Last Review: 
December 2023 
Policy Owner: 
Chief Data Officer 
Policy Classification: 
Governance 
Next Review: 
December 2026 
Security Classification: 
Unclassified 
Page 8 of 8