This is an HTML version of an attachment to the Official Information request 'Publication of OIA responses'.












d.
Information Records Management Policy
e.
ICT Acceptable Use Policy
f.
Risk Management Policy
g.
Official Information Act Requests Policy
h.
Social Media Policy
i.
Data merging framework
j.
Data sharing guidance
k.
Information Gathering Policy
l.
Legal Services Policy
m.
Te Ki Taurangi – Our promise
n.
Enterprise Data Governance Policy
o.
Child Protection Policy
10. Relevant legislation, regulations and standards
a.
Privacy Act 2020
b.
Privacy Codes of Practice
c.
Official Information Act 1982
d.
Public Records Act 2005
e.
Any other legislation with privacy provisions (e.g., Immigration Act 2009)
f.
Data Protection and Use Policy
g.
Algorithm Charter
11. Measures of success and compliance management
11.1 
The Chief Privacy Officer will assess the effectiveness of this policy based on the following 
measures of success: 
a.
staff are aware of MBIE expectations relating to the collection, storage, use and sharing of
personal information as measured by timely and quality completion and submission of
Privacy Act requests, Privacy Threshold Assessments, and responses to internal staff
surveys
b.
an increase in privacy maturity or maintenance of ‘Managed’ privacy maturity, as rated by
the annual Privacy Maturity Assessment Framework self-assessment and reported to the
Government Chief Privacy Officer
c.
an increase in perceptions of MBIE’s trustworthiness in managing personal information, as
measured by the annual MBIE Privacy Survey, through customer and stakeholder
engagement, and measures such as complaints
d.
a reduction in harm caused through privacy events, as measured by a decrease in upheld
privacy complaints made to MBIE or the Office of the Privacy Commissioner.
11.2 
The Chief Privacy Officer will monitor compliance with this policy as follows: 
a.
a completion rate of 95% mandatory privacy training within MBIE’s induction period (three
months)
b.
completion rate of 100% of Privacy Threshold Assessments for all new initiatives and
changes that impact MBIE’s management of personal information
c.
completion rate of 100% of Privacy Impact Assessments or documented acceptance of risk
from business change owners for all changes where a Privacy Impact Assessment has been
recommended
Title: 
Privacy Policy 
Date of Issue: 
August 2015 
Dep Sec Sponsor: 
Deputy Secretary, Strategy and 
Assurance 
Version: 
5.1 
Last Review: 
November 2023 
Policy Owner: 
Chief Privacy Officer 
Policy Classification: 
Governance 
Next Review: 
November 2026 
Security Classification: 
Unclassified 
Page 7 of 8 

d. 
event reporting and analysis of all privacy events reported to the Privacy Team to assess the 
effectiveness of the Policy. 
11.3 
Compliance information regarding the performance of this policy will be provided to the relevant 
business group and the Enterprise Risk, Compliance and Insurance branch on a quarterly basis. 
12. Non-compliance 
12.1 
Failure to comply with this policy may be considered a breach of the Code of Conduct. 
12.2 
Any action taken as a result of a breach of any of the obligations set out in this policy will be 
conducted in good faith, a fair process will be followed and the person involved will have a full 
opportunity to respond to the concerns or al egations. 
Title: 
Privacy Policy 
Date of Issue: 
August 2015 
Dep Sec Sponsor: 
Deputy Secretary, Strategy and 
Assurance 
Version: 
5.1 
Last Review: 
November 2023 
Policy Owner: 
Chief Privacy Officer 
Policy Classification: 
Governance 
Next Review: 
November 2026 
Security Classification: 
Unclassified 
Page 8 of 8