
IR-01-26-23336
21 July 2026
Marcus
[FYI request #35001 email]
Dear Marcus
Request for information
Thank you for your Official Information Act 1982 (OIA) request of 30 June 2026, in which
you requested copies of the Privacy Impact Assessments (PIAs) performed for Staff Safety
Persons of Interest (SSPOI) and Search X.
Police has identified the following documents within the scope of your request:
•
Privacy Impact Assessment High Risk Person of Interest
•
Privacy Impact Assessment Search X
Copies of these documents are attached. Certain information has been withheld under
section 9(2)(a) of the OIA to protect people’s privacy.
We trust this response addresses your areas of interest. If not, you have the right to seek
an investigation and review by the Ombudsman of the way your request has been handled.
Information on how to do so is available at
www.ombudsman.parliament.nz or freephone
0800 802 602.
Respectful y
Mike Webb
Chief Assurance Officer
New Zealand Police
Brief Privacy Analysis
SAS HR-POI Dashboard
PROJECT SUMMARY:
Overview
This is a risk-prioritisation model used to rank those who have assaulted police or
have presented/discharged a firearm at a police officer. The algorithm is used to
identify individuals who have a high chance of assaulting a frontline officer.
A data mining and regression modelling approach has been used to identify common
features amongst individuals who in the past have either assaulted a police officer or
presented or discharged a firearm at a police officer.
Methodology
As an initial step, the case notes of 34 people who had presented or discharged a
firearm at a police officer in the last 2 years were examined in detail.
In total, all people with a person record number in NIA were assessed (2.5 million
people) across 2,100 metrics. Metrics included: presence or absence in a table; counts
of codes, flags and IDs, date and date-time frequencies; percentiles (including 10th
25th, 75th, 90 percentiles), medians, means and counts of all continuous numeric data.
All individuals were then assigned one of two outcome categories. Those that had
assaulted a police officer and those that hadn’t.
The regression modelling identified several metrics that were common amongst
individuals who had assaulted a police officer or who had presented or discharged a
firearm at a police officer.
Key metrics (46) that were highly predictive included cleared offence counts, number
of prosecutions, offending severity, family violence offending, recency of offending,
frequency of alerts etc. These features were also highlighted via a deep dive into the
case notes of these individuals.
Ethnicity, gender, age, gang affiliation, and location identifiers were not predictive or
important to the model.
Outputs
The model was used to develop a matrix of scores, and a list of people who may,
based on their offending history, present a risk to frontline staff in the future. The list
is designed to inform decision making in relation to contact with these individuals.
The model, the matrix of scores, and the list are regularly checked, validated, and
updated monthly. The dashboard updates daily.
Primary and secondary functions
The key function of this technology is as an early warning system to alert frontline
staff to people who are high risk.
This is carried out via a NIA Safety Alert (staff will be
notified of the risk via a NIA Safety Alert).
Secondary functions include:
• Identifying high risk individuals with active warrants to arrest.
• Wrapping social services around high risk individuals to prevent further
instances of crime and harm.
1.2 PERSONAL INFORMATION THAT THE PROJECT WILL INVOLVE
Type of personal
Source of
Purpose of information
Information
Information
for the project
A wide range of variables
NIA records
To form the basis of a risk
associated with an individual NIA
identification and
record. Examples include:
cleared
prioritisation model.
offence counts, number of
Individuals are added to a list
prosecutions, offending severity,
depending on the algorithm-
family violence offending, recency
generated risk ranking.
of offending, frequency of alerts
etc.
2. PRIVACY ASSESSMENT
2.1 AREAS THAT ARE RISKY FOR PRIVACY
Does the project involve
Yes
No
If yes, explain your response
any of the fol owing?
(tick) (tick)
Information management general y
A substantial change to an existing policy,
process or system that involves personal
The HR-POI Dashboard uses statistical
information
modelling and regression analysis to
Example: New legislation or policy that
identify individuals who are likely to
makes it compulsory to col ect or disclose
present a safety risk to frontline staff.
information
The algorithm has a 90% accuracy rate.
The list currently includes around 3,000
names.
This approach is distinct from the
approach to date, which has been
structured around the national Top 5
Most Wanted. This has performed
poorly as a predictive risk tool.
Does the project involve
Yes
No
If yes, explain your response
any of the fol owing?
(tick) (tick)
Any practice or activity that is listed on a risk
[check re alg orithm]
register kept by your organisation
Example: Practices or activities listed on our
risk register or personal and safety register
Collection
A new collection of personal information
Example: Col ecting information about
individuals’ location
A new way of collecting personal information
Example: Col ecting information online rather
than on paper forms
Storage, security and retention
A change in the way personal information is
stored or secured
Example: Storing information in the cloud
A change to how sensitive information is
managed
Example: Moving personal or financial
records to a new database
Transferring personal information offshore or
using a third-party contractor
Example: Outsourcing the payrol function or
storing information in the cloud
Use or disclosure
A new use or disclosure of personal
Polic e staff can be expected to rely on
information that is already held
and take action based on the
Example: Sharing information with other
information provided in the dashboard.
parties in a new way
The reliability of the dashboard as a
predictive tool depends on the accuracy
of the algorithm (90%).
Noting the inherent biases in Police -
held data, particularly regarding
ethnicity and gender.
Noting the need to provide for
appropriate controls over access to the
dashboard.
The expectation is that staff use the
dashboard in conjunction with a TENR
risk assessment, rather than as a
predictive tool alone.
Sharing or matching personal information
held by different organisations or currently
held in different datasets
Example: Combining information with other
information held on public registers, or
sharing information to enable organisations
to provide services jointly
Individuals’ access to their information
Does the project involve
Yes
No
If yes, explain your response
any of the fol owing?
(tick) (tick)
A change in policy that results in people
having less access to information that you
hold about them
Example: Archiving documents into a facility
from which they can’t be easily retrieved
Identifying individuals
Establishing a new way of identifying
Cu
rrently there is no way to exclude a
individuals
person or remove them from the list.
Example: A unique identifier, a biometric, or
There could be a benefit in reflecting
an online identity system
the currency of the offending.
Individuals will be flagged on NIA with
an alert.
The algorithm currently has no process
for review at present.
New intrusions on individuals’ property, person or activities
Surveillance, tracking or monitoring of
movements, behaviour or communications
Example: Installing a new CCTV system
Changes to our premises that will involve
private spaces where clients or customers
may disclose their personal information
Example: Changing the location of the
reception desk, meeting rooms where people
may discuss personal details
New regulatory requirements that could lead
to compliance action against individuals on
the basis of information about them
Example: New legislative conditions for a
service i.e. vetting
List anything else that may impact on privacy,
such as bodily searches, or intrusions into
physical space
2.2 INITIAL RISK ASSESSMENT
If you answered “Yes” to any of the questions above, use the table below to give a rating –
Low (L),
Medium (M), or
High (H) – for each of the aspects of the project set out in the first column.
For risks that you’ve identified as Medium or High, indicate (in the right-hand column) how the
project plans to mitigate or eliminate the risk (if this is known).
If you answered “No” to al the questions in 2.1 above, move on to section 3 below.
Aspect of the Project
Rating
Describe any medium and high
(L, M or H)
risks and how to mitigate them
Level of information handling
H
The Dashboard represents a substantial
L – Minimal personal information will be
collation and processing of NIA-held data.
handled
M – A moderate amount of personal
Access to NIA and the Dashboard is
information (or information that could
limited to Police staff with a business
become personal information) will be
need. Access to the list is only on a need
handled
to know basis (access to the HRPOI is
H – A significant amount of personal
restricted to approved staff that have
information (or information that could
been nominated by districts) who need
become personal information) will be
access to the list for their roles (for
handled
example – DMIs, AOS Commanders, Intel
staff).
Access is control ed and must be
requested through the BAU support
process. Access will be regularly audited
and reviewed.
Sensitivity of the information (eg
M
Access to NIA and the Dashboard is
personal, financial, race)
limited to Police staff with a business
L – The information will not be sensitive
need. Access to the list is only on a need
M – The information may be considered
to know basis (access to the HRPOI is
to be sensitive
restricted to approved staff that have
H – The information will be highly
been nominated by districts) who need
sensitive
access to the list for their roles (for
example – DMIs, AOS Commanders, Intel
staff).
Access is control ed and must be
requested through the BAU support
process. Access will be regularly audited
and reviewed.
Significance of the changes
M
The HR POI Dashboard represents a
L – Only minor change to existing
change in the way NZ Police identifies
functions/activities
high risk individuals.
M – Substantial change to existing
functions/activities; or a new initiative
An annual review of the ongoing
H – Major overhaul of existing
suitability and function of the Dashboard
functions/activities; or a new initiative
is proposed by the business owner. A
that’s significantly different
review of the algorithm and any
adjustments could be part of the annual
review process.
A governance / oversight body is yet to be
identified. [check]
Interaction with others
L
L – No interaction with other agencies
M – Interaction with one or two other
agencies
H – Extensive cross-agency (that is,
government) interaction or cross-
sectional (non-government and
government) interaction
Public impact
M
There may be a public perception risk
L – Minimal impact on the organisation
about Police using a algorithmic tool to
and clients
targeting individuals who are a risk to
M – Some impact on clients is likely due
staff safety, as opposed to the community
to changes to the handling of personal
information; or the changes may raise
It would be appropriate to refer the HR
public concern
POI algorithm to the external panel for its
H – High impact on clients and the wider
consideration and comment.
public, and concerns over aspects of
project; or negative media is likely
Messaging around this tool should reflect
the objectives to protect staff and the
wider community, with better informed
frontline staff who can act to accurately
prevent and deflect high risk interactions.
3. Summary of privacy impact
The privacy impact for this project has been assessed as:
Tick
Low – There is little or no personal information involved; or the use of personal information is
uncontroversial; or the risk of harm eventuating is negligible; or the change is minor and
something that the individuals concerned would expect; or risks are fully mitigated
Medium – Some personal information is involved, but any risks can be mitigated satisfactorily
High – Sensitive personal information is involved, and several medium to high risks have been
identified
Reduced risk – The project will lessen existing privacy risks
Inadequate information – More information and analysis is needed to fully assess the privacy
impact of the project.
3.1 Reasons for the privacy impact rating
The privacy impact is medium to high. The information is whol y based on NIA-held information
sources. The Dashboard and associated list of high risk individuals is sensitive material that would
attract a high public interest.
4. Recommendation
A full privacy impact assessment is not required due to the expectation that the business owners
are referring the Dashboard and algorithm to an oversight body. In addition, it is recommended
that the external panel has the opportunity to review and comment on the algorithm.
5. Sign off
Include
•
Project Manager
•
Legal or Privacy Officer
•
Senior or Executive Leader