This is an HTML version of an attachment to the Official Information request 'SSPOI and SearchX PIAs'.



IR-01-26-23336 
21 July 2026 
Marcus 
[FYI request #35001 email]  
Dear Marcus 
Request for information 
Thank you for your Official Information Act 1982 (OIA) request of 30 June 2026, in which 
you requested copies of the Privacy Impact Assessments (PIAs) performed for Staff Safety 
Persons of Interest (SSPOI) and Search X. 
Police has identified the following documents within the scope of your request: 

Privacy Impact Assessment High Risk Person of Interest

Privacy Impact Assessment Search X
Copies of these documents are attached. Certain information has been withheld under 
section 9(2)(a) of the OIA to protect people’s privacy.   
We trust this response addresses your areas of interest. If not, you have the right to seek 
an investigation and review by the Ombudsman of the way your request has been handled. 
Information on how to do so is available at www.ombudsman.parliament.nz or freephone 
0800 802 602. 
Respectful y 
Mike Webb 
Chief Assurance Officer 
New Zealand Police 

Brief Privacy Analysis 
 
SAS HR-POI Dashboard 
 
PROJECT SUMMARY:  

 
Overview 
This is a risk-prioritisation model used to rank those who have assaulted police or 
have presented/discharged a firearm at a police  officer.  The algorithm is used to 
identify individuals who have a high chance of assaulting a frontline officer.  
A data mining and regression modelling approach has been  used to identify common 
features amongst individuals who in the past have either assaulted a police  officer or 
presented or discharged a firearm at a police  officer.  
Methodology 
As an initial step,  the case notes of 34 people who had presented or discharged a 
firearm at a police officer in the last 2 years were examined in detail.   
In total, all people with a person record number in NIA were assessed (2.5 million 
people) across 2,100 metrics. Metrics included: presence or absence in a table; counts 
of codes, flags and IDs, date and date-time frequencies; percentiles (including 10th 
25th, 75th, 90 percentiles), medians, means and counts of all continuous numeric data. 
All  individuals were then assigned one of two outcome categories. Those that had 
assaulted a police officer and those that hadn’t. 
The regression modelling identified several metrics that were common amongst 
individuals who had assaulted a police officer or who had presented or discharged a 
firearm at a police officer.  
Key  metrics (46) that were highly predictive included cleared offence counts, number 
of prosecutions, offending severity, family violence offending, recency of offending, 
frequency of alerts etc.  These features were also highlighted via a deep dive into the 
case notes of these individuals.  
Ethnicity,  gender, age, gang affiliation, and location identifiers were not predictive or 
important to the model.  
Outputs 
The model was used to develop a matrix of scores, and a list of people who may, 
based on their offending history, present a risk to frontline staff in the future. The list 
is designed to inform decision making in relation to contact with these individuals. 
The model, the matrix of scores, and the list are regularly checked, validated, and 
updated monthly. The dashboard updates daily. 
Primary and secondary functions 
 

The key function of this technology is as an early warning system to alert frontline 
staff to people who are high risk. This is carried out via a NIA Safety Alert (staff will be 
notified of the risk via a NIA Safety Alert). 
Secondary functions include: 
•  Identifying high risk individuals with active warrants to arrest. 
•  Wrapping social services around high risk individuals to prevent further 
instances of crime and harm. 
 
 
1.2 PERSONAL INFORMATION THAT THE PROJECT WILL INVOLVE 
 
  Type of personal 
Source of 
Purpose of information 
Information 
Information 
for the project 
A wide range of variables 
NIA records 
To form the basis of a risk 
associated with an individual NIA 
identification and 
record. Examples include: cleared 
prioritisation model.  
offence counts, number of 
Individuals are added to a list 
prosecutions, offending severity, 
depending on the algorithm-
family violence offending, recency 
generated risk ranking. 
of offending, frequency of alerts 
 
 
etc.   
 
2. PRIVACY ASSESSMENT 

 
2.1 AREAS THAT ARE RISKY FOR PRIVACY 

  Does the project involve 
Yes 
No 
If yes, explain your response 
any of the fol owing? 
(tick)  (tick) 
Information management general y 
A substantial change to an existing policy, 
   
 
 
process or system that involves personal 
The HR-POI Dashboard uses statistical 
information 
modelling and regression analysis to 
Example: New legislation or policy that 
identify individuals who are likely to 
makes it compulsory to col ect or disclose 
present a safety risk to frontline staff. 
information 
The algorithm has a 90% accuracy rate. 
The list currently includes around 3,000 
names. 
This approach is distinct from the 
approach to date, which has been 
structured around the national Top 5 
Most Wanted. This has performed 
poorly as a predictive risk tool. 
 

Does the project involve 
Yes 
No 
If yes, explain your response 
any of the fol owing? 
(tick)  (tick) 
Any practice or activity that is listed on a risk   
  [check re alg  orithm] 
register kept by your organisation 
Example: Practices or activities listed on our 
risk register or personal and safety register 
Collection 
A new collection of personal information 
 
 
 
 
Example: Col ecting information about 
individuals’ location 
A new way of collecting personal information 
 
   
 
Example: Col ecting information online rather 
than on paper forms 
Storage, security and retention 
A change in the way personal information is 
 
   
 
stored or secured 
Example: Storing information in the cloud  
A change to how sensitive information is 
 
   
 
managed 
Example: Moving personal or financial 
records to a new database 
Transferring personal information offshore or 
 
   
 
using a third-party contractor 
Example: Outsourcing the payrol  function or 
storing information in the cloud 
Use or disclosure 
A new use or disclosure of personal 
   
Polic e staff can be expected to rely on 
information that is already held 
and take action based on the 
Example: Sharing information with other 
information provided in the dashboard. 
parties in a new way 
The reliability of the dashboard as a 
predictive tool depends on the accuracy 
of the algorithm (90%). 
Noting the inherent biases in Police -
held data, particularly regarding 
ethnicity and gender. 
Noting the need to provide for 
appropriate controls over access to the 
dashboard. 
The expectation is that staff use the 
dashboard in conjunction with a TENR 
risk assessment, rather than as a 
predictive tool alone. 
 
Sharing or matching personal information 
 
   
 
held by different organisations or currently 
held in different datasets 
Example: Combining information with other 
information held on public registers, or 
sharing information to enable organisations 
to provide services jointly 
Individuals’ access to their information 

Does the project involve 
Yes 
No 
If yes, explain your response 
any of the fol owing? 
(tick)  (tick) 
A change in policy that results in people 
 
   
 
having less access to information that you 
hold about them 
Example: Archiving documents into a facility 
from which they can’t be easily retrieved  
Identifying individuals 
Establishing a new way of identifying 
   
Cu  
rrently there is no way to exclude a 
individuals 
person or remove them from the list. 
Example: A unique identifier, a biometric, or 
There could be a benefit in reflecting 
an online identity system 
the currency of the offending.   
Individuals will be flagged on NIA with 
an alert. 
The algorithm currently has no process 
for review at present. 
New intrusions on individuals’ property, person or activities 
 
 
 
 
Surveillance, tracking or monitoring of 
 
   
 
movements, behaviour or communications 
Example: Installing a new CCTV system 
Changes to our premises that will involve 
 
   
 
private spaces where clients or customers 
may disclose their personal information 
Example: Changing the location of the 
reception desk, meeting rooms  where people 
may discuss personal details 
New regulatory requirements that could lead   
   
 
to compliance action against individuals on 
the basis of information about them 
Example: New legislative conditions for a 
service i.e. vetting 
List anything else that may impact on privacy,   
   
 
such as bodily searches, or intrusions into 
physical space 
 
2.2 INITIAL RISK ASSESSMENT 

If you answered “Yes” to any of the questions above, use the table below to give a rating – Low (L)
Medium (M), or High (H) – for each of the aspects of the project set out in the first column. 
 
For risks that you’ve identified as Medium or High, indicate (in the right-hand column) how the 
project plans to mitigate or eliminate the risk (if this is known). 
If you answered “No” to al  the questions in 2.1 above, move on to section 3 below. 
 
Aspect of the Project 
Rating 
Describe any medium and high  
(L, M or H) 
risks and how to mitigate them 

 Level of information handling 

 The Dashboard represents a substantial 
L – Minimal personal information will be 
collation and processing of NIA-held data. 
handled 
 
M – A moderate amount of personal 
Access  to NIA and the Dashboard is 
information (or information that could 
limited to Police staff with a business 
become personal information) will be 
need. Access to the list is only on a need 
handled 
to know basis (access to the HRPOI is 
H – A significant amount of personal 
restricted to approved staff that have 
information (or information that could 
been nominated by districts)  who need 
become personal information) will be 
access to the list for their roles (for 
handled 
example – DMIs, AOS Commanders, Intel 
staff). 
Access is control ed and must be 
requested through the BAU support 
process. Access will be regularly audited 
and reviewed. 
 
Sensitivity of the information (eg 

Access to NIA and the Dashboard is 
personal, financial, race) 
limited to Police staff with a business 
L – The information will not be sensitive 
need. Access to the list is only on a need 
M – The information may be considered 
to know basis (access to the HRPOI is 
to be sensitive 
restricted to approved staff that have 
H – The information will be highly 
been nominated by districts)  who need 
sensitive 
access to the list for their roles (for 
example – DMIs, AOS Commanders, Intel 
staff). 
Access is control ed and must be 
requested through the BAU support 
process. Access will be regularly audited 
and reviewed. 
 
Significance of the changes 

The HR POI Dashboard represents a 
L – Only minor change to existing 
change in the way NZ Police identifies 
functions/activities 
high risk individuals. 
M – Substantial change to existing 
 
functions/activities; or a new initiative 
An annual review of the ongoing 
H – Major overhaul of existing 
suitability and function of the Dashboard 
functions/activities; or a new initiative 
is proposed by the business owner. A 
that’s significantly different 
review of the algorithm and any 
adjustments could be part of the annual 
review process. 
A governance / oversight body is yet to be 
identified. [check] 

Interaction with others 

 
L – No interaction with other agencies 
M – Interaction with one or two other 
agencies 
H – Extensive cross-agency (that is, 
government) interaction or cross-
sectional (non-government and 
government) interaction 
Public impact 

There may be a public perception risk 
L – Minimal impact on the organisation 
about Police using a algorithmic tool to 
and clients 
targeting individuals who are a risk to 
M – Some impact on clients is likely due 
staff safety, as opposed to the community 
to changes to the handling of personal 
 
information; or the changes may raise 
It would be appropriate to refer the HR 
public concern 
POI algorithm to the external panel for its 
H – High impact on clients and the wider 
consideration and comment. 
public, and concerns over aspects of 
 
project; or negative media is likely 
Messaging around this tool should reflect 
the objectives to protect staff and the 
wider community, with better informed 
frontline staff who can act to accurately 
prevent and deflect high risk interactions. 
 
3.  Summary of privacy impact 
The privacy impact for this project has been assessed as: 
Tick 
Low – There is little or no personal information involved; or the use of personal information is 
uncontroversial; or the risk of harm eventuating is negligible; or the change is minor and 
 
something that the individuals concerned would expect; or risks are fully mitigated 
Medium – Some personal information is involved, but any risks can be mitigated satisfactorily 
 
 
High – Sensitive personal information is involved, and several medium to high risks have been 
identified 
 
 
Reduced risk – The project will lessen existing privacy risks 
 
Inadequate information – More information and analysis is needed to fully assess the privacy 
impact of the project. 
 
 
3.1  Reasons for the privacy impact rating 

 
The privacy impact is medium to high. The information is whol y based on NIA-held information 
sources. The Dashboard and associated list of high risk individuals is sensitive material that would 
attract a high public interest. 
 
4.  Recommendation  
  A full privacy impact assessment is not required due to the expectation that the business owners 
are referring the Dashboard and algorithm to an oversight body. In addition, it is recommended 
that the external panel has the opportunity to review and comment on the algorithm. 
 
5. Sign off 

 
Include 
• 
Project Manager 

• 
Legal or Privacy Officer 
• 
Senior or Executive Leader