Debate on Crown Entities, Public Organisations,and State Enterprises — Privacy Commissioner
I rise to speak to the financial review of the Privacy Commissioner. I have absolutely no complaints at all, I have to say, about the Office of the Privacy Commissioner; I think it is a very well-respected office. The Privacy Commissioner is very well respected the length and breadth of this country, and certainly I have never, I do not think, heard any claims from the Government that are adverse to this. That brings me to the issue I want to raise under this heading as to why the Privacy Commissioner’s office has not been consulted on the next bill on the Order Paper.
The Office of the Privacy Commissioner, of course, works to develop and promote a culture in which personal information is protected and respected, and that is absolutely correct. The website of the office also states that the Privacy Commissioner’s office has a wide range of functions. Some of these include investigating complaints about breaches of privacy, running education programmes, and examining proposed legislation—my point—and how it may affect individual privacy, which is a very serious issue.
The bill I am referring to is the Social Security (Entitlement Cards) Amendment Bill. I wonder why a Minister such as the Minister of Justice, who prides himself on his thoroughness, has not drawn to the attention of the Government the fact this bill should have come before the Office of the Privacy Commissioner. At the Social Services Committee we investigated this bill in detail, and the Law Society gave us a very good submission on clause 5(2), which allows a microchip to be embedded in the SuperGold card—the smart card put forward by the Minister of Foreign Affairs.
It is interesting, of course, that the Minister of Foreign Affairs considers himself to be part of the Opposition, yet he is able to put forward a Government bill. It is a very interesting concept indeed, but that is what we have. I guess the Order Paper is so short these days that every bill is welcomed. But I think there is a real issue that needs to be addressed in this bill, and that is that clause 5(2) should be omitted. I propose to put forward a Supplementary Order Paper to omit this clause.
I would like, briefly, to go through the recommendations the Law Society made on this bill. The major recommendation was that the committee call for a general review of the principles governing the use of highly functional technology such as microchip technology on Government-issued cards generally, and that the matter be referred to the Office of the Privacy Commissioner. I heartily agree with this point that the Law Society has made. Technology that is not being widely used anywhere else—and, in fact, is not available for use on cards—will now be enshrined in law, setting a precedent that has not been through the proper process.
The proposed provision will allow information—the cardholder’s name, identifying numbers assigned, a coded number indicating the cardholder’s class of eligibility, and a couple of other things—to be carried on embedded microchips, which is a precedent we do not have at present. The Law Society stated that the prospect of microchips being embedded on cards issued by the Government raised a more general concern, due to the functionality that microchips can possess, including their ability to operate as radio frequency ID tags. This matter is a very serious one, indeed.
During the select committee process when the commentary on the bill was being put forward, the ACT party put forward a minority view, which was adopted by the New Zealand National Party and United Future. But the minority view went into the body of the report and stated that we were all very concerned about the introduction of clause 5(2) to allow information to be stored on an embedded microchip. The Government claims it has no plans to use this provision, which begs the question of why this clause is in this legislation in the first place.
ACT members believe therefore that the provision regarding microchips should be deleted, and, as I said, I will put forward a Supplementary Order Paper on that during the Committee stage of this debate. Clause 5(2) should be deleted from the legislation. It is our view that a more general inquiry into the use of microchips—particularly around the issues of privacy, which, of course, would rightly go through the Office of the Privacy Commissioner—is necessary before legislation allowing microchips is enacted. This would enshrine in law a precedent that does not exist at the moment. Who knows where this will go? We have had microchipping of dogs. Now we have microchipping of cards. Where does this matter end?
It is a delight to rise and speak to the financial review of the Privacy Commissioner.
💬 Gerry Brownlee: Not for the people listening. You’ve already had two goes tonight.
Mr Brownlee should give it a chance; he might find it a delight yet.
It is great to hear that the member from the ACT party has such fine things to say about the Privacy Commissioner. It is an entity that as the financial review demonstrates, is performing extremely well. The Justice and Electoral Committee conducted the financial review for the Privacy Commissioner on 15 March. That is when we heard evidence from the current commissioner, Marie Shroff. I was very new to the committee on that occasion, and it was a pleasure to hear her evidence and have her answer the committee’s questions. I have always thought that the entity of the Privacy Commissioner is probably slightly misnamed. Really, the job of the office is all about information management rather than simply privacy, but judging by the material we received from the Audit Office, and the patently very satisfactory answers we received to our questions, it is very clear that the office is good hands under the current commissioner. We noted that the office received good ratings for all aspects of its financial management, and those same ratings were received in the previous financial year.
One thing we did have some questions about was the fact that organisations in the justice sector, like the police, the Ministry of Social Development, the Accident Compensation Corporation, the Immigration Service, and the Department of Corrections tended to feature consistently on the list of entities that were highly complained about, in terms of raw numbers, to the Office of the Privacy Commissioner. So we asked her about that. She said that in fact the numbers that had been reported showed a decline on previous years, and that she felt that the fact there were this number of complaints about these agencies was perhaps at least partly explicable by the nature of their work and the sheer amount of personal information they administer. But it was a good thing to hear that performance was improved there.
We also asked about technology—particularly the effect of increasingly sophisticated technology—on issues such as the greater likelihood of electronic crime, including identity fraud. The commissioner told us that she was aware of these threats, and that she was working very hard to ensure that there was proper awareness by the public about them. In a 2006 public opinion survey, for example, more than 80 percent of respondents signalled that the handling of information on the Internet and by businesses was a key privacy concern. The office has also initiated a regular forum where Government and non-governmental organisations meet to receive information and discuss technology issues regarding the handling of personal information. It is good to see that the commissioner is on the case there, and is dealing with contemporary issues as they arise.
She commented also that the private sector was increasingly taking its privacy obligations seriously, and that the public sector needs to be continually monitored, in terms of the administration of data-matching programmes to ensure that those programmes are being appropriately administered. We welcome that scrutiny.
We were also concerned to ensure that the public had access to information about the role of the commissioner. We heard about a toll-free phone service receiving 6,000 calls a year, a website, and about the plain English information on privacy rights included on it, as well as a text search engine.
We were also very interested to hear that the commissioner’s office was engaged in public education—for example, on changing best practices relating to privacy and information management. One example given was the Credit Reporting Privacy Code 2004 issued by the commissioner, which requires the credit industry to give people free access to their credit records and to limit the information it may store about an individual.
Finally, we heard about the international context of privacy and information management. The office has concluded a memorandum of understanding with the Australian Privacy Commissioner concerning cross-border information exchanges, and is also aware of APEC developments in the privacy and information management area. It is good to know that our international competitiveness is being safeguarded in the privacy and information management area by a very competent and capable public entity such as the Privacy Commissioner.
Again, briefly, I will put on the record my support for, comment on, and acknowledgment of the performance of the Privacy Commissioner. I think Marie Shroff has done an outstanding job. I acknowledge the ACT member Heather Roy’s comments in that regard and thank her for them. Marie has taken a number of steps to further advance the work of the organisation in all areas, in terms of its turn round of inquiry and complaint, and its provision of information. Its reputation, both domestically and internationally, has enhanced the performance of the office.
I thank the members for their comments, although I note that Heather Roy spent a great deal of her time talking about something completely unrelated directly to the financial review. Be that as it may, I thank her for her positive comments.
Report noted.
New Zealand Fire Service Commission
🗣️ Spoke in this debate (3)
- Mark Burton (New Zealand Labour Party — Member for Taupō)
- Charles Chauvel (New Zealand Labour Party — List Member)
- Heather Roy (ACT New Zealand — List Member)