🧪 EXPERIMENTAL / ALPHA — this is an independent prototype, not an official record. Data may be incomplete or wrong - always check the linked Hansard source before relying on it.
Hot Air

Tuesday, 13 November 2012

Electronic Identity Verification Bill

Part 3 Miscellaneous provisions
HansardID: 66e6bc9d-561a-4a7b-a34d-d81c05e111e7
Back to debates
šŸ—£ļø Speech Ruth Dyson (New Zealand Labour Party — Member for Port Hills)
Time unknown

Thank you very much for giving me the opportunity to speak on Part 3 of the Electronic Identity Verification Bill. This is one of two bills that the Committee will be considering during the course of the evening relating to very similar activities.

I want to just draw your attention to the fact that over the dinner break—there are always interesting conversations, are there not, that occur over the dinner break—this evening there were several conversations happening at the table that I was at. My friend and colleague Kris Faafoi was talking about his children, and referred to one of them by his nickname, Freddie. At the other side of the table Annette King, who was listening, misunderstood the conversation, thinking we were talking about Freddie Mercury, and started talking about how fabulous Queen was. Then somebody else at another part of the table thought we were talking about the royal visit. It actually was quite confusing. I can see that the Minister in the chair, the Minister for the Environment, is very intrigued by it. It brought us to the point of saying how important clarity of identification is, which is actually the very point of this legislation—to ensure that—

šŸ’¬ Hon Amy Adams: It’s a long way round.

Well, you know, elaboration can sometimes be of assistance. I look forward to my neighbour from Canterbury the Hon Amy Adams taking a call. I am sure she will make a fine contribution in this debate.

I had the pleasure of chairing the Government Administration Committee. As the Committee will notice, in Part 3, ā€œMiscellaneous provisionsā€ā€”sometimes when you get to miscellaneous provisions you think ā€œWell, there’s not a lot left in this bill.ā€ā€”there are a few quite significant amendments that have been made by the select committee. Perhaps more important, and I will speak on this in a later call, Supplementary Order Paper 128, which is the only Supplementary Order Paper that I have yet seen tabled in the name of the Minister of Internal Affairs, the Hon Chris Tremain, who has not yet taken a call—I am sure the Hon Amy Adams, who is standing in for him in the meantime, will do a fine job—actually amends this part of the bill.

In clause 54, which is the first clause in this part, the select committee removed the entire original drafting and replaced it. It is pretty important to note the specificity of that, given that the clause is dealing with the Official Information Act. We obviously had concerns about information obtained under the Official Information Act, and we wanted to make sure that the relevant sections that are described in clause 54 are, in fact, adhered to, and to ensure that there is clarity in the relationship between this bill, the Electronic Identity Verification Bill, and the Official Information Act. The select committee clarified in paragraph (a) that ā€œsections 20A to 21A are given precedence by section 52(3)(a) and (b)ā€ of the Official Information Act. Paragraph (b) of the new clause 54 states that ā€œsection 39(3)(b)(i) incorporates by reference provisionsā€ of the Official Information Act. Paragraph (c) of the new clause 54 says that ā€œsection 48(2) extends the applicationā€ of the Official Information Act. That was quite a significant change. As I said, often when you get to miscellaneous provisions in a bill you think they are not going to arouse much of a debate, but we did have a lot of discussion about this clause at the select committee, and, as I say, the Minister’s only Supplementary Order Paper is referenced through this part.

Likewise, with regard to the next clause, clause 55, we replaced subclauses (1) and (2), to ensure that the relationship was really clear between this current bill—soon to be an Act, I hope—and the privacy legislation. Of course, we had a lot of discussion about the privacy legislation. It was discussed much more than the Official Information Act. There have been a lot of concerns expressed in the House about use and abuse, or potential abuse, of the privacy legislation. I remember that the Minister for Social Development some time ago was attacked—well, her policy was attacked—in the paper by two women who were on the domestic purposes benefit who had been in receipt of the training incentive allowance and were undertaking university qualifications. That is a jolly fine thing for anyone to aspire to, but particularly women who are trying to raise a child on their own. For them to be able to take that additional leap is a big thing, and we as a Parliament and as a society should support it. They dared to criticise the Minister’s policy to reduce the application of the training incentive allowance so that it did not cover the very qualifications that they were going for.

At that time Paula Bennett released their private details. It was not a leak. She was very open about the fact that she had released their private details. But what was of concern to me and, I know, many others was whether it was actually a breach of the particular women’s privacy when those details were released—whether it had application under the Privacy Act. So a proceeding was taken under the human rights legislation. Paula Bennett wrote to that office about this issue and said ā€œI acknowledge that you consider that I was wrong to do so and that this resulted in a breach of Ms Fuller’s privacy. As you also know, I don’t accept that view.ā€ So you can see in that example of actions in relation to one’s individual privacy that people have very different views about what is acceptable and what is not.

In a previous contribution prior to the dinner adjournment I heard my colleague Dr David Clark from Dunedin North talk about breaches of privacy through mistakes made by staff, often because of electronic transfer of information. With the Inland Revenue Department mistakes, thousands and thousands of New Zealanders have had their personal information transferred electronically to the wrong person by the Inland Revenue Department. In the last year the Inland Revenue Department has sent the personal information of 6,300 people to the wrong people. That is a huge number of people. When we are talking about people under this legislation giving authority for their information to be accessed by that department or by other departments, to perhaps be shared, these are the sorts of concerns that we have to be really aware of. We as a Parliament have to be very rigorous to ensure that the concerns that have been expressed in relation to Work and Income breaches—not only when the Minister so boldly defied the Office of Human Rights Proceedings deliberation but also, of course, more recently with the Work and Income kiosk shambles, where despite repeated warnings Work and Income continued to leave vulnerable people at risk of having their personal information accessed—are addressed. The incidents I have just referred to in terms of the Inland Revenue Department and its releasing personal information are the issues that have to be paramount in our consideration as we work through Part 3 of this legislation.

The final point I want to make is in relation to offences and penalties. It is really clear that our select committee, from its consideration, considered that there should be no tolerance of breaches of the provisions here. Of course, if people are a little anxious about an electronic transfer system but see a conviction made under it and some appropriate penalties dealt out, then their confidence in the system will increase. I would prefer that there were no breaches of access to identification, at all, but if there are, whether they are by accident or done willingly, then we must certainly have appropriate provisions. Clauses 56 through to 61 cover those offences, and there were very few alterations that the select committee made to them.

The next section of Part 3 deals with liability, and once again you will see that the select committee made some significant changes. They were more technical than policy-driven in that area. Subclause (1) under clause 61, ā€œProtection from liabilityā€, has been replaced, but that was not a significant policy area at all. The remaining clauses of Part 3 deal with regulations.

I look forward, as I said, to the Minister in the chair making a contribution to this debate. There has been a bit of work that the select committee undertook. First of all, we were a bit puzzled about why we had two bills with such similar names that appeared, on the face of it, to do quite—

šŸ—£ļø Speech DENIS O’ROURKE (NZ First)
Time unknown

As I have already said, New Zealand First supports the Electronic Identity Verification Bill overall. There are some aspects in Part 3, however, that I do wish to comment upon. First of all, relating to unauthorised hacking, deleting, and altering of information in respect of clause 56(3), New Zealand First does approve of the penalty increases there, for individuals being up to $250,000 or 10 years’ imprisonment, and for organisations being up to $1 million. The point here is that these are significant penalties, and they need to be significant, because we need a very strong deterrent for these sorts of activities these days. One could list many and various instances when very severe cases of hacking and altering of information has occurred in many areas, both in the public and private sectors. The point, however, is that significant penalties are very important, so that is supported.

However, when I look at clause 58(1)(a), relating to unauthorised access, I said in an earlier speech that I thought it would be wise to add an offence of attempting to access, after the place where the word ā€œaccessā€ is used in the clause, and also to expand it to define what would constitute an attempt. I find it a little bit difficult to know whether access needs to be a successful access, or a complete accessing of information, or whether some sort of an attempt to do so would itself be a sufficient offence for the purposes of the bill. I would have liked to see some amendment of that particular clause to cover that kind of issue. Of course, it is not too late to do that. Perhaps the Government could have a look at it. Similarly, the same thing arises in clause 58(3), where again the words ā€œattempts to useā€ are specified. Again, we could add something about ā€œattemptsā€ in that section too. I think it is very important indeed that the bill should specifically cover attempts, so that we know what is meant by access and we know what is meant by an attempted access.

Moving on, when I look at penalties I think the Government should also reconsider clause 58(4), concerning accessing of information and using information, because I think that we need higher penalties than are specified there. I think they should go up, in respect of an individual, from 2 years’ imprisonment or a $50,000 maximum fine to up to 5 years’ imprisonment or a $200,000 fine. For corporations I think it would be appropriate for the penalty to be raised from $200,000, which for many corporations is not a huge sum of money, to at least $500,000 for the illegal accessing and using of information. I think that we need to understand that the possibility of commercial gain from some of these illegal activities is quite large, especially for corporations. We need strong penalties to deter that sort of behaviour. Organisations that hack information would be doing so for commercial gain, and they cannot be imprisoned, so we need to have very high financial penalties. That is what we in New Zealand First would like to see. There might also be other possible penalties such as deregistering a company, but, at the very least, much higher financial penalties are warranted.

In respect of the regulating powers, New Zealand First agrees with new clause 65A, concerning regulations to prescribe the length of time that electronic identity credentials, photographs, records of usage history, status information, and technical codes are retained after their cancellation, revocation, or expiry. We also approve in particular of the requirement for the regulations for these purposes to be subject first to consultation with the Privacy Commissioner. I think that is very appropriate indeed. New Zealand First also approves of allowing a different duration to be set in regulations for electronic identity credentials issued to children under 14 years of age, because, of course, children’s appearances change dramatically as they age and generally they hold fewer identity documents, which can limit the effectiveness of biometric checks on them. With those reservations and some of those suggestions, which we think would improve the bill, New Zealand First would be very happy to support all parts of it.

šŸ—£ļø Speech Hon Amy Adams (New Zealand National Party — Member for Selwyn)
Time unknown

I am going to take just a brief call on Part 3 of the Electronic Identify Verification Bill to address the points raised by the New Zealand First member Denis O’Rourke in his last contribution. Mr O’Rourke expressed some concern that there was no provision making it an offence to attempt to carry out those particular actions listed in clauses 56, 58, and others. I just wanted to reassure the member that the reason there is not a specific provision making it an offence to attempt those actions is that it is an offence under section 72(1) of the Crimes Act, and the way legislation is drafted is that we have it in the Crimes Act rather than repeating it in every piece of legislation. That is a fairly standard approach to drafting. The point was considered, and I can assure him that it is, in fact, an offence to attempt to carry out any of those activities that he talked about.

The other point that I thought I would just briefly address is his concern around increasing the penalties, and just assure him that the reason the penalties sit where they are is to ensure that they are at an appropriate alignment with similar offences in other legislation. As he will understand, that is a core part of good drafting. In this case they have been lined up with a number of similar offences, such as, for example, the use of electoral information for a commercial purpose under the Electoral Act. In order to maintain proportionality with similar related offences, they have been set at that level. I hope that clears that up for the member.

šŸ—£ļø Speech Hon Kris Faafoi (New Zealand Labour Party — Member for Mana)
Time unknown

Thank you very much, Mr Chair, for offering me the chance to speak to Part 3 of the Electronic Identity Verification Bill. As I said in my contributions in Part 1 and Part 2, it is absolutely fundamental that, if we are going to roll out this Igovt system and expand it out through what is already existing, the public need to have 100 percent confidence in the security and the monitoring and also the consequences if the laws—as they stand, or as they are proposed—are transgressed. There are grounds for serious concern within the public because of the number of recent glitches in the security of private information that we have seen in a number of Government departments. Of course, there has been most recently Novopay, where the private details—[Interruption] Yes, ā€œNo payā€, I should say. There have been instances when the private details of teachers have been forwarded on to schools where they do not work. There was a case with ACC where the details of over 6,000 individuals were sent to one individual. There has been the case of the Inland Revenue Department and 7,000 individuals affected there, and then, of course, we had the Ministry of Social Development and the cases of the kiosks where one individual was able to access quite a lot of sensitive information. I do want to talk about that in respect of Part 1 and Part 2, and especially around access, and then the provisions in clauses 56 to 60, I believe, which cover the penalties if someone is found to improperly access information that is held within this realm.

During Part 2 I did ask the Minister in the chair for some assurances, given the concerns that would be out there in the public at the moment around security, about whether or not the Government departments involved in this legislation have done enough to assure the New Zealand public and the Minister that the information involved is safe. I also asked the Minister in the chair what level of monitoring is going to be carried out, given the fact that, I believe, in the case of the Ministry of Social Development there were some flags raised about 6 months—or a year, I think it may have been—before the issue was highlighted in the media. Nothing was done, publicly at least, from the time that that was raised privately until the issue was raised by citizen journalist Keith Ng. I think if it is still possible to get a reply from the Minister in the chair, the Minister for the Environment, about the level of monitoring, that would be good.

I mentioned Keith Ng, and I also want to ask the Minister in the chair whether there was any talk or any possibility—because Part 3 sets out the offences of accessing the information and the penalties—that in the case of Keith Ng there might be some kind of protection for people who, like a blogger or a citizen journalist, are accessing this information because they believe there is a potential gap in security. They might believe that the only way for them to find out whether or not there is a gap in security is to do what Keith Ng did, which was to go into that Work and Income office and access the information to see whether he could access it. But from my reading of the bill as it stands there does not seem to be any protection for anyone who, with good intentions and no malice, goes in to access this kind of information.

That is just something I want to throw out there, because, given the nature of the area we are talking about—and we are talking about digital storage—the expertise for these kinds of things, as we have seen in the last couple of months, to try to test it, or hack the information, does not necessarily rest within the Government departments. They could not find the security gaps or the security lapses that had existed for some time. It took someone external to test the system to see whether there were some gaps. So we have got a case where there may be a third party who comes in, who may have a little bit of knowledge about a potential threat to the security of the system, and who does what Keith Ng has done, which was to go in, access that information, and, with no malice, actually go to the authorities and to the media about a potential security lapse. I am just wondering whether the Minister in the chair could elaborate as to whether, because of the nature of this—and I am no technology guru—the expertise in this area might not lie within the Government departments. It might lie with those who are more technically advanced than those within the department. If they do test it and find a lapse in security, I ask whether or not there will be some protection within the law as it stands now to protect that person, because they have actually done the public a good service by highlighting the issue of a security lapse. Hopefully, as the Minister in the chair has taken one call to answer a question from Denis O’Rourke, it would be good if I could potentially get a reply to that question.

There are some penalties, both monetary and also in terms of imprisonment, that are contained within clauses 56 to 60. If someone commits an offence that is set out in clause 56, they are liable for a term of imprisonment not exceeding 10 years, a fine not exceeding $250,000, or, if it is an organisation, a fine not exceeding $1 million. I think Denis O’Rourke talked about the level of penalties within clause 58(4), and he was answered by the Minister, but I have, since that time, had a chat to my colleague, the chair of the Government Administration Committee, Ruth Dyson. She said that during the select committee process, which was some time ago, I understand, the level of punishment and the penalties that are contained within the bill were debated, and the members of the select committee thought that it was appropriate to have the level of punishment as it is set in the bill as it stands. Also, clause 58 looks at an issue that I highlighted in the debate on Part 2, which was around access. It relates to offences relating to improper access to the information that is held on the service database. That also carries penalties of imprisonment for an individual of a term not exceeding 2 years, a fine not exceeding $50,000, or, for an organisation, a fine not exceeding $200,000. So I guess that does answer some of the questions that I posed in the debate on Part 2 around the monitoring, and what kinds of penalties would be carried out if someone was found to be improperly accessing the database.

In terms of improper access, there is serious concern. Again, I just want to highlight the concerns that there will be out in the community about the level of security around private information. It is a serious concern. It is a real concern. As many people have pointed out, the journey of this bill might have been slightly different if it had happened in the context of recent events. I think there would have been much more scrutiny around the protections that the Department of Internal Affairs and other agencies could offer around the security of information, given we have had a series of serious blunders, I guess you could call them, around the security of private information from the Government in the last year or two. So I just want to reiterate that public confidence is absolutely essential to making sure that the Igovt roll-out and expansion beyond what is already in place is a success. There is concern amongst the community because of the glitches at Work and Income, ACC, the Inland Revenue Department, and the Ministry of Education with security of private information recently.

I would like the Minister in the chair to potentially answer some of the questions that have been posed. I just remind the Minister in the chair about, maybe, that one issue of the likes of citizen journalists or bloggers who may expose glitches in this system, having some protection from prosecution—[Interruption] Yes, whistleblowers. If they do highlight glitches in the current system, I ask whether or not they potentially have any protection—if they, with no malice, do highlight some shortcomings of the current system.

šŸ—£ļø Speech Chris Auchinvole (New Zealand National Party — List Member)
Time unknown

It is, as always, a pleasure to debate these matters with Kris Faafoi, whom we have just heard from. I am not sure what he had for dinner, but I really feel he is arguing against himself, and I think there are serious consequences to what is being suggested. On the one hand he is castigating the Government for having identified problems with some of the computer systems and saying that it is unforgivable, it should never have happened, there was insufficient testing, and it must never be allowed to happen again, but on the other hand he is suggesting seriously—because he is a serious person—that if a hacker goes in, as long as they can say ā€œOh no, it was for non-malicious reasons.ā€, they should be forgiven and not prosecuted. I cannot follow the logic. If people breach security, they breach security, and for someone in this Committee to stand up and say that that is fine leaves me somewhat amazed. I am sure on reflection he would not expect the Minister to say: ā€œYes, on the one hand it was dreadful that we had those security breaches, but, no, as long as they can say it was without malice and it was just to highlight a problem, that’s OK.ā€

I had the experience of losing my company identification to a well-established company that handled information, bank details, and everything else. It sold its files. It sold its files to American interests, and American interests then had the liberty to phone you up and ask you about your business. They already knew all about it. They had everything there. ā€œWe’ve got your file right on our desk. We feel that you should buy these shares.ā€, and so on and so forth. There was no protection against that company doing that. There was no protection.

I would like to reassure the Committee, in the light of Kris Faafoi’s statements, that the Government Administration Committee certainly considered this bill, the Electronic Identity Verification Bill, very, very seriously. Indeed, the officials went away and did remedial work—extra work, extra research. I think they worked extremely diligently, and I do not doubt that the chair of the committee, who is sitting beside Kris Faafoi, will bear that out. They worked very, very hard, and we took this very seriously. I would hate for anyone to think that this committee was slipshod in its processes, because we were not.

Let us have a look. We talked about the level of fines. Let us just see what they are, what we have lifted them to. It was previously imprisonment for a term not exceeding 10 years or a fine not exceeding $250,000. The prison term continues not to exceed 10 years and the fine continues not to exceed $250,000—or both—but if an organisation gets involved, then it is a fine not exceeding a million smackers. That starts to erode the profits they might receive from selling information that they could gain. So it becomes quite a risky operation. But I would not be at all surprised, because this is valuable information, if an organisation, a shonky one, was prepared to give it a go—have a go—and see whether it works. If it does, fine. Pocket the profits. If it does not, they may say that they were doing it for non-malicious purposes to show there was a breach in the system. Under Kris Faafoi, they are forgiven because they have shown the Government there was an error. Sorry, it does not wash. I feel that we should distance ourselves from that sort of peculiar, slipshod logic.

šŸ—£ļø Speech Ruth Dyson (New Zealand Labour Party — Member for Port Hills)
Time unknown

I did not realise that the member who has just resumed his seat, Chris Auchinvole, was going to do so so rapidly. I want to begin by just endorsing his comments. I did refer earlier to the Minister of Internal Affairs and the members of the Government Administration Committee, and the officials, and I want to just reinforce that point. Some people would look at this bill, the Electronic Identity Verification Bill, and say: ā€œWell, hmm?ā€. Perhaps they would not get very excited about it. I suppose it is not a bill that you would get really excited about, but that does not mean it is not important, and it certainly does not mean that you should not apply a lot of rigour to it and ensure that the anxiety that we referred to earlier is considered seriously and dealt with, even if we do not think it is entirely appropriate to do legislative amendments or frame legislation on terms of unwarranted anxiety. But we want a system where people’s confidence will grow. We want the benefits of electronic identification to be given to Government departments, agencies, and individuals, but we also want people who are using the system to have their confidence grow because of the rigidity of the system, the rigour of the system, so that we are not likely to get the sorts of breaches that we have been talking about earlier in the debate. Also, if there is some breach, appropriate penalties should be dished out to those who breach it.

I want to refer now to clause 61, which is the only clause in the bill that has an amendment from the Hon Chris Tremain. It really draws further on the comments that my colleague Kris Faafoi was making in relation to Keith Ng, who is the—what was the term he used?

šŸ’¬ Kris Faafoi: ā€œCitizen journalistā€.

Citizen journalist. There you are; that is an interesting term. He is a blogger. He is a person who has strongly and competently held views and expresses them through social media and other outlets. I want to correct the deputy chair of the Government Administration Committee. The kiosk system was not hacked. There was no hacking involved. It did not involve anything that bordered on anything illegal. The system was used in the manner it was intended to be used, but it delivered a whole lot of information that should not have been delivered to the people who were accessing it. So they did not hack into the system; they just accessed it and kept putting in the details that they were asked to put in, and they suddenly got a whole lot of information that breached other people’s privacy.

The point that Kris Faafoi was making is that if you read clause 61—it is talking about protection from liability—subclause (1) says: ā€œSubsections (1A) and (1B) apply to an act done or omitted—(a) by the chief executive or an employee or agent of the department; and (b) in the course of—(i) performing functions or duties or exercising powers under this Act; or (ii) purporting to perform functions or duties or exercise powers under this Act.ā€, and subclause (1A) says: ā€œNeither the chief executive nor the employee or agent is under any criminal liability for the act.ā€ The point that Kris Faafoi was making was to ask whether this has any bearing on the example that he used, where Keith Ng went into a legitimate public space of Work and Income and, without any hacking or otherwise unauthorised or illegal actions or engagement with the Work and Income computer system, was able to access a whole lot of information that was personal and private to other people and should not have been shared. But he was not accessing it illegally; he was just following due process, as I understand it. There does not seem to be anything in this clause at all to respond to that situation.

I think the question that Kris Faafoi raised with the Minister in the chair, the Hon Amy Adams, is worthy of some consideration. The select committee did not consider it, and that was for a very simple reason: that incident had not occurred, it had not happened, and it was not in the public domain. We did not know about it until after the select committee had deliberated on it. As Chris Auchinvole alluded to, given the serious attention that we gave to what appears to be quite an innocent and small bill, I know that our select committee would have given it further consideration in terms of the protection from liability that should be accorded to Mr Ng.

šŸ—£ļø Speech Kanwaljit Singh Bakshi (New Zealand National Party — List Member)
Time unknown

Thank you, Mr Chair, for allowing me to participate in this debate on Part 3 of the Electronic Identity Verification Bill. This part deals with very important issues, where we have defined what sort of penalties are in place if somebody plays with the information held within the system. We just heard from my good friend Chris Auchinvole about his personal experience of how his information was sold to an overseas company. This part defines that if an individual or a corporate sells or plays with the information that is being held, they will get severe penalties. As multiple Government agencies exchange information, it is critical to ensure that the fundamentals of this proposal are absolutely right.

My colleagues and I in the Government Administration Committee have considered the bill and have suggested amendments to the bill that we believe will enhance the legislation. Members of the committee have recommended the application of higher penalties to organisations. The present version of the bill has suggested penalties for individuals and organisations that misuse the services. However, the committee considered that the penalties currently being applied to the individuals, as well as to organisations, are unlikely to restrict organisations from misusing the services. So, for instance, if an organisation hacks into the service database, the maximum penalty is a fine. The view of the committee is that it is unlikely to stop organisations with malicious intentions.

The Government Administration Committee has recommended the imposition of fines that are likely to have severe financial repercussions on those organisations and that could deter them from misuse, and says that these should be applied. The committee also recommended that a specific time period be inserted into the legislation that prescribes the length of time electronic identity credentials, photographs, records of usage history, status information, and technical codes are retained after their cancellation, revocation, or expiry of data.

Before I conclude, I would like to thank the officials for their help during the select committee process. I hope this will be a bill that will help to safeguard the database we have in electronic form.

šŸ—£ļø Speech Hon Dr Megan Woods (New Zealand Labour Party — Member for Wigram)
Time unknown

It is my pleasure to take a call on the Electronic Identity Verification Bill, which is a very timely piece of legislation for many reasons. Members have gone over the current events that make this a piece of legislation that we need to think about very carefully.

One of the things that struck me as I have sat here listening to the speeches in the Chamber tonight is that a number of members of this House went to a cross-party forum this evening. This was for a number of our small and medium sized enterprises and high-tech companies, and people were talking about working with the Government and how it is that they could add to the weightless economy. It dawned on me that there is no more weighty responsibility for the Government than when it is dealing with people’s private information. This is really what this bill gets to the heart of. I think that Part 3 of this bill has some incredibly important points to make in terms of how it is that this piece of legislation interacts with the very legislation that protects our rights in this country. Specifically, I am referring to the Official Information Act and the Privacy Act.

Some very interesting points have been drawn out as we have gone through this debate tonight, and I would like to address a couple of those as we go through the bill. This is important, as a number of my colleagues have noted in this debate. Kris Faafoi, who is getting quoted a lot in this debate tonight, finished his speech—

šŸ’¬ Hon Annette King: Name-dropper.

I am being a name-dropper. Kris Faafoi finished his speech by saying that it is absolutely imperative that individuals have confidence when the Government is dealing with private information. I think many of us have instances of constituents in increasing numbers coming to visit us and sharing their anxiety at the personal information that the Government has stored about them and what might come about because of that.

But Labour is supporting this bill, and, as I said, I want to address some of the points in the debate. I specifically want to pick up on what Ruth Dyson talked about in terms of clause 61 of this bill and the point that was brought up in Chris Auchinvole’s speech in response to Kris Faafoi. [Interruption] There is another name—Annette King!

In terms of Government responsibility, and the allegation that when someone is just carrying out their normal duties, and there is no malice involved, and they come across information, we need to recognise it for what it is—this bill, in clause 61, does. The example of Keith Ng has been used and it is a good one, because putting a USB stick into a computer is not hacking. Keith Ng was merely using the portal in the way it was designed, and clause 61 does cover this.

This brings to mind some other breaches that we have had in terms of people’s personal information. If you receive by email from a Government department the details of a whole lot of people’s personal information, as happened in the case of ACC, is the person receiving that email going to be liable? Well, no—clause 61 actually covers that off, because there is no malice intended.

But what if you are a teacher, or you are a principal, or you are an administrator at a school and you receive from the Ministry of Education, because of the breakdown of the Novopay system, personal information and bank account details of teachers from another school? That has been happening with the Novopay system, so is it something people could be liable for? That is why clause 61 of this bill is incredibly important—it does cover that off. It does cover off this protection from liability.

I think these are things that we have to be very mindful of, because we are dealing with a technology and we are in an era when technology is being employed to move around massive amounts of data. So we do need to empower chief executives to protect people from liability when things go wrong, through no fault of their own, and when it is someone else’s problem.

But when we look at some other provisions of this bill—and there are some incredibly important ones under this part—and we look at the relationship with the Official Information Act, we see some really important interfaces here between these two pieces of legislation. What we see is that we have the Government having the responsibility to deal with it. We see reporting to the Privacy Commissioner being an incredibly important protection that people will be given under this legislation. So this is a bill that Labour is happy to support.

The question was put that the amendments set out on Supplementary Order Paper 128 in the name of the Hon Chris Tremain to clause 61 be agreed to.

Amendments agreed to.

Part 3 as amended agreed to.

Schedule 1 agreed to.

Schedule 2 agreed to.

Clauses 1 and 2

Clause 1 agreed to.

Clause 2 agreed to.

Bill to be reported with amendment presently.

šŸ—£ļø Spoke in this debate (6)