Responsibility for policy: Chief Operating Officer (Privacy Officer)
Approving authority: Vice-Chancellor
Last reviewed: June 2026
Next review date: June 2031

Print version

Application

  1. This policy applies to all staff of the University of Waikato.

Purpose

  1. The purpose of this policy is to set out the obligations and responsibilities of staff with respect to the collection, protection, access, use, storage, retention, disclosure, sharing and management of personal information governed by and in accordance with:
  2. This policy also establishes the requirements for responding to and reporting a privacy breach to the University’s Privacy Officer and the Office of the Privacy Commissioner, where required.

Related Documents

  1. The following documents set out further information relevant to this policy:

Definitions

  1. In this policy:

personal information means information about an identifiable individual.

privacy breach means any unauthorised or accidental access to, disclosure, alteration, loss, destruction or issue of personal information as defined in the Privacy Act 2020

Privacy Officer means the staff member appointed by the University to carry out the functions of a Privacy Officer in accordance with the Privacy Act 2020.

Responsibilities

  1. Staff who collect, update, use, store, disclose or share personal information must adhere to the Privacy Principles set out in the Privacy Act 2020; a brief summary of the principles is provided in the Appendix to this policy.
  2. Where the University processes personal data that is subject to the European Union General Data Protection Regulation (GDPR), staff must comply with any additional obligations arising under that regulation.
  3. Staff may only access personal information for a lawful University purpose and on a demonstrably need-to-know basis.
  4. Staff who are undertaking or supervising research must also, where applicable, comply with the regulations relating to the archiving of data and the privacy, storage and use of personal information contained in the University's Ethical Conduct in Human Research and Related Activities Regulations.
  5. Staff must take reasonable steps to protect personal information against loss, unauthorised access, modification, disclosure or other misuse.
  6. Staff must ensure that personal information is retained, archived and securely disposed of in accordance with:
  7. Staff must ensure that the use of emerging technologies, including artificial intelligence (AI) systems, automated decision-making tools and biometric technologies involving personal information is undertaken in accordance with applicable law, University policy and relevant ethical standards.
  8. Staff must immediately report any actual or suspected privacy breach to the Privacy Officer in accordance with the University’s Privacy Breach Procedures; the Privacy Officer will determine whether a privacy breach must be reported to the Office of the Privacy Commissioner in accordance with mandatory reporting requirements.
  9. Line managers are responsible for ensuring that all systems, processes and practices in the areas for which they are responsible conform with this policy.
  10. Any questions by staff or students about the interpretation of, or compliance with, this policy must be referred to the Privacy Officer.
  11. Requests for personal information and complaints of interference with privacy by staff or students must be referred to the Privacy Officer.
  12. The Privacy Officer is responsible for:
    • ensuring that the University complies with the provisions of the Privacy Act 2020
    • dealing with requests and complaints made under the Privacy Act 2020, and
    • working with the Office of the Privacy Commissioner in relation to reporting and investigations conducted under the Privacy Act 2020.

Responsibility for monitoring compliance

  1. The Privacy Officer is responsible for monitoring compliance with this policy, and reporting any breaches to the Vice-Chancellor, external agencies and affected individuals (where appropriate).
  2. Breaches of this policy may result in disciplinary action under the Staff Code of Conduct.