Map / Privacy & data

Trace the information before moving it.

A system-change map should show what personal and operational information enters, where it travels, who can act on it, and how an incident is handled.

Data route

Seven questions for every flow.

  1. Purpose: what business outcome requires this information?
  2. Collection: who or what provides it, and what notice or choice is presented?
  3. Fields: which elements are necessary, sensitive, derived, or optional?
  4. Access: which roles, vendors, support people, and automated processes can reach it?
  5. Use and disclosure: what decisions, messages, exports, integrations, and overseas transfers follow?
  6. Retention: how long is it useful, what rule supports that period, and how is deletion verified?
  7. Recovery: how are mistakes corrected, access removed, incidents contained, and affected people supported?
Do not map only the production database. Include email attachments, spreadsheets, logs, analytics, backups, support tools, AI prompts, exports, screenshots, and test fixtures.

Privacy Act questions belong in discovery.

The New Zealand Office of the Privacy Commissioner publishes the Privacy Act 2020 information privacy principles, covering collection, storage, use, disclosure, access, correction, retention, overseas disclosure, and unique identifiers. The Commissioner also publishes breach-management guidance. The organisation should use these official materials with qualified advice to decide what applies.

In delivery, we can convert those decisions into technical controls such as role boundaries, field minimisation, audit events, retention jobs, export restrictions, documented vendor paths, and an incident runbook. Those controls support a privacy programme; they do not themselves prove legal compliance.

AI and automation need an explicit lane.

If an AI service or automated rule will see personal, confidential, or commercially sensitive information, record the provider, model or service, processing location, retention settings, training-use settings, permitted inputs, human review point, and failure response. Avoid sending real records into an experimental tool merely because it is convenient.

  • Use representative synthetic data until access is approved.
  • Separate recommendations from automatic actions.
  • Log material automated decisions and their input version.
  • Give an accountable person a way to stop and correct the workflow.

Breach readiness is part of the design.

The Privacy Commissioner describes containment, assessment, notification, record-keeping, and reflection as components of breach management. A project should therefore name the incident owner, escalation channel, logging available, vendor contacts, evidence-preservation steps, and the person responsible for deciding whether notification is required.

Read the official privacy principles and breach-management guidance.

Map before migration

Bring one data flow.

We can turn it into a concrete route with owners, controls, and open decisions.

Start the data map