We use cookies to make your experience better. To comply with the new e-Privacy directive, we need to ask for your consent to set the cookies. Learn more.
Privacy Policy
1) Introduction
This policy covers how Blacks Fasteners Ltd ("Blacks", "we", "us", "our") will manage personal information about individual customers, employees, suppliers and other third parties in accordance with the Privacy Act 2020, the Credit Reporting Privacy Code 2020 (the "CRPC"), and any applicable amendments, including Information Privacy Principle 3A (IPP 3A) effective 1 May 2026.
This policy covers personal information including:
- What personal information we collect
- How and why we collect it
- How we use it
- Who we share it with
- Where we store it and our security protocols
- How long we keep it
- Allowing the individual to access and correct it
- When and how we disclose it
Scope
This policy applies to all personal information we collect from customers, employees (full-time, part-time and casual), suppliers, third parties and other stakeholders in both physical and digital forms. It covers information collected through our website (www.blacksfasteners.co.nz), our branch locations, our ecommerce platform, and in the course of our business operations.
This policy does not limit or exclude any of your rights under the Privacy Act 2020. For further information on the Act, visit the Office of the Privacy Commissioner at www.privacy.org.nz.
When Does This Policy Apply?
This policy applies whenever you interact with Blacks, including online or when using a product or service, such as:
- Entering or buying from one of our physical stores or our website
- Applying for a customer trade credit account
- Setting up an online account or completing a customer survey
- Requesting delivery of a product or an on-site engineering service
- Entering an online competition on our website or social media channels
- Subscribing to marketing and sales communications
- Speaking with us or one of our representatives during a product or service enquiry
- Contacting us by telephone, email, text or online
- Applying for employment with us
When Does This Policy Not Apply?
This policy only applies to websites managed by Blacks or data collected and stored on behalf of Blacks. If you follow a link to a third-party website from a Blacks website, the privacy policy of that third-party website applies, and Blacks accepts no liability for breaches of privacy once that link is followed.
2) What is Personal Information?
Personal information refers to information that can be used to identify an individual. This ranges from information like names, addresses and IRD numbers to photos of people, lists of items they buy and online search data.
Personal information does not include information we hold about organisations. However, it does relate to any information we hold about an identifiable individual relating to their role within an organisation.
3) Who We Are
Blacks Fasteners Ltd is a New Zealand-based wholesaler and distributor of fasteners, fixings and related products to the engineering and construction sectors. We operate multiple branch locations and a distribution warehouse across New Zealand, along with an ecommerce platform. We provide trade credit facilities to approved business customers.
Privacy Officer Contact Details:
- Brian Greenwood, Blacks Fasteners Ltd
- 34 Nga Mahi Road, Sockburn, Christchurch 8042
- Email: privacy@blacksfasteners.co.nz
- Phone: 03 348 0340
4) What Personal Information We Collect
Blacks collects a variety of personal information depending on the nature of our relationship with you. We only collect personal information when it is required for a specific purpose. The main categories are outlined below.
4.1 Personal Information About Customers
We collect personal information from customers in order to supply and manage customer transactions for products and/or services, including:
- Contact details (name, address, phone, email)
- Date of birth
- Account and marketing preferences
- Information and recordings of any calls, including details of the products you purchased or reasons for contacting us
- Information about products or services you purchased from or sold to us, the place of purchase, deliveries and returns, batch information, and details of your ownership of the product
- Credit and finance information, including identification information from a valid government identity document (e.g., driver license number)
- Trade references and financial references provided in credit applications
- Order history, account transactions and payment information
4.2 Personal Information Collected from Our Website
We collect personal information from persons who use and interact with our website, social media pages and email marketing, which may include:
- Interests and preferences you supply during account creation
- Address of your internet service provider and the name of the web page directing you, along with your clicks and interactions with our website
- Information about your visit to our website including the pages you visited and which items or information you clicked on
- Product reviews, comments, photos and public posts you have submitted
- The date, time and general geographic location from which you are visiting
- The URLs of the pages you visit
- Your email address and contact details if you have provided them
- Transaction details, purchase history and billing or account information
- Online service information and technical logs including IP addresses, domain logs, browser type, device and application settings, errors and other hardware activity
- Cookies and similar tracking technologies (see Section 13 below)
4.3 Personal Information About Employees and Applicants
We collect personal information to assess a potential applicant's suitability for a role, along with information required for administrative purposes during the employment relationship, which may include:
- Name, address and contact details
- Age and date of birth
- IRD and bank account details
- Sex/gender
- Work history and experience
- Educational history
- Police check / criminal record (where applicable and with consent)
- Emergency contact details
- Health information relevant to the role (e.g., pre-employment medical, ACC claims)
- Immigration/Visa status and right to work in New Zealand
- Performance records, disciplinary records, and training records
4.4 Video Footage and CCTV
Blacks sometimes takes video and photographs in areas of public access where we conduct business. Our stores and warehouses operate CCTV cameras for security purposes. CCTV footage is stored securely and access is restricted to authorised personnel.
4.5 Information We Collect from Third Parties (Indirect Collection — IPP 3A)
In accordance with Information Privacy Principle 3A (IPP 3A) of the Privacy Act 2020, we advise you that we may also collect personal information about you from sources other than you directly, including:
- Credit reporting bureaux — including Centrix Credit Bureau of New Zealand, Equifax New Zealand, and/or Experian New Zealand — when we request a credit report as part of a credit application or ongoing account management.
- Trade referees and other third parties named in your credit application.
- Publicly available sources, including the New Zealand Companies Office, the Personal Property Securities Register (PPSR), and court records.
- Your employer or business, where you are nominated as a contact person on a trade account.
- Third-party service providers that support our website, marketing and business operations.
- Recruitment agencies or referees, in the case of employment applications.
5) How We Collect Information
Where we can, we collect information directly from the individual concerned. For example, we collect information from you when you:
- Become a Blacks customer or employee, and during the course of our relationship when you make a purchase, return, exchange, or where we request verification of your identity
- Set up a Blacks account or complete a customer survey
- Order through our retail store, internal sales or our website
- Request delivery of a product or an on-site engineering service
- Apply for trade credit
- Enter an online competition on our website or social media channels
- Subscribe to marketing and sales communications
- Visit our website and allow the tracking of cookies
- Speak with us or one of our representatives during a product or service enquiry
- Contact us by telephone, email, text or online
Where information is collected indirectly (from third parties), see Section 4.5 above.
6) Why We Collect Information and How We Use Your Information
We take reasonable steps to ensure that information is up to date, complete, relevant and accurate before we use it. We may use your personal information for any of the following purposes:
- Managing customer and supplier relationships: Including verification, account setup and ongoing account administration.
- Providing products and services: Fulfilling orders placed online, in-branch or via our sales team, and arranging deliveries.
- Credit management: Assessing credit applications, conducting credit checks, managing trade credit accounts, invoicing and debt collection (see Section 8).
- Credit reporting: Sharing credit information with credit reporting bureaux in accordance with the Credit Reporting Privacy Code 2020 (see Section 8).
- Security and fraud prevention: Protecting our business and our customers from fraud, unauthorised access and other security risks.
- Customer service and quality assurance: Answering queries, continuous improvement from relevant feedback, training staff and quality assurance purposes.
- Marketing and communications: Sending you information about our products, services, promotions and events where you have opted in or where we are otherwise permitted to do so. You may opt out at any time (see Section 14).
- Competitions and promotions: Conducting prize draws, contests and other promotional offers.
- Research and feedback: Contacting you for research and feedback purposes, including customer surveys and loyalty programmes.
- Website operation and improvement: Analysing website usage, improving our ecommerce platform and ensuring website security.
- Employment: Assessing applications for employment, managing the employment relationship and meeting our obligations as an employer (see Section 7).
- Legal and regulatory compliance: Complying with our obligations under applicable laws, including the Privacy Act 2020, the CRPC, tax legislation, health and safety requirements and employment law.
- Internal business operations: Record-keeping, reporting, auditing and business improvement.
7) Employee Data Handling
In addition to the general obligations set out in this policy, Blacks has specific responsibilities in relation to the personal information of employees and job applicants. This section outlines how we handle employee data throughout the employment lifecycle.
7.1 Recruitment and Pre-Employment
- During recruitment, we may collect personal information from applicants and third parties for the purpose of assessing suitability for a role. This includes:
- Information provided in CVs, cover letters, application forms and interviews.
- Information obtained from referees you have nominated, with your consent.
- Results of pre-employment checks, including police vetting (where applicable and with your consent), credit checks (for finance-related roles, with your consent), and verification of qualifications.
- Information provided by recruitment agencies acting on your behalf.
If your application is unsuccessful, we will retain your information for a reasonable period (generally up to 12 months) in case a suitable opportunity arises, unless you request earlier deletion.
7.2 During Employment
Throughout the employment relationship, we collect and use employee personal information for the following purposes:
- Payroll administration, including salary/wages, tax (IRD), KiwiSaver, and bank account details.
- Leave management, including annual leave, sick leave, bereavement leave and parental leave.
- Health and safety obligations, including incident reporting, ACC claims, and workplace assessments (in accordance with the Health and Safety at Work Act 2015).
- Performance management, including appraisals, goal-setting, disciplinary processes and training records.
- Internal communications and IT system access (e.g., email, intranet, business applications).
- Monitoring of company-owned devices and systems where required for security, compliance or operational purposes. Employees will be advised of any monitoring in place.
- Emergency contact details, for use in the event of a workplace emergency.
- Immigration and visa information, to verify the right to work in New Zealand.
7.3 Disclosure of Employee Information
We may disclose employee personal information to the following parties, for the purposes described:
- Inland Revenue (IRD): For tax, PAYE and KiwiSaver obligations.
- ACC: For workplace injury claims and levy administration.
- KiwiSaver providers: For retirement savings administration.
- Insurance providers: For group insurance or health benefit schemes, if applicable.
- External payroll or HR service providers: Who process data on our behalf under contractual confidentiality obligations.
- Government and regulatory bodies: Where required by law (e.g., WorkSafe, Immigration NZ, NZ Police for vetting).
- Professional advisors: Our lawyers, accountants and auditors, as reasonably required.
- Prospective employers: Where you have consented to us providing a reference.
7.4 Employee Rights
Employees have the same rights as all individuals under the Privacy Act 2020, including the right to:
- Request access to personal information held about them (IPP 6). We will respond within 20 working days.
- Request correction of any inaccurate, incomplete or misleading information (IPP 7).
- Be informed of the purposes for which their information is collected and used.
- Complain to the Privacy Commissioner if they believe their privacy has been breached.
Employees should direct privacy-related requests to the Privacy Officer or their manager in the first instance.
7.5 Confidentiality and Access Controls
Access to employee personal information is restricted to authorised personnel who need the information to perform their duties (e.g., HR, payroll, direct managers). All staff with access to employee records are required to maintain confidentiality. Employee files — whether physical or digital — are stored securely with appropriate access controls.
7.6 Post-Employment
When an employee leaves Blacks (whether through resignation, redundancy, retirement or termination), we will:
- Retain employment records for a minimum of seven years after the end of employment, as required for tax, ACC and legal purposes.
- Securely destroy or de-identify personal information that is no longer required after the retention period has expired.
- Revoke access to company systems, email and premises promptly upon departure.
- Provide a reference for the departing employee only with their consent, and limited to factual information.
Provide a reference for the departing employee only with their consent, and limited to factual information.
8) Credit Reporting and Credit Information
As a provider of trade credit, Blacks collects, holds, uses and discloses credit information in accordance with the Credit Reporting Privacy Code 2020 (as amended). This section explains how we handle credit information.
8.1 Credit Checks
When you apply for a trade credit account with us, we may request a credit report about you and/or your business from one or more of the following credit reporting bureaux:
- Centrix Credit Bureau of New Zealand — www.centrix.co.nz/privacy
- Equifax New Zealand — www.equifax.co.nz/privacy
- Experian New Zealand — www.experian.co.nz/privacy
We will only request a credit report with your consent, as provided in our credit application form.
8.2 Information We Share with Credit Bureaux
We may provide the following types of information to credit reporting bureaux:
- Your identity information (name, date of birth, address, driver licence number)
- Details of your credit account with us (account type, credit limit, account status)
- Your repayment history
- Default information, where a payment is overdue and has been referred for debt collection (defaults under $125 will not be listed)
- Serious credit infringements
8.3 Notification of Indirect Collection by Credit Bureaux (IPP 3A)
When we provide your personal information to a credit reporting bureau, that bureau collects your information indirectly from us. In accordance with IPP 3A of the Privacy Act 2020, we advise you that:
- Each bureau will collect your credit information for the purpose of providing credit reporting services.
- This may include making your credit information available to other credit providers who request a credit report about you.
- Details of how each bureau handles your personal information, including your rights, can be found in their respective Privacy Statements (linked in Section 8.1 above).
- You have the right to access your credit report and request corrections — see Section 11 of this policy
8.4 How Long Credit Information Is Retained
Under the Credit Reporting Privacy Code 2020, credit reporting bureaux are subject to maximum reporting periods for different types of credit information. Generally:
- Credit account information may be disclosed until two years after the account is closed.
- Default information may be disclosed for up to five years.
- Court judgments and insolvency information may be disclosed for up to five years.
- Identification information may be retained indefinitely.
For full details, refer to Schedule 1 of the Credit Reporting Privacy Code 2020, available on the
Privacy Commissioner's website at www.privacy.org.nz.
9) Disclosure of Information
We may share your personal information with the following categories of recipients, for the purposes described in this policy:
- Credit reporting bureaux: Centrix, Equifax and/or Experian, as described in Section 8.
- Debt collection agencies: Where your account is overdue and has been referred for collection.
- Professional advisors: Our lawyers, accountants, auditors and insurers, as reasonably required.
- IT and service providers: Third-party providers that support our website, ecommerce platform, payment processing, cloud storage and business systems.
- Freight and logistics providers: To fulfil and deliver your orders.
- Government and regulatory bodies: Where required by law (e.g., Inland Revenue, NZ Customs, WorkSafe, ACC).
- Related companies: Other entities within the Blacks Fasteners group, if applicable.
- Other parties: With your consent, or where otherwise permitted or required by law.
We will not sell your personal information to third parties. We will not use your personal information for direct marketing by third parties without your explicit consent. We will not use credit information obtained from credit reporting bureaux for direct marketing purposes.
10) Overseas Disclosure
Some of our service providers (e.g., cloud hosting, software platforms) may store or process your personal information overseas. Where we disclose personal information to an overseas recipient, we will take reasonable steps to ensure that the recipient is subject to privacy protections comparable to those under the Privacy Act 2020, or that the disclosure is otherwise permitted under the Act.
If you would like to know more about where your information may be stored, please contact our Privacy Officer.
11) Your Rights
Under the Privacy Act 2020, you have the following rights in relation to your personal information:
- Right of access (IPP 6): You may request access to the personal information we hold about you. We will respond within 20 working days.
- Right of correction (IPP 7): You may request that we correct any personal information that is inaccurate, incomplete or misleading. If we have disclosed the incorrect information to a third party, we will take reasonable steps to notify them of the correction.
- Right to complain: If you believe your privacy has been breached, you may complain to us first (see Section 19). If you are not satisfied with our response, you may complain to the Privacy Commissioner at www.privacy.org.nz.
- Credit report access: You may request a copy of your credit report directly from the credit reporting bureaux listed in Section 8.1. This is free of charge.
To make an access or correction request, please contact our Privacy Officer using the details in Section 3. We may ask you to verify your identity before processing your request.
12) Storage and Security
We take reasonable steps to protect personal information from loss, unauthorised access, use, modification, disclosure or misuse. Our security measures include:
- Storing information in controlled computer servers with managed logical access protected by surveillance and security technology
- Access controls and role-based permissions for our business systems
- Encryption of data in transit (SSL/TLS) on our website and ecommerce platform
- Following security and data operating procedures to ensure the appropriate handling of sensitive information
- Secure storage of physical records in locked facilities
- Controlling and monitoring physical access to our premises
- Limiting access to sensitive personal information to authorised personnel
- Regular review and updating of our IT security policies and procedures
- Staff training on privacy and data protection obligations
- Destroying personal information pursuant to the law and our record retention policies
13) Cookies and Website Analytics
Our website uses cookies and similar technologies to improve your browsing experience, analyse website traffic and support our marketing activities.
13.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help us remember your preferences, understand how you use our site and improve our services.
13.2 Types of Cookies We Use
|
Cookie Type |
Purpose |
Duration |
|
Essential |
Required for the website and ecommerce platform to function (e.g., shopping cart, login sessions) |
Session / persistent |
|
Analytics |
Help us understand how visitors use our website (e.g., Google Analytics) |
Up to 2 years |
|
Functional |
Remember your preferences and settings |
Up to 1 year |
|
Marketing |
Used to deliver relevant advertising and track campaign effectiveness |
Up to 2 years |
13.3 Managing Cookies
You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may affect the functionality of our website and ecommerce platform. For more information on managing cookies, visit www.allaboutcookies.org.
14) Cookies and Website Analytics
We may send you marketing communications about our products, services, promotions and events where:
- You have opted in to receive marketing communications; or
- You are an existing customer and the communication relates to similar products or services, and you have not opted out.
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, or by contacting our Privacy Officer. Opting out of marketing will not affect transactional communications related to your account (e.g., invoices, order confirmations, account notices).
We will not use credit information obtained from credit reporting bureaux for direct marketing purposes.
15) Retention
We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law. When personal information is no longer needed, we will securely destroy or de-identify it.
|
Information Type |
Retention Period |
|
Customer account and transaction records |
7 years after last transaction (tax/legal requirements) |
|
Credit application forms |
7 years after account closure |
|
Credit reporting information |
As per CRPC Schedule 1 retention periods |
|
Employee records |
7 years after end of employment (or as required by law) |
|
Unsuccessful job applications |
Up to 12 months (unless consent given to retain longer) |
|
Marketing consent records |
Until consent is withdrawn |
|
Website analytics data |
Up to 26 months (Google Analytics default) |
16) Data Breach Response
Blacks is committed to protecting the personal information we hold. Despite our security measures, privacy breaches can occur. This section outlines our approach to identifying, containing, assessing and responding to privacy breaches in accordance with Part 6 of the Privacy Act 2020.
16.1 What Is a Privacy Breach?
Under the Privacy Act 2020, a privacy breach includes:
- Unauthorised or accidental access to personal information;
- Unauthorised or accidental disclosure of personal information;
- Loss of personal information (e.g., lost devices, misplaced files);
- Alteration or destruction of personal information;
- Any action that prevents us from accessing personal information, whether temporarily or permanently (e.g., ransomware).
A privacy breach can be caused by a malicious actor, a system failure, or simple human error (e.g., emailing a file to the wrong person, CC'ing instead of BCC'ing, losing an unencrypted device).
16.2 When Is a Breach Notifiable?
A privacy breach is notifiable if it is reasonable to believe that it has caused, or is likely to cause, serious harm to any affected individual. The Privacy Act 2020 requires us to consider the following factors when assessing whether serious harm is likely:
- The nature of the personal information involved (e.g., financial data, health information, government identifiers such as IRD numbers are more likely to cause serious harm);
- What action has been taken to reduce the risk of harm (e.g., whether the breach has been contained, whether the data was encrypted);
- Whether the information is protected by a security measure (e.g., encryption, password protection);
- The nature of the harm that could result, including financial loss, identity theft, physical safety risks, psychological harm, and reputational damage;
- The number of individuals affected;
- Who has obtained, or could obtain, the information (e.g., a trusted party vs. an unknown actor).
The Privacy Commissioner has indicated that organisations should err on the side of notifying. If there is genuine uncertainty about whether the threshold is met, it is generally safer to report than to stay silent.
16.3 Our Four-Step Breach Response Process
Our breach response follows the four-step framework recommended by the Office of the Privacy Commissioner:
1. Contain the Breach
As soon as a breach is identified or suspected:
- Take immediate steps to contain the breach and limit any further unauthorised access or disclosure.
- Isolate affected systems, revoke access, change passwords, or recover lost information where possible.
- Preserve evidence for investigation purposes — do not destroy or alter any relevant records.
- Assign the breach to the Privacy Officer or a designated member of the breach response team.
2. Assess the Risks
The Privacy Officer will assess the breach to determine:
- What personal information was involved and how sensitive it is.
- How many individuals are affected.
- Who has obtained or could obtain the information.
- What harm could result and how likely it is.
- Whether the breach meets the threshold for a notifiable privacy breach (i.e., likely to cause serious harm).
- What steps have been or can be taken to mitigate the harm.
A written record of the assessment will be made and retained, regardless of whether the breach is notifiable.
3. Notify
If the breach is assessed as notifiable, we will:
- Notify the Office of the Privacy Commissioner (OPC) as soon as practicable, and in any event within 72 hours of becoming aware that the breach is notifiable.
- Notify all affected individuals as soon as practicable, providing: a description of the breach; the type of personal information involved; what we are doing in response; steps the individual can take to protect themselves; and our contact details for further information.
- Where it is not practicable to notify affected individuals directly (e.g., due to the number of individuals or lack of contact details), give public notice in accordance with the Act.
Even where a breach is not notifiable, we may choose to notify affected individuals voluntarily where it is appropriate to do so.
4. Review and Prevent
After the breach has been contained and notifications made, we will:
- Conduct a post-incident review to identify the root cause of the breach.
- Implement corrective actions to prevent a recurrence (e.g., additional training, system changes, policy updates).
- Update this response plan if the review identifies improvements.
- Report findings to the Senior Leadership Team and, where relevant, update any ISO 9001 quality management documentation.
- Record the breach and response in our breach register for audit and compliance purposes.
16.4 Roles and Responsibilities
|
Role |
Responsibility |
|
Privacy Officer |
Leads breach response; conducts assessment; coordinates notifications to OPC and affected individuals; maintains breach register. |
|
Senior Leadership Team |
Receives escalated breach reports; approves external communications; ensures resourcing for response and remediation. |
|
IT Manager |
Assists with containment of digital breaches; secures systems; preserves digital evidence; advises on technical root cause. |
|
All Staff |
Report suspected breaches immediately to their manager or the Privacy Officer. Do not attempt to investigate or conceal a breach. |
16.5 Breach Register
We maintain a breach register that records all privacy breaches (whether notifiable or not), including: the date and nature of the breach; the personal information involved; the individuals affected; the assessment outcome; actions taken to contain and remediate the breach; and whether notification was made to the OPC and/or affected individuals. This register is reviewed regularly as part of our ongoing compliance programme.
16.6 Testing and Review
This data breach response process will be tested periodically (at least annually) and reviewed after any significant breach event. Testing may include tabletop exercises, scenario walkthroughs, or simulated breach drills. The Privacy Officer is responsible for scheduling and documenting these reviews.
16.7 Consequences of Non-Compliance
Failure to notify a notifiable privacy breach is an interference with privacy under the Privacy Act 2020. The Privacy Commissioner has the power to issue compliance notices and may publicly name organisations that fail to comply with their breach notification obligations. Affected individuals may also make a complaint to the Human Rights Review Tribunal, which can award damages.
17) Childrens Policy
Our products and services are designed for business customers. We do not knowingly collect personal information from children under the age of 18. If we become aware that we have inadvertently collected personal information from a child, we will take steps to delete it promptly.
18) Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or business operations. When we make material changes, we will update the "Last Updated" date at the top of this policy and, where appropriate, notify you by email or through our website.
We encourage you to review this policy periodically. The current version will always be available on our website.
19) How to Contact Us or Make a Complaint
If you have any questions about this Privacy Policy, wish to make an access or correction request, or have a privacy complaint, please contact:
Brian Greenwood - Privacy Officer
Blacks Fasteners Ltd
34 Nga Mahi Road, Sockburn, Christchurch
Email: privacy@blacksfasteners.co.nz
Phone: 03 348 0340
We will acknowledge your complaint within five working days and aim to resolve it within 20 working days. If you are not satisfied with our response, you may refer your complaint to:
Office of the Privacy Commissioner
PO Box 10094, Wellington 6143
Phone: 0800 803 909
Website: www.privacy.org.nz
20) References
- Privacy Act 2020 (NZ) — www.legislation.govt.nz/act/public/2020/0031/latest/LMS23223.html
- Privacy Amendment Act 2025 (NZ) — Information Privacy Principle 3A
- Credit Reporting Privacy Code 2020 (as amended March 2026) — www.privacy.org.nz
- OPC IPP 3A Guidance — www.privacy.org.nz/focus-areas/ipp3a
- OPC Privacy Breach Response Plan — www.privacy.org.nz
- Office of the Privacy Commissioner — www.privacy.org.nz
- Health and Safety at Work Act 2015 (NZ)
