Agencies and councils are not judged on whether the work was done. They are judged on whether it can be shown. A request answered well but reconstructed badly six months later still becomes a complaint, and the reconstruction costs more than the answer did.
That changes what good IT looks like here. Access control, retention, logging and the audit trail stop being hygiene and become the deliverable. We build public sector environments so the record is a by-product of doing the work, not a project that starts when someone asks a question.
The rules NZ agencies and councils work under
Official Information Act 1982 and the Local Government Official Information and Meetings Act 1987. Twenty working days to decide, withholding grounds that have to be reasoned rather than asserted, and an Ombudsman who can ask exactly how you reached the answer. The two Acts ask for the same discipline and then wire it differently.
Privacy Act 2020. Notifiable privacy breaches go to the Office of the Privacy Commissioner, and public sector holdings are almost entirely in scope. The controls have to be both strong and demonstrable.
Public Records Act 2005. Full and accurate records, created and maintained, with disposal only under an authorised schedule. Archives New Zealand audits against it. Cloud migrations and mailbox cleanups are where this quietly goes wrong.
NZISM and the Protective Security Requirements. The New Zealand Information Security Manual sets the technical baseline your security team assesses against. We design to it rather than retrofitting to it after a review.
