27 January 2023
Reference 2223-1107
M Jones
[FYI request #21212 email] Tēnā koe
Thank you for writing to the Ministry of Business, Innovation and Employment (MBIE) on 24 November
2022, to request the following, under the Official Information Act 1982 (the OIA):
a copy of MBIE's full feedback to the Government Chief Privacy Officer (GCPO) on their draft Privacy
Maturity Assessment Framework.
On 6 December 2022, you clarified your request to be for the following:
MBIE’s 2020-21 Privacy maturity self-assessment, as submitted to the Government Chief Privacy Officer,
as part of the PMAF beta test in June, but also any supplementary feedback on the beta version of the
PMAF itself, including any commentary on the addition of considerations from the DPUP, and any
concerns or comments about the new structure and content of the new PMAF.
MBIE recognises the need to be a responsible and trustworthy kaitiaki (guardian) of the personal
information we collect and use to support the delivery of our services and functions. We acknowledge
the importance of engendering trust from the public through our privacy practices, and inclusion of Te
Ao Māori worldviews in privacy and data governance.
One way we measure our effectiveness in this regard is through the Privacy Maturity Assessment
Framework (PMAF), which was developed by the Government’s Chief Privacy Officer (GCPO), to give
agencies a way to assess both their privacy capacity and maturity.
This is done through a self-assessment across five core expectations:
• Taking a people-centred approach
• Building and maintaining a privacy culture
• Building and maintaining privacy capability
• Establishing a sense of collective responsibility; and
• Being a capable treaty partner.
More information about the PMAF can be found on the GCPO’s website, at the following address:
https://www.digital.govt.nz/standards-and-guidance/privacy-security-and-risk/privacy/privacy-
maturity-assessment-framework-pmaf-and-self-assessments/. MBIE submits the PMAF self-assessment annually. The 2022 self-assessment showed MBIE as an
organisation is at a 'managed' privacy maturity, indicating that the efforts and resources we have
committed to our privacy programme have succeeded in laying a foundation on which we can continue
to build maturity.
Documents relating to the first (‘beta’) PMAF assessment are attached, as follows:
• The email from MBIE’s Chief Legal Advisor Ann Brennan to the GCPO, sent on 28 June 2021,
with MBIE’s feedback on the draft PMAF, as
Document 1
•
MBIE 2020-21 Privacy Maturity Self-assessment Framework Beta Test Report to the Government
Chief Privacy Officer, an internal memo coversheet signed by MBIE’s Chief Executive on 23 June
2021, approving the submission of MBIE’s self-assessment to the GCPO, as
Document 2
•
Privacy Maturity Assessment Framework Tool (Beta), guidance from the GCPO to agencies about
the new PMAF as
Document 3.
• MBIE’s submission to the GCPO, as
Document 4. •
Appendix II to the PMAF Beta Test document, which contains the text also in MBIE’s submission
to the GCPO, for additional readability (due to constraints in the initial PMAF template), as
Document 5.
I have withheld one mobile number from
Document 1 under section 9(2)(a) of the OIA, to protect the
privacy of natural persons.
Thank you again for writing to MBIE. Under section 28(3) of the OIA, you have the right to refer our
response to an Ombudsman for review.
Nāku noa, nā
Ann Brennan
MBIE Chief Legal Advisor & Chief Privacy Officer
Legal, Ethics and Privacy
Ngā Pou o te Taumaru
1
1
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
2
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
3
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
4
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
5
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED
ACT
INFORMATION
OFFICIAL
THE
UNDER
RELEASED