New Zealand Government Web Standards

21.1 Security requirements for internet exchange of personal information

New standards released

The New Zealand Web Standards 2.0 were released in March 2009 and replace the previous version, the New Zealand Government Web Standards 1.0 (below).  See Meeting the standards for more information.

The Standard

21.1 For exchange of personal information between web site user and the environment hosting the agency web site(s), the hosting environment must as a minimum:

Guide to this standard

An example of personal information is credit card details when making online payments.

Rationale for this standard

This standard recognises the importance that government places upon the security of personal information. Agencies are required to implement Security in the Government Sector (SIGS), which includes a set of minimum internet security standards. (Department of the Prime Minister and Cabinet on 1 July 2002). Privacy Principle 5, Privacy Act 1993, states the responsibility an agency has of ensuring that security safeguards protect personal information.

A government agency must be confident of the security of personal information exchanged between a client and an agency web site.