rebuilding trust and confidence: acc’s privacy journey opc technology and privacy forum, 20...

18
Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Upload: phoebe-preston

Post on 16-Dec-2015

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Rebuilding trust and confidence: ACC’s privacy journey

OPC Technology and Privacy Forum, 20 February 2014Paul Holmes and Fiona Colman, ACC

Page 2: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Contents

– About ACC

– Privacy at ACC

– Then– Now– Future

Page 3: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

About ACC

Page 4: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

About ACC

– Comprehensive, no-fault personal injury cover for all New Zealand residents and visitors to New Zealand

– Governed by the Accident Compensation Act 2001

– Funded by New Zealanders through five accounts

Page 5: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Every day…

letters sent

claims processed

calls answered

25,000 7,000 24,000

*Correct as at May 2013

Page 6: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Claims volumes

4.4m

1.7m

1 EVERY

seconds

CLAIMSPER YR

*Correct as at May 2013

Page 7: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Privacy at ACC

Page 8: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

March 2012

Page 9: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

August 2012

Page 10: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Structural changes

•Privacy Group – BAU, full time Privacy Officer

•Project team – progress Independent Review recommendations

•Taskforce – targeted breach reduction

•Customer Information Teams – pre-release file checking

Page 11: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Mechanical changes

•ACC-specific breach definition

•Organisation-wide reporting process established

•Breach root cause analysis

•Breach management process

•Training for all staff

Page 12: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Establishing accountability

ACC Privacy Strategy sets accountability for privacy with:

•ACC Board

•Executive

•Managers

•Staff

Page 13: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

ACC privacy now

•Positive feedback

•Reduced complaints about privacy

•Many Review recommendations actioned

•Privacy by Design, through PIAs

•International/national networks

•Advisor to other agencies

•Third party accountability

•Breach numbers reduced

•Reporting tool operating

•Heightened staff awareness of privacy

•Breach simulation and incident response team

Page 14: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Lessons learned

Communicate

Plan

Co-ordinate

Page 15: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Challenges for the future

•Keeping up momentum

•Embedding good practice, especially for new staff

•Looking wider than ‘Disclosure’

Page 16: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Questions

Page 17: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Web addresses

www.acc.co.nz to access:

Independent Review http://www.acc.co.nz/about-acc/overview-of-acc/acc-and-your-personal-information/index.htm

– ACC’s privacy notice and privacy policy http://www.acc.co.nz/privacy/index.htm?ref=footer

– ACC’s privacy strategy http://www.acc.co.nz/privacy/privacy-notice/WPC120320

Contact us: [email protected]

Page 18: Rebuilding trust and confidence: ACC’s privacy journey OPC Technology and Privacy Forum, 20 February 2014 Paul Holmes and Fiona Colman, ACC

Thanks