Does Cyber Crucible comply with New Zealand's Privacy Act 2020?
Short answer: Cyber Crucible supports a New Zealand agency's obligations under the Privacy Act 2020 by collecting no customer content, credentials, or keys and processing on the endpoint. The Information Privacy Principles — particularly storage and security (IPP 5) and cross-border disclosure (IPP 12) — have minimal surface because there is little personal information in its custody.
How it aligns
- IPP 5 security — encryption, access control, and autonomous endpoint protection.
- IPP 12 cross-border — on-premises deployment keeps personal information in New Zealand; no customer content is transferred offshore for security processing.
- Breach support for the agency's notifiable-privacy-breach obligations.
Vendor-selection notes
The Privacy Act 2020 introduced mandatory breach notification and compliance notices; prompt incident information supports both. Documentation is available on request.