NZ's Biometric Code grace period ends 3 August 2026
If your business was already using biometric systems — facial recognition, fingerprint entry, attendance scanners — before November 2025, the transition window closes on 3 August 2026. Here's what full compliance means.
ReadTwo Privacy Act deadlines land on 10 December 2026
Automated decision-making transparency commences and the Children's Online Privacy Code must be registered on the same day. What each one is, who it touches, and what to do before December.
ReadThe Cyber Security Act 2024 is now fully in force — what applies to you
Ransomware payment reporting, smart-device security standards and the Cyber Incident Review Board have all commenced. A plain-English rundown of which obligations touch an ordinary Australian business.
ReadIncident response and business resilience: a plain-English guide
What a working incident response plan actually needs, how it links to your notification duties in Australia and New Zealand, and where to start without buying a bank-sized security program.
ReadUpdating your business continuity plan: lessons from global environmental disruption
Companies now anticipate US$714 billion in future financial impact from extreme weather, yet only 35% of those disclosing treat it as a material risk. This guide covers what to change in your continuity plan, and how it intersects with your Australian breach-notification duties.
ReadThe financial difference between a documented response and winging it
Organisations with a tested incident response plan save an average of US$2.66 million per breach. This guide sets out what that gap is built from, what Australian law already requires of you, and how to close it without a bank-sized security program.
Read