• Government

Draft data protection standard opens for public comment

The department has published a draft standard setting out how government agencies must collect, store, and share personal data. Public comments are open for six weeks.


  • 4 min read
  • Digital Development Department
The consultation runs on the department's open policy platform. Placeholder image.
The consultation runs on the department's open policy platform. Placeholder image.

Every government service that asks a citizen for their name, address, or identification number relies on rules for how that information is handled afterwards. Until now, those rules have differed from one agency to the next. The draft data protection standard is the department's attempt to make them consistent across government.

What the standard covers

The document sets baseline requirements in four areas: what data an agency may collect for a given service, how long it may keep it, who inside government may access it, and how a person can see or correct their own records. Each requirement is written as a testable rule rather than a general principle, so agencies and auditors can check compliance directly.

It also defines a short list of things agencies may not do — reusing data collected for one service to make decisions in another without a clear legal basis, for example, or keeping identifying records after the purpose they were collected for has ended.

A standard only works if the people expected to follow it helped write it. That is what this consultation is for.

Director General, Digital Development Department
Draft clauses are versioned publicly, so changes between drafts stay visible. Placeholder image.
Draft clauses are versioned publicly, so changes between drafts stay visible. Placeholder image.

How to respond

The draft is published in full on the department's policy platform alongside a structured comment form. Responses can address the standard as a whole or any individual clause. Agencies adopting shared platforms are encouraged to comment on the sections dealing with access control and retention, which affect them most directly.

After the comment period closes, the department will publish every substantive response it receives, along with a summary of the changes made. A final version is expected before the end of the year, with a phased adoption timeline for existing services.

Until the standard is finalized, existing agency data-protection practices remain in force. The department has asked agencies not to begin large changes to their systems until the final text is confirmed.