A swathe of government departments have been ordered not to use web and information communications technology service providers not on an approved list following disclosure of a major data privacy breach over the weekend.
The Treasury, which suffered an embarrassing data breach prior to the Budget, is among those required to use only those providers who appear on an approved 'all-of-government ICT common capabilities procurement list', Prime Minister Jacinda Ardern announced at her post-Cabinet press conference.
The move follows the inadvertent publication online of key personal detail, including birth certificates, driver's licences, and passport numbers of 302 people who applied to be part of the Tuia 250 Voyage trainee scheme - an initiative linked to commemorating the arrival of Captain James Cook in New Zealand waters in 1769.
With immediate effect, all government departments deemed to have "small" ICT capabilities will be bound by the new requirement to use only approved providers, where previously the list's use was voluntary.
Some surprisingly significant agencies are covered by that definition. Along with the Treasury, the Department of Prime Minister and Cabinet, the State Services Commission, Ministry of Defence, Ministry of Transport, Ministry of Housing and Urban Development and the Crown Law Office were singled out by Ardern as being covered by the order.
Also on the list are the Ministries of Women's Affairs and Pacific Peoples, the Education Review Office and the recently formed Te Arawhiti, which is tasked with managing relations between the Crown and Maori.
"They must review planned and future ICT projects, implement common capability security and privacy-related government chief digital officer guidance," said Ardern. "They must follow the government chief information officer's information security standards and policies and they must obtain the government chief information officer's certification that they are compliant with these requirements."
The move is a clear sign of the Cabinet's frustration with sloppy data management by government agencies and its capacity to damage public confidence in the Crown's ability to maintain citizens' data privacy - a core requirement in the social contract between a government and its people.
Ardern said the unnamed firm that established Tuia 250 website was not on the all-of-government procurement list.
"My understanding is that list has not been mandatory but as I've set out, as an interim step while we work through what we need to do to prevent this ever happening again, we will now be requiring those small agencies to procure from that list over the near future as we work to secure all New Zealanders' data and restore confidence in the systems and the agencies who are providing the services to the NZ public," Ardern said.