Customer and Product Data Act 2025

Regulated data services - Additional obligations - Electronic system

28: Electronic system must comply with prescribed technical or performance requirements

You could also call this:

"Your computer system must follow special rules to share data safely and easily"

If you have data that others need to access, you need to make sure your computer system follows certain rules. These rules are set out in regulations and standards. You have to make sure your system meets these requirements.

The rules might cover different things to make sure the system works well. They could be about keeping the data safe and making sure only the right people can see it. They might also say how quickly the system should respond when someone asks for information.

The rules could also be about making sure the system is available when people need it, and that it's easy for people to use. They might say the system should be accessible to everyone, including people who might have trouble using computers.

There might also be rules about keeping an eye on how the system is working and reporting on this to the person in charge. This helps make sure everything is running smoothly.

Remember, these are just examples of what the rules might cover. The actual rules will be written down in the regulations and standards.

This text is automatically generated. It might be out of date or be missing some parts. Find out more about how we do this.

This page was last updated on

View the original legislation for this page at https://legislation.govt.nz/act/public/1986/0120/latest/link.aspx?id=LMS911741.


Previous

27: Data holder must operate electronic system for providing regulated data services, or

"Companies must have a computer system ready to handle data requests"


Next

29: Chief executive may require data holder to test electronic system, or

"Boss can ask you to check if your computer system follows the rules"

Part 2Regulated data services
Additional obligations: Electronic system

28Electronic system must comply with prescribed technical or performance requirements

  1. A data holder must ensure that the electronic system referred to in section 27 complies with the technical or performance requirements specified in the regulations and the standards.

  2. Regulations or standards made for the purposes of this section may (without limitation) relate to any of the following:

  3. security and identity verification measures:
    1. reliability and timeliness of responses to requests for regulated data services:
      1. availability:
        1. usability:
          1. accessibility:
            1. monitoring use and functionality:
              1. reporting on any of the matters referred to in paragraphs (a) to (f) (including to the chief executive).