Country-specific guidance Current

Storing client identity evidence securely in New Zealand

A practical approach, starting from what the AML/CFT Act and Privacy Act actually require.

Collecting and verifying a client's identity evidence is only useful if it stays secure once you have it. This guide sets out a practical approach grounded in the AML/CFT Act's record-keeping obligation and the Privacy Act's security principle. It is general information, not legal or IT security advice.

Action plan

1 Keep identity evidence with your other due diligence records The AML/CFT Act treats identity and verification evidence as its own category of record your firm must keep.

Department of Internal Affairs guidance confirms that identity and verification evidence is a distinct category of record reporting entities must keep under the AML/CFT Act, alongside records relevant to establishing the business relationship. Store this evidence together with your other customer due diligence records, not scattered across separate systems or individual staff inboxes.

  • Store identity evidence with your other customer due diligence records
  • Avoid leaving evidence in individual staff email inboxes or personal drives
  • Keep the evidence identifiable and retrievable at any time, not just archived

Done when: Identity evidence is stored with other due diligence records, retrievable at any time

DIA: AML/CFT guideline on record keeping
2 Apply security safeguards reasonable in the circumstances The Privacy Act separately requires reasonable safeguards for any personal information you hold, including identity evidence.

Information Privacy Principle 5 requires an agency holding personal information to protect it with safeguards that are reasonable in the circumstances, against loss, and against access, use, modification, or disclosure that isn't authorised. Identity evidence is personal information, so this obligation applies to it directly, separately from your AML/CFT record-keeping obligation.

  • Restrict access to stored identity evidence to staff who genuinely need it
  • Apply safeguards proportionate to how sensitive the evidence is
  • Review who has access periodically, especially after staff changes

Done when: Reasonable security safeguards are applied to stored identity evidence, with access limited to staff who need it

Privacy Commissioner: Information Privacy Principle 5
3 Plan for secure disposal once retention ends, not just secure storage Security doesn't stop being relevant once the retention period is over.

Once your firm's retention period for a piece of identity evidence has ended, disposing of it securely matters as much as how it was stored. Build a disposal step into your retention schedule so evidence doesn't sit indefinitely, or get discarded insecurely, once it's no longer required to be kept.

  • Confirm the applicable retention period before disposing of any evidence
  • Dispose of evidence securely once retention ends, not by ordinary deletion or discarding alone
  • Record when evidence was disposed of, consistent with your retention schedule

Done when: A secure disposal step is applied once the retention period for a piece of evidence has ended

See setting a record retention schedule