Incident response, policy continuity, workforce certification, and board evidence. One environment, built for the Privacy Act 2020.
Serious privacy breaches notified to the OPC rose 43% in 2024/25, the highest on record. IPP 3A mandatory notification obligations in force 1 May 2026. Source: OPC Annual Report 2024/25 · Privacy Amendment Act 2025
Every organisation gets an isolated environment built to its structure and Privacy Act obligations. Operational in days.
Dedicated domain. No shared infrastructure. Branded to the organisation from day one.
Privacy Act 2020 and IPP 3A mapped to the organisation's structure and responsibilities.
Workforce modules activated. Individual completion records from day one.
72-hour breach response active. Timestamped from first awareness. OPC-ready.
Governance posture visible. Evidence exportable. Board-ready from activation.
| Incident response | Timestamped records from first awareness through OPC notification |
| Policy management | Version-controlled obligations current to IPP 3A |
| Workforce readiness | Individual certification evidence board-reportable |
| Board reporting | Governance visibility at every level of the organisation |
ComplianceLayer is operational governance infrastructure. Not a policy generator, document repository, or training portal.
| BreachReady NZ | Incident governance |
| PolicyLayer | Policy governance |
| AiReady NZ | Workforce governance |
Structured triage from first awareness through OPC notification and board reporting. Every step timestamped. Notifiability assessed at each stage.
Built to Privacy Act 2020 · section 113 and OPC notification guidance · May 2024
Privacy policies and compliance documents version controlled and ownership assigned. Current to IPP 3A.
Aligned to the Privacy Amendment Act 2025 · IPP 3A in force 1 May 2026
Individual certification records and board-reportable evidence of workforce AI readiness. Governance continuity when staff change.
Covers obligations under the Privacy Act 2020 and Privacy Amendment Act 2025 as they apply to AI use in NZ organisations
Governance posture visible at board level. Audit evidence, board papers, and director liability records generated from live organisational data.
Director liability exposure under Privacy Act reform · Bell Gully 2026 and the NZ Cyber Security Strategy 2026
Each tool operates independently and updates the central governance record in real time. No sequential setup. No dependency on another tool being completed first.
A 6-step triage workflow that applies sections 112 to 117 of the Privacy Act 2020 to the specific circumstances of an incident. Notifiability is assessed automatically. Six documents are generated on completion.
A 6-step intake wizard that generates a complete, plain-English privacy policy specific to the organisation. Industry, jurisdiction, data types, and third-party tools are all factored in. The output is ready to publish.
12 structured modules covering AI governance, the Privacy Act 2020, and NZ-specific obligations. Each module includes assessment. Completion is recorded individually and reported at board level.
A live dashboard that draws from all three tools. Governance posture, workforce readiness, policy status, and incident history in one place. Board-ready exports available at any point without manual preparation.
No sales pitch. No obligation. Just a straight conversation about whether ComplianceLayer fits the organisation.
See the live platform first ↗