Compliance
Every search is authorised, recorded and defensible
Data providers and regulators will hold you to the same standard whichever platform you use. intelID is built so that standard is enforced on every query, by every user, without depending on anyone remembering.
Why compliance sits at the centre of the product
An enquiry that cannot be justified afterwards is a liability regardless of how good the result was. The people most exposed are the ones running searches at volume: recovery teams, investigators, process servers and risk analysts, all of whom may run hundreds of queries a month across several provider portals with no single record tying any of them to a stated basis.
intelID treats the justification as part of the search rather than as paperwork that follows it. The declaration is captured before results are returned, it is stored with the query, and it is visible to the organisation’s administrators. If the enquiry is ever questioned, the answer is a retrieved record with a timestamp, not a recollection.
Controls in place
- Authorised purpose declaration
- Every search requires the user to declare an authorised purpose before results are returned. The declaration is bound to the query and stored with it, so the basis for an enquiry exists as a record from the moment it is run.
- Credit reporting access
- Credit reporting data is handled in alignment with the Credit Reporting Privacy Code 2020. Access is restricted to users whose role and declared purpose permit it, and the restriction is enforced at the platform rather than left to the user's judgement. A full credit report on an individual is supplied only with that person's consent, or where the Code permits access without it, such as recovery of an existing debt, and the report may not be used for any purpose other than the one declared.
- Register and licence conditions
- Each source carries the access conditions of the register or licence behind it, including the authorised purpose test that applies to credit reporting information and the audit rights held by credit reporters and other providers. Those conditions are applied by role before the search runs, not after it.
- Screening results
- Sanctions, politically exposed person and adverse media results are indicators for review rather than findings, and run under the same declared purpose, role grant and audit record as every other source.
- Full audit logging
- Every query is logged with the user, the timestamp, the declared purpose, the subject searched and the sources queried. Logs cannot be edited after the fact and can be produced if a search is questioned.
- Role-based access control
- Sources and functions are granted by role. An organisation controls which of its users can reach which data, and a user cannot see a source their role has not been granted.
- Encryption in transit and at rest
- Data is encrypted in transit and at rest across the platform, including audit records and account information.
- Hosting and offshore processing
- The platform runs on Google Cloud Platform infrastructure, with the controls described on the security page. Data is held in the Australia/New Zealand region, and some processing or support may occur outside New Zealand. Where information is transferred outside New Zealand we take reasonable steps to ensure the recipient is subject to safeguards comparable to those in the Privacy Act 2020, in accordance with Information Privacy Principle 12.
- Vendor security programme
- Our vendor security programme is benchmarked to SOC 2 Type II providers. intelID does not itself claim a SOC 2 attestation.
The legal framework we operate under
One consolidated list, rather than a different set of references on every page.
- Privacy Act 2020Platform wide
- Governs collection, use, disclosure, storage, retention, access and correction across the platform. Information Privacy Principle 12 applies where any processing or support occurs outside New Zealand.Read Privacy Act 2020
- Credit Reporting Privacy Code 2020Credit reporting data
- Applies to Equifax and Centrix data, including credit linked address and contact information and full individual and commercial credit reports. Sets who may access the data, the permitted purposes, and when consent is required.Read Credit Reporting Privacy Code 2020
- Land Transfer Act 2017LINZ property and title data
- The land title register is maintained under this Act and searched under LINZ licensing terms.Read Land Transfer Act 2017
- Personal Property Securities Act 1999PPSR
- Establishes the register of security interests over personal property, searched under MBIE terms of use.Read Personal Property Securities Act 1999
- Companies Act 1993Companies Office data
- Company registration, directors, shareholders, addresses for service and filing history are public register information under this Act and related registers legislation.Read Companies Act 1993
- Insolvency Act 2006Insolvency registers
- Bankruptcy, no asset procedures and debt repayment orders are published by the Insolvency and Trustee Service under this Act. Company insolvency events are published under the Companies Act 1993.Read Insolvency Act 2006
- Private Security Personnel and Private Investigators Act 2010Vetting of users
- Where an applicant carries out investigation work, we confirm the licence or certificate of approval position with the Private Security Personnel Licensing Authority before an account is issued.Read Private Security Personnel and Private Investigators Act 2010
- Anti-Money Laundering and Countering Financing of Terrorism Act 2009Customer due diligence use
- Reporting entities use intelID to support customer due diligence, beneficial ownership tracing and enhanced due diligence. The obligation to meet the Act remains with the reporting entity.Read Anti-Money Laundering and Countering Financing of Terrorism Act 2009
- Credit Contracts and Consumer Finance Act 2003Lending and collections users
- Relevant to the authorised purpose declared by lenders and recovery teams when searching in connection with an existing or proposed credit contract.Read Credit Contracts and Consumer Finance Act 2003
- Crimes Act 1961, sections 249 and 252Limits on access
- No source is reached by accessing a computer system without authorisation. Every source is licensed, a public register, or publicly available information.Read Crimes Act 1961, sections 249 and 252
- Harmful Digital Communications Act 2015Limits on use
- Results may not be used to harass, intimidate or cause harm to a search subject. Accounts are withdrawn where they are.Read Harmful Digital Communications Act 2015
- Fair Trading Act 1986How we describe the service
- Coverage, sources and results are described as they are. Nothing is presented as available unless it is.Read Fair Trading Act 1986
- Contract and Commercial Law Act 2017Terms and electronic records
- Supports acceptance of our terms of use and the electronic form of the audit record.Read Contract and Commercial Law Act 2017
The legal basis attached to each individual source is set out on the data sources page, and the contractual position is in our terms of use and privacy policy.
Authorised purpose in practice
The declaration is a control, not a formality.
When an account is issued, the authorised purposes the organisation may search under are set as part of the approval. A debt recovery firm and a law firm preparing for litigation are not granted the same access, because the lawful basis on which each may reach credit reporting data is different. Role-based access reflects that difference at the level of the individual user.
At search time the user selects and declares the purpose that applies to the file in front of them. That declaration is written into the audit record alongside the subject and the sources queried. Where a pattern of searches does not match the purpose an account was issued for, it is visible in the log before it becomes a complaint, and access can be restricted or withdrawn.
What we do not do with subject data
These limits are contractual as well as technical.
- No marketing use of subject data.
- No resale of subject data.
- No public indexing of subject data. Search engines cannot reach it and it is not exposed on this website.
- No accounts without verification of the user, the organisation and the intended authorised purpose.
- No source that cannot be reached lawfully for a declared authorised purpose.
Disclosures that are permitted
Two disclosures sit outside those limits, and both exist to keep the licences and the service running:
- To a data provider carrying out an audit or compliance review of access to its data, where our licence with that provider requires it.
- To service providers who host, support or secure the service, and only to the extent needed to perform those functions on our behalf.
The complete list of circumstances in which information may be disclosed is set out in our privacy policy.
Vetting before access
Verification is the reason there is no signup button on this site.
We confirm the identity of the applicant, the standing of the organisation, any relevant licence or professional registration, and the authorised purpose for which searches will be run. Accounts are issued only after that check is complete, and role-based access is set at the same time. Where an organisation’s circumstances change, the access position is reviewed rather than left as it was.
The infrastructure, encryption, access control and incident response arrangements supporting this framework are described on the security page. The legal basis attached to each individual source is set out on the data sources page, and the point in the workflow at which the declaration is captured is shown on the platform page.
Compliance questions
Which laws does intelID operate under?
The consolidated list is on this page and covers the Privacy Act 2020, the Credit Reporting Privacy Code 2020, the Land Transfer Act 2017, the Personal Property Securities Act 1999, the Companies Act 1993, the Insolvency Act 2006, the Private Security Personnel and Private Investigators Act 2010, the AML/CFT Act 2009, the Credit Contracts and Consumer Finance Act 2003, sections 249 and 252 of the Crimes Act 1961, the Harmful Digital Communications Act 2015, the Fair Trading Act 1986 and the Contract and Commercial Law Act 2017.
Is intelID compliant with the Privacy Act 2020?
Yes. Collection, use, disclosure, storage and retention of information through the platform are handled against the information privacy principles in the Privacy Act 2020.
How is credit reporting data handled?
Credit reporting data is handled in alignment with the Credit Reporting Privacy Code 2020, including restrictions on who may access it and the purposes for which it may be accessed.
Is intelID SOC 2 certified?
No. intelID does not hold a SOC 2 attestation. Our vendor security programme is benchmarked to SOC 2 Type II providers, and the platform is hosted on Google Cloud Platform. Some processing or support may occur outside New Zealand under Information Privacy Principle 12.
What is recorded when a search is run?
The user, the timestamp, the declared authorised purpose, the subject searched and the sources queried are recorded in the audit log.
Is subject data ever used for anything else?
No. Subject data is not used for marketing, is not resold, and is not exposed to public indexing.
What happens if a user searches outside their authorised purpose?
The query is recorded against that user and their declared purpose. Organisation administrators can review activity, and access can be restricted or withdrawn where a search falls outside the terms the account was issued under.
Ask for the compliance detail before you apply
If your organisation needs to review our data-handling position before requesting access, contact us and we will provide it.