Compliance
Every search is authorised, recorded and defensible
Data providers and regulators will hold you to the same standard whichever platform you use. intelID is built so that standard is enforced on every query, by every user, without depending on anyone remembering.
Why compliance sits at the centre of the product
An enquiry that cannot be justified afterwards is a liability regardless of how good the result was. The people most exposed are the ones running searches at volume: recovery teams, investigators, process servers and risk analysts, all of whom may run hundreds of queries a month across several provider portals with no single record tying any of them to a stated basis.
intelID treats the justification as part of the search rather than as paperwork that follows it. The declaration is captured before results are returned, it is stored with the query, and it is visible to the organisation’s administrators. If the enquiry is ever questioned, the answer is a retrieved record with a timestamp, not a recollection.
Controls in place
- Privacy Act 2020
- The platform is operated to comply with the Privacy Act 2020. Information is collected for the declared purpose, used only for that purpose, held securely, and retained only as long as that purpose requires. The information privacy principles are applied to the platform as a whole, not just to the account record.
- Credit Reporting Privacy Code 2020
- Credit reporting data is handled in alignment with the Code. Access is restricted to users whose role and declared purpose permit it, and the restriction is enforced at the platform rather than left to the user's judgement.
- Authorised-purpose declaration
- Every search requires the user to declare an authorised purpose before results are returned. The declaration is bound to the query and stored with it, so the basis for an enquiry exists as a record from the moment it is run.
- Full audit logging
- Every query is logged with the user, the timestamp, the declared purpose, the subject searched and the sources queried. Logs cannot be edited after the fact and can be produced if a search is questioned.
- Role-based access control
- Sources and functions are granted by role. An organisation controls which of its users can reach which data, and a user cannot see a source their role has not been granted.
- Encryption in transit and at rest
- Data is encrypted in transit and at rest across the platform, including audit records and account information.
- Hosting and offshore processing
- The platform runs on Google Cloud Platform infrastructure, with the controls described on the security page. Data is held in a hosting region selected for the service, and some processing or support may occur outside New Zealand. Where information is transferred outside New Zealand we take reasonable steps to ensure the recipient is subject to safeguards comparable to those in the Privacy Act 2020, in accordance with Information Privacy Principle 12.
- Vendor security programme
- Our vendor security programme is benchmarked to SOC 2 Type II providers. intelID does not itself claim a SOC 2 attestation.
Authorised purpose in practice
The declaration is a control, not a formality.
When an account is issued, the authorised purposes the organisation may search under are set as part of the approval. A debt recovery firm and a law firm preparing for litigation are not granted the same access, because the lawful basis on which each may reach credit reporting data is different. Role-based access reflects that difference at the level of the individual user.
At search time the user selects and declares the purpose that applies to the file in front of them. That declaration is written into the audit record alongside the subject and the sources queried. Where a pattern of searches does not match the purpose an account was issued for, it is visible in the log before it becomes a complaint, and access can be restricted or withdrawn.
What we do not do with subject data
These limits are contractual as well as technical.
- No marketing use of subject data.
- No resale of subject data.
- No public indexing of subject data. Search engines cannot reach it and it is not exposed on this website.
- No accounts without verification of the user, the organisation and the intended authorised purpose.
- No source that cannot be reached lawfully for a declared authorised purpose.
Disclosures that are permitted
Two disclosures sit outside those limits, and both exist to keep the licences and the service running:
- To a data provider carrying out an audit or compliance review of access to its data, where our licence with that provider requires it.
- To service providers who host, support or secure the service, and only to the extent needed to perform those functions on our behalf.
The complete list of circumstances in which information may be disclosed is set out in our privacy policy.
Vetting before access
Verification is the reason there is no signup button on this site.
We confirm the identity of the applicant, the standing of the organisation, any relevant licence or professional registration, and the authorised purpose for which searches will be run. Accounts are issued only after that check is complete, and role-based access is set at the same time. Where an organisation’s circumstances change, the access position is reviewed rather than left as it was.
The infrastructure, encryption, access control and incident response arrangements supporting this framework are described on the security page. The legal basis attached to each individual source is set out on the data sources page, and the point in the workflow at which the declaration is captured is shown on the platform page.
Compliance questions
Is intelID compliant with the Privacy Act 2020?
Yes. Collection, use, disclosure, storage and retention of information through the platform are handled against the information privacy principles in the Privacy Act 2020.
How is credit reporting data handled?
Credit reporting data is handled in alignment with the Credit Reporting Privacy Code 2020, including restrictions on who may access it and the purposes for which it may be accessed.
Is intelID SOC 2 certified?
No. intelID does not hold a SOC 2 attestation. Our vendor security programme is benchmarked to SOC 2 Type II providers, and the platform is hosted on Google Cloud Platform. Some processing or support may occur outside New Zealand under Information Privacy Principle 12.
What is recorded when a search is run?
The user, the timestamp, the declared authorised purpose, the subject searched and the sources queried are recorded in the audit log.
Is subject data ever used for anything else?
No. Subject data is not used for marketing, is not resold, and is not exposed to public indexing.
What happens if a user searches outside their authorised purpose?
The query is recorded against that user and their declared purpose. Organisation administrators can review activity, and access can be restricted or withdrawn where a search falls outside the terms the account was issued under.
Ask for the compliance detail before you apply
If your organisation needs to review our data-handling position before requesting access, contact us and we will provide it.