POTRAZ inspections: what inspectors ask for and how to prepare
POTRAZ compliance inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026. They are risk based, and healthcare is in the first wave along with other high volume and sensitive data environments. An inspector asks for your Data Controller licence, your DPO appointment, your registers, your procedures and your training records. StoneGuard prepares all of it with a certified DPO.
Last reviewed 2 September 2026.
What changed on 1 September 2026
Compliance inspections begin on 1 September 2026. Registration under Statutory Instrument 155 of 2024 had been the obligation for some time. What is new is that POTRAZ now comes to look.
Inspections follow a risk based model. Priority goes to organisations that hold large volumes of personal data and to those that hold sensitive data. Healthcare is in the first wave.
If you are in a first wave sector, the practical question is no longer whether to register. It is whether you can produce current evidence on the day.
What an inspector asks to see
An inspection is an evidence exercise. These are the items an organisation is expected to be able to produce.
Your Data Controller licence. Issued by POTRAZ in the exact registered name of the entity being inspected, and current rather than expired.
Your DPO appointment. Evidence that a qualified Data Protection Officer is appointed and was notified to POTRAZ on Form DP2.
Your record of processing activities. A current record of what personal data you hold, why, where it lives, who you share it with and how long you keep it. Current is the operative word.
Your privacy policy and consent wording. The notices you actually give people, matching what you actually do.
Your breach response procedure. A written procedure, and staff who know what to do when an incident happens.
Your data subject request procedure. How a person asks for their data, who handles it and within what timeline.
Your training records. Evidence that staff training was delivered, as CDPG 1 of 2025 requires, with names and dates against it.
Your impact assessments. A data protection impact assessment for higher risk processing, which typically covers health data and data about children.
Your security measures. How personal data is protected, including physical records and access controls, not only the systems.
Where organisations come up short
Registered but nothing behind it. A licence was obtained and then nothing was built. The registers, procedures and training that the licence presupposes were never put in place.
Documents that went stale. A record of processing activities written once and never updated, while systems, suppliers and staff changed around it.
The wrong entity. A group licensed one company and assumed the others were covered. POTRAZ licenses the legal entity, and each entity is inspected in its own name.
No training record. A policy was circulated by email. Training under CDPG 1 of 2025 means a delivered session with an attendance record.
Paper records forgotten. Systems were secured and filing rooms were not. Personal data on paper is still personal data.
Getting inspection ready with StoneGuard
A $90 consultation establishes where you stand, and is credited in full toward your package when you proceed. Packages start at $250. POTRAZ fees are paid to POTRAZ at cost, ex VAT, and are separate from the StoneGuard service fee. You will always see two numbers, never one blended figure.
Consultation. A $90 consultation opens the engagement. We work out what personal data you hold, which POTRAZ tier you fall into and what is missing. The fee is credited in full toward your package when you proceed.
Gap analysis. A certified Data Protection Officer assesses your organisation against the Cyber and Data Protection Act on the StoneGuard platform and gives you a scored report with the gaps ranked.
Licensing. We prepare and file your Data Controller licence application and your DPO appointment notification, and we handle the correspondence with POTRAZ until the licence is granted.
Documentation. Your record of processing activities, privacy policy, consent wording, breach response procedure and data subject request procedure are drafted and put in place.
Training. Staff training is delivered, which CDPG 1 of 2025 makes mandatory for licensed data controllers.
Ongoing DPO. A certified Data Protection Officer stays on record for you after the licence is granted, keeps the registers current, handles data subject requests and breaches, files the annual renewal and attends POTRAZ inspections.
Your certified DPO attends the inspection with you and produces the evidence from the platform.
Frequently asked questions
When did POTRAZ inspections start?
POTRAZ compliance inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026.
Which sectors are inspected first?
Inspections follow a risk based model, with priority given to high volume and sensitive data environments. Healthcare is in the first wave.
What does a POTRAZ inspection cover?
An inspector asks for your Data Controller licence, evidence of your Data Protection Officer appointment, your record of processing activities, your privacy policy and consent wording, your breach response and data subject request procedures, your staff training records, your impact assessments where higher risk processing applies, and your security measures for both systems and paper records.
We are registered with POTRAZ. Is that enough for an inspection?
Registration is the starting point, not the finish. An inspection tests the documentation the licence presupposes: current registers, working procedures, delivered training and evidence of security. Organisations that registered and stopped there are the ones that struggle on the day.
How quickly can we get inspection ready?
It depends on what already exists. The consultation establishes the gap in the first conversation, and the $90 fee is credited in full toward the package. The work that takes time is the gap analysis, the registers and the training, so the sooner it starts the better positioned you are.
Get licensed and inspection ready
A $90 consultation opens the engagement and is credited in full toward your package when you proceed. Compliance packages start at $250. POTRAZ fees are separate and are paid to POTRAZ at cost, ex VAT.