Security Level Agreement Template for New Zealand

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Security Level Agreement?

This Security Level Agreement template is designed for use in New Zealand business contexts where organizations need to establish clear, measurable security standards and responsibilities with their service providers or clients. The document is particularly relevant in light of the Privacy Act 2020 and increasing cybersecurity requirements across various sectors. It provides a comprehensive framework for defining security controls, response procedures, and performance metrics while ensuring compliance with New Zealand's legal and regulatory requirements. The agreement is essential for organizations handling sensitive data, implementing security services, or requiring specific security standards from their service providers. It includes detailed technical specifications, compliance requirements, and operational procedures tailored to meet both local and international security standards.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

New Zealand

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Security Level Agreement

A Security Level Agreement (SLA) is a legally binding contract that establishes specific, measurable security standards and performance requirements between your organization and service providers. Under New Zealand law, these agreements are essential for defining accountability, response procedures, and compliance obligations when handling sensitive data or critical systems.

When do you need this document?

You need a Security Level Agreement when engaging cloud service providers to handle customer data, ensuring Privacy Act 2020 compliance through defined security controls. Organizations implementing managed security services require these agreements to establish clear performance metrics and incident response procedures. If you're a data center provider or technology infrastructure company, this document protects both parties by defining security responsibilities and liability frameworks. Companies handling payment card information, healthcare records, or government data must establish these agreements to meet industry compliance requirements. When your business undergoes security audits or regulatory assessments, having comprehensive security agreements demonstrates due diligence and proper risk management.

Key legal considerations

Your Security Level Agreement must clearly define security incident notification timeframes, particularly for privacy breaches requiring notification under the Privacy Act 2020. The document should specify liability allocation for security failures, including financial responsibility for data breaches and system compromises. Include detailed service level metrics with penalties for non-compliance, ensuring enforceability under the Contract and Commercial Law Act 2017. The agreement must address cross-border data transfer requirements, particularly when using international service providers or cloud services. Consider including intellectual property protections for security methodologies and requiring appropriate insurance coverage for cybersecurity incidents. Termination clauses should address secure data return and destruction procedures to prevent unauthorized access to sensitive information.

Legal requirements in New Zealand

Under the Privacy Act 2020, your Security Level Agreement must include mandatory privacy breach notification procedures, requiring service providers to notify you immediately of any potential privacy breaches. The agreement should reference compliance with the New Zealand Information Security Manual (NZISM) for government-related services or contracts. Include provisions for regular security assessments and penetration testing as required by industry standards and regulatory frameworks. The document must specify data sovereignty requirements, ensuring personal information of New Zealand residents remains subject to New Zealand privacy law regardless of where it's processed. For electronic transactions and digital signatures, ensure compliance with the Contract and Commercial Law Act 2017's electronic transaction provisions. Consider incorporating requirements for security certifications such as ISO 27001 or SOC 2, which are increasingly expected by New Zealand regulators and business partners.

GOVERNING LAW

Applicable law

This Security Level Agreement is drafted to comply with New Zealand law. Key legislation includes:

Privacy Act 2020: Fundamental legislation governing how personal information is collected, used, stored, and disclosed in New Zealand. Includes mandatory privacy breach reporting and cross-border data protection requirements.
Contract and Commercial Law Act 2017: Provides the legal framework for electronic transactions and digital signatures, essential for security agreements and digital business operations.
Crimes Act 1961 (specifically sections relating to computer crimes): Contains provisions relating to computer system crimes and unauthorized access, which are relevant for defining security breach scenarios and responses.
Fair Trading Act 1986: Ensures fair trading practices and could apply to representations made about security levels and services provided.
NZISM (New Zealand Information Security Manual): Government guidelines for information security, providing baseline security controls and best practices that should be considered in security agreements.
Telecommunications (Interception Capability and Security) Act 2013: Relevant for security agreements involving telecommunications networks and services, especially regarding interception capabilities and network security.
Consumer Guarantees Act 1993: Applies if the security services are being provided to consumers, ensuring services meet quality and fitness-for-purpose requirements.
Public Records Act 2005: Important if the security agreement involves public sector organizations or government data, setting requirements for record-keeping and information management.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it