In Brief:
Major data breaches are becoming a recuring issue for New Zealand business and agencies with the potential for major emotional and economic harm for individuals whose private and confidential information might be compromised in such events.
It is increasingly common for entities that have suffered such breaches to ask the Court to make orders requiring the world at large to destroy and refrain from using information compromised in these events. This article considers what this achieves.
Summary: ....
Following the large-scale cyberattack on Manage My Health, the High Court made orders against the unknown hackers and anyone else who might obtain the stolen information prohibiting anyone accessing, storing, publishing, sharing, disclosing or otherwise using the stolen data and requiring anyone possessing it to delete it. Those orders were made permanent in July 2026 in Manage My Health Ltd v Unknown Defendants [2026] NZHC 2119.
Manage My Health is not the first case of its kind. Following the 2021 Waikato DHB cyberattack, the High Court restrained Radio New Zealand and unknown defendants from accessing, using or disclosing information from a stolen dataset and required copies to be deleted: Waikato District Health Board v Radio New Zealand Ltd [2021] NZHC 2002. Similar orders were obtained by Te Whatu Ora and the Ministry of Justice following the 2022 ransomware attack on IT provider Mercury IT: Te Whatu Ora Health New Zealand v Unknown Defendants [2022] NZHC 3568. More recently, in Neighbourly Ltd v Unknown Defendants [2026] NZHC 1, the High Court granted orders concerning member data which had been advertised for sale on the dark web.
There is therefore now a developing line of New Zealand authority for using injunctions to try to contain stolen data.
But if you're one of the people who has had data compromised in one of these breaches, you might be wondering about the point of all this. Afterall, the hackers already have the information, and the order doesn’t get it back or stop copies being made. And of course, the people responsible may be overseas, impossible to identify, and (it’s probably safe to assume) someone who is prepared to hack and steal your data in the first place is unlikely to be particularly troubled by an order of the Court.
You might be forgiven for asking then if injunctions after breaches merely legal theater, or do they serve a relevant purpose?
Injunctive relief of this kind obviously does little to alleviate the understandable and often significant emotional distress of knowing that your personal and, in some of these cases, highly private and confidential information has been compromised. But most of the time a data breach will not, in and of itself, cause direct, measurable financial harm. Rather, the potential for measurable harm tends to arise afterwards if stolen information is subsequently published, copied, indexed by search engines, sold, used for fraud or blackmail, or accessed by someone interested in a particular individual.
Some compromised information can be changed to protect against these uses. Passwords can be reset and credit cards cancelled, for example, and account activity can be monitored. Entities affected by a data breach absolutely should be helping people whose data has been compromised to take these steps.
But other information, such as a person's medical history, legal records, or address and contact details, can't be protected in this way. If data of this kind has been compromised, a different approach is needed to limit the fallout.
The Manage My Health and similar injunctions should be understood as one such approach. They are containment measures which work, to the extent they can, by making further distribution and use of the compromised information legally risky. Knowingly breaching a court order can amount to contempt and, under the Contempt of Court Act 2019, penalties can include substantial fines and, for individuals, imprisonment.
An order applying beyond the original hackers also makes it easier to approach someone who holds the data, or provides access to it, and require its removal without first having to go through the costly process of seeking separate orders against specific defendants on a case-by-case basis.
So while injunctions of this kind are unlikely to eliminate the criminal market for, and use of, stolen data, they can make that information harder to distribute and less useful and marketable to those who might otherwise be prepared to use compromised data, but are less inclined to do so when there are legal consequences.
Of course, an injunction is also a tool which may help reduce the legal risk and liability of the entity which suffered the breach. Once a breach has occurred, there may be questions about what could reasonably have been done to prevent further loss and whether subsequent harm could have been avoided. The Privacy Act 2020 expressly recognises the importance of steps taken after a breach to reduce the risk of harm. For the reasons outlined above, injunctions are clearly a useful part of the toolkit for attempting to achieve this.
So not only do these steps have some inherent, even if limited, benefit for the victims of a data breach, they may also matter if affected people later seek compensation.
That is important, but it should not obscure the other side of the equation. Taking appropriate steps to contain a breach after it has happened does not answer the question of whether the information was adequately protected in the first place, nor does it necessarily relieve the organisation responsible of liability for harm already caused. For those affected, the injunction may limit what happens next, while leaving open quite separate questions about how the breach occurred, whether reasonable safeguards were in place, and whether there is a claim for the consequences.
GCA Lawyers advises individuals and groups affected by privacy and data breaches, including incidents affecting large numbers of people.
If your personal information has been compromised and you would like advice about your rights, potential compensation or whether a collective claim may be appropriate, contact us to discuss your circumstances.


