UC-012_PetIdent_NZ_vendor_due_diligence.pdf
EV-2026-0135 · Vendor DD · linked to Companion Animals AI — image-based dog ID
Artefact ID
EV-2026-0135
Type
Vendor DD
Linked use case
Uploaded by
Procurement Lead
Uploaded at
2026-05-04 09:22
Size
480 KB
SHA-256
ccdd…eeff (truncated for display)
Hash chain
Verified · chained to previous entry
Summary
Vendor due diligence for PetIdent (NZ-based supplier providing dog image-ID for impounded animals). Includes assessment of cross-border data flow.
Chain of custody
Compiled by Procurement Lead following NZ-specific cross-border review template. Hash chained at upload.
Key facts
- Vendor
- PetIdent Limited (NZBN 9429048 277192, registered Auckland)
- Data hosting
- AWS Sydney (ap-southeast-2). Vendor is NZ-incorporated but elected AU hosting for AU customers.
- Cross-border data flow
- Image upload AU → AU. NO data flows to NZ. PPIPA s.19 cross-border requirements satisfied via data residency.
- PII involved
- Animal photos and owner contact (where dog is registered). Owner contact retained only for impound match.
- Certifications
- ISO 27001, no IRAP (NZ vendor — accepted with mitigating controls)
- Insurance
- $5m PI, $5m PL (lower than enterprise standard — accepted given low transaction value)
- Reference customers (AU)
- Wagga Wagga, Tweed Shire, Snowy Monaro
- Annual cost
- AUD $4,200/year
- Risk recommendation
- Proceed with annual review. Low business criticality.