Privacy Laws
11 min read

Guide on the New Zealand Privacy Act 2020 (NZPA)

By Safna|November 21, 2025
Guide on the New Zealand Privacy Act 2020 (NZPA)

New Zealand is one of the few countries with an EU adequacy decision, meaning it has a strong privacy foundation. The New Zealand Privacy Act of 2020 strengthens the rights of individuals and the responsibilities of organisations regarding the collection, use, and protection of personal information. Here is a detailed guide.

Effective date: December 1, 2020

Law text: Privacy Act 2020

What is the New Zealand Privacy Act?

The Privacy Act 2020 is the primary law governing the collection, use, storage, and sharing of personal information in New Zealand. It replaced the Privacy Act 1993 and came into force on December 1, 2020.

The Act sets clear rules for organisations and businesses, known as agencies, on handling personal data. It gives individuals more control over their information and introduces stronger protections against misuse.

Key highlights include:

  • Mandatory breach notification for serious privacy breaches
  • Stronger powers for the Privacy Commissioner
  • Clear rules for sharing information with overseas organisations
  • Legal obligations for all businesses that collect personal data in or from New Zealand

The Privacy Act also sets out 13 Information Privacy Principles (IPPs) that guide how agencies must collect, use, store, and disclose personal information. 

The law applies to both public and private sector agencies, including overseas companies doing business in New Zealand.

In September, the New Zealand Government enacted the Privacy Amendment Act 2025. It introduces new transparency requirements (IPP 3A) for data collection from third parties and expands the grounds for refusing DSAR requests.

What is personal information under the NZPA 2020?

Personal information means any data about a living person who can be identified. 

It can include:

  • Names and contact details
  • Address
  • Health or financial records
  • Purchase history or account numbers
  • Photos, recordings, notice

The individual doesn’t need to be named. If they could be identified through details like their home address or online identifiers, the law still treats it as personal information.

The law applies whether the information is sensitive (like medical history) or basic (like an email address). If there's a reasonable chance someone can be identified from the information, it falls under the Privacy Act.

Who does the New Zealand Privacy Act 2020 apply to?

The Privacy Act 2020 applies to any person, business, or organisation that handles personal information in New Zealand, even if they’re not based there. 

It covers both local and overseas agencies. Here is a detailed breakdown:

  • New Zealand agencies: Organisations operating in New Zealand, regardless of whether the personal information was collected.
  • Overseas agencies: Organisations outside New Zealand carrying on business within the country and collecting or holding personal information about New Zealand residents.
  • Individuals not based in New Zealand: Individuals temporarily in New Zealand who collect personal data while physically present in New Zealand or hold personal information while in New Zealand, even if they didn’t collect it there.

Meaning of Agency under the New Zealand Privacy Act

The Privacy Act does not expressly require consent for processing personal data. However, it is important to comply with other obligations, including the 13 Information Privacy Principles.

For online cookies, ensure that you are transparent about it and also provide a measure to opt out of it.

New Zealand Privacy Commissioner’s website informs users that they can opt out of cookies in their privacy statement.

Also, if you don't have a cookie policy and cookie banner yet, consider having one to ensure foolproof compliance.

Create a cookie banner and policy for your website

Sign up for CookieYes and customise your cookie management the easiest way

Get a free trial
  • 14-day free trial
  • Cancel anytime

What are the 13 Information Privacy Principles (business obligations)?

IPP 1: Purpose of collection

An agency should only collect personal information if:

  • There is a lawful purpose that is connected to its function,
  • Data is necessary for that purpose.

You can’t just collect information in anticipation of any future purposes that may arise. Also, avoid collecting personal data if the purpose can be achieved without it.

IPP 2: Source of personal information

When a business or organisation collects personal information, it should ideally get that information directly from the person it’s about.

However, there are situations where it’s okay to collect it from another source. For example:

  • When it doesn’t harm the individual’s interests.
  • When collecting it directly would defeat the purpose (like during an investigation).
  • The concerned person permits data collection from someone else.
  • The information is already publicly available.
  • It’s needed for law enforcement, legal proceedings, protecting public revenue, or preventing serious threats to health or safety.
  • It’s not practical to get the information directly.
  • The information will only be used in a way that doesn’t identify anyone.

IPP 3: Collection of personal information from the individual concerned

When an organisation collects personal information directly from someone, it must ensure transparency.

You must inform the individuals of at least the following before collection, or if that’s not possible, as soon as possible afterwards:

  • What information is being collected
  • Why is it needed
  • Who will receive or use it?
  • Who is collecting it, and who will store it
  • The law under which data is collected, if applicable
  • What happens if the person doesn’t provide the personal data
  • Their rights to access and correct their information

IPP 4: Manner of collection of personal information

An organisation may collect personal information only if it:

  • Complies with the law (lawful manner), and
  • Collects the information fairly and reasonably in a way that does not intrude unnecessarily into a person’s private life.

When collecting information from children or young people, the organisation must take extra care to ensure the process is appropriate and respectful.

IPP 5: Storage and security

Agencies that hold personal information must take reasonable steps to protect it from:

  • Loss
  • Unauthorised access, use, or disclosure, and
  • Any other misuse

Similarly, ensure that those others they share data with also follow the security obligations.

IPP 6: Access to personal information

Individuals have the right to know whether an organisation holds any personal information about them.

If they ask, the organisation must:

  • Confirm whether it has their information, and
  • Provide access to that information if it does.

When giving access, the organisation should also tell the person that they have the right to request corrections if the information is wrong or outdated.

IPP 7: Correction of personal information

Agencies must allow people to request corrections to their personal information if it is inaccurate, incomplete, or misleading.

It should also take reasonable steps to ensure that all personal information it holds is accurate, up to date, complete, and relevant for its intended purpose.

When corrections are made or statements are attached, the organisation should, as far as practical, notify anyone else it has previously shared the information with.

IPP 8: Check information before using or sharing it

Before using or disclosing personal information, an organisation must take reasonable steps to make sure it is accurate, up to date, complete, relevant, and not misleading.

IPP 9: Don’t keep information longer than necessary

Organisations should only keep personal information for as long as it’s needed for the purpose it was collected. Once it’s no longer required, it should be securely deleted or anonymised.

IPP 10: Use information only for its intended purpose

Personal information collected for one reason should not be used for another, unless:

  • The new use is closely related to the original purpose
  • The person gives consent
  • It is for research or statistics in a way that doesn’t identify individuals
  • It is publicly available information
  • Required for law enforcement, legal proceedings, or to prevent serious threats to health or safety

In simple terms, organisations can’t repurpose personal data without a valid, lawful reason.

IPP 11: Limit disclosure of personal information

An organisation must not share personal information with others unless:

  • It’s for the same or a directly related purpose
  • The person agrees
  • The information is publicly available
  • Sharing is needed for law enforcement, legal processes, or to prevent serious harm.

This principle helps ensure that personal data is not shared unnecessarily.

IPP 12: Sending information outside New Zealand

If an organisation shares personal information with an overseas entity, it must make sure the recipient:

  • Has privacy protections similar to New Zealand’s
  • Is part of a binding privacy scheme or agreement
  • The individual gives informed consent, knowing the risks

In short, organisations must ensure comparable privacy safeguards before sending data abroad.

IPP 13:  Use of unique identifiers

A unique identifier, like a customer number, can be assigned only when necessary for an organisation’s functions.

The organisation must:

  • Ensure the person’s identity is clearly verified
  • Prevent misuse by means such as masking part of account numbers.
  • Not require people to share identifiers from other organisations unless it’s directly relevant.

This principle prevents tracking and misuse of identifiers across different systems.

What are the privacy rights?

New Zealand's Privacy law ensures the following rights to its people:

  • Transparency: Individuals have the right to know when, why, and how their personal information is collected and used.
  • Right to purpose limitation and security: Personal data can only be used for the reason it was collected, and must be protected with appropriate security measures.
  • Right to access: Individuals can request a copy of the personal information an organisation holds about them.
  • Right to correction: They can ask for their information to be corrected or updated if it’s inaccurate, incomplete, or misleading.

Data Protection Impact Assessment and breach notifications

The Privacy Commissioner of New Zealand recommends that agencies conduct a Privacy Impact Assessment to identify any risks that may arise from certain data processing activities, such as:

  • Use of new technologies or collection of new types of personal data
  • Substantial change in legal policies
  • Processing of high-risk data like health information
  • Establishing a new way to identify individuals

Any cases of data breaches that can potentially cause serious harm to the concerned individual must be reported to both the affected person and the commissioner within 72 hours of notice of the breach.

Serious harms could mean physical or psychological harm, financial loss, or family violence.

Do I need to appoint a Data Protection Officer?

Yes. Agencies have to assign a privacy officer to make sure they comply with the Privacy Act.

For smaller companies, it's usually fine for a manager or the in-house legal expert to handle this job. But larger organisations need to appoint someone who is a data privacy expert.

Do I need to publish a privacy policy?

Yes. IPP 3 lays down the transparency requirements that all agencies dealing with New Zealand Personal data must follow.

Your Privacy statement must include the following details:

  • Information about the collection of personal data
  • Sources from which the data is collected
  • Why is it collected
  • How it will be used
  • Who will receive the information
  • Whether it is optional or compulsory to give the data
  • The consequences for not giving the information

Generate a privacy policy in no time

Go for effortless policy management with CookieYes

Get a free trial
  • 14-day free trial
  • Cancel anytime

What are the fines and penalties for non-compliance?

Breaches such as misleading an agency, obstructing the Commissioner, or failing to report a notifiable privacy breach are offences and can result in fines of up to NZD 10,000.

The Privacy Commissioner oversees and enforces New Zealand’s privacy laws. When a privacy breach or complaint arises, the Commissioner can investigate and usually seeks to resolve matters through conciliation or mediation. If the issue remains unresolved, a formal investigation may follow, and while the Commissioner’s opinion isn’t legally binding, it carries significant weight.

Serious cases can be referred to the Director of Human Rights Proceedings, who may take them to the Human Rights Review Tribunal for a binding decision, including potential damages. The Commissioner also has the authority to issue compliance notices or access directions to ensure organisations meet their legal obligations.

What are the differences between NZ Privacy Act vs GDPR?

AspectNZ Privacy ActGDPR
Effective dateDecember 1, 2020May 25, 2018
ScopeApplies to agencies collecting/holding personal data in or from New Zealand, including overseas agencies operating in NZApplies to any entity processing personal data of individuals in the EU, regardless of the entity’s location
Privacy notice requirementYesYes
ConsentNot requiredOpt-in consent required
Privacy principles13 Privacy principles7 data protection principles
Enforcement authorityPrivacy CommissionerData Protection Authority
Breach notificationWithin 72 hours of knowledgeWithin 72 hours of knowledge
Privacy rights
  • Right to know
  • Right to access
  • Right to correct
  • Right to know
  • Right to access
  • Right to correct
  • Right to erasure
  • Right to object 
  • Right to restrict
  • Right to portability
  • Automated decision-making rights
PenaltiesUp to NZD 10,000Up to 20,000 Euros or 4% of annual turnover

FAQ on New Zealand Privacy Act

What is the Privacy Act 2025 in New Zealand?

The Privacy Amendment Act 2025 is the latest amendment to the Privacy Act 2020. It adds a new principle 3A (IPP 3A), requiring organisations to inform individuals when their personal information is collected from third parties.

It also empowers the Office of the Privacy Commissioner to assess the privacy laws of other countries (or blocs) when advising on overseas disclosure.

The amendment will fully take effect on 1 May 2026.

What is the New Zealand equivalent of GDPR?

The New Zealand equivalent of the GDPR is the Privacy Act 2020.

Like the GDPR, the Privacy Act 2020 sets rules for how personal information must be collected, used, stored, and shared. It gives individuals rights over their data and places clear responsibilities on businesses and organisations that handle personal information.

While it’s not as strict or broad as the GDPR, it follows similar principles, such as:

  • Data transparency
  • Individual access rights
  • Data breach notification
  • Limits on how data is used or disclosed

The NZ Privacy Act also applies to overseas businesses that operate in New Zealand or collect data from New Zealand residents.


 Safna

Safna

CIPP/E from the International Association of Privacy Professionals (IAPP) | Data privacy writer at CookieYes.