New Zealand is one of the few countries with an EU adequacy decision, meaning it has a strong privacy foundation. The New Zealand Privacy Act of 2020 strengthens the rights of individuals and the responsibilities of organisations regarding the collection, use, and protection of personal information. Here is a detailed guide.
The Privacy Act 2020 is the primary law governing the collection, use, storage, and sharing of personal information in New Zealand. It replaced the Privacy Act 1993 and came into force on December 1, 2020.
The Act sets clear rules for organisations and businesses, known as agencies, on handling personal data. It gives individuals more control over their information and introduces stronger protections against misuse.
Key highlights include:
Mandatory breach notification for serious privacy breaches
Stronger powers for the Privacy Commissioner
Clear rules for sharing information with overseas organisations
Legal obligations for all businesses that collect personal data in or from New Zealand
The Privacy Act also sets out 13 Information Privacy Principles (IPPs) that guide how agencies must collect, use, store, and disclose personal information.
The law applies to both public and private sector agencies, including overseas companies doing business in New Zealand.
In September, the New Zealand Government enacted the Privacy Amendment Act 2025. It introduces new transparency requirements (IPP 3A) for data collection from third parties and expands the grounds for refusing DSAR requests.
What is personal information under the NZPA 2020?
Personal information means any data about a living person who can be identified.
It can include:
Names and contact details
Address
Health or financial records
Purchase history or account numbers
Photos, recordings, notice
The individual doesn’t need to be named. If they could be identified through details like their home address or online identifiers, the law still treats it as personal information.
The law applies whether the information is sensitive (like medical history) or basic (like an email address). If there's a reasonable chance someone can be identified from the information, it falls under the Privacy Act.
Who does the New Zealand Privacy Act 2020 apply to?
The Privacy Act 2020 applies to any person, business, or organisation that handles personal information in New Zealand, even if they’re not based there.
It covers both local and overseas agencies. Here is a detailed breakdown:
NewZealandagencies: Organisations operating in New Zealand, regardless of whether the personal information was collected.
Overseasagencies: Organisations outside New Zealand carrying on business within the country and collecting or holding personal information about New Zealand residents.
IndividualsnotbasedinNewZealand: Individuals temporarily in New Zealand who collect personal data while physically present in New Zealand or hold personal information while in New Zealand, even if they didn’t collect it there.
Meaning of Agency under the New Zealand Privacy Act
Is consent required for data processing under the New Zealand Privacy Act?
The Privacy Act does not expressly require consent for processing personal data. However, it is important to comply with other obligations, including the 13 Information Privacy Principles.
For online cookies, ensure that you are transparent about it and also provide a measure to opt out of it.
New Zealand Privacy Commissioner’s website informs users that they can opt out of cookies in their privacy statement.
What are the 13 Information Privacy Principles (business obligations)?
IPP 1: Purpose of collection
An agency should only collect personal information if:
There is a lawful purpose that is connected to its function,
Data is necessary for that purpose.
You can’t just collect information in anticipation of any future purposes that may arise. Also, avoid collecting personal data if the purpose can be achieved without it.
IPP 2: Source of personal information
When a business or organisation collects personal information, it should ideally get that information directly from the person it’s about.
However, there are situations where it’s okay to collect it from another source. For example:
When it doesn’t harm the individual’s interests.
When collecting it directly would defeat the purpose (like during an investigation).
The concerned person permits data collection from someone else.
The information is already publicly available.
It’s needed for law enforcement, legal proceedings, protecting public revenue, or preventing serious threats to health or safety.
It’s not practical to get the information directly.
The information will only be used in a way that doesn’t identify anyone.
IPP 3: Collection of personal information from the individual concerned
When an organisation collects personal information directly from someone, it must ensure transparency.
You must inform the individuals of at least the following before collection, or if that’s not possible, as soon as possible afterwards:
What information is being collected
Why is it needed
Who will receive or use it?
Who is collecting it, and who will store it
The law under which data is collected, if applicable
What happens if the person doesn’t provide the personal data
Their rights to access and correct their information
IPP 4: Manner of collection of personal information
An organisation may collect personal information only if it:
Complies with the law (lawful manner), and
Collects the information fairly and reasonably in a way that does not intrude unnecessarily into a person’s private life.
When collecting information from children or young people, the organisation must take extra care to ensure the process is appropriate and respectful.
IPP 5: Storage and security
Agencies that hold personal information must take reasonable steps to protect it from:
Loss
Unauthorised access, use, or disclosure, and
Any other misuse
Similarly, ensure that those others they share data with also follow the security obligations.
IPP 6: Access to personal information
Individuals have the right to know whether an organisation holds any personal information about them.
If they ask, the organisation must:
Confirm whether it has their information, and
Provide access to that information if it does.
When giving access, the organisation should also tell the person that they have the right to request corrections if the information is wrong or outdated.
IPP 7: Correction of personal information
Agencies must allow people to request corrections to their personal information if it is inaccurate, incomplete, or misleading.
It should also take reasonable steps to ensure that all personal information it holds is accurate, up to date, complete, and relevant for its intended purpose.
When corrections are made or statements are attached, the organisation should, as far as practical, notify anyone else it has previously shared the information with.
IPP 8: Check information before using or sharing it
Before using or disclosing personal information, an organisation must take reasonable steps to make sure it is accurate, up to date, complete, relevant, and not misleading.
IPP 9: Don’t keep information longer than necessary
Organisations should only keep personal information for as long as it’s needed for the purpose it was collected. Once it’s no longer required, it should be securely deleted or anonymised.
IPP 10: Use information only for its intended purpose
Personal information collected for one reason should not be used for another, unless:
The new use is closely related to the original purpose
The person gives consent
It is for research or statistics in a way that doesn’t identify individuals
It is publicly available information
Required for law enforcement, legal proceedings, or to prevent serious threats to health or safety
In simple terms, organisations can’t repurpose personal data without a valid, lawful reason.
IPP 11: Limit disclosure of personal information
An organisation must not share personal information with others unless:
It’s for the same or a directly related purpose
The person agrees
The information is publicly available
Sharing is needed for law enforcement, legal processes, or to prevent serious harm.
This principle helps ensure that personal data is not shared unnecessarily.
IPP 12: Sending information outside New Zealand
If an organisation shares personal information with an overseas entity, it must make sure the recipient:
Has privacy protections similar to New Zealand’s
Is part of a binding privacy scheme or agreement
The individual gives informed consent, knowing the risks
In short, organisations must ensure comparable privacy safeguards before sending data abroad.
IPP 13: Use of unique identifiers
A unique identifier, like a customer number, can be assigned only when necessary for an organisation’s functions.
The organisation must:
Ensure the person’s identity is clearly verified
Prevent misuse by means such as masking part of account numbers.
Not require people to share identifiers from other organisations unless it’s directly relevant.
This principle prevents tracking and misuse of identifiers across different systems.
What are the privacy rights?
New Zealand's Privacy law ensures the following rights to its people:
Transparency: Individuals have the right to know when, why, and how their personal information is collected and used.
Rightto purposelimitationandsecurity: Personal data can only be used for the reason it was collected, and must be protected with appropriate security measures.
Righttoaccess: Individuals can request a copy of the personal information an organisation holds about them.
Righttocorrection: They can ask for their information to be corrected or updated if it’s inaccurate, incomplete, or misleading.
Data Protection Impact Assessment and breach notifications
The Privacy Commissioner of New Zealand recommends that agencies conduct a Privacy Impact Assessment to identify any risks that may arise from certain data processing activities, such as:
Use of new technologies or collection of new types of personal data
Substantial change in legal policies
Processing of high-risk data like health information
Establishing a new way to identify individuals
Any cases of data breaches that can potentially cause serious harm to the concerned individual must be reported to both the affected person and the commissioner within 72 hours of notice of the breach.
Serious harms could mean physical or psychological harm, financial loss, or family violence.
Do I need to appoint a Data Protection Officer?
Yes. Agencies have to assign a privacy officer to make sure they comply with the Privacy Act.
For smaller companies, it's usually fine for a manager or the in-house legal expert to handle this job. But larger organisations need to appoint someone who is a data privacy expert.
Do I need to publish a privacy policy?
Yes. IPP 3 lays down the transparency requirements that all agencies dealing with New Zealand Personal data must follow.
Your Privacy statement must include the following details:
Information about the collection of personal data
Sources from which the data is collected
Why is it collected
How it will be used
Who will receive the information
Whether it is optional or compulsory to give the data
The consequences for not giving the information
Generate a privacy policy in no time
Go for effortless policy management with CookieYes
What are the fines and penalties for non-compliance?
Breaches such as misleading an agency, obstructing the Commissioner, or failing to report a notifiable privacy breach are offences and can result in fines of up to NZD 10,000.
The Privacy Commissioner oversees and enforces New Zealand’s privacy laws. When a privacy breach or complaint arises, the Commissioner can investigate and usually seeks to resolve matters through conciliation or mediation. If the issue remains unresolved, a formal investigation may follow, and while the Commissioner’s opinion isn’t legally binding, it carries significant weight.
Serious cases can be referred to the Director of Human Rights Proceedings, who may take them to the Human Rights Review Tribunal for a binding decision, including potential damages. The Commissioner also has the authority to issue compliance notices or access directions to ensure organisations meet their legal obligations.
What are the differences between NZ Privacy Act vs GDPR?
Aspect
NZ Privacy Act
GDPR
Effective date
December 1, 2020
May 25, 2018
Scope
Applies to agencies collecting/holding personal data in or from New Zealand, including overseas agencies operating in NZ
Applies to any entity processing personal data of individuals in the EU, regardless of the entity’s location
Privacy notice requirement
Yes
Yes
Consent
Not required
Opt-in consent required
Privacy principles
13 Privacy principles
7 data protection principles
Enforcement authority
Privacy Commissioner
Data Protection Authority
Breach notification
Within 72 hours of knowledge
Within 72 hours of knowledge
Privacy rights
Right to know
Right to access
Right to correct
Right to know
Right to access
Right to correct
Right to erasure
Right to object
Right to restrict
Right to portability
Automated decision-making rights
Penalties
Up to NZD 10,000
Up to 20,000 Euros or 4% of annual turnover
FAQ on New Zealand Privacy Act
What is the Privacy Act 2025 in New Zealand?
The Privacy Amendment Act 2025 is the latest amendment to the Privacy Act 2020. It adds a new principle 3A (IPP 3A), requiring organisations to inform individuals when their personal information is collected from third parties.
It also empowers the Office of the Privacy Commissioner to assess the privacy laws of other countries (or blocs) when advising on overseas disclosure.
The amendment will fully take effect on 1 May 2026.
What is the New Zealand equivalent of GDPR?
The New Zealand equivalent of the GDPR is the Privacy Act 2020.
Like the GDPR, the Privacy Act 2020 sets rules for how personal information must be collected, used, stored, and shared. It gives individuals rights over their data and places clear responsibilities on businesses and organisations that handle personal information.
While it’s not as strict or broad as the GDPR, it follows similar principles, such as:
Data transparency
Individual access rights
Data breach notification
Limits on how data is used or disclosed
The NZ Privacy Act also applies to overseas businesses that operate in New Zealand or collect data from New Zealand residents.