Privacy Act 2020
New Zealand / Aotearoa New Zealand
In force since 1 December 2020
The Privacy Act 2020 replaced the Privacy Act 1993. The latest significant change is IPP3A, introduced by the Privacy Amendment Act 2025 and effective from 1 May 2026.
Asia & Africa
The Privacy Act applies broadly to organisations and businesses that collect, hold, use, or disclose personal information. Covered agencies can include government departments and agencies, companies and businesses, online businesses and retailers, charities and community organisations, clubs and societies, and other organisations that handle personal information. The Act can also apply to overseas agencies carrying on business in New Zealand, subject to the Act's scope and exceptions. There are specific exclusions and exemptions, including certain personal or domestic activities, judicial functions of courts and tribunals, and certain news-media activities.
The Privacy Act provides several enforcement mechanisms, including compliance notices, access directions, complaints and proceedings before the Human Rights Review Tribunal. Certain offences under the Act can result in a maximum fine of NZ$10,000. The Privacy Commissioner can also issue compliance notices requiring agencies to take or stop specified actions. The Human Rights Review Tribunal may also provide remedies for privacy interference, including orders relating to access and damages in appropriate cases.
The New Zealand Privacy Act 2020 focuses on responsible collection and handling of personal information rather than blanket consent.
The Privacy Act contains 13 Information Privacy Principles governing how agencies handle personal information:
No. The Privacy Act 2020 does not impose a blanket consent requirement for all personal information processing.
The Act is primarily based on the Information Privacy Principles. An organisation may be able to collect, use, or disclose personal information without obtaining consent where the relevant IPP permits the activity.
However, transparency and fair collection are central requirements. Organisations should clearly explain what information they collect, why they collect it, who may receive it, and how it will be used.
Consent can still be relevant in specific circumstances, including particular disclosures, overseas transfers, marketing activities, or where another applicable law requires consent.
New Zealand does not have a standalone blanket cookie-consent requirement equivalent to the consent regimes found in some other jurisdictions.
However, cookies and online tracking can involve the collection, use, or disclosure of personal information. Organisations should therefore consider whether their collection practices comply with the Information Privacy Principles, particularly requirements relating to:
For websites using analytics, advertising technologies, pixels, session recording, or other tracking technologies, a clear privacy and tracking notice can help explain what information is collected and why.
Where consent is required under another applicable law, contractual requirement, platform rule, or the organisation's chosen compliance framework, ConsentX can also support consent collection and evidence.
Transparency is a central requirement under the Privacy Act.
When collecting personal information directly, organisations should generally explain:
The introduction of IPP3A from 1 May 2026 adds similar transparency requirements for indirect collection, subject to specified exceptions.
ConsentX can help organisations present concise collection and tracking notices at the point where information is collected.
One of the most important recent New Zealand privacy developments is Information Privacy Principle 3A.
IPP3A applies when an organisation collects personal information about an individual from someone or something other than the individual themselves.
Where applicable, the organisation must take reasonable steps to ensure the individual is aware of:
IPP3A contains exceptions, so organisations should assess whether a particular collection falls within an exception rather than treating the notification obligation as universal.
The Privacy Act does not use a single comprehensive “sensitive personal information” category in the same way as some other privacy laws.
Instead, the fairness and reasonableness of collection can depend on factors including:
Organisations should take particular care when collecting information that could create significant privacy risks, including health, financial, biometric, identity, children's, or other highly personal information.
New Zealand also has sector-specific privacy codes, including rules covering health information, telecommunications information, credit reporting, and biometric processing.
The Privacy Act provides individuals with important rights relating to their personal information.
Right to access. Individuals can request access to personal information held about them. Agencies generally need to respond to access requests within 20 working days, subject to the Act's provisions for extensions and other circumstances.
Right to correction. Individuals can request correction of personal information that is inaccurate, incomplete, misleading, or otherwise incorrect.
Right to complain. Individuals can complain to the Office of the Privacy Commissioner where they believe their privacy rights have been interfered with.
ConsentX can support structured request intake and workflow management for access and correction requests.
Agencies must take reasonable safeguards to protect personal information against:
Security controls should be proportionate to the nature and sensitivity of the information and the risks involved.
Organisations should also maintain processes for identifying, containing, investigating, documenting, and responding to privacy incidents.
A privacy breach becomes notifiable when personal information has been accessed, disclosed, altered, lost, or destroyed without authorisation and it is reasonable to believe that the affected individual has suffered, or is likely to suffer, serious harm.
A notifiable privacy breach must be reported to the Office of the Privacy Commissioner as soon as practicable after the agency becomes aware that the criteria have been met.
The OPC currently expects notification generally within 72 hours, unless there are circumstances justifying a different timeframe. The statutory wording itself uses “as soon as practicable” rather than establishing a universal 72-hour statutory deadline.
Affected individuals may also need to be notified.
ConsentX can help maintain evidence and records that support privacy incident investigation and compliance workflows.
Information Privacy Principle 12 governs certain disclosures of personal information outside New Zealand.
Before making a covered overseas disclosure, an organisation generally needs to establish that the recipient:
Importantly, IPP12 does not automatically apply to every offshore cloud-storage or processing arrangement. Where an overseas provider acts only as an agent for storage or processing, the information may continue to be treated as held by the New Zealand agency under section 11.
Organisations should therefore distinguish between disclosure to an overseas recipient and use of an overseas service provider as an agent.
IPP9 limits how long agencies can retain personal information.
Personal information should not be kept for longer than required for the purposes for which it may lawfully be used.
Organisations should establish appropriate retention and disposal processes based on:
The Privacy Act does not create a blanket GDPR-style right to erasure. However, deletion or disposal may be required or appropriate in particular circumstances.
Every agency covered by the Privacy Act is required to have a privacy officer.
The privacy officer is responsible for helping the organisation comply with the Act, dealing with access and correction requests, and working with the Privacy Commissioner during investigations.
The role does not require a particular formal qualification, but the privacy officer should understand the organisation's privacy obligations and information-handling practices.
The Privacy Act gives the Privacy Commissioner the ability to issue codes of practice that modify how the privacy principles apply to particular industries, organisations, or types of information.
Examples include:
Organisations operating in regulated sectors should therefore assess both the Privacy Act and any applicable privacy code.
New Zealand has introduced specific regulatory requirements around biometric processing.
The Biometric Processing Privacy Code 2025 came into force on 1 May 2026, with amendments made to reflect the introduction of IPP3A.
Organisations using facial recognition, fingerprints, voice recognition, behavioural biometrics, or other biometric technologies should assess whether the Biometric Processing Privacy Code applies in addition to the general Privacy Act requirements.
Present clear information about cookies, tracking technologies, data collection, and processing activities at relevant points of collection.
Capture and manage user choices where consent is required or where an organisation chooses to use consent as part of its privacy framework.
Control non-essential tracking technologies so that website scripts can be governed according to configured regional and consent rules.
Maintain records of consent and user preferences, including the relevant timestamp and context, to support internal audits and compliance documentation.
Support structured intake and workflow management for access and correction requests.
Maintain relevant records and audit trails that can help privacy teams investigate incidents and demonstrate governance processes.
Apply New Zealand-specific configurations alongside requirements from other jurisdictions where the organisation operates internationally.
Help communicate relevant data-sharing and overseas-processing information through privacy and consent experiences.
Privacy compliance is not limited to adding a cookie banner. ConsentX helps organisations build a structured privacy experience across collection notices, consent and preference management, tracking controls, consent evidence, data requests, and regional compliance rules. With ConsentX, organisations can centralise privacy controls across websites and digital properties while maintaining evidence of user choices and supporting operational privacy workflows. Get started with ConsentX and build a more transparent, audit-ready privacy experience for New Zealand users.
This page provides a general plain-English overview of the New Zealand Privacy Act 2020 and related privacy requirements. It is not legal advice and does not cover every exemption, industry-specific privacy code, regulatory guidance, or individual compliance circumstance. Organisations should review the current legislation and Office of the Privacy Commissioner guidance and obtain qualified New Zealand legal advice where necessary.
Identify cookies, trackers, pixels, analytics technologies, advertising scripts, forms, and other technologies that may collect or transmit personal information.
Identify where personal information is collected, including:
Ensure individuals receive appropriate information about why data is collected, who receives it, and how it will be used.
Review whether information is obtained from third parties, data brokers, partners, public sources, or other external sources.
Where IPP3A applies, configure appropriate notice processes for indirect collection.
Where consent is required or chosen as a compliance mechanism, provide users with clear choices and maintain appropriate records.
Use prior-script blocking and regional rules to control analytics, advertising, and other non-essential technologies according to your configured compliance requirements.
Store records of relevant consent and preference decisions so your privacy team can demonstrate what users were told and what choices they made.
Route privacy requests to the appropriate team and track deadlines and status through a central workflow.
Identify third parties receiving personal information outside New Zealand and assess whether the relevant IPP12 requirements are satisfied.
Keep records and workflows that help privacy teams identify, investigate, document, and respond to potentially notifiable privacy breaches.