New Zealand Privacy Act 2020: A Plain-English Guide for Small Businesses

A practical guide to New Zealand's Privacy Act 2020 for small businesses. Who's covered (everyone), the Information Privacy Principles, the new IPP 3A, access requests, breach notification, the Biometric Code, and penalties.

Last updated: 2026-06-23

New Zealand takes the opposite approach to Australia: the Privacy Act 2020 applies to every business, no matter how small. If you collect information about customers, staff, or suppliers, it applies to you — and a notable new obligation took effect in May 2026. This guide explains what you need to know.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified lawyer or privacy professional for guidance specific to your business. The information here is based on the Privacy Act 2020 and guidance from the Office of the Privacy Commissioner (OPC), as of the date below.

The Privacy Act 2020 has been in force since 1 December 2020, is regulated by the Office of the Privacy Commissioner (OPC), and is built around the Information Privacy Principles (IPPs).

Does This Law Apply to Your Business?

Almost certainly, yes. The Act applies to all "agencies" — a term that includes virtually every business and organisation of any size. There is no small-business exemption. It also has extraterritorial reach: it applies to overseas businesses that carry on business in New Zealand, even without a physical presence there.

What Rights Do Individuals Have?

RightPrincipleKey detail
AccessIPP 6Request your personal information; respond within 20 working days
CorrectionIPP 7Ask for your information to be corrected
Notification (direct)IPP 3Be told why information is collected and who holds it
Notification (indirect)IPP 3ANew (1 May 2026): be made aware when info is collected from a third party
Complain to the OPCPrivacy ActComplain; the Human Rights Review Tribunal can award damages

Access (IPP 6). You must respond as soon as reasonably practicable, and no later than 20 working days after receiving a request. If you refuse, you must give reasons and explain the right to complain to the OPC.

The new IPP 3A (indirect collection). Since 1 May 2026, when you collect personal information about someone from a source other than that individual — buying a marketing list, using a data broker, enriching records from a third party — you must take reasonable steps to make the person aware of the collection (what, why, who holds it, and their access and correction rights). A generic "we may collect from third parties" line is no longer enough. It applies to information collected on or after 1 May 2026.

What Your Business Must Do

The IPPs cover the lifecycle of personal information: collect only what you need, for a lawful purpose, fairly and (usually) directly (IPP 1-4); notify people (IPP 3 and the new 3A); keep it secure (IPP 5); give access and correction (IPP 6-7); ensure accuracy (IPP 8); don't keep it longer than needed (IPP 9); use and disclose only for the purpose collected (IPP 10-11); take care disclosing overseas (IPP 12); and limit unique identifiers (IPP 13).

In practice: publish a clear privacy statement (see do I need a privacy policy?), build a data inventory, add an IPP 3A notification step wherever you collect indirectly, and set up an access process you can run inside 20 working days.

If you use biometric technologies (facial recognition, fingerprint, voice), note the binding Biometric Processing Privacy Code 2025, in force since 3 November 2025, with a transition period for existing processing ending 3 August 2026.

Breach Notification

New Zealand has a mandatory notifiable-breach scheme. If a privacy breach has caused, or is likely to cause, serious harm, you must notify both the Privacy Commissioner and the affected individuals as soon as practicable. Failing to notify a notifiable breach is an offence. Use the OPC's NotifyUs tool to assess and report.

Penalties

New Zealand does not have GDPR-style fines. The maximum penalty for offences is NZ$10,000, imposed by a court — the Commissioner cannot levy large administrative fines (and has publicly argued the regime needs strengthening). The Commissioner can, however, issue compliance notices and access directions, and individuals can take complaints to the Human Rights Review Tribunal, which can award damages. Don't mistake the modest fine for low risk — Tribunal damages and reputational harm usually outweigh it.

References

Last reviewed: June 2026. Privacy laws change frequently. Verify all statutory references against the current text of the Act and consult qualified legal counsel before making compliance decisions for your business.