All frameworks
NZAct 2020 · IPP 3A from 1 May 2026

NZ Privacy Act compliance

New Zealand's principles-based privacy law.

The New Zealand Privacy Act 2020, regulated by the Office of the Privacy Commissioner (OPC), governs how any agency collects, uses, discloses, stores and gives access to personal information. It runs on 13 Information Privacy Principles (IPPs), a mandatory notifiable-breach regime, and a strong accountability model — and it applies to overseas businesses that operate in New Zealand.

Start from the basics

The standard

New Zealand Privacy Act 2020 (+ Privacy Amendment Act 2025)

Who needs it

Any agency — New Zealand or overseas — that handles the personal information of people in New Zealand: local businesses and public-sector bodies, and any offshore company carrying on business in New Zealand, regardless of where it is incorporated or where its servers sit.

13+1

Privacy Principles (IPP 1–13 + 3A)

The basics

What is NZ Privacy Act?

The Act is built around 13 Information Privacy Principles that cover the whole lifecycle of personal information — how it may be collected, why you must be transparent, how long you can keep it, how it must be secured, and an individual's rights to access and correct it. It is principles-based rather than prescriptive: you apply the IPPs to your own context rather than ticking a fixed control list.

Since December 2020 it has carried a mandatory breach-notification regime: if a privacy breach is likely to cause serious harm, you must notify the OPC and affected individuals as soon as practicable. IPP 12 governs cross-border disclosure, section 201 requires every agency to appoint a Privacy Officer, and section 9 gives the Act extraterritorial reach over overseas agencies carrying on business in New Zealand.

The Privacy Amendment Act 2025 adds a new principle, IPP 3A, which requires transparency when personal information is collected indirectly — from someone other than the individual concerned. IPP 3A comes into force on 1 May 2026, so it is the near-term change agencies need to prepare for now.

Why it matters

What NZ Privacy Act does for your business

Breach notification is mandatory

Notifiable-breach obligations mean a privacy breach likely to cause serious harm must reach the OPC and affected individuals as soon as practicable. Failing to notify is itself an offence — this is not a discretionary courtesy.

IPP 3A is coming

The new indirect-collection transparency principle takes effect on 1 May 2026. Agencies that collect personal information from third parties need new notices and processes in place before it lands.

It reaches overseas businesses

Section 9 gives the Act extraterritorial effect: if you carry on business in New Zealand, you are bound whether or not you have a physical presence there — so it becomes a market-access requirement.

What it covers

13 IPPs + the new IPP 3A

The Information Privacy Principles govern collection, use, disclosure, storage, security, access and correction — with IPP 3A adding indirect-collection transparency from 1 May 2026.

Notifiable breaches

A serious-harm test decides notifiability; notify the OPC and affected individuals as soon as practicable after becoming aware of a qualifying breach.

Cross-border disclosure

IPP 12 restricts sending personal information overseas unless comparable safeguards, consent or another lawful basis apply.

Accountability & reach

Section 201 requires a Privacy Officer in every agency, and section 9 extends the Act to overseas agencies carrying on business in New Zealand.

The hard way

Done by hand, the Privacy Act means mapping 13 (soon 14) principles across every system, drafting collection notices per product, running a serious-harm assessment and notification the moment a breach is suspected, and tracking cross-border disclosures in spreadsheets — all while getting ready for IPP 3A. That is exactly the repetitive, deadline-driven work software should run for you.

The easier way, with Compliance One

  • Ships the full New Zealand Privacy Act control set — all 13 Information Privacy Principles plus the new IPP 3A — enabled by default with a Statement of Applicability.
  • Runs the notifiable-breach workflow off a pre-seeded Office of the Privacy Commissioner authority: a serious-harm assessment, dual OPC and individual notifications, and a retained breach record.
  • Handles Privacy Officer designation (s.201), a cross-border disclosure register (IPP 12), collection notices, and access/correction request tracking.
  • Cross-maps every obligation to ISO 27001 security controls and aligns with the Australian Privacy Act's APPs, so a trans-Tasman programme shares most of its evidence.

Do it once, reuse it everywhere. Evidence you collect for NZ Privacy Act is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Who enforces the Privacy Act 2020?
The Office of the Privacy Commissioner (OPC). It investigates complaints, can issue compliance notices, and receives mandatory notifications of privacy breaches likely to cause serious harm. The Act is a law you comply with, not a certificate you earn.
What is IPP 3A and when does it apply?
IPP 3A is a new Information Privacy Principle, added by the Privacy Amendment Act 2025, requiring transparency when you collect personal information indirectly — from someone other than the individual. It comes into force on 1 May 2026, so notices and processes should be ready before then.
Does it apply to us if we're outside New Zealand?
Yes, if you carry on business in New Zealand. Section 9 gives the Act extraterritorial reach regardless of where you're incorporated or where your data is stored.
We already have ISO 27001 or comply with Australia's Privacy Act — does that help?
A lot. Compliance One cross-maps the IPPs to ISO 27001 security controls, and the Act aligns closely with the Australian Privacy Principles (APPs), so much of your existing security and privacy evidence carries straight over.

Ready to tackle NZ Privacy Act?

See exactly how Compliance One maps NZ Privacy Act to your environment in a 30-minute walkthrough — and how much of it we handle for you.