Preparing for NZ open banking and the Customer and Product Data Act 2025
New Zealand has spent the last few years building toward a consumer data right, and in 2025 it became law: the Customer and Product Data Act 2025 (the CPD Act). It creates a framework for people and businesses to securely share the data that organisations hold about them, and the product data organisations publish, with accredited third parties they choose. Banking is expected to be the first designated sector, which is why the shorthand for all of this is open banking.
If you operate in financial services, or you plan to build on top of bank data, this is the regime that will govern how that data moves. And it does not replace your privacy obligations, it stacks on top of them.
What the CPD Act actually sets up
- Designated sectors: the government designates a sector (banking first), which brings its data holders into scope.
- Accreditation: third parties that want to receive customer data must be accredited to a security and conduct standard, so data only flows to vetted requestors.
- Secure, consented data sharing: customers authorise sharing through a controlled flow, and can see and revoke what they have shared.
- Product data: standardised product information (rates, fees, terms) can be published and compared, powering better switching and comparison tools.
Open banking is not a loosening of privacy, it is privacy with the plumbing built in. The CPD Act is about giving people control of data that was always theirs, and holding the recipients to a real standard before they can touch it.
How it connects to the Privacy Act
The CPD Act and the Privacy Act 2020 are designed to work together. The Privacy Act sets the baseline for handling personal information (the 13 IPPs, security safeguards under IPP 5, cross-border limits under IPP 12, and the notifiable-breach regime). The CPD Act adds the consent, accreditation and secure-sharing machinery for designated data. If you are getting accredited, or preparing to share customer data, you need both sets of obligations evidenced, not one.
Getting ahead of it
The practical work is familiar even if the regime is new: strong access control and encryption, a clean cross-border disclosure register, a rehearsed breach workflow, consent and authorisation records, and the security controls an accreditation assessor will want to see. In Compliance One the New Zealand Privacy Act control set ships enabled and cross-maps to ISO 27001, so the security evidence you build for accreditation and the privacy evidence you build for the IPPs come from one source of truth. When banking is designated and the deadlines firm up, you are extending a programme, not starting one.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.