All resources
Guide 8 min read

New Zealand's Privacy Act 2020: the 13 IPPs (and the new IPP 3A)

C1The Compliance One team20 September 2026

New Zealand's Privacy Act 2020 is principles-based, not prescriptive. Instead of a fixed control list, it gives you 13 Information Privacy Principles (IPPs) that cover the full lifecycle of personal information, and asks you to apply them to your own context. It is regulated by the Office of the Privacy Commissioner (OPC), and it reaches overseas agencies that carry on business in New Zealand, wherever they are based.

If you have worked with Australia's Privacy Act or the GDPR, the shape will feel familiar. The details, and one brand-new principle, are where the work is.

The 13 principles, grouped

  • Collection (IPP 1 to 4): only collect what you need for a lawful purpose, collect it from the individual where you can, tell them what you are doing, and collect it fairly and without undue intrusion.
  • Storage and access (IPP 5 to 7): protect personal information with reasonable safeguards, and let people see and correct what you hold about them.
  • Quality and limits (IPP 8 to 10): check accuracy before you use it, do not keep it longer than needed, and use it only for the purpose you collected it for.
  • Disclosure and identifiers (IPP 11 to 13): limit when you disclose it, restrict cross-border disclosure under IPP 12, and do not misuse unique identifiers.

IPP 3A: the new principle for 1 May 2026

The Privacy Amendment Act 2025 adds IPP 3A, which fills a real gap. Until now, the duty to be transparent about collection (IPP 3) focused on information collected directly from the individual. IPP 3A extends that transparency to indirect collection, when you obtain personal information about someone from a third party rather than from the person themselves.

If you buy, receive or otherwise collect personal information from someone other than the individual, IPP 3A says you generally have to make sure that person is told. It comes into force on 1 May 2026, so the time to build the notices and processes is now.

Who is bound, and the duties beyond the principles

The Act binds any agency, public or private, that handles the personal information of people in New Zealand. Section 9 gives it extraterritorial reach over overseas agencies carrying on business there. Every agency must appoint a Privacy Officer under section 201, and since December 2020 there has been a mandatory notifiable-breach regime for breaches likely to cause serious harm.

In Compliance One the full New Zealand Privacy Act control set ships enabled, all 13 IPPs plus the new IPP 3A, with a Statement of Applicability, a pre-seeded OPC breach authority, a cross-border disclosure register for IPP 12, and cross-maps to ISO 27001 so your existing security evidence carries over. Getting ready for 1 May 2026 becomes a plan, not a scramble.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.