New Zealand’s Privacy Act 2020 is the main law setting out how organisations may collect, store, use and share your personal information. It replaced the 1993 Act, added stronger enforcement powers, and introduced a mandatory breach-notification regime that touches everyone who shops online, uses a government service, or signs up to anything that stores their data. This guide explains, in plain terms, what the Act gives you as an individual, what it demands of businesses, and the practical steps you can take to protect your own privacy alongside the law.
Key Points
- The law: The Privacy Act 2020 governs how organisations in New Zealand collect, store, use and share personal information.
- 13 principles: Thirteen enforceable Information Privacy Principles (IPPs) cover collection, security, access, correction, use, cross-border disclosure (IPP 12) and unique identifiers (IPP 13).
- Your key rights: Free access to your data and free correction requests, each with a 20-working-day response deadline.
- Breach rules: Agencies must notify the Privacy Commissioner and affected people of any breach likely to cause serious harm.
- Enforcement: Complaints to the Privacy Commissioner are free; the Human Rights Review Tribunal can award damages up to NZ0,000.
- Your part: Encrypted DNS, a reputable audited VPN and local file encryption reduce exposure the law alone cannot.
How the Privacy Act 2020 works
The Act is built around thirteen Information Privacy Principles (IPPs). These are not vague aspirations — they are legally enforceable standards that any “agency” must follow. In the Act, an agency means almost any organisation that holds personal information: businesses, government departments, NGOs, clubs, and even individuals holding information in a professional capacity. The Office of the Privacy Commissioner (OPC) oversees compliance and can investigate complaints, issue compliance notices, and refer serious cases to the Human Rights Review Tribunal.
The thirteen principles cover the whole lifecycle of personal data. Grouped by purpose, they work like this:
- Collection (IPPs 1–4): An agency may only collect information for a lawful purpose connected to its function, should collect it directly from you where practicable, and must tell you why it is being collected and who will receive it.
- Storage and security (IPP 5): Agencies must take reasonable steps to protect information from loss, misuse or unauthorised access. “Reasonable” is context-dependent — a hospital holding medical records is held to a higher standard than a sports club holding a membership list.
- Access and correction (IPPs 6–7): You can ask what an agency holds about you and request corrections. It must respond within 20 working days.
- Accuracy and retention (IPPs 8–9): Agencies must check information is accurate before using it, and must not keep it for longer than they need it.
- Use and disclosure (IPPs 10–11): Information collected for one purpose generally cannot be used or disclosed for an unrelated purpose without your authorisation.
- Cross-border disclosure (IPP 12): This is the principle most relevant to cloud and VPN users. An agency may only send personal information to an organisation outside New Zealand if the recipient is subject to comparable privacy safeguards — or if you have given informed consent.
- Unique identifiers (IPP 13): Agencies may only assign an identifier (such as a customer number) where necessary, and must not adopt an identifier that another agency has already assigned to you.
The 2020 Act also introduced mandatory breach notification. If an agency suffers a notifiable privacy breach that is likely to cause serious harm, it must notify both the Privacy Commissioner and the affected individuals as soon as practicable. Failing to notify is itself an offence.
Your rights as an individual
Most New Zealanders under-use the rights the Act gives them. These are enforceable entitlements, not soft suggestions.
Right of access (IPP 6): You can submit a privacy request to any agency asking what personal information it holds about you. It has 20 working days to respond. Information can be withheld in limited situations — for example, if disclosure would prejudice an investigation — but the agency must tell you it is withholding and why.
Right of correction (IPP 7): If information is wrong, you can ask for it to be corrected. If the agency declines, you can require it to attach a statement noting that you requested the correction.
Right to complain: If you believe an agency has breached a principle, you can complain to the Privacy Commissioner at no cost. The OPC usually attempts mediation first. If that fails, the matter can go to the Human Rights Review Tribunal, which has district-court-level powers and can award damages up to a maximum of NZ$350,000.
Sensitive information: Data about health, finances, ethnicity, religion and sexual orientation attracts heightened care in practice, because misuse of it is more likely to cause serious harm — which matters both for collection justification and for breach assessment.
NZ-specific context: ISPs, Five Eyes and data sovereignty
New Zealand sits inside the Five Eyes intelligence alliance with Australia, the United States, the United Kingdom and Canada. This matters because member agencies share signals intelligence and can, under certain frameworks, request data from one another. The Privacy Act does not override intelligence law: the Government Communications Security Bureau Act and the Intelligence and Security Act 2017 sit alongside it and create lawful exceptions.
Your internet service provider — whether Chorus-based fibre delivered through Spark, One NZ, 2degrees or a smaller reseller — is an agency under the Act. It holds connection metadata: timestamps, data volumes and, in some cases, DNS query logs. The Telecommunications (Interception Capability and Security) Act 2013 (TICSA) separately requires ISPs to maintain interception capability for lawful government access. That is not part of the Privacy Act, but it shapes the real-world privacy landscape for NZ internet users.
Cloud storage and SaaS tools used by NZ businesses — Microsoft 365, Google Workspace, Salesforce — involve cross-border data flows. Under IPP 12, a business using these services must take reasonable steps to ensure the overseas recipient protects the information consistently with the Act. In practice that means reviewing data-processing agreements and, where offered, choosing data-residency options that keep data in Australia or New Zealand rather than routing it through overseas data centres.
New Zealand streaming platforms — TVNZ+, ThreeNow, Neon, Sky Sport Now and Whakaata Māori — are also NZ agencies subject to the Act. If you want to know what viewing and account data one of them holds about you, you can submit a privacy request directly to them.
Protecting your own privacy under the Act’s framework
The Privacy Act protects you from organisations mishandling your data. It does not protect you from your own exposure — that needs deliberate technical choices. Here is a practical setup for NZ users who want their own tools to align with the Act’s intent.
- Audit what you have shared. Submit privacy requests to the handful of organisations that hold the most data about you: your bank, your ISP, your health provider, your main social platform and any loyalty programme you use. This is free and gives you a real picture of your exposure.
- Use a reputable VPN for network-layer privacy. A VPN (virtual private network) encrypts traffic between your device and the VPN server, stopping your ISP from logging the content of your browsing. It does not make you anonymous, but it does reduce the metadata your ISP can collect. Prefer a provider with Australian servers for low latency, an independently audited no-logs policy, and incorporation outside Five Eyes. See our best VPN guide for current picks tested on NZ connections.
- Harden your DNS. Your ISP’s default DNS resolver can log every domain you visit. Switching to an encrypted resolver (DNS-over-HTTPS or DNS-over-TLS) such as Cloudflare’s 1.1.1.1 or NextDNS is free and quick; our walkthrough on how to change your router’s DNS covers it step by step.
- Review app permissions on mobile. Apps that collect your location, contacts or health data are agencies under the Act. Revoke permissions you do not actively use, and re-check them every few months.
- Use unique email aliases per service. Tools such as SimpleLogin or Apple’s Hide My Email let you create per-service addresses. If a service is breached, you know exactly which one leaked and can disable that alias without affecting your main inbox.
- Encrypt sensitive files before cloud upload. If you store personal documents in Dropbox, OneDrive or Google Drive, encrypt them locally first with a tool like Cryptomator so the content stays unreadable even if the provider is compelled to disclose it.
Be cautious with free tools: many free VPNs and privacy apps monetise through data collection, which is precisely what you are trying to avoid. Our guide to genuinely trustworthy free VPN options explains which to trust and which to skip.
Choosing a VPN in a Privacy Act context
When picking a VPN with New Zealand privacy in mind, the criteria that matter are jurisdiction (outside Five Eyes preferred), an independently audited no-logs policy, real AU/NZ server presence, and transparent pricing. The table below summarises leading options as of 2026; prices are approximate and shift with promotions, so confirm current NZD figures on each provider’s own site.
VPN Comparison
| Provider | Jurisdiction | No-logs audit | NZ server | AU server | Approx. NZD/month (annual) | Protocols |
|---|---|---|---|---|---|---|
| ExpressVPN | British Virgin Islands | Yes (KPMG, Cure53, PwC) | Yes | Yes | ~NZ–14 | Lightway, OpenVPN, IKEv2 |
| NordVPN | Panama | Yes (Deloitte, PwC) | Yes | Yes | ~NZ–9 | NordLynx (WireGuard), OpenVPN |
| Mullvad | Sweden | Yes (Cure53) | No | Yes | ~NZ flat (no annual discount) | WireGuard, OpenVPN |
| Proton VPN | Switzerland | Yes (Securitum) | No | Yes | ~NZ–13 | WireGuard, OpenVPN, Stealth |
| Surfshark | Netherlands | Yes (Deloitte) | Yes | Yes | ~NZ –6 | WireGuard, OpenVPN, IKEv2 |
For most NZ users, NordVPN or Proton VPN offer a good balance of price, audit credibility and AU/NZ server availability. Mullvad is the strongest choice if payment anonymity matters to you — it accepts cash and cryptocurrency and does not require an email address, which sits closely with the Act’s data-minimisation spirit. Proton VPN’s Swiss base places it outside both EU and Five Eyes legal reach, a meaningful distinction for threat models involving government data requests. Whichever you choose, remember a VPN is a personal privacy tool, not a legal compliance mechanism.
Business obligations under the Act
If you run a business in New Zealand — even a sole trader with a client list — you are an agency under the Act, and the obligations are more demanding than many small operators realise.
Privacy Officer: Every agency must designate a Privacy Officer. For a small business this is usually the owner. The role covers handling access requests, managing breach responses and keeping privacy practices current; the person’s contact details should be reachable by anyone wanting to make a request.
Privacy Impact Assessments (PIAs): Before launching a new product, service or system that collects personal information, agencies should run a PIA. The OPC offers a free assessment tool. It is not mandatory in every case, but it is best practice and provides a defence if a complaint arises later.
Breach response: If you suffer a breach — a hacked database, a misdirected email with client data, a stolen laptop — assess whether it is likely to cause serious harm. If so, notify the OPC and the affected individuals promptly using the OPC’s online breach tools. The Act does not set a fixed deadline, but “as soon as practicable” is interpreted strictly.
Third-party processors: If a payroll provider, CRM or marketing platform processes personal data on your behalf, you remain responsible for that data. Your contracts should include privacy obligations, and you should verify each provider’s security practices.
Children’s data: The Act sets no specific age threshold, but OPC guidance is clear that collecting data from children needs particular care around consent and purpose. If under-16s are likely to use your service, review your collection practices carefully.
Because these principles overlap heavily with the OPC’s own role and with breach handling, it is worth reading them alongside our companion New Zealand Privacy Act overview, which focuses on the legislative detail.
Sources
- Privacy Act 2020 — New Zealand Legislation
- Office of the Privacy Commissioner — Information Privacy Principles
- OPC — Principle 12: Disclosure outside New Zealand
- OPC — Privacy breaches and notification
- OPC — New Zealand–EU data protection adequacy
- Ministry of Justice — Human Rights Review Tribunal remedies
- Telecommunications (Interception Capability and Security) Act 2013
Frequently Asked Questions
Does the Privacy Act 2020 apply to overseas companies?
Yes, with nuance. The Act applies to any agency that carries on business in New Zealand and collects personal information from New Zealanders, even if it is incorporated overseas. A US-based SaaS company with NZ customers is generally subject to the Act for those customers’ data. Enforcing it against overseas entities is harder in practice, but the legal obligation exists, and the Privacy Commissioner can cooperate with overseas counterparts.
How does the NZ Privacy Act compare with the EU’s GDPR?
The GDPR is broader in some respects — it includes a right to erasure and stricter consent rules — but the Privacy Act 2020 was deliberately aligned closer to it. That alignment is why the European Commission reaffirmed New Zealand’s data-protection adequacy status on 15 January 2024, allowing personal data to flow freely from the EU to NZ without extra safeguards. The main practical gap is enforcement: GDPR fines can reach 4% of global turnover, whereas NZ penalties are capped at NZ$10,000 for certain offences, though the Human Rights Review Tribunal can award higher damages in individual cases.
Can I ask my ISP what data it holds about me?
Yes. ISPs such as Spark, One NZ and 2degrees are agencies under the Act. You can submit a formal access request for the personal information they hold, including account data, billing history and metadata logs, and they have 20 working days to respond. Some information may be withheld if it relates to lawful interception under TICSA, but they must tell you a withholding ground applies.
Does using a VPN make me compliant with the Privacy Act?
No. A VPN is a personal privacy tool, not a compliance tool. For a business, running a VPN does not replace having a Privacy Officer, a breach-response plan and proper data-handling practices. For individuals, a VPN reduces the metadata your ISP can collect and encrypts your traffic in transit, which aligns with the Act’s data-minimisation spirit, but it grants no legal rights beyond what the Act already provides.
What counts as a “serious harm” breach that must be notified?
The Act does not define serious harm exhaustively, but OPC guidance weighs the sensitivity of the information (health, financial and identity data rank higher), the likelihood of misuse, the number of people affected, and whether those affected are vulnerable. A set of well-hashed passwords for a low-risk service is unlikely to meet the threshold; a spreadsheet of clients’ health records emailed to the wrong recipient almost certainly does.




