A data breach letter usually arrives weeks after the fact, and it rarely tells you exactly what to do next. This guide covers what New Zealand law requires of the organisation that lost your information, what the recent breaches here looked like, and the specific steps that protect you — in the order that matters.
What the law requires after a breach
Under the Privacy Act 2020, an organisation that has a privacy breach likely to cause someone serious harm must notify the Privacy Commissioner and the affected people as soon as practicable. The Office of the Privacy Commissioner expects that notification through its NotifyUs tool, ideally within 72 hours of the organisation becoming aware. Failing to notify is an offence with a fine of up to NZ$10,000.
| Your right | What it means |
|---|---|
| To be told | If the breach is likely to cause you serious harm, you must be notified, usually directly |
| To see what they hold | You can request your personal information; organisations have 20 working days to respond |
| To complain | Complain to the organisation first, then to the Privacy Commissioner (0800 803 909) |
| To have it corrected | You can ask for inaccurate information to be corrected |
Breach reporting is climbing. The Privacy Commissioner’s 2025 annual report recorded 1,093 breach notifications, up 27 per cent, and 1,598 complaints, up 21 per cent. Maximum penalties remain low by international standards; a June 2026 political proposal for fines of up to NZ$10 million is a policy idea, not law. Our Privacy Act guide covers the wider rules, including the new collection principle that took effect on 1 May 2026.
Recent New Zealand breaches
| Breach | When | What was exposed |
|---|---|---|
| Latitude Financial | March 2023 | More than a million New Zealand driver licence numbers |
| MediaWorks | March 2024 | About 2.4 million records claimed by the attacker |
| Inland Revenue and Meta | February 2024, revealed November 2024 | Data on 268,000 taxpayers shared with Meta through an advertising tool |
| Neighbourly | Confirmed January 2026 | User names, email addresses and messages; owner Stuff sought a High Court injunction over the data on the dark web |
| Manage My Health | December 2025; inquiry report May 2026 | Health information of nearly 100,000 patients, about 91 per cent in Northland |
| Canvas (Instructure) | April to May 2026 | Learning-platform data at institutions including the University of Auckland, AUT and Victoria University of Wellington, in a global attack |
The Manage My Health inquiry is the most detailed look yet at how a New Zealand breach happens. The Privacy Commissioner found that both the portal operator and Health New Zealand breached the rule requiring health information to be stored securely, pointing to weak detection and monitoring and over-reliance on vendor assurances, and issued compliance notices to both.
What to do if your data was in a breach
1. Work out what was taken
The notification should say. Passwords, identity documents, financial details and health information each call for different steps. If the letter is vague, ask the organisation directly — you are entitled to know what they held about you.
2. Passwords and accounts
If a password was exposed, change it there and anywhere you reused it, starting with email. Turn on two-factor authentication. Our Have I Been Pwned guide shows how to see which breaches include your email address, and the password manager guide makes unique passwords painless.
3. Identity documents
If a driver licence or passport number was exposed, ask about replacing the document. A lost or compromised passport can be reported through passports.govt.nz or on 0800 22 50 50.
4. Freeze your credit file
If you think someone could apply for credit in your name, ask a credit reporter to suppress your file. Centrix, Equifax and Experian all offer this; under the Credit Reporting Privacy Code a single request now applies to all three, the initial freeze lasts 10 working days, and it can be extended. While it is in place, lenders cannot see your file, which stops most fraudulent applications.
5. Watch for follow-up scams
Breach data fuels targeted phishing: messages that quote your real details to seem legitimate, including fake “breach compensation” offers. Treat any contact about the breach with suspicion and go to the organisation’s website yourself. Our guide to cyber attacks in New Zealand covers the common patterns.
6. Get help
- IDCARE (0800 121 068) supports people whose identity has been compromised.
- The NCSC takes reports at ncsc.govt.nz/report or 0800 114 115.
- Your bank, straight away, if financial details or money are involved.
- The Privacy Commissioner, if the organisation does not deal with your complaint properly.
Reducing your exposure
You cannot stop companies being breached, but you can limit what they hold. Give the minimum information a form requires, delete accounts you no longer use, use a separate email alias for sign-ups, and keep two-factor authentication on the accounts that matter. A VPN protects your traffic on public Wi-Fi but does nothing for data already sitting in a company’s database — our cyber security guide sets out what each tool does and does not cover.
Disclaimer
General information only, not legal advice. Breach details are drawn from Privacy Commissioner publications and news reports current to September 2026; contact the organisation involved for information about your own records.
Reference sources
- Office of the Privacy Commissioner — Sorting out privacy breaches
- Office of the Privacy Commissioner — NotifyUs
- Office of the Privacy Commissioner — Manage My Health inquiry findings
- Office of the Privacy Commissioner — How to freeze your credit information
- 1News — Neighbourly confirms data breach
- NewsWire — Canvas hack affects Auckland, AUT and Victoria students
- IDCARE — Credit suppressions in New Zealand
- New Zealand Legislation — Privacy Act 2020
- National Cyber Security Centre — Report an incident
Frequently asked questions
Do companies have to tell me about a data breach in NZ?
Yes, if the breach is likely to cause you serious harm. They must notify you and the Privacy Commissioner as soon as practicable.
What should I do first after a data breach?
Find out what was exposed, change any affected passwords starting with email, turn on two-factor authentication, and freeze your credit file if identity details were taken.
How do I freeze my credit in New Zealand?
Ask Centrix, Equifax or Experian to suppress your credit file. One request now covers all three, lasts 10 working days at first, and can be extended.
Can I get compensation after a data breach?
Sometimes. Complain to the organisation first, then to the Privacy Commissioner. If a complaint is not resolved, it can go to the Human Rights Review Tribunal, which can award damages. Be wary of unsolicited “compensation” offers, which are often scams.
How do I check if my details were in a breach?
Watch for notification letters, and check your email address on Have I Been Pwned, which lists breaches that include it.
What is the penalty for not reporting a breach in NZ?
Failing to notify the Privacy Commissioner of a notifiable breach is an offence with a fine of up to NZ$10,000.




