Data Breach in NZ: What to Do When Your Details Are Leaked

Data Breach in NZ: What to Do Next

A data breach letter usually lands weeks after the event, and it rarely spells out what you should actually do next. This guide explains what New Zealand law requires of the organisation that lost your information, what the country’s recent breaches have looked like, and the specific steps that protect you — set out in the order that matters most. It is written for everyday readers, so each technical term is explained the first time it appears.

Key points

  • The law: Under the Privacy Act 2020, organisations must report serious breaches to the Privacy Commissioner and to you as soon as practicable; the OPC expects notification within 72 hours.
  • The penalty: Failing to notify is an offence with a fine of up to NZ,000. A June 2026 proposal for NZ million fines is a policy idea, not law.
  • Do first: Find out what was taken, change reused passwords (start with email), turn on two-factor authentication.
  • Protect your identity: Freeze your credit file with one free request that covers Centrix, Equifax and Experian for 10 working days.
  • Stay alert: Expect targeted phishing and fake “compensation” offers after any breach.
  • Get help: IDCARE (0800 121 068) and the NCSC (0800 114 115) support affected New Zealanders for free.

What New Zealand law requires after a breach

A data breach (also called a privacy breach) is any unauthorised access to, or loss of, personal information an organisation holds about you. Under the Privacy Act 2020, an organisation that suffers a breach likely to cause someone serious harm must notify both the Privacy Commissioner and the affected people as soon as practicable.

The Office of the Privacy Commissioner (OPC) explains the process in its guidance on sorting out privacy breaches, and it wants serious breaches reported through its online NotifyUs tool. The OPC’s guidance is that notification should happen no later than 72 hours after an organisation becomes aware of a notifiable breach — that is guidance, not a fixed statutory deadline, but it sets the expectation. Failing to notify the Commissioner without a reasonable excuse is a criminal offence carrying a fine of up to NZ$10,000.

“Serious harm” is the test that decides whether a breach must be reported. There is no rigid checklist, but the OPC weighs factors such as how sensitive the information is (health records and identity documents rank high), whether it was protected by encryption, who obtained it, and whether it could be used for fraud, discrimination or physical harm. A leaked email address alone may not meet the threshold; the same address bundled with a password, date of birth and licence number very likely does.

Alongside those duties, the Act gives you rights you can use straight away. The table below summarises the ones that matter most after a breach.

Your rightWhat it means in practice
To be toldIf a breach is likely to cause you serious harm, you must be notified, usually directly by the organisation.
To see what they holdYou can request the personal information an organisation holds about you; it has 20 working days to respond.
To have it correctedYou can ask for inaccurate personal information to be corrected.
To complainComplain to the organisation first, then to the Privacy Commissioner (0800 803 909) if you are not satisfied.

Breach reporting in New Zealand is climbing steeply. The Privacy Commissioner’s 2025 annual report recorded 1,093 privacy breach notifications, up 27 per cent on the previous year, and 1,598 complaints, up 21 per cent. Maximum penalties remain modest by international standards. In June 2026 the Green Party proposed lifting the maximum fine to NZ$10 million for organisations following the Manage My Health hack — but that is an opposition policy idea, not law, and the current cap stays at NZ$10,000.

The rules themselves are also evolving. A new information privacy principle, IPP 3A, took effect on 1 May 2026 and requires organisations that collect your personal information from someone other than you (indirect collection) to make you aware of it. Our Privacy Act 2020 guide walks through the wider framework and the latest changes.

Recent data breaches in New Zealand

Understanding the pattern helps you judge how seriously to take a notification. The incidents below are among the largest confirmed or investigated in recent years, drawn from official findings and reputable reporting.

BreachWhenWhat was exposed
Latitude FinancialMarch 2023Around 1,037,000 New Zealand driver licence numbers, plus tens of thousands of passport numbers across Australia and NZ.
MediaWorksMarch 2024Competition-entry data; the attacker claimed about 2.4 million records, and MediaWorks notified roughly 403,000 people.
Inland Revenue and MetaFebruary 2024, revealed late 2024Details of 268,000 taxpayers shared with Meta through a custom-audience advertising tool.
NeighbourlyConfirmed January 2026Names, email addresses, posts and messages; owner Stuff won a High Court injunction over data offered on the dark web.
Manage My HealthDisclosed December 2025; findings May 2026Health information of nearly 100,000 patients, about 91 per cent of them in Northland.
Canvas (Instructure)April–May 2026Learning-platform data at institutions including the University of Auckland, AUT and Victoria University of Wellington, in a global attack.

The Manage My Health inquiry is the most detailed public look yet at how a New Zealand breach unfolds. The Commissioner found that both the portal operator and Health New Zealand breached Rule 5 of the Health Information Privacy Code, which requires health information to be stored securely. The report pointed to weak detection and monitoring — including no system to flag when large volumes of records were accessed — and over-reliance on vendor assurances, and the Commissioner moved to issue compliance notices to both parties.

The other cases show how varied the risk is. The Neighbourly breach exposed messages and location data rather than card numbers, while the Canvas hack hit a third-party platform used by universities, showing that your data can be lost by a supplier you never chose. For the bigger picture of how these attacks happen, see our guide to cyber attacks in New Zealand.

Two patterns are worth taking away from this list. First, the most damaging leaks tend to involve identity documents and health records, because those cannot simply be reset the way a password can — a leaked driver licence number stays valid until you replace the document. Second, several of these incidents were not caused by the organisation you dealt with directly, but by a contractor, platform or advertising tool it used. That is why limiting how much information you hand over in the first place is as important as anything a company does to defend its systems.

What to do if your data was in a breach

The steps below run from most urgent to least. Work through them in order; you do not need to do everything at once, but the first three are worth doing the day you find out.

Breach response checklist

  1. Read the notification and note exactly which categories of information were exposed.
  2. Change the password on the affected account and anywhere you reused it, email first.
  3. Turn on two-factor authentication for email, banking and other key accounts.
  4. Freeze (suppress) your credit file if identity or financial details were involved.
  5. Report a lost or exposed passport or licence and arrange a replacement document.
  6. Tell your bank immediately if money or financial details are at risk.
  7. Save copies of the notification and any reports you make, in case you need them later.
  8. Stay alert for phishing messages that quote your real details, and verify any contact independently.

1. Work out what was actually taken

The notification should tell you what categories of information were involved. This matters because passwords, identity documents, financial details and health information each call for different responses. If the letter is vague, contact the organisation and ask directly — you are entitled to know what it held about you and, under the Act, to request a copy of that information. Keep the notification itself; it is your record of when you were told, which can matter if you later need to complain or prove you acted promptly.

2. Secure your passwords and accounts

If a password was exposed, change it on the affected service and anywhere you reused it, starting with your email account, because email is the master key attackers use to reset everything else. Turn on two-factor authentication (2FA) — a second login step, usually a code from an app — wherever it is offered. Our Have I Been Pwned guide shows how to check which breaches include your email address, and a password manager makes it painless to give every account a long, unique password.

3. Replace exposed identity documents

If a driver licence or passport number was exposed, ask about replacing the document so the leaked number can no longer be used to impersonate you. A lost or compromised passport can be reported through passports.govt.nz or on 0800 22 50 50. Waka Kotahi (NZ Transport Agency) handles driver licence replacements. Keep a note of when and to whom you reported it, in case you need to prove you acted.

4. Freeze (suppress) your credit file

If someone could use your details to apply for credit in your name, ask a credit reporter to place a suppression — often called a credit freeze — on your file. New Zealand has three credit reporters: Centrix, Equifax and Experian. Under the Credit Reporting Privacy Code a single request can now be passed between all three, so you no longer have to contact each one separately. The initial suppression lasts 10 working days and can be extended, and it is free. While it is in place, lenders cannot access your file, which blocks most fraudulent applications. The OPC explains the process in its note on how to freeze your credit information, and IDCARE has a plain-language fact sheet on suppressions in New Zealand.

5. Watch for follow-up scams

Breach data fuels targeted phishing — messages that quote your real name, address or account details to seem legitimate. These often include fake “breach compensation” or “account verification” offers designed to harvest more information or money. Treat any unexpected contact about the breach with suspicion, never click links in it, and reach the organisation by typing its website address yourself or calling a number you already trust.

6. Where to get help

  • IDCARE (0800 121 068) is a free, not-for-profit service with specialist counsellors who build a step-by-step response plan if your identity has been compromised.
  • The National Cyber Security Centre (NCSC) takes incident reports at its online reporting page or on 0800 114 115 (the number that replaced the old CERT NZ line).
  • Your bank, straight away, if financial details or money are involved — banks can watch for or block suspicious transactions.
  • The Privacy Commissioner, if the organisation does not handle your complaint properly.

How to reduce your exposure

You cannot stop companies being breached, but you can limit how much they hold and how exposed you are when it happens. A few habits make a measurable difference:

  • Give the minimum information a form actually requires, and skip optional fields.
  • Delete accounts and subscriptions you no longer use, so old data is not sitting in a forgotten database.
  • Use a separate email alias for sign-ups and competitions, keeping your main address for people you trust.
  • Keep two-factor authentication switched on for the accounts that matter most — email, banking and any store of identity documents.
  • Check your email against known breaches periodically rather than only when a letter arrives.

It is worth being clear about what a virtual private network (VPN) — a tool that encrypts your internet traffic — can and cannot do here. A VPN protects data in transit, such as on public Wi-Fi, but it does nothing for information already sitting in a company’s database. The same goes for antivirus software: it defends your own devices, not a third party’s servers. No single tool prevents breaches; the point is to know which risk each one addresses so you are not relying on the wrong protection. Our cyber security guide sets out how those layers fit together.

Finally, a note on timing. The most valuable window is the first day or two after you learn of a breach, because that is when criminals move fastest to use fresh data. Doing the top three steps — checking what was taken, changing reused passwords, and turning on two-factor authentication — quickly matters more than doing everything perfectly. You can extend a credit suppression or replace a document later; you cannot undo a fraudulent account opened while you waited.

Disclaimer: This article is general information only and is not legal advice. Breach details are drawn from Privacy Commissioner publications and reputable news reports current to September 2026; for information about your own records, contact the organisation involved or seek professional advice.

Frequently asked questions

Do companies have to tell me about a data breach in NZ?

Yes, if the breach is likely to cause you serious harm. In that case the organisation must notify both you and the Privacy Commissioner as soon as practicable, and failing to notify the Commissioner without a reasonable excuse is an offence.

What should I do first after a data breach?

Find out what was exposed, change any affected passwords starting with your email, turn on two-factor authentication, and freeze your credit file if identity or financial details were taken. Those first steps close off the most common ways criminals exploit leaked data.

How do I freeze my credit in New Zealand?

Ask Centrix, Equifax or Experian to place a suppression on your credit file. One request can now be passed between all three, the initial freeze lasts 10 working days, it can be extended, and it is free. Lenders cannot see your file while it is active.

Can I get compensation after a data breach?

Sometimes. Complain to the organisation first, then to the Privacy Commissioner. If a complaint is not resolved, it can be referred to the Human Rights Review Tribunal, which can award damages. Be wary of unsolicited “compensation” offers that arrive by email or text — they are usually scams.

How do I check if my details were in a breach?

Watch for notification letters or emails, and check your email address on Have I Been Pwned, a free service that lists known breaches containing it. If you are unsure whether a message is genuine, contact the organisation directly rather than replying.