The Privacy Commissioner is New Zealand’s independent statutory officer responsible for promoting and protecting personal-information rights under the Privacy Act 2020. If you want to understand your rights around data collection, complain about how an organisation handled your information, or simply work out what protections apply to you as an NZ resident, the Office of the Privacy Commissioner (OPC) is your first port of call — not a VPN provider, not a lawyer, and not a government ministry. This 2026 guide explains what the office does, what recently changed in the law, and how to protect yourself in practice.
Key Points
- The Office of the Privacy Commissioner (OPC) is an independent regulator enforcing the Privacy Act 2020; the current Commissioner is Michael Webster.
- It handles personal-information disputes — collection, storage, use, disclosure and access — not internet censorship or state surveillance.
- New for 2026: the Biometric Processing Privacy Code 2025 (in force 3 Nov 2025; existing systems compliant by 3 Aug 2026) and IPP 3A on indirect-collection notification (from 1 May 2026).
- Complaints are free and need no lawyer; raise it with the organisation first, then file at privacy.org.nz. Access requests must be answered within 20 working days.
- The OPC cannot award compensation itself (that is the Human Rights Review Tribunal) or oversee lawful interception under TICSA/Five Eyes.
What the Privacy Commissioner does
The current Privacy Commissioner is Michael Webster, who has held the role since 2022. The office does not regulate internet traffic or block websites. Its job is to oversee how organisations collect, store, use, and share personal information — and to give you recourse when they get it wrong.
The OPC sits outside the standard public-service structure. The Commissioner is appointed by the Governor-General on the recommendation of the House of Representatives, which gives the office genuine independence from the executive branch. In practice this means the Commissioner can investigate government agencies — including the Police, IRD, and GCSB — with the same authority applied to private companies. The office also issues guidance, runs inquiries into systemic issues, publishes case notes from completed investigations, and makes submissions to Parliament on proposed laws affecting privacy.
The Privacy Act 2020 and what it introduced
The Privacy Act 2020 replaced the 1993 Act and came into force on 1 December 2020. It is built around a set of Information Privacy Principles (IPPs) — plain-language rules that govern how personal information can be collected, used, and disclosed. The 2020 Act brought several changes that matter to everyday NZ users:
- Mandatory breach notification: Organisations must notify the OPC and affected individuals of any privacy breach that has caused, or is likely to cause, serious harm. Notification must happen as soon as practicable.
- Compliance notices: The Commissioner can issue binding compliance notices, not just recommendations. Non-compliance can be referred to the Human Rights Review Tribunal.
- Cross-border data flows: Organisations sending personal information overseas must take reasonable steps to ensure the recipient provides comparable protection. This matters given how much NZ data sits with offshore cloud regions and US-based software platforms.
- Extended reach: The Act can apply to overseas businesses that are ‘carrying on business’ in New Zealand, even without a local office.
Note that the Privacy Act 2020 itself does not create GDPR-style ‘special categories’ for sensitive data. Health information is governed by the separate Health Information Privacy Code, and — as of 2025 — biometrics have their own code, covered next.
What changed for 2026: the Biometric Code and IPP 3A
Two developments make 2026 a genuinely different landscape from earlier years, and both are easy to miss.
Biometric Processing Privacy Code 2025
Biometric information means data derived from your body or behaviour — a face scan, fingerprint, voiceprint, or iris pattern — used by an automated system to identify or verify you. The OPC issued the Biometric Processing Privacy Code 2025, which came into force on 3 November 2025. It sets specific rules for any organisation using automated biometric systems, including a proportionality test (you must weigh the privacy intrusion against the benefit), transparency requirements, and limits on certain uses such as inferring emotions. New biometric systems had to comply from 3 November 2025; systems already running before that date have until 3 August 2026 to comply. This is directly relevant to retailers using facial-recognition cameras, banks and fintechs doing identity verification, and any app that scans your face.
IPP 3A — new indirect-collection notification (from 1 May 2026)
The Privacy Amendment Act 2025 received royal assent on 24 September 2025 and adds a new principle, IPP 3A, which takes effect on 1 May 2026. Until now, notification duties largely applied when an organisation collected information directly from you. Under IPP 3A, when an organisation collects your personal information from someone other than you — a third party or data source — it must take reasonable steps to make you aware of key matters (that the collection happened, why, who will receive the data, and your rights to access and correct it), unless an exception applies. In short, more of the quiet, behind-the-scenes data gathering now comes with a duty to tell you.
NZ-specific issues: Five Eyes, ISPs, and jurisdiction
New Zealand is a founding member of the Five Eyes signals-intelligence alliance, alongside Australia, Canada, the United Kingdom, and the United States. This is a publicly acknowledged arrangement, not a conspiracy theory. Practically, it means communications metadata collected by NZ agencies can be shared with partner agencies under frameworks that sit largely outside the Privacy Act. Surveillance powers are governed separately by the GCSB Act and the Telecommunications (Interception Capability and Security) Act 2013 (TICSA), not by the OPC.
This creates a real gap. The Privacy Commissioner can investigate how Spark, One NZ, or 2degrees handle your customer data under the Privacy Act. The Commissioner cannot investigate lawful interception carried out under a TICSA warrant, nor override intelligence-sharing arrangements. If your concern is state surveillance rather than commercial misuse, the relevant oversight body is the Inspector-General of Intelligence and Security — not the OPC.
For ISP customers specifically, the Privacy Act requires your provider to hold your personal information securely, use it only for the purposes collected, and give you access to it on request. Chorus, the wholesale fibre operator behind most NZ broadband (its Hyperfibre plans now scale up to 8 Gbps, on a network capable of 10 Gbps), holds infrastructure data, while your retail ISP holds your account and usage data. To see what your ISP has on you, make a subject-access request directly — the organisation must respond within 20 working days.
How to file a complaint with the Privacy Commissioner
The complaints process is free and does not require a lawyer. Here is how it works in practice:
- Raise it with the organisation first. The OPC expects you to contact the organisation directly before complaining. Most issues are resolved at this stage. Put it in writing — email is fine — and keep a copy.
- Give them time to respond. An access request must be answered within 20 working days. For a general privacy concern, two to four weeks is a reasonable window.
- File with the OPC if unresolved. Use the online complaint form at privacy.org.nz. You will describe the organisation, the information involved, what you asked for, and what happened, attaching any correspondence.
- The OPC assesses the complaint. Not every complaint proceeds. The office may decline matters that are out of jurisdiction, trivial, or already resolved. If accepted, it contacts the organisation and attempts mediation.
- Investigation and outcome. If mediation fails, the Commissioner can investigate formally and issue a compliance notice. If the organisation still does not comply, the matter can go to the Human Rights Review Tribunal, which can award damages.
There is no filing fee at any stage. Tribunal proceedings can involve legal costs if you choose to hire a lawyer, but many complainants represent themselves.
Protecting your privacy beyond the OPC
The Privacy Commissioner provides recourse after something goes wrong. Practical protection happens before anything goes wrong, and works best as a layered approach across three areas: what data you share, where it goes, and who can see it in transit.
Data minimisation
The IPPs require organisations to collect only what is necessary for their stated purpose. You can reinforce that by not volunteering more than you are asked for: use separate email addresses for different services, review app permissions regularly (especially location and contacts access), and opt out of marketing data sharing where the option exists. NZ retailers, loyalty programmes, and streaming services including TVNZ+, Neon, and Sky Sport Now all collect behavioural data, and their privacy policies are legally required to disclose it.
Encryption in transit
Your ISP can often see the domains you visit even over HTTPS, because standard DNS lookups (the system that turns a web address into a numeric IP) are usually unencrypted. Switching to an encrypted resolver (DNS-over-HTTPS or DNS-over-TLS) closes that gap and adds negligible latency on a local fibre connection; our guide on changing DNS on your router walks through it. A VPN goes further, encrypting all traffic between your device and the VPN server so your ISP sees only the VPN connection, not the destinations. That matters in NZ because TICSA requires ISPs to maintain interception capability — meaning your ISP must be technically able to hand your traffic to authorities under warrant. A VPN does not defeat a warrant served on the VPN provider, but your ISP cannot hand over browsing data it never saw. For a fuller breakdown, see our guide to the best VPNs for New Zealand.
Device and account hygiene
Strong unique passwords, two-factor authentication, and up-to-date software are not glamorous, but they prevent the majority of personal data losses that end up before the Commissioner. The OPC’s own case notes show that a large share of complaints stem from inadequate security — lost devices, weak passwords, and misconfigured cloud storage — rather than deliberate misuse. Reducing that exposure also reduces your risk of ending up in a privacy breach in the first place.
Comparing privacy tools for NZ users in 2026
The VPN options below are assessed against NZ-relevant criteria: server availability in Australia and the US (the two most useful regions for NZ users), independently audited no-logs policies, and pricing in NZD context. As a performance yardstick, on a fast Auckland fibre line with the server set to Sydney you would typically expect WireGuard-based connections to sustain several hundred Mbps with latency around 28–35 ms; NZ-to-US West Coast connections have a physics-imposed floor of roughly 138 ms round-trip, so expect about 150–180 ms in practice.
VPN Comparison
| Provider | Audited no-logs | WireGuard | NZ-relevant servers | Approx. NZD/month (2-yr plan) | Jurisdiction |
|---|---|---|---|---|---|
| Mullvad | Yes | Yes | AU, US, JP | ~NZ | Sweden |
| ExpressVPN | Yes | Yes (Lightway) | AU, NZ, US | ~NZ–14 | British Virgin Islands |
| NordVPN | Yes | Yes (NordLynx) | AU, NZ, US | ~NZ–8 | Panama |
| Proton VPN | Yes | Yes | AU, US, JP | ~NZ–11 | Switzerland |
| Surfshark | Yes | Yes | AU, NZ, US | ~NZ –6 | Netherlands |
Prices are indicative and change with promotions; check the provider for current NZD pricing.
None of these providers are subject to NZ jurisdiction, which is relevant given Five Eyes. Sweden, Switzerland, Panama, and the Netherlands sit outside the alliance; the British Virgin Islands operates under UK law but has no data-retention requirement. If you want a no-cost starting point, our free VPN guide covers the options that are actually usable from NZ without crippling data caps. For NZ streaming, services such as ThreeNow and TVNZ+ are geo-locked to NZ IP addresses, so a VPN with NZ exit nodes lets you reach them while travelling; conversely, watching overseas libraries of Netflix or Disney+ from NZ needs an overseas exit node, and reliability varies as services block known VPN ranges.
What the Privacy Commissioner cannot do
Understanding the limits of the OPC is as important as knowing its powers. The Commissioner:
- Cannot award compensation directly — only the Human Rights Review Tribunal can, and only after a formal complaint process.
- Cannot investigate intelligence agencies’ lawful interception — that falls to the Inspector-General of Intelligence and Security.
- Cannot regulate content — the Broadcasting Standards Authority handles broadcast complaints, and NZ Police handle illegal content.
- Cannot act on behalf of deceased persons — the Privacy Act protects living individuals only.
- Cannot effectively compel overseas organisations with no NZ presence, even where the Act’s extended-reach provisions technically apply.
- Cannot override the Telecommunications Act or TICSA — lawful interception under warrant is outside its jurisdiction.
The overseas point is worth dwelling on. If a foreign platform is ‘carrying on business’ in New Zealand, the OPC can investigate and issue compliance notices, and it can coordinate with counterpart regulators through international enforcement networks. But enforcement against a company with no NZ assets is largely theoretical. In those cases, practical protection comes from the tools above rather than from filing a complaint. For a broader look at staying private online here, see our overview of using a VPN in New Zealand.
Disclaimer: This guide provides general information about New Zealand privacy law and is not legal advice. Laws and codes change, and how they apply depends on your circumstances. For advice about a specific situation, contact the Office of the Privacy Commissioner or a qualified lawyer.
Sources
Frequently Asked Questions (FAQ)
What is the Privacy Commissioner’s role in New Zealand?
The Privacy Commissioner is an independent statutory officer who administers the Privacy Act 2020. The office promotes privacy rights, investigates complaints about how organisations handle personal information, issues guidance and codes of practice, and can compel compliance through binding notices. It covers both government agencies and private-sector organisations operating in New Zealand.
How do I make a complaint to the Privacy Commissioner?
First raise the issue directly with the organisation and give it a reasonable chance to respond, typically two to four weeks. If it is unresolved, file a complaint online at privacy.org.nz. The process is free and does not require a lawyer, and the OPC will attempt mediation before any formal investigation. If a matter reaches the Human Rights Review Tribunal, compensation can be awarded.
What are the Biometric Code and IPP 3A that took effect around 2025 and 2026?
The Biometric Processing Privacy Code 2025 came into force on 3 November 2025 and sets rules for organisations using automated biometric systems such as facial recognition; existing systems must comply by 3 August 2026. IPP 3A, added by the Privacy Amendment Act 2025 and effective from 1 May 2026, requires organisations that collect your information from someone other than you to take reasonable steps to notify you, unless an exception applies.
Does the Privacy Act 2020 cover what my ISP does with my data?
Yes. Spark, One NZ, 2degrees, and other NZ ISPs are bound by the Privacy Act. They must collect only necessary information, keep it secure, use it only for stated purposes, and give you access on request. However, lawful interception under a TICSA warrant is a separate framework that sits outside the Privacy Commissioner’s jurisdiction.
Can a VPN protect me from Privacy Act breaches?
A VPN protects your data in transit — it stops your ISP and network observers from seeing your browsing activity. It does not control how a website or app handles data once you have submitted it, so it would not prevent a company you signed up with from suffering a breach. The Privacy Act and the OPC address that scenario, while a VPN addresses surveillance and interception in transit; for full protection you want both.




