Frameworks

The Privacy Act 2020, explained for business

The Privacy Act 2020 is New Zealand’s core privacy law. It sets out how organisations must collect, use, store and protect personal information — and, since 2020, requires you to report serious privacy breaches to the Privacy Commissioner and affected people.

The Privacy Act 2020 is New Zealand’s core privacy law. It sets out how organisations must collect, use, store and protect personal information — and, since 2020, requires you to report serious privacy breaches to the Privacy Commissioner and affected people.

The essentials

What it requires

  • It applies to almost every NZ organisation that handles personal information, regardless of size.
  • It sets 13 Information Privacy Principles covering collection, use, storage, access and disclosure.
  • You must take reasonable security safeguards to protect personal information.
  • Notifiable breaches: serious privacy breaches must be reported to the Office of the Privacy Commissioner and affected individuals.
  • It applies to personal information sent overseas, with conditions.

How to comply

Practical steps

  • Know what personal information you hold and where it lives.
  • Apply reasonable safeguards — MFA, access control, encryption, backups.
  • Have a breach response plan so you can assess and report quickly.
  • Train staff on handling personal information.
  • Review third parties and overseas data flows.

FAQ

Common questions

Does the Privacy Act 2020 apply to small businesses?

Yes. It applies to nearly every organisation in New Zealand that handles personal information, regardless of size — there is no small-business exemption.

What is a notifiable privacy breach?

A privacy breach that has caused, or is likely to cause, serious harm. These must be reported to the Office of the Privacy Commissioner and to affected individuals as soon as practicable.

What counts as reasonable security safeguards?

There's no fixed checklist, but it means protection appropriate to the sensitivity of the data — typically MFA, access controls, encryption, tested backups and staff training.

How is this different from the GDPR?

The Privacy Act 2020 is New Zealand's law and applies to NZ organisations. The EU's GDPR may also apply if you handle data about people in the EU, but for most NZ organisations the Privacy Act is the primary obligation.

Let’s talk

Every good plan starts with a conversation, and there’s no obligation in having one.