The Privacy Act 2020 is New Zealand's general data protection statute. It sets out how any organisation, public or private, may collect, store, use, disclose and give access to personal information, which the Act defines as information about an identifiable individual. It replaced the Privacy Act 1993, a law drafted before e-commerce and programmatic trading, and exists partly to keep New Zealand's rules close enough to European standards that personal data can move from the European Union without extra contracts. Royal assent came on June 30, 2020, and the Act took effect on December 1, 2020.
Unlike the European Union's General Data Protection Regulation (GDPR), it has no lawful bases and no general consent requirement. It works instead through principles, a regulator with unusual rule-making power and a complaints system that favours settlement over punishment.
How the principles work
The core of the Act is a set of Information Privacy Principles (IPPs), originally 13 and now 14. IPP 1 requires a lawful purpose. IPPs 2 to 4 govern collection: from whom, with what notice, and by fair means, with extra care for children. IPP 5 covers security, IPPs 6 and 7 give rights of access and correction, and IPPs 8 and 9 cover accuracy and retention. IPPs 10 and 11 limit use and disclosure to the purposes for which information was obtained, subject to exceptions. IPP 12 governs sending information abroad and IPP 13 restricts unique identifiers.
According to an analysis by the Future of Privacy Forum, the Act treats collection, use and disclosure as separate acts with separate rules. IPP 12 permits a cross-border disclosure on one of six grounds, among them express informed consent, a recipient that is itself carrying on business in New Zealand and subject to the Act, and a recipient bound by comparable safeguards, for instance by contract.
The regulated party is an agency, which the Ministry of Justice describes as any person or body, corporate or unincorporated, in either sector. Reach is extraterritorial. The Act covers overseas agencies carrying on business in New Zealand whether or not they have a local office, receive payment or intend to profit there, according to Linklaters.
The Privacy Commissioner can also issue codes of practice, with legal force, that modify the principles for a sector, class of information or activity. Seven were in operation as of September 2026, according to Linklaters, including the Health Information Privacy Code and the new Biometric Processing Privacy Code.
Breaches, notices and the Tribunal
The 2020 Act introduced mandatory breach notification. When an agency reasonably believes a privacy breach has caused or is likely to cause serious harm, it must notify the Commissioner and affected people as soon as practicable. Failure without reasonable excuse is an offence carrying a fine of up to NZ$10,000. The statute sets no fixed deadline; the Office of the Privacy Commissioner (OPC) expects notification within 72 hours, according to PwC New Zealand, and some compliance vendors present that guidance figure as if it were law.
Compliance notices are the Commissioner's main enforcement tool. They are enforced through the Human Rights Review Tribunal, and ignoring one is another NZ$10,000 offence. Individual complaints move from investigation to attempted settlement and, failing that, to the Tribunal, which can award damages, including for humiliation, to individuals or a represented class. Insurer Vero has stated that an award of up to NZ$350,000 may be made to each class member.
From 1993 to IPP 3A
New Zealand legislated early. The 1993 Act created the modern Commissioner's office, and the European Commission found the country adequate under the old Data Protection Directive in 2012. The Law Commission began reviewing the 1993 law in 2006 and reported in 2011. A replacement bill reached Parliament in March 2018 and passed its third reading on June 24, 2020, according to the OPC's own report to the European Commission.
Enforcement was modest by design. Then-Commissioner John Edwards said in 2020 that the Act was built to sit mid-range among global privacy laws, with compliance notices tested before any move to European-scale fines, according to the Future of Privacy Forum.
Europe shaped the next step. The Ministry of Justice has said that indirect collection was flagged as a gap during the EU's adequacy assessment. The European Commission's review of 11 legacy adequacy decisions, published on January 15, 2024, kept New Zealand's status. A Privacy Amendment Bill introduced in September 2023 added IPP 3A, which requires an agency that collects personal information from someone other than the individual to take reasonable steps to tell that person, unless an exception applies. It drew 55 submissions and received royal assent on September 23, 2025. Technical changes applied the next day; IPP 3A took effect on May 1, 2026, and does not reach information collected earlier.
Codes moved too. The Biometric Processing Privacy Code came into force on November 3, 2025, with systems already running given until August 3, 2026.
Where advertising meets the principles
New Zealand is a small market but sits on most platforms' rollout lists. OpenAI announced ChatGPT advertising expansion to New Zealand on March 26, 2026, and its minimum campaign spend table lists 25 NZD. New Zealand advertisers were among those facing an automatic advanced matching default that sends hashed form data to the platform unless switched off. Not every product arrives: Waze ads launched in 41 countries without it.
Take a common transaction. A New Zealand retailer uploads hashed customer emails to an overseas platform for matching. Hashing does not settle the question, since regulators elsewhere treat hashed identifiers as identifiable. Under IPP 11 that is a disclosure, lawful only if it fits the purposes customers were told about at collection. Under IPP 12 it is a cross-border disclosure; on the Future of Privacy Forum's reading, no extra safeguard is needed if the platform itself carries on business in New Zealand and is covered by the Act. If the platform uses the data for its own purposes, it has collected indirectly and IPP 3A applies to it. If it holds the data only on the retailer's behalf, the OPC's guidance on third-party providers treats the retailer as the responsible agency.
IPP 3A lands hardest on list rental and on the data broker model. The OPC's own guidance works through a fictional agency, Sterling Draper, that receives a marketing list with contact and demographic data from a partner and delays notice until its campaign begins. The Marketing Association asked the Justice Committee to exempt registered charities, single-use list agreements and time-limited exchanges. None of those exemptions was adopted, according to the association.
The biometrics code reaches measurement. Rule 10 bars using biometric processing to infer health, emotion, personality or attention level unless a narrow exception applies. OPC examples state that inferring emotions from faces would generally not be permitted.
Limits and disputes
The main criticism is that penalties do not deter. Beyond fines of up to NZ$10,000 for a short list of offences, there is no civil penalty regime. The Act also omits a right to erasure, a right to data portability and specific protections around automated decision-making.
Privacy Commissioner Michael Webster has made the case repeatedly. "We see multimillion dollar penalties in Australia for organisations who fail to protect personal information, but in New Zealand there's no civil penalty regime," he said in December 2025, according to NZ Lawyer. The OPC's 2024/25 annual report recorded complaints up by a fifth and notified serious breaches up more than 40%, according to RNZ.
Ministers have been slower to commit. In May 2024 Justice Minister Paul Goldsmith said there were "no current plans to amend the offences and penalties," according to the NZ Herald. By early 2026 he said the government "will take advice on whether further strengthening is justified," according to Law News.
Not the same as
Privacy Act 1993. The repealed predecessor, with no mandatory breach notification and narrower territorial reach.
Australia's Privacy Act 1988. A separate statute whose regulator can seek large civil penalties. An exposure draft published by the Attorney-General's Department would require consent before personal information is traded, naming cookie and pixel disclosures in programmatic advertising as examples.
GDPR. The EU regulation built on lawful bases, consent and fines of up to 4% of global turnover. New Zealand's adequacy status means EU law treats the two regimes as comparable, not identical.
Unsolicited Electronic Messages Act 2007. New Zealand's anti-spam law, enforced by the Department of Internal Affairs. It requires consent before commercial email or text messages are sent; the Privacy Act does not.
Recent developments
Manage My Health notified the OPC on January 1, 2026 of a breach of its patient portal, and the Commissioner opened an inquiry on January 21. Phase one findings, released on May 27, 2026, put the number of affected patients at 99,416. Both the company and Health New Zealand were found to have breached the security rule of the health code, and Webster said he intended to issue compliance notices. In June he asked the government for powers to impose serious financial penalties, according to RNZ.
IPP 3A has applied since May 1, 2026, and the biometrics transition ended on August 3. The OPC's 2026 survey found 71% of respondents concerned about children's privacy and 67% about AI-driven decisions, according to the OPC.
Consultation on Australia's draft closed on September 18, 2026, with a 72-hour breach notification deadline among its proposals, a point PPC Land flagged in its weekly review. Adequacy status is also not permanent, as the EDPB's August 2026 concerns about the EU-US framework show.
Timeline
- 1993: The Privacy Act 1993 is enacted and the modern Office of the Privacy Commissioner is established.
- 2006: The Law Commission begins work on updating the 1993 Act.
- 2011: The Law Commission publishes its review of the Privacy Act 1993 (Report 123).
- 2012: The European Commission adopts its adequacy decision for New Zealand under Directive 95/46/EC.
- March 2018: The Privacy Bill is introduced to Parliament.
- June 24, 2020: The Privacy Bill passes its third reading.
- June 30, 2020: The Privacy Act 2020 receives royal assent.
- December 1, 2020: The Privacy Act 2020 comes into force, replacing the 1993 Act.
- September 2023: The Privacy Amendment Bill is introduced to Parliament.
- January 15, 2024: The European Commission's first review of 11 legacy adequacy decisions confirms New Zealand's status.
- May 2, 2024: The Privacy Amendment Bill has its first reading and is referred to the Justice Committee.
- October 25, 2024: The Justice Committee reports back, recommending the bill be passed.
- September 23, 2025: The Privacy Amendment Act 2025 receives royal assent.
- September 24, 2025: The Act's technical amendments take effect.
- November 3, 2025: The Biometric Processing Privacy Code comes into force for new processing.
- January 1, 2026: Manage My Health notifies the OPC of a breach of its patient portal.
- January 21, 2026: The Privacy Commissioner announces an inquiry into the Manage My Health breach.
- May 1, 2026: IPP 3A, covering indirect collection, comes into force.
- May 27, 2026: Phase one findings of the Manage My Health inquiry are released, with 99,416 patients affected.
- June 3, 2026: The Privacy Commissioner asks the government for powers to impose serious financial penalties.
- August 3, 2026: The biometrics code applies in full to processing that began before November 3, 2025.
Related PPC Land coverage
- Australia would force ad tech to get consent before sharing pixels - The Australian exposure draft requiring consent before personal information is traded, with a 72-hour breach deadline.
- AI agents now buy media, so agencies are metering them by the token - Weekly review placing the Australian draft and its consultation timetable in context.
- ChatGPT Ads finally leave the US: UK, Japan, Korea, Brazil and Mexico next - The timeline recording OpenAI's March 2026 expansion to New Zealand.
- OpenAI gains 32 ChatGPT ad markets in 5 days as India goes live - The minimum campaign spend table, including the New Zealand dollar floor.
- ChatGPT advertisers face 10 days to opt out of automatic advanced matching - The hashed form data default applied across markets including New Zealand.
- Waze ads gain 41 countries including all 27 EU member states - A launch list that leaves New Zealand out.
- Explaining data broker - The business model most directly affected by notification duties for indirect collection.
- Explaining de-identification - Why regulators treat hashed and pseudonymised identifiers as personal data.
- Explaining GDPR - The European regime New Zealand's adequacy status is measured against.
- EDPB puts EU-US data pact in doubt as FTC's five commissioners lose shield - How an adequacy finding can come under pressure after it is granted.
Summary
Who. The Office of the Privacy Commissioner, led by Michael Webster since July 2022, administers the Act. It binds every agency handling personal information in New Zealand, including overseas companies carrying on business there, with the Human Rights Review Tribunal as the adjudicating body and the Ministry of Justice responsible for policy.
What. New Zealand's general privacy statute, built on Information Privacy Principles, sector codes of practice, mandatory notification of serious breaches and compliance notices, with maximum fines of NZ$10,000.
When. Assented to on June 30, 2020 and in force from December 1, 2020, with IPP 3A added from May 1, 2026 and a biometrics code phased in between November 3, 2025 and August 3, 2026.
Where. New Zealand, with extraterritorial reach to foreign agencies doing business there and rules governing any disclosure of personal information abroad.
Why. The Act replaced a 1993 law unsuited to digital data, keeps New Zealand's EU adequacy status intact, and now requires notice when personal information arrives through lists, partners or platforms rather than from the person concerned.
Discussion