Asia-Pacific New Zealand

New Zealand Privacy Act 2020: IPPs, Breaches, Compliance

New Zealand's Privacy Act 2020: the 13 information privacy principles, notifiable breach rules, IPP 12 cross-border limits, and the Privacy Commissioner's powers.

Regulation

Privacy Act 2020 (in force 1 December 2020)

Max Penalty

Fines up to NZD 10,000 per offence; compliance notices; Human Rights Review Tribunal damages (awards have exceeded NZD 160,000)

Enforcing Authority

Office of the Privacy Commissioner (OPC)

Official Source

www.privacy.org.nz

Executive Summary

  • The Privacy Act 2020 replaced the 1993 act on 1 December 2020, keeping the principles-based model: 13 information privacy principles (IPPs) governing collection, use, security, access, and disclosure.
  • It added mandatory notifiable privacy breach reporting: breaches likely to cause serious harm must go to the Privacy Commissioner and affected individuals as soon as practicable.
  • IPP 12 restricts cross-border disclosures to recipients under comparable safeguards, prescribed countries, or with informed consent.
  • Enforcement is compliance-first: the Commissioner issues compliance notices and access directions; criminal fines cap at NZD 10,000, but Human Rights Review Tribunal damages and reputational exposure carry the real weight.
  • New Zealand holds EU adequacy (since 2012, maintained after review), one of the few Asia-Pacific jurisdictions with it; a new IPP 3A (2026) extends notification duties to indirectly collected data.

New Zealand runs the lightest-touch privacy regime of any EU-adequate jurisdiction: thirteen principles, a conciliation-minded Commissioner, and criminal fines that would not cover a GDPR fine’s rounding error. The design relies on different levers, mandatory breach notification with public accountability, tribunal damages that reach six figures per person, and adequacy status the country actively protects. For businesses, the trap is complacency: the paperwork burden is low, but the collection principles are stricter than GDPR’s, and the 2020 act reaches any offshore business serving New Zealanders.

RegulationPrivacy Act 2020 (from 1 December 2020)
Structure13 information privacy principles
Max fineNZD 10,000 per offence (+ tribunal damages)
Enforcing authorityPrivacy Commissioner
Official textPrivacy Act 2020, NZ Legislation
EU adequacyYes

The IPPs in working order

  • Collection (IPPs 1-4). Collect only what is necessary for a lawful purpose connected to your functions; collect directly from the individual unless an exception applies; tell them what, why, who, and their rights at collection; collect fairly and non-intrusively. From 2026, IPP 3A extends the notification duty to information collected indirectly, closing the third-party-source gap.
  • Custody (IPPs 5, 8-9). Reasonable security safeguards; accuracy checks before use; retention no longer than the purpose requires.
  • Individual rights (IPPs 6-7). Access to one’s information (the Commissioner can issue binding access directions) and correction, with statement-of-correction fallback.
  • Use and disclosure (IPPs 10-11). Use and disclose only for the collection purpose or a directly related one, with listed exceptions (consent, safety, law enforcement).
  • Offshore and identifiers (IPPs 12-13). Comparable-safeguard conditions for foreign disclosure; restrictions on unique identifiers.

The breach regime and the offshore rule

Notifiable-breach practice since 2020 shows the OPC receiving several hundred serious-harm notifications yearly, with email misdirection and cyber-attack the leading causes, and the Commissioner has publicly criticized under-reporting relative to Australia. Assess serious harm quickly, notify via NotifyUs, and document non-notified assessments, the offence attaches to failing to notify the Commissioner.

For trans-Tasman and global operators, note the asymmetries with Australia: no turnover-scaled penalties, no small-business exemption, and an accountability model (IPP 12) closer to Australia’s APP 8 than to GDPR adequacy gating. The NDB comparison is useful when building one incident playbook for both countries. Check what your NZ-facing surfaces collect with a free scan.

Frequently Asked Questions

Who does the Privacy Act 2020 apply to?

Every 'agency': businesses, government departments, and organizations of any size, in New Zealand, plus overseas agencies carrying on business in New Zealand regardless of physical presence, explicit extraterritoriality that captures offshore platforms serving NZ users. There is no small-business exemption, unlike Australia.

What makes a breach notifiable?

A privacy breach that has caused, or is likely to cause, serious harm to affected individuals, assessed on sensitivity, protections, who obtained the data, and mitigations. Notify the Commissioner (via the NotifyUs portal) and affected individuals as soon as practicable; failure to notify the Commissioner is an offence (up to NZD 10,000).

How do the IPPs differ from GDPR obligations?

The IPPs are outcome-standards rather than documented-accountability rules: no mandatory records of processing, DPIAs, or DPO (a privacy officer is required, but the role is lighter). Rights center on access and correction (IPPs 6-7); there is no erasure, portability, or objection right. Collection rules (IPPs 1-4) are stricter than GDPR in demanding direct collection from the individual as the default.

What does IPP 12 require for offshore disclosure?

Before disclosing personal information to a foreign person or entity (not mere storage with a processor, which stays an NZ 'use'), the agency must reasonably believe the recipient is subject to comparable safeguards or a prescribed binding scheme, obtain express informed consent, or fit another exception. Cloud hosting where the provider only stores data does not trigger IPP 12.

What are the real enforcement risks in New Zealand?

Not fines: the criminal maxima are NZD 10,000. The operative risks are compliance notices (enforceable through the tribunal), access directions, Human Rights Review Tribunal proceedings where damages for humiliation and injury to feelings have exceeded NZD 160,000 per plaintiff and class complaints are possible, and the Commissioner's public naming practice. The OPC has also called publicly for a civil penalty regime, so the ceiling may rise.

Regulatory Crosswalk

GDPRAustralian Privacy PrinciplesNZ IPPs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.