New Zealand runs the lightest-touch privacy regime of any EU-adequate jurisdiction: thirteen principles, a conciliation-minded Commissioner, and criminal fines that would not cover a GDPR fine’s rounding error. The design relies on different levers, mandatory breach notification with public accountability, tribunal damages that reach six figures per person, and adequacy status the country actively protects. For businesses, the trap is complacency: the paperwork burden is low, but the collection principles are stricter than GDPR’s, and the 2020 act reaches any offshore business serving New Zealanders.
| Regulation | Privacy Act 2020 (from 1 December 2020) |
|---|---|
| Structure | 13 information privacy principles |
| Max fine | NZD 10,000 per offence (+ tribunal damages) |
| Enforcing authority | Privacy Commissioner |
| Official text | Privacy Act 2020, NZ Legislation |
| EU adequacy | Yes |
The IPPs in working order
- Collection (IPPs 1-4). Collect only what is necessary for a lawful purpose connected to your functions; collect directly from the individual unless an exception applies; tell them what, why, who, and their rights at collection; collect fairly and non-intrusively. From 2026, IPP 3A extends the notification duty to information collected indirectly, closing the third-party-source gap.
- Custody (IPPs 5, 8-9). Reasonable security safeguards; accuracy checks before use; retention no longer than the purpose requires.
- Individual rights (IPPs 6-7). Access to one’s information (the Commissioner can issue binding access directions) and correction, with statement-of-correction fallback.
- Use and disclosure (IPPs 10-11). Use and disclose only for the collection purpose or a directly related one, with listed exceptions (consent, safety, law enforcement).
- Offshore and identifiers (IPPs 12-13). Comparable-safeguard conditions for foreign disclosure; restrictions on unique identifiers.
The breach regime and the offshore rule
Notifiable-breach practice since 2020 shows the OPC receiving several hundred serious-harm notifications yearly, with email misdirection and cyber-attack the leading causes, and the Commissioner has publicly criticized under-reporting relative to Australia. Assess serious harm quickly, notify via NotifyUs, and document non-notified assessments, the offence attaches to failing to notify the Commissioner.
For trans-Tasman and global operators, note the asymmetries with Australia: no turnover-scaled penalties, no small-business exemption, and an accountability model (IPP 12) closer to Australia’s APP 8 than to GDPR adequacy gating. The NDB comparison is useful when building one incident playbook for both countries. Check what your NZ-facing surfaces collect with a free scan.