Cookie Policy Generator New Zealand
The Privacy Act 2020, thirteen information privacy principles, IPP12 on offshore transfers, and the Consumer Guarantees Act.
New Zealand regulates cookies through the information privacy principles rather than a consent statute, which puts the emphasis on IPP3 notification - telling people what is collected and why at the point of collection - and on IPP12 for the offshore providers most trackers involve.
New Zealand’s Privacy Act 2020 replaced the 1993 Act and introduced mandatory notification of privacy breaches, compliance notices, and IPP12 - a cross-border disclosure rule requiring you to be satisfied the overseas recipient will protect the information to a comparable standard.
The Act applies to every agency handling personal information, with no turnover threshold. That is a meaningful difference from Australia, where businesses under AUD 3 million are largely outside the regime.
On the consumer side, the Consumer Guarantees Act and Fair Trading Act give statutory rights that cannot be contracted out of in consumer transactions, and misrepresenting them is itself a breach the Commerce Commission enforces.
What a cookie policy in New Zealand has to cover
Which cookies collect personal information under the Privacy Act 2020
IPP3 notification: what is collected, why, and who receives it
IPP12 analysis for offshore analytics and advertising providers
How a visitor turns tracking off, and the effect on the site
Where a stricter overseas standard applies because you also serve UK or EU visitors
How New Zealand actually moves personal data
Offshore hosting and SaaS
Most New Zealand businesses use Australian or US infrastructure, which is a cross-border disclosure engaging IPP12 rather than an ordinary sub-processing arrangement.
Customer records and access requests
IPP6 gives individuals a right of access with a twenty-working-day response requirement.
Marketing lists
Governed by the Unsolicited Electronic Messages Act separately from the Privacy Act.
Employee information
Covered by the same principles, with additional obligations where the information is used in employment decisions.
Breach assessment
The serious-harm test drives whether a breach is notifiable, and the assessment has to happen quickly enough to notify as soon as practicable.
Third parties the draft will ask you about
Stripe · Xero · NZ Post · AWS ap-southeast-2 · Vend or Shopify · Mailchimp
The rules that apply
Privacy Act 2020 and the 13 IPPs
Collection, use, disclosure, storage, access and correction principles, applying to every agency regardless of size.
IPP12 cross-border disclosure
Before sending personal information overseas you must be satisfied the recipient is subject to comparable safeguards, or rely on a listed exception.
Notifiable privacy breaches
Breaches causing or likely to cause serious harm must be notified to the Privacy Commissioner and affected individuals as soon as practicable.
Consumer Guarantees Act
Non-excludable guarantees on goods and services in consumer transactions.
Unsolicited Electronic Messages Act
Consent, identification and unsubscribe requirements for commercial electronic messages.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
New Zealand compliance essentials
Document your IPP12 position per offshore recipient
What safeguards apply, and which exception you rely on if none do.
Publish a privacy statement covering all thirteen principles
Including collection purpose, access and correction, and complaints.
Build the twenty-working-day access workflow
With identity verification and a record of each request.
Write the breach assessment runbook
Applying the serious-harm test and the notification route to the Privacy Commissioner.
State consumer guarantees before your own terms
And never describe them as excluded.
Where this usually goes wrong
Treating offshore hosting as ordinary processing
IPP12 requires you to be satisfied about the recipient’s protections before disclosing, and to be able to explain why.
Assuming a small-business exemption
There is none. The Privacy Act applies to every agency.
Missing the twenty-working-day access deadline
It is a statutory timeframe with a complaint route attached.
Contracting out of consumer guarantees
Void in consumer transactions and independently actionable as a misrepresentation.
No breach assessment process
The serious-harm test cannot be applied retrospectively at leisure - notification is required as soon as practicable.
Frequently asked questions
Does the Privacy Act apply to small businesses in New Zealand?
Yes. Unlike Australia, there is no turnover threshold - the Act applies to every agency that handles personal information.
Can I use overseas cloud services?
Yes, but IPP12 requires you to be satisfied the recipient is subject to comparable safeguards before disclosing, or to rely on a listed exception such as the individual’s informed authorisation.
How quickly must I answer an access request?
As soon as reasonably practicable and no later than twenty working days after receiving it.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator New Zealand
Answer a short questionnaire and get a draft written for New Zealand. Free to start, no card required.
Generate your cookie policyOther documents for New Zealand
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.