By country

Privacy Policy Generator New Zealand

The Privacy Act 2020, thirteen information privacy principles, IPP12 on offshore transfers, and the Consumer Guarantees Act.

Generate your privacy policy Read the privacy policy guide

A New Zealand privacy statement is structured around the thirteen information privacy principles rather than around lawful bases, and the clause that most often needs work is IPP12: the specific position on every overseas recipient your data reaches.

New Zealand’s Privacy Act 2020 replaced the 1993 Act and introduced mandatory notification of privacy breaches, compliance notices, and IPP12 - a cross-border disclosure rule requiring you to be satisfied the overseas recipient will protect the information to a comparable standard.

The Act applies to every agency handling personal information, with no turnover threshold. That is a meaningful difference from Australia, where businesses under AUD 3 million are largely outside the regime.

On the consumer side, the Consumer Guarantees Act and Fair Trading Act give statutory rights that cannot be contracted out of in consumer transactions, and misrepresenting them is itself a breach the Commerce Commission enforces.

What a privacy policy in New Zealand has to cover

How New Zealand actually moves personal data

Offshore hosting and SaaS

Most New Zealand businesses use Australian or US infrastructure, which is a cross-border disclosure engaging IPP12 rather than an ordinary sub-processing arrangement.

Customer records and access requests

IPP6 gives individuals a right of access with a twenty-working-day response requirement.

Marketing lists

Governed by the Unsolicited Electronic Messages Act separately from the Privacy Act.

Employee information

Covered by the same principles, with additional obligations where the information is used in employment decisions.

Breach assessment

The serious-harm test drives whether a breach is notifiable, and the assessment has to happen quickly enough to notify as soon as practicable.

Third parties the draft will ask you about

Stripe · Xero · NZ Post · AWS ap-southeast-2 · Vend or Shopify · Mailchimp

The rules that apply

Privacy Act 2020 and the 13 IPPs

Collection, use, disclosure, storage, access and correction principles, applying to every agency regardless of size.

IPP12 cross-border disclosure

Before sending personal information overseas you must be satisfied the recipient is subject to comparable safeguards, or rely on a listed exception.

Notifiable privacy breaches

Breaches causing or likely to cause serious harm must be notified to the Privacy Commissioner and affected individuals as soon as practicable.

Consumer Guarantees Act

Non-excludable guarantees on goods and services in consumer transactions.

Unsolicited Electronic Messages Act

Consent, identification and unsubscribe requirements for commercial electronic messages.

What the generated privacy policy contains

New Zealand compliance essentials

  1. Document your IPP12 position per offshore recipient

    What safeguards apply, and which exception you rely on if none do.

  2. Publish a privacy statement covering all thirteen principles

    Including collection purpose, access and correction, and complaints.

  3. Build the twenty-working-day access workflow

    With identity verification and a record of each request.

  4. Write the breach assessment runbook

    Applying the serious-harm test and the notification route to the Privacy Commissioner.

  5. State consumer guarantees before your own terms

    And never describe them as excluded.

Where this usually goes wrong

Treating offshore hosting as ordinary processing

IPP12 requires you to be satisfied about the recipient’s protections before disclosing, and to be able to explain why.

Assuming a small-business exemption

There is none. The Privacy Act applies to every agency.

Missing the twenty-working-day access deadline

It is a statutory timeframe with a complaint route attached.

Contracting out of consumer guarantees

Void in consumer transactions and independently actionable as a misrepresentation.

No breach assessment process

The serious-harm test cannot be applied retrospectively at leisure - notification is required as soon as practicable.

Frequently asked questions

Does the Privacy Act apply to small businesses in New Zealand?

Yes. Unlike Australia, there is no turnover threshold - the Act applies to every agency that handles personal information.

Can I use overseas cloud services?

Yes, but IPP12 requires you to be satisfied the recipient is subject to comparable safeguards before disclosing, or to rely on a listed exception such as the individual’s informed authorisation.

How quickly must I answer an access request?

As soon as reasonably practicable and no later than twenty working days after receiving it.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator New Zealand

Answer a short questionnaire and get a draft written for New Zealand. Free to start, no card required.

Generate your privacy policy

Other documents for New Zealand

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.