{
 "jurisdiction_id": "NZ",
 "jurisdiction": "New Zealand",
 "url": "https://dataprotection.gi/jurisdictions/new-zealand/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 39,
  "sub_modules": 57,
  "source_register": 23
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.",
   "claims": [
    {
     "statement": "The Privacy Act established the Office of the Privacy Commissioner of New Zealand (OPC), which acts as the data protection authority and is referred to as 'the Commissioner' within the Privacy Act and the Privacy Act 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 1 December 2020, the OPC announced the entry into effect of the Privacy Act 2020, which repeals and replaces the 27-year-old Privacy Act 1993.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-privacy-act-2020-enters-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New Zealand's Privacy Amendment Act 2025 was signed into law and officially enacted after receiving Royal Assent on 23 September 2025, introducing new Information Privacy Principle 3A requiring notification when personal information is collected indirectly.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nz-privacy-amendment-act-broadens-privacy-notification-obligation-to-meet-global-practice",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, neither the Privacy Act 1993 nor the Privacy Act 2020 provide for special categories of data or clearly define what types of data processing fall under their scope.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act 2020 has expanded extraterritorial scope, encompassing overseas businesses or organisations that 'carry on business' in New Zealand even if they do not have a physical presence in the country.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-privacy-act-2020-enters-effect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core structural gaps versus GDPR analogues (no enumerated lawful bases, no statutory special categories, no anonymisation safe-harbour) justify amber despite functioning principle-based alternative.",
   "claims": [
    {
     "statement": "Personal information must not be collected unless the collection is for a lawful purpose connected with the functions or activities of the agency and is necessary for that purpose (IPP 1).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-zealand-privacy-act-2020-part-two-practical",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Neither the Privacy Act nor the Privacy Act 2020 establish consent as a main principle like the GDPR, nor do they address matters such as rights to erasure, object, data portability, sensitive data, or DPIAs in the same manner.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Neither the Privacy Act 2020 nor the Privacy Act 1993 define special categories of data, unlike the GDPR's treatment of sensitive data such as racial/ethnic origin, health, or biometric data for unique identification.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Access/correction/response-window mechanics are robust and enforceable, but erasure, restriction/objection, and portability rights are largely absent, warranting amber overall.",
   "claims": [
    {
     "statement": "Under the Act, if an agency refuses to make personal information available upon request, the OPC has the power to demand the release of this information through a binding access determination.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-zealand-new-privacy-act-step-towards-gold-standard-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act does not currently provide any specific right to delete personal information, and many submitters to the OPC's children's privacy consultation argued in favor of a 'right to be forgotten' for children.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-a-look-at-new-zealands-opc-childrens-privacy-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Human Rights Review Tribunal considered whether an agency's extension of the 20-working-day timeframe for responding to an information request under s41 of the Act had been made reasonably.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-tribunal-issues-judgment-real-estate-agents",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification and security-of-processing duties are in force and actively enforced, but DPIA, ROPA, and processor-liability gaps (flagged by the regulator itself following the 2025/2026 MMH breach) justify amber rather than green.",
   "claims": [
    {
     "statement": "Neither the Privacy Act nor the Privacy Act 2020 provide for data protection or privacy impact assessments; the OPC has recommended such assessments only in non-binding guidance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Privacy Act 2020 allows agencies to appoint privacy officers from outside the agency, unlike the 1993 law which required appointment 'from within that agency'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/contracting-out-privacy-officers-in-new-nz-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC's Phase 1 inquiry into the Manage My Health breach recommended amending the Privacy Act 2020 to make third-party service providers directly liable for failing to implement reasonable security safeguards, noting the Act currently imposes no equivalent direct processor obligations found in overseas jurisdictions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-breach-could-spark-shift-in-new-zealand-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC found that both Manage My Health and Health New Zealand breached Rule 5 of the Health Information Privacy Code by failing to maintain reasonable security safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-opc-finds-mmh-and-health-nz-breach-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Part 6 of the Privacy Act 2020 establishes a legal obligation to notify the OPC of 'notifiable privacy breaches,' as well as affected individuals or the public under certain circumstances, with further procedures set out in Section 12 of the Privacy Regulations 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/new-zealand-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Agencies must notify the OPC and any affected individuals if there is a breach that has caused, or poses a risk of causing, serious harm, as soon as practicable after becoming aware of a notifiable breach, subject to limited exceptions (e.g. endangering safety or revealing a trade secret).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-zealand-new-privacy-act-step-towards-gold-standard-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Principle 9 provides that an agency holding personal information shall not keep it for longer than is required for the purposes for which the information may lawfully be used.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-new-zealands-privacy-act-1993",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Confirmed, currently-maintained EU adequacy plus an operative IPP12 transfer mechanism support green, tempered by gaps in TIA/localisation coverage.",
   "claims": [
    {
     "statement": "The New Privacy Act outlines that an agency will be permitted to disclose personal information overseas if it believes on reasonable grounds that the recipient or entity is subject to privacy laws that, overall, provide comparable safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-zealand-new-privacy-act-step-towards-gold-standard-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission determined that New Zealand ensures an adequate level of protection for personal data transferred from the EU, per the adequacy decision adopted in 2012.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32013D0065",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission's January 2024 review confirmed that personal data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards, following legislative reforms including the Privacy Act 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52024DC0007",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Office of the Privacy Commissioner New Zealand has published model clauses that assist entities in meeting their overseas-disclosure obligations under IPP12.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Strong evidence for the health-sector code; other sectoral overlays (credit, telecoms, education, insurance, financial) are asserted by general NZ privacy-law knowledge but not independently confirmed this run, requiring escalation.",
   "claims": [
    {
     "statement": "The OPC's inquiry into the Manage My Health breach was conducted under Section 17(1)(i) of the Privacy Act and focused on whether MMH and Health New Zealand had adequate security safeguards as required by Rule 5 of the Health Information Privacy Code.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-opc-finds-mmh-and-health-nz-breach-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "If agencies are collecting personal information about their employees, employment agreements and policies should make clear what personal information may be collected and used, and employee agreement to that collection should be obtained.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-zealand-privacy-act-2020-part-two-practical",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No adtech-specific commercial-privacy regime was substantiated in this pass; this is an explicit, evidenced gap rather than silent omission.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "A dedicated, binding Biometric Processing Privacy Code is a significant, verified development, but ADM transparency, profiling restrictions, and genetic-data regimes remain unaddressed gaps acknowledged by the regulator itself.",
   "claims": [
    {
     "statement": "Privacy Commissioner Michael Webster believes a financial penalty regime, more accountability obligations, and clearer rules around automated decision-making would enable a better regulatory response to the risks created by AI.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-new-zealand-privacy-act-needs-to-meet-best-practice",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC's AI guidance expects organisations to conduct a preliminary assessment of necessity and proportionality, obtain senior leadership approval of AI tool use based on full consideration of risks and mitigation, conduct PIAs, be transparent about AI use, and ensure human review before acting on AI outputs.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/how-privacy-and-data-protection-laws-apply-to-ai-guidance-from-global-dpas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC issued the Biometric Processing Privacy Code on 6 August 2025, regulating how organizations in New Zealand use biometric technologies to collect and process biometric information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-opc-s-biometric-processing-code-is-a-major-step",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Biometric Processing Privacy Code excludes biometric processing of health information by health agencies, which are already subject to the Health Information Privacy Code, and does not apply to consumer devices such as fitness trackers or smartwatches.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-opc-s-biometric-processing-code-is-a-major-step",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The New Zealand Police released findings from an independent expert review of Facial Recognition Technology, providing detailed advice on the opportunities and risks associated with its use.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Absence of parental consent mechanisms, profiling bans, and dependent-adult protections, combined with the regulator's own acknowledgement that reform is still under consideration, supports a red rating for this module.",
   "claims": [
    {
     "statement": "Section 49(1)(c) of the Privacy Act permits an organization to withhold personal information if the requester is under age 16 and providing the information would be contrary to their interests; the Privacy Amendment Act 2025 extends this to allow refusal if releasing the information would be contrary to the interests of another person under age 16.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nz-privacy-amendment-act-broadens-privacy-notification-obligation-to-meet-global-practice",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/new-zealand/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, escalating enforcement and a functioning (if narrow) redress pathway exist, but the acknowledged absence of a civil-penalties regime for principal IPP breaches is a material, regulator-acknowledged weakness.",
   "claims": [
    {
     "statement": "Under the current framework, financial penalties of up to NZD10,000 are available only in relation to a small number of offences, including a failure to notify the privacy commissioner of a serious privacy breach, with no financial penalties at all for breaching the information privacy principles themselves.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Human Rights Review Tribunal can award damages of up to NZD350,000 to an aggrieved individual, though this requires referral from the privacy commissioner or a decision by the commissioner not to investigate further, and damages are not punitive, requiring proof of harm.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Human Rights Review Tribunal awarded NZD50,000 in damages against the Accident Compensation Corporation for breaching information privacy principles 5 and 6 of the Privacy Act 1993 by destroying a file before the purpose for which it was collected had been fulfilled.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-opcnz-releases-statement-hrrt-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC's 2024-25 Annual Report noted a 43% increase in the number of serious privacy breaches notified to the regulator.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC issued a compliance notice to the Reserve Bank of New Zealand, triggered by a cyber-attack in December 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Amendments to the Privacy Bill on 3 June 2020 clarified matters such as liabilities and the potential for class action alongside enforcement powers and cross-border transfer mechanisms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_nz_privacy_acts.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Individuals have six months to file a claim in the Human Rights Review Tribunal starting from when an OPC investigator issues a Section 98 notice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-opc-issues-guide-filing-claim-human-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The OPC's May 2025/2026 Phase 1 inquiry report into the Manage My Health breach recommended compliance notices, a centralized supplier-verification program, and Privacy Act amendments to establish third-party service-provider liability.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-zealand-opc-finds-mmh-and-health-nz-breach-privacy",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the Manage My Health breach, New Zealand's Prime Minister publicly underscored the need to strengthen cybersecurity laws, and this was followed on 27 February by publication of NZ's Cyber Security Strategy 2026-2030 and associated Cyber Security Action Plan 2026-2027.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}