🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
NZ · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 23 sources retrieved model claude-sonnet-5 ·

New Zealand

NZ schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 39 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
39Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.

Primary frameworkPrivacy Act 2020 (NZ)
Traffic-light rationale — GreenComprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.

Sub-modules (5)

Regulator And AuthorityGreen

The OPC, led by Privacy Commissioner Michael Webster, is the statutory data protection authority referred to as 'the Commissioner' under the Act.

Claims: CLM-NZ-1a2b3c4d

Act And InstrumentsGreen

Primary instruments are the Privacy Act 2020, Privacy Regulations 2020, and the Privacy Amendment Act 2025; the OPC also issues binding codes of practice with the force of law.

Claims: CLM-NZ-2b3c4d5e, CLM-NZ-3c4d5e6f

Material ScopeAmber

The Act protects 'personal information' held by public and private sector 'agencies'; unlike the GDPR it does not define special categories of data or clearly delineate types of processing caught.

Claims: CLM-NZ-4d5e6f7a

Territorial ScopeGreen

The 2020 Act expanded territorial scope to overseas businesses/organisations 'carrying on business' in New Zealand even absent physical presence.

Claims: CLM-NZ-5e6f7a8b

Regulator Registration And FilingAmber

No general registration or filing regime for controllers/agencies was identified; the Act relies on principles-based compliance rather than registration.

Absence provenance: not recorded. Searched: New Zealand Privacy Act controller registration requirement, OPC registration filing obligation.

Category narrative88 words

New Zealand's data-protection regime is anchored in the Privacy Act 2020, which repealed and replaced the Privacy Act 1993 and entered into force 1 December 2020, overseen by the Office of the Privacy Commissioner (OPC). The regime is principles-based (13 Information Privacy Principles), has extraterritorial reach for overseas agencies 'carrying on business' in NZ, and was amended in 2025 (Privacy Amendment Act 2025, Royal Assent 23 September 2025) to add IPP3A on indirect-collection notification. There is no general controller registration/filing obligation, consistent with the Act's light-touch, principles-based design.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Privacy Act established the Office of the Privacy Commissioner of New Zealand (OPC), which acts as the data protection authority and is referred to as 'the Commissioner' within the Privacy Act and the Privacy Act 2020.
  2. ConfirmedDataGuidanceOn 1 December 2020, the OPC announced the entry into effect of the Privacy Act 2020, which repeals and replaces the 27-year-old Privacy Act 1993.
  3. ProbableIAPPNew Zealand's Privacy Amendment Act 2025 was signed into law and officially enacted after receiving Royal Assent on 23 September 2025, introducing new Information Privacy Principle 3A requiring notification when personal information is collected indirectly.
  4. ConfirmedDataGuidanceUnlike the GDPR, neither the Privacy Act 1993 nor the Privacy Act 2020 provide for special categories of data or clearly define what types of data processing fall under their scope.
  5. ConfirmedDataGuidanceThe Privacy Act 2020 has expanded extraterritorial scope, encompassing overseas businesses or organisations that 'carry on business' in New Zealand even if they do not have a physical presence in the country.

#

Core structural gaps versus GDPR analogues (no enumerated lawful bases, no statutory special categories, no anonymisation safe-harbour) justify amber despite functioning principle-based alternative.

Primary frameworkPrivacy Act 2020 (NZ) - Information Privacy Principles
Traffic-light rationale — AmberCore structural gaps versus GDPR analogues (no enumerated lawful bases, no statutory special categories, no anonymisation safe-harbour) justify amber despite functioning principle-based alternative.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art 6-style lawful bases; IPP1 requires collection for a lawful purpose connected to the agency's functions and that collection be necessary for that purpose.

Claims: CLM-NZ-6f7a8b9c

Special CategoriesAmber

Neither Act defines special/sensitive categories of data; the OPC has issued non-binding guidance addressing sensitive personal information, and sector codes (health, biometric) provide de facto heightened protection for particular data types.

Claims: CLM-NZ-8b9c0d1e

Pseudonymisation And AnonymisationRed

No statutory definition or safe-harbour for pseudonymisation/anonymisation was located.

Absence provenance: not recorded. Searched: New Zealand Privacy Act pseudonymisation anonymisation definition.

Category narrative74 words

New Zealand's regime does not use a GDPR-style enumerated 'lawful basis' menu or treat consent as a central organising principle. Collection is instead governed by necessity/purpose principles (IPP1-IPP4). The Act does not define statutory special/sensitive categories of data, though the OPC has issued non-binding guidance on 'sensitive personal information' and sector-specific codes (Health Information Privacy Code, Biometric Processing Privacy Code) impose heightened rules for particular data classes. Pseudonymisation/anonymisation are not defined in the Act.

Sources and claims (3)
  1. ConfirmedDataGuidancePersonal information must not be collected unless the collection is for a lawful purpose connected with the functions or activities of the agency and is necessary for that purpose (IPP 1).
  2. ConfirmedDataGuidanceNeither the Privacy Act nor the Privacy Act 2020 establish consent as a main principle like the GDPR, nor do they address matters such as rights to erasure, object, data portability, sensitive data, or DPIAs in the same manner.
  3. ConfirmedDataGuidanceNeither the Privacy Act 2020 nor the Privacy Act 1993 define special categories of data, unlike the GDPR's treatment of sensitive data such as racial/ethnic origin, health, or biometric data for unique identification.

#

Access/correction/response-window mechanics are robust and enforceable, but erasure, restriction/objection, and portability rights are largely absent, warranting amber overall.

Primary frameworkPrivacy Act 2020 (NZ) - IPP 6, IPP 7
Traffic-light rationale — AmberAccess/correction/response-window mechanics are robust and enforceable, but erasure, restriction/objection, and portability rights are largely absent, warranting amber overall.

Sub-modules (5)

Access RightGreen

IPP6 grants individuals a right to confirm and access personal information held about them; OPC can issue binding access determinations where an agency refuses release.

Claims: CLM-NZ-9c0d1e2f

Rectification And ErasureAmber

IPP7 provides a correction right; there is no general statutory right to erasure/deletion, and OPC's children's privacy consultation records calls for a 'right to be forgotten' for children not yet enacted.

Claims: CLM-NZ-0d1e2f3a

Restriction And ObjectionRed

No GDPR Art 18/21-style formal restriction or objection right was located; use/disclosure limits (IPP10/IPP11) provide indirect, narrower protection.

Absence provenance: not recorded. Searched: New Zealand Privacy Act right to object right to restrict processing.

Data PortabilityRed

No data portability right equivalent to GDPR Art 20 was identified.

Absence provenance: not recorded. Searched: New Zealand Privacy Act data portability right.

Deadlines And Response WindowsGreen

Access requests must generally be responded to within 20 working days under s41, with extensions permissible where reasonable; the Human Rights Review Tribunal has reviewed the reasonableness of such extensions.

Claims: CLM-NZ-1e2f3a4b

Category narrative63 words

Individuals have an access right (IPP6) and correction right (IPP7), with a statutory 20-working-day response window (extendable on reasonable grounds) enforceable via OPC binding access determinations/enforceable access directions. The Act does not provide a standalone right to erasure ('right to be forgotten'), restriction, objection, or portability comparable to GDPR Arts 16-21, a gap the OPC's own children's-privacy consultation has flagged for possible reform.

Sources and claims (3)
  1. ConfirmedDataGuidanceUnder the Act, if an agency refuses to make personal information available upon request, the OPC has the power to demand the release of this information through a binding access determination.
  2. ProbableIAPPThe Privacy Act does not currently provide any specific right to delete personal information, and many submitters to the OPC's children's privacy consultation argued in favor of a 'right to be forgotten' for children.
  3. ConfirmedDataGuidanceThe Human Rights Review Tribunal considered whether an agency's extension of the 20-working-day timeframe for responding to an information request under s41 of the Act had been made reasonably.

#

Breach notification and security-of-processing duties are in force and actively enforced, but DPIA, ROPA, and processor-liability gaps (flagged by the regulator itself following the 2025/2026 MMH breach) justify amber rather than green.

Primary frameworkPrivacy Act 2020 (NZ), Part 6; Privacy Regulations 2020
Traffic-light rationale — AmberBreach notification and security-of-processing duties are in force and actively enforced, but DPIA, ROPA, and processor-liability gaps (flagged by the regulator itself following the 2025/2026 MMH breach) justify amber rather than green.

Sub-modules (7)

Accountability And DpiaAmber

Neither the Privacy Act 1993 nor the Privacy Act 2020 mandate data protection/privacy impact assessments; the OPC has only recommended such assessments in non-binding guidance.

Claims: CLM-NZ-2f3a4b5c

Dpo RequirementsGreen

Agencies must appoint one or more privacy officers, who may be located within or outside the agency (including contracted-out arrangements), unlike the 1993 Act's internal-only requirement.

Claims: CLM-NZ-3a4b5c6d

Ropa RequirementsRed

No explicit records-of-processing-activities obligation equivalent to GDPR Art 30 was identified.

Absence provenance: not recorded. Searched: New Zealand Privacy Act records of processing obligation.

Joint Controller ArrangementsAmber

Agencies remain responsible for protecting personal information handled by third-party service providers on their behalf (s11), but the OPC's MMH inquiry found the Act imposes no direct security obligation on the processor itself and recommended reform.

Claims: CLM-NZ-4b5c6d7e

Security MeasuresAmber

IPP5 requires agencies to take reasonable steps to protect personal information against loss or unauthorised access, use, modification or disclosure; the OPC's MMH inquiry found both MMH and Health NZ breached Rule 5 of the Health Information Privacy Code for failing to maintain reasonable security safeguards.

Claims: CLM-NZ-5c6d7e8f

Breach NotificationGreen

Part 6 of the Act requires notification to the OPC and affected individuals of 'notifiable privacy breaches' causing or likely to cause serious harm, with detailed procedures in s12 of the Privacy Regulations 2020; failure to notify is an offence.

Claims: CLM-NZ-6d7e8f9a, CLM-NZ-7e8f9a0b

Retention And DisposalGreen

IPP9 prohibits agencies from keeping personal information longer than required for the purposes for which it may lawfully be used.

Claims: CLM-NZ-8f9a0b1c

Category narrative111 words

Agencies must appoint one or more privacy officers (internal or external) and maintain reasonable security safeguards (IPP5) and retention limits (IPP9). Part 6 of the Act creates a mandatory notifiable-privacy-breach regime (OPC + affected individuals, for breaches causing or likely to cause serious harm), detailed further in the Privacy Regulations 2020. There is no mandatory DPIA requirement (only non-binding OPC guidance recommending PIAs), no explicit ROPA obligation, and no direct statutory security obligation on processors/third-party service providers equivalent to GDPR Art 28 — a gap highlighted by the OPC's own Manage My Health (MMH) breach inquiry, which recommended amending the Act to make third-party service providers directly liable for security failures.

Sources and claims (7)
  1. ConfirmedDataGuidanceNeither the Privacy Act nor the Privacy Act 2020 provide for data protection or privacy impact assessments; the OPC has recommended such assessments only in non-binding guidance.
  2. ConfirmedIAPPThe Privacy Act 2020 allows agencies to appoint privacy officers from outside the agency, unlike the 1993 law which required appointment 'from within that agency'.
  3. ProbableIAPPThe OPC's Phase 1 inquiry into the Manage My Health breach recommended amending the Privacy Act 2020 to make third-party service providers directly liable for failing to implement reasonable security safeguards, noting the Act currently imposes no equivalent direct processor obligations found in overseas jurisdictions.
  4. ConfirmedDataGuidanceThe OPC found that both Manage My Health and Health New Zealand breached Rule 5 of the Health Information Privacy Code by failing to maintain reasonable security safeguards.
  5. ConfirmedDataGuidancePart 6 of the Privacy Act 2020 establishes a legal obligation to notify the OPC of 'notifiable privacy breaches,' as well as affected individuals or the public under certain circumstances, with further procedures set out in Section 12 of the Privacy Regulations 2020.
  6. ConfirmedDataGuidanceAgencies must notify the OPC and any affected individuals if there is a breach that has caused, or poses a risk of causing, serious harm, as soon as practicable after becoming aware of a notifiable breach, subject to limited exceptions (e.g. endangering safety or revealing a trade secret).
  7. ConfirmedIAPPPrinciple 9 provides that an agency holding personal information shall not keep it for longer than is required for the purposes for which the information may lawfully be used.

#

Confirmed, currently-maintained EU adequacy plus an operative IPP12 transfer mechanism support green, tempered by gaps in TIA/localisation coverage.

Primary frameworkPrivacy Act 2020 (NZ) - IPP 12; EU Adequacy Decision 2013/65/EU
Traffic-light rationale — GreenConfirmed, currently-maintained EU adequacy plus an operative IPP12 transfer mechanism support green, tempered by gaps in TIA/localisation coverage.

Sub-modules (6)

Transfer MechanismsGreen

IPP12 permits overseas disclosure where the agency believes on reasonable grounds the recipient is subject to privacy laws that, overall, provide comparable safeguards, among other prescribed mechanisms.

Claims: CLM-NZ-9a0b1c2d

Adequacy ReceivedGreen

New Zealand is not itself an adequacy 'recipient' jurisdiction in the EU sense (it is the adequacy grantee/recipient of an EU finding); this sub-module is not applicable in the way it would be for an EU member state and is scoped instead to NZ's status as an EU adequacy partner (see adequacy_granted).

Absence provenance: not recorded. Searched: New Zealand adequacy decisions received from other regimes.

Adequacy GrantedGreen

The European Commission determined New Zealand ensures an adequate level of data protection under Directive 95/46/EC (Commission Decision, December 2012), and its January 2024 review confirmed data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards.

Claims: CLM-NZ-0b1c2d3e, CLM-NZ-1c2d3e4f

Sccs And BcrsGreen

The OPC has published model contract clauses to assist agencies in meeting IPP12 obligations for overseas disclosure, functioning as an SCC-equivalent mechanism.

Claims: CLM-NZ-2d3e4f5a

Transfer Impact AssessmentAmber

No formal Schrems II-style transfer impact assessment requirement was identified as part of IPP12 compliance.

Absence provenance: not recorded. Searched: New Zealand Privacy Act transfer impact assessment IPP12.

Data LocalisationGreen

No general data-localisation mandate was identified for New Zealand under the Privacy Act.

Absence provenance: not recorded. Searched: New Zealand data localisation requirement Privacy Act government cloud.

Category narrative73 words

IPP12 (introduced by the 2020 Act) governs overseas disclosure of personal information, permitting transfer where the receiving agency is subject to comparable safeguards, via individual authorisation, prescribed binding schemes, or OPC-published model contract clauses. New Zealand itself holds EU adequacy status, originally granted under Directive 95/46/EC in December 2012 and reaffirmed as continuing in the European Commission's January 2024 review of 11 adequacy decisions. No data-localisation mandate or formal transfer-impact-assessment requirement was identified.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe New Privacy Act outlines that an agency will be permitted to disclose personal information overseas if it believes on reasonable grounds that the recipient or entity is subject to privacy laws that, overall, provide comparable safeguards.
  2. ConfirmedEUR-LexThe European Commission determined that New Zealand ensures an adequate level of protection for personal data transferred from the EU, per the adequacy decision adopted in 2012.
  3. ConfirmedEUR-LexThe European Commission's January 2024 review confirmed that personal data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards, following legislative reforms including the Privacy Act 2020.
  4. ProbableDataGuidanceThe Office of the Privacy Commissioner New Zealand has published model clauses that assist entities in meeting their overseas-disclosure obligations under IPP12.

#

Strong evidence for the health-sector code; other sectoral overlays (credit, telecoms, education, insurance, financial) are asserted by general NZ privacy-law knowledge but not independently confirmed this run, requiring escalation.

Primary frameworkPrivacy Act 2020 (NZ) - Codes of Practice regime
Traffic-light rationale — AmberStrong evidence for the health-sector code; other sectoral overlays (credit, telecoms, education, insurance, financial) are asserted by general NZ privacy-law knowledge but not independently confirmed this run, requiring escalation.

Sub-modules (7)

Financial Sector OverlayAmber

No financial-sector-specific privacy code was confirmed in this research pass; general Privacy Act obligations apply to financial agencies alongside AML/CFT obligations administered by other regulators.

Absence provenance: not recorded. Searched: New Zealand financial sector privacy code overlay.

Health Sector OverlayAmber

The Health Information Privacy Code governs health agencies' handling of health information; its Rule 5 security requirement was found breached in the OPC's Manage My Health inquiry.

Claims: CLM-NZ-3e4f5a6b

Telecoms And EprivacyAmber

A Telecommunications Information Privacy Code is understood to exist under the OPC's code-making power but was not independently verified this pass.

Absence provenance: not recorded. Searched: New Zealand Telecommunications Information Privacy Code.

Employment DataAmber

Employment-related personal information (e.g., security camera footage, references) is governed by the general IPPs rather than a dedicated employment code; agencies are advised to reflect collection purposes in employment agreements.

Claims: CLM-NZ-4f5a6b7c

Credit And ScoringAmber

A Credit Reporting Privacy Code is understood to exist but was not independently verified in this research pass.

Absence provenance: not recorded. Searched: New Zealand Credit Reporting Privacy Code details.

EducationRed

No education-sector-specific privacy overlay was identified in this research pass.

Absence provenance: not recorded. Searched: New Zealand education sector privacy code.

InsuranceRed

No insurance-sector-specific privacy overlay was identified in this research pass.

Absence provenance: not recorded. Searched: New Zealand insurance sector privacy rules.

Category narrative92 words

Sector-specific overlays operate via OPC-issued binding codes of practice that adapt the IPPs to particular data classes or industries. The Health Information Privacy Code (HIPC) governs health-sector personal information (its Rule 5 security requirement was central to the 2025/2026 Manage My Health breach findings). A Credit Reporting Privacy Code and Telecommunications Information Privacy Code are understood to exist but were not independently verified in this research pass. Employment data is subject to the general IPPs without a dedicated employment code identified. Education and insurance sector-specific overlays were not identified in this pass.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe OPC's inquiry into the Manage My Health breach was conducted under Section 17(1)(i) of the Privacy Act and focused on whether MMH and Health New Zealand had adequate security safeguards as required by Rule 5 of the Health Information Privacy Code.
  2. ProbableDataGuidanceIf agencies are collecting personal information about their employees, employment agreements and policies should make clear what personal information may be collected and used, and employee agreement to that collection should be obtained.

#

No adtech-specific commercial-privacy regime was substantiated in this pass; this is an explicit, evidenced gap rather than silent omission.

Traffic-light rationale — RedNo adtech-specific commercial-privacy regime was substantiated in this pass; this is an explicit, evidenced gap rather than silent omission.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie-consent statute was identified; general IPPs would apply to any personal information collected via trackers.

Absence provenance: not recorded. Searched: New Zealand cookie consent law ePrivacy equivalent.

Dark PatternsRed

No NZ-specific dark-pattern prohibition was identified.

Absence provenance: not recorded. Searched: New Zealand dark patterns privacy law prohibition.

Opt Out SignalsRed

No recognised technical opt-out signal (e.g., Global Privacy Control) regime was identified for New Zealand.

Absence provenance: not recorded. Searched: New Zealand Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room specific rules were identified.

Absence provenance: not recorded. Searched: New Zealand clean room data collaboration privacy rules.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' concept or cross-context advertising rule was identified.

Absence provenance: not recorded. Searched: New Zealand cross-context advertising sale share rules.

Direct MarketingAmber

No dedicated direct-marketing consent/suppression regime was independently verified in this research pass beyond general IPP use/disclosure limits.

Absence provenance: not recorded. Searched: New Zealand direct marketing consent suppression rules Privacy Act.

Category narrative56 words

No NZ-specific cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal (e.g. GPC), clean-room framework, or CPRA-style 'sale/share' concept was identified; the general Privacy Act IPPs apply to any online collection of personal information but do not create adtech-specific rules. A dedicated direct-marketing/anti-spam statute may exist in New Zealand but was not verified in this research pass.

#

A dedicated, binding Biometric Processing Privacy Code is a significant, verified development, but ADM transparency, profiling restrictions, and genetic-data regimes remain unaddressed gaps acknowledged by the regulator itself.

Primary frameworkBiometric Processing Privacy Code 2025; Privacy Act 2020 IPPs (applied to AI via OPC guidance)
Traffic-light rationale — AmberA dedicated, binding Biometric Processing Privacy Code is a significant, verified development, but ADM transparency, profiling restrictions, and genetic-data regimes remain unaddressed gaps acknowledged by the regulator itself.

Sub-modules (6)

Profiling RestrictionsRed

No Art 22 GDPR-analogue profiling restriction was identified; general IPPs apply to any profiling activity involving personal information.

Absence provenance: not recorded. Searched: New Zealand Privacy Act profiling restriction Article 22 analogue.

Automated Decision Making TransparencyAmber

Commissioner Webster has stated he believes clearer rules around automated decision-making would enable a better regulatory response to AI risks, indicating this remains an identified gap rather than a codified right.

Claims: CLM-NZ-5a6b7c8d

Ai Risk AssessmentsAmber

The OPC's AI guidance expects organisations to conduct privacy impact assessments, obtain senior leadership approval based on full consideration of risks and mitigation, and ensure human review before acting on AI outputs, though this is guidance rather than a binding statutory AI risk-assessment obligation.

Claims: CLM-NZ-6b7c8d9e

Biometric RegimeGreen

The Biometric Processing Privacy Code, issued 6 August 2025, adapts the 13 IPPs specifically to biometric processing, covering the full information lifecycle and introducing necessity and proportionality assessments; it excludes biometric processing of health information (covered by the Health Information Privacy Code) and consumer devices such as fitness trackers.

Claims: CLM-NZ-7c8d9e0f, CLM-NZ-8d9e0f1a

Genetic DataRed

No dedicated genetic-data regime was identified for New Zealand.

Absence provenance: not recorded. Searched: New Zealand genetic data privacy regime.

State Surveillance CarveoutsAmber

New Zealand Police commissioned an independent expert review of facial recognition technology (FRT) use, providing advice on opportunities and risks; broader statutory state-surveillance carve-out detail was not fully verified this pass.

Claims: CLM-NZ-9e0f1a2b

Category narrative117 words

New Zealand has no standalone AI statute; the OPC has instead issued guidance (June and October 2023) applying the 13 IPPs to AI systems, recommending PIAs, senior-leadership approval, transparency, human review, and consideration of Te Ao Māori perspectives. Commissioner Michael Webster has publicly called for clearer automated-decision-making rules and a financial penalty regime to better govern AI risk. Biometric processing is now regulated via the OPC's binding Biometric Processing Privacy Code (issued 6 August 2025), which imposes necessity/proportionality assessments and notice obligations across the biometric information lifecycle, while excluding consumer devices and health-agency biometric processing (covered by the Health Information Privacy Code). No Art 22 GDPR-style profiling restriction, genetic-data regime, or codified state-surveillance carve-out framework was substantiated.

Sources and claims (5)
  1. ConfirmedIAPPPrivacy Commissioner Michael Webster believes a financial penalty regime, more accountability obligations, and clearer rules around automated decision-making would enable a better regulatory response to the risks created by AI.
  2. ConfirmedIAPPThe OPC's AI guidance expects organisations to conduct a preliminary assessment of necessity and proportionality, obtain senior leadership approval of AI tool use based on full consideration of risks and mitigation, conduct PIAs, be transparent about AI use, and ensure human review before acting on AI outputs.
  3. ConfirmedIAPPThe OPC issued the Biometric Processing Privacy Code on 6 August 2025, regulating how organizations in New Zealand use biometric technologies to collect and process biometric information.
  4. ConfirmedIAPPThe Biometric Processing Privacy Code excludes biometric processing of health information by health agencies, which are already subject to the Health Information Privacy Code, and does not apply to consumer devices such as fitness trackers or smartwatches.
  5. ProbableDataGuidanceThe New Zealand Police released findings from an independent expert review of Facial Recognition Technology, providing detailed advice on the opportunities and risks associated with its use.

#

Absence of parental consent mechanisms, profiling bans, and dependent-adult protections, combined with the regulator's own acknowledgement that reform is still under consideration, supports a red rating for this module.

Primary frameworkPrivacy Act 2020 (NZ) - s49(1)(c)
Traffic-light rationale — RedAbsence of parental consent mechanisms, profiling bans, and dependent-adult protections, combined with the regulator's own acknowledgement that reform is still under consideration, supports a red rating for this module.

Sub-modules (5)

Age VerificationRed

No formal age-verification regime was identified; age 16 functions only as a threshold for a narrow information-withholding ground, not a general consent-age mechanism.

Claims: CLM-NZ-0f1a2b3c

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: not recorded. Searched: New Zealand minor profiling ban privacy.

Education SettingsRed

No education-settings-specific children's data rule was identified in this research pass.

Absence provenance: not recorded. Searched: New Zealand education settings children's data privacy rule.

Dependent AdultsRed

No dependent-adults-specific privacy protection regime was identified in this research pass.

Absence provenance: not recorded. Searched: New Zealand dependent adults privacy protection elderly incapacitated.

Category narrative103 words

New Zealand's Privacy Act does not contain a GDPR Art 8/COPPA-style parental-consent regime or a general age-of-consent threshold for data processing. Age 16 is used only as a narrower ground allowing an agency to withhold information from (or about) a requester under that age where release would be contrary to their interests, a ground extended by the Privacy Amendment Act 2025. The OPC's children's privacy consultation has surfaced options — a 'best interests of the child' obligation and a child-specific right to be forgotten — that are under discussion but not yet enacted. No minor-profiling ban, education-settings-specific rule, or dependent-adults regime was substantiated.

Sources and claims (1)
  1. ConfirmedIAPPSection 49(1)(c) of the Privacy Act permits an organization to withhold personal information if the requester is under age 16 and providing the information would be contrary to their interests; the Privacy Amendment Act 2025 extends this to allow refusal if releasing the information would be contrary to the interests of another person under age 16.

#

Active, escalating enforcement and a functioning (if narrow) redress pathway exist, but the acknowledged absence of a civil-penalties regime for principal IPP breaches is a material, regulator-acknowledged weakness.

Primary frameworkPrivacy Act 2020 (NZ) - Parts 5-8
Traffic-light rationale — AmberActive, escalating enforcement and a functioning (if narrow) redress pathway exist, but the acknowledged absence of a civil-penalties regime for principal IPP breaches is a material, regulator-acknowledged weakness.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

OPC powers include compliance notices and enforceable access directions; criminal offence fines are capped at NZD10,000 and there is no general civil penalty for IPP breaches; HRRT damages awards (e.g., NZD50,000 in the ACC case) provide the main financial remedy.

Claims: CLM-NZ-1a2b3c4e, CLM-NZ-2b3c4d5f, CLM-NZ-3c4d5e6a

Enforcement Activity IndexAmber

The OPC's 2024-25 Annual Report noted a 43% increase in serious privacy breaches notified to the regulator, and the OPC issued a compliance notice to the Reserve Bank of New Zealand in 2021 following a cyber-attack.

Claims: CLM-NZ-4d5e6f7b, CLM-NZ-5e6f7a8c

Regulator Funding And CapacityAmber

No specific data on OPC funding levels or headcount was identified in this research pass.

Absence provenance: not recorded. Searched: Office of the Privacy Commissioner New Zealand funding budget headcount.

Collective Redress And Class ActionsAmber

2020 amendments to the Privacy Bill clarified the potential for class actions, and HRRT damages could accumulate substantially in a class-action context, though the process remains lengthy and requires OPC referral.

Claims: CLM-NZ-6f7a8b9d

Private Right Of ActionAmber

Individuals can file a claim in the HRRT within six months of an OPC Section 98 notice, or following a Commissioner decision not to investigate further, rather than through unrestricted direct court access.

Claims: CLM-NZ-7a8b9c0e

Recent Developments 180DAmber

Within the last 180 days, the OPC's Phase 1 Manage My Health inquiry recommended legislative amendment for third-party service-provider liability; New Zealand published its Cyber Security Strategy 2026-2030 (27 February 2026) and associated Action Plan 2026-2027; and public/political pressure (including a parliamentary petition) for a civil-penalties regime has intensified.

Claims: CLM-NZ-8b9c0d1f, CLM-NZ-9c0d1e2a

Category narrative182 words

The OPC can issue compliance notices and binding/enforceable access directions, and can investigate complaints, but criminal offences under the Act (e.g., failure to notify a serious breach, misleading an agency, destroying requested information) carry a maximum fine of only NZD10,000, and there is no general civil-penalties regime for breaches of the information privacy principles themselves. The Human Rights Review Tribunal (HRRT) can award damages (e.g., NZD50,000 against ACC in 2020; reported ceiling around NZD350,000), but access requires OPC referral or a decision not to investigate, and claims must be filed within six months of a Section 98 notice. Enforcement activity has intensified: the OPC's 2024-25 Annual Report recorded a 43% rise in notified serious breaches, and its 2025/2026 Phase 1 inquiry into the Manage My Health breach recommended compliance notices, a centralised health-sector supplier verification programme, and legislative amendments for third-party liability. The Commissioner and commentators are actively campaigning for a financial penalties regime, referencing Australia's AUD50 million maximum penalty as a comparator; NZ's Cyber Security Strategy 2026-2030 (published 27 February 2026) is cited as a first concrete sign of possible reform.

Sources and claims (9)
  1. ConfirmedIAPPUnder the current framework, financial penalties of up to NZD10,000 are available only in relation to a small number of offences, including a failure to notify the privacy commissioner of a serious privacy breach, with no financial penalties at all for breaching the information privacy principles themselves.
  2. ProbableIAPPThe Human Rights Review Tribunal can award damages of up to NZD350,000 to an aggrieved individual, though this requires referral from the privacy commissioner or a decision by the commissioner not to investigate further, and damages are not punitive, requiring proof of harm.
  3. ConfirmedDataGuidanceThe Human Rights Review Tribunal awarded NZD50,000 in damages against the Accident Compensation Corporation for breaching information privacy principles 5 and 6 of the Privacy Act 1993 by destroying a file before the purpose for which it was collected had been fulfilled.
  4. ConfirmedIAPPThe OPC's 2024-25 Annual Report noted a 43% increase in the number of serious privacy breaches notified to the regulator.
  5. ConfirmedDataGuidanceThe OPC issued a compliance notice to the Reserve Bank of New Zealand, triggered by a cyber-attack in December 2020.
  6. ConfirmedDataGuidanceAmendments to the Privacy Bill on 3 June 2020 clarified matters such as liabilities and the potential for class action alongside enforcement powers and cross-border transfer mechanisms.
  7. ConfirmedDataGuidanceIndividuals have six months to file a claim in the Human Rights Review Tribunal starting from when an OPC investigator issues a Section 98 notice.
  8. ProbableDataGuidanceThe OPC's May 2025/2026 Phase 1 inquiry report into the Manage My Health breach recommended compliance notices, a centralized supplier-verification program, and Privacy Act amendments to establish third-party service-provider liability.
  9. ProbableIAPPFollowing the Manage My Health breach, New Zealand's Prime Minister publicly underscored the need to strengthen cybersecurity laws, and this was followed on 27 February by publication of NZ's Cyber Security Strategy 2026-2030 and associated Cyber Security Action Plan 2026-2027.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for New Zealand
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 39 claim(s), 23 source(s) in the cumulative register.