#
Comprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.
Sub-modules (5)
Regulator And AuthorityGreen
The OPC, led by Privacy Commissioner Michael Webster, is the statutory data protection authority referred to as 'the Commissioner' under the Act.
Claims: CLM-NZ-1a2b3c4d
Act And InstrumentsGreen
Primary instruments are the Privacy Act 2020, Privacy Regulations 2020, and the Privacy Amendment Act 2025; the OPC also issues binding codes of practice with the force of law.
Claims: CLM-NZ-2b3c4d5e, CLM-NZ-3c4d5e6f
Material ScopeAmber
The Act protects 'personal information' held by public and private sector 'agencies'; unlike the GDPR it does not define special categories of data or clearly delineate types of processing caught.
Claims: CLM-NZ-4d5e6f7a
Territorial ScopeGreen
The 2020 Act expanded territorial scope to overseas businesses/organisations 'carrying on business' in New Zealand even absent physical presence.
Claims: CLM-NZ-5e6f7a8b
Regulator Registration And FilingAmber
No general registration or filing regime for controllers/agencies was identified; the Act relies on principles-based compliance rather than registration.
Absence provenance: not recorded. Searched: New Zealand Privacy Act controller registration requirement, OPC registration filing obligation.
Sources and claims (5)
- ConfirmedDataGuidance — The Privacy Act established the Office of the Privacy Commissioner of New Zealand (OPC), which acts as the data protection authority and is referred to as 'the Commissioner' within the Privacy Act and the Privacy Act 2020.
- ConfirmedDataGuidance — On 1 December 2020, the OPC announced the entry into effect of the Privacy Act 2020, which repeals and replaces the 27-year-old Privacy Act 1993.
- ProbableIAPP — New Zealand's Privacy Amendment Act 2025 was signed into law and officially enacted after receiving Royal Assent on 23 September 2025, introducing new Information Privacy Principle 3A requiring notification when personal information is collected indirectly.
- ConfirmedDataGuidance — Unlike the GDPR, neither the Privacy Act 1993 nor the Privacy Act 2020 provide for special categories of data or clearly define what types of data processing fall under their scope.
- ConfirmedDataGuidance — The Privacy Act 2020 has expanded extraterritorial scope, encompassing overseas businesses or organisations that 'carry on business' in New Zealand even if they do not have a physical presence in the country.