AntCrow
(Guides · New Zealand)

The Privacy Act 2020 and your website

If your website collects a name, an email address, or an IP address, the Privacy Act 2020 applies to you. Most New Zealand business sites are quietly non-compliant in the same three ways, and all three are straightforward to fix.

Reviewed by AntCrowLast reviewed 10 min read

The Privacy Act 2020 came into force on 1 December 2020, replacing the 1993 Act. It applies to almost every New Zealand business and organisation regardless of size, with no small-business exemption. If your website has a contact form, a newsletter signup, an analytics script, or a chat widget, you are collecting personal information and the Act applies.

There are fourteen principles now, and most guides still say thirteen

The Act is built around Information Privacy Principles governing how personal information is collected, stored, used, and disclosed. Nearly every guide online says there are thirteen. As of 1 May 2026 there are fourteen: the Privacy Amendment Act 2025 inserted a new principle, IPP 3A, which requires you to notify people when you collect their personal information indirectly rather than from them directly. That covers purchased lists, data enrichment services, lead generation partners, and CRM appends. It is not retrospective, but it applies to indirect collection from that date onward, and it is the obligation most likely to catch a business that buys marketing data.

Four principles do most of the work on a typical business website. Principle 3 requires you to tell people you are collecting their information, why, and who will get it. Principle 5 requires reasonable security safeguards. Principle 11 limits who you can disclose information to. Principle 12 governs sending personal information outside New Zealand, which is where most sites assume they are exposed and often are not, for reasons covered below.

The three things most New Zealand business sites get wrong

  1. No privacy statement, or one that does not describe what actually happens. A privacy policy copied from a template and never matched to the site's real tools does not satisfy Principle 3. It has to describe what you genuinely collect and where it genuinely goes.
  2. Silence about offshore transfer. Principle 12 places conditions on sending personal information overseas. Most sites use offshore analytics, form services, email platforms, and hosting without ever mentioning it. The fix is disclosure and appropriate safeguards, not necessarily changing providers.
  3. No plan for a breach. Since December 2020, notification of privacy breaches that are likely to cause serious harm has been mandatory, to both the Privacy Commissioner and the affected people, as soon as practicable. Most small businesses have never considered what they would do, and the time to work it out is not during an incident.

What a compliant privacy statement actually contains

Principle 3 requires that people know certain things at the point their information is collected. In practice that means a privacy statement, linked from every page and referenced near any form, which states in plain language what you collect, why you collect it, who else receives it, whether it goes overseas and where, how long you keep it, and how someone can access or correct what you hold about them. The right of access and correction under Principles 6 and 7 is not optional and is the part most templates omit entirely. Write it in language a customer can read, not in the legal boilerplate that makes people scroll past.

  • What personal information the site collects, including through forms, analytics, and any chat or booking tool.
  • Why it is collected and what it will be used for.
  • Who else receives it, including named third-party services.
  • Whether it is stored or processed outside New Zealand, and in which countries.
  • How long it is retained, and what happens to it afterwards.
  • How a person can request access to their information or ask for a correction.
  • How to make a complaint, including that a complaint can be made to the Office of the Privacy Commissioner.
  • A contact point for privacy enquiries, and the date the statement was last updated.

Cookies and analytics in New Zealand

New Zealand has no direct equivalent of the European cookie consent rules, which is why you see fewer consent banners on New Zealand sites than on European ones. That does not make analytics exempt from the Act. Where cookies or analytics collect information that can identify a person, including in some circumstances an IP address, the Information Privacy Principles apply, so collection should be disclosed and the data handled accordingly. If your site serves European or United Kingdom visitors, the GDPR and UK GDPR may apply to those visitors independently of New Zealand law, and that is a genuinely different and stricter regime worth taking advice on.

Offshore hosting is usually not the problem people think it is

Principle 12 restricts disclosing personal information to a foreign person or entity, and it is routinely misread as meaning you cannot use overseas hosting or analytics. Section 11 of the Act treats information held by an agent acting solely on your behalf, which is what a hosting provider, content delivery network, or processor is, as still being held by you. On that basis it is not a disclosure, and Principle 12 is not engaged. The Privacy Commissioner's own guidance indicates you generally do not need a Principle 12 agreement with a cloud provider. Where Principle 12 genuinely bites is when the overseas party uses the data for its own purposes, which describes advertising platforms and some analytics products rather than your web host. That distinction is worth understanding before anyone sells you a migration you do not need.

Two things follow from this. First, you remain fully accountable for what your provider does with the data, so due diligence and disclosure still matter. Second, New Zealand holds a European Commission adequacy decision, reconfirmed in January 2024, which means personal data can flow from the European Economic Area to New Zealand without additional contractual machinery. That is a genuine commercial advantage for New Zealand businesses serving European customers, and almost nobody uses it in their sales conversations.

Marketing email is governed by a different law entirely

This surprises people, and the penalties are far higher than the Privacy Act's. Sending marketing email in New Zealand is governed not by the Privacy Act but by the Unsolicited Electronic Messages Act 2007, administered by the Department of Internal Affairs. It requires consent, accurate sender identification, and a functional unsubscribe facility in every message. Two details catch people out. A single message can be spam under this Act, since there is no bulk-sending threshold. And the Department of Internal Affairs states penalties can reach $500,000, with real enforcement action taken against New Zealand businesses. A pre-ticked newsletter checkbox, or a form that quietly enrols anyone who makes an enquiry, is the common failure.

A practical compliance checklist

  1. List every tool on your site that touches personal information: forms, analytics, chat, booking, email marketing, CRM, hosting.
  2. For each one, record what it collects and which country it stores data in.
  3. Write or rewrite your privacy statement so it describes that reality accurately.
  4. Link the privacy statement from every page, and reference it beside every form.
  5. Make sure marketing consent is express, unticked by default, and recorded.
  6. Confirm every marketing email carries accurate sender details and a working unsubscribe.
  7. Secure what you hold: HTTPS everywhere, access limited to people who need it, and no personal data sitting in shared inboxes or spreadsheets indefinitely.
  8. Set a retention period and actually delete data when it expires.
  9. Write a one-page breach response plan naming who decides, who notifies, and how quickly.
  10. Review the whole thing annually, and whenever you add a new tool to the site.

Common questions

  • If it collects personal information, which includes a contact form, a newsletter signup, or analytics that can identify visitors, then yes in practical terms. The Privacy Act 2020 applies to organisations of every size with no small-business exemption, and Principle 3 requires that people be told what is collected, why, and who receives it. A privacy statement is the standard way of meeting that obligation.

Sources

Every factual claim on this page traces to one of the following. If you find something here that is out of date, we would genuinely like to know.

  1. Privacy Act 2020. New Zealand Legislation.
  2. The 13 Information Privacy Principles. Office of the Privacy Commissioner.
  3. Privacy breaches and NotifyUs. Office of the Privacy Commissioner.
  4. Unsolicited Electronic Messages Act 2007. New Zealand Legislation.
  5. New Zealand spam law for businesses. Department of Internal Affairs.
  6. Privacy Amendment Act 2025, introducing IPP 3A. New Zealand Legislation, In force 1 May 2026.
  7. Disclosing personal information outside New Zealand. Office of the Privacy Commissioner.

Want this handled rather than explained?

AntCrow builds websites with all of the above built in. Tell us what you are trying to achieve and we will tell you honestly what is worth doing.

Start a project