What we do

Compliance & privacy

The obligations you actually have, in plain English.

Most business owners we meet are carrying one of two beliefs: that privacy law doesn't apply to them, or that it applies in some vague and terrifying way they'd rather not look at. Usually the truth is narrower and more manageable than either. But you do have to know which one you are.

Privacy law, the regulator and the penalties are all different on each side of the Tasman. Pick yours.

Start here

Does the Privacy Act apply to you at all?

The Privacy Act applies to organisations with an annual turnover of more than $3 million. Under that, most businesses fall inside what's called the small business exemption and the Act largely doesn't reach them.

There's a big exception, and it catches people out constantly. Health service providers are covered regardless of turnover. A two-person physiotherapy practice turning over $180,000 has the same obligations as a hospital. So do allied health, dental, psychology, and a long tail of businesses that don't think of themselves as healthcare at all.

Two more things worth knowing if you think you're exempt. First, turnover moves — plenty of businesses cross $3 million without anyone noticing the compliance consequence. Second, the exemption is expected to go. More on that further down.

Start here

In New Zealand it applies to you. There is no size test.

The Privacy Act 2020 came into force on 01/12/2020, replacing the Privacy Act 1993. It reaches every agency that handles personal information, and the Privacy Commissioner's own list of covered agencies names small businesses and sole traders outright. No turnover threshold. No headcount threshold. No carve-out to go looking for.

Which means a two-person business has the same privacy obligations as a bank. Fewer records and fewer staff, identical rules. That catches out anyone who has read Australian guidance and assumed it travels.

The numbering is different too, and it matters. If someone has told you your security obligation is "APP 11", that is the Australian principle. In New Zealand it is IPP 5 — storage and security, and for health information it is Rule 5 of the Health Information Privacy Code. Rule 5 is the one the Commissioner has actually been enforcing.

What the data says

Breach notifications are at their highest since the scheme started.

The Notifiable Data Breaches scheme has been mandatory since 22 February 2018. If a breach is likely to result in serious harm you have to assess it, tell the affected individuals and notify the OAIC. Here's the current picture.

1,205

Breach notifications in 2025, up 8% on 1,112 in 2024

716

Of those, caused by malicious or criminal attack

225

Health services, the top reporting sector at 19%

87%

Of Australians are more concerned about privacy than five years ago

Who's reporting

After health services on 225, finance reported 157 and the Australian Government 118. If you're a healthcare business reading this and thinking you're too small to be a target — you're in the sector that reports more breaches than any other in the country.

What your customers think

From the OAIC's Australian Community Attitudes to Privacy Survey, released 28/05/2026: complaints to the OAIC rose 73% this financial year, only 4% of Australians think AI companies are trustworthy with personal information, and 68% said they'd use more digital services if they were confident their data was handled fairly. That last figure is the commercial argument, not the legal one.

What the data says

Breach notifications to the Privacy Commissioner rose 27% in a year.

Where a breach has caused, or is likely to cause, serious harm you notify two parties: the Privacy Commissioner through NotifyUs, and the people affected. These are the most recent published figures, for the year to 30/06/2025.

1,093

Privacy breach notifications received in the year to 30/06/2025

27%

Up on the year before — the trend is the same as Australia's

1,598

Complaints received, up 21% on the prior year

$13,000

Average negotiated settlement, paid to 6.5% of accepted complainants

How fast you have to move

The statutory framing is "as soon as you are practically able". The guidance on the NotifyUs page is firmer: ideally within 72 hours of realising you have a notifiable breach, even if you are still investigating. You can report what happened without sending the Commissioner any personal information. If you suspect someone is in immediate danger, Police on 111 come first, before the regulator.

What the settlement figure actually tells you

Complaint processing can take up to twelve months. So the realistic cost of getting this wrong in New Zealand is a year of your attention, a public finding, and a settlement in the low tens of thousands — not a headline fine. That is a manageable number and a miserable year. Most people who have been through one say the year was the expensive part.

Source: Office of the Privacy Commissioner Annual Report 2025, covering 01/07/2024 to 30/06/2025.

Enforcement

This stopped being theoretical in 2026.

For years the honest answer to "what actually happens if we get this wrong?" was "probably nothing". That answer has aged badly. A sample from the past few months:

Date What happened Why it matters to you
11/06/2026 The Commissioner found against Optus in the White Pages breach. Size is no defence. Neither is the fact that the data was already semi-public.
15/06/2026 American Express Australia was ordered to compensate a complainant. An individual complaint, not a mass breach, ended in a payment.
24/06/2026 The Commissioner found privacy breaches by Medmate Australia and Monash IVF over third-party tracking pixels on health websites. Your marketing tag manager is now a privacy control. Most businesses have never looked at what their pixels collect.
16/07/2026 Preliminary inquiries into the Qantas 2025 data incident were completed. The regulator is following through on large incidents rather than letting them fade.

We're describing public regulatory outcomes, not giving you a legal reading of them. If any of these look uncomfortably like your business, the next call is to a privacy lawyer, and we'll say that plainly.

Enforcement

Compliance notices, not ruinous fines. Plan for the right risk.

We are not going to tell you New Zealand hands out Australian-sized penalties, because it doesn't, and you would know. The confirmed exposure is a fine of up to $10,000 where an agency defies an enforceable Tribunal access order, sitting alongside compliance notices and access directions from the Commissioner. What you are really managing is regulatory attention and a public finding with your name on it.

Date What happened Why it matters to you
27/05/2026 Phase 1 findings in the Manage My Health inquiry: both Manage My Health and Health NZ breached Rule 5 of the Health Information Privacy Code. The Commissioner intends to issue compliance notices to both. Nearly 100,000 people affected. The finding was about storage and security, not about consent forms.
29/06/2026 A variation to the Oranga Tamariki compliance notice extended the timeframes on two outstanding actions. Compliance notices are live, tracked instruments. They don't close when the media release does.
27/03/2026 Compliance assurance reports released for the three national credit reporting companies. The Commissioner does sector-wide assurance work, not just incident response.
11/03/2026 New privacy guidance issued for the education sector. He works sector by sector. Health and education have both had their turn.

Public regulatory outcomes, described rather than interpreted. The Manage My Health findings are Phase 1 only — a later phase may still be running, so treat 27/05/2026 as where that story had got to, not where it ends.

What's changing

Two things worth having on your radar, and one that probably isn't yours.

01

Ransomware payments are now reportable

The Cyber Security Act 2024 (Act No. 98, 2024, assent 29/11/2024) introduced ransomware payment reporting in Part 3. The short version: paying a ransom is now a reportable event, not a private commercial decision.

There's also a limited use obligation in sections 29 and 30 that restricts how a report can be used against you — the point being to make organisations more willing to tell someone. Worth understanding before you're at 2am on a Saturday making the decision.

02

The small business exemption is expected to go

The second tranche of Privacy Act reform has been flagged for years: removing the small business exemption, removing the employee records exemption, adding a "fair and reasonable" test for how you handle data, and creating a statutory tort for serious invasions of privacy.

The direction of travel is well established. The timing is not. We're not going to give you a date, because nobody has confirmed one, and anyone quoting you a deadline is guessing. Treat it as expected, not scheduled.

03

SOCI, and why it's probably not about you

The Security of Critical Infrastructure Act gets mentioned a lot in sales meetings. Most small and medium businesses are not directly regulated under it. Where it reaches you is through the supply chain: if you service a client who is captured, their obligations flow down to you as contract clauses and security questionnaires. That's a commercial requirement to answer well, not a law you're breaching.

What's changing

Two things that arrived in 2026, and one that probably isn't yours.

01

A fourteenth principle landed on 01/05/2026

IPP 3A, brought in by the Privacy Amendment Act 2025, deals with information you collect about someone from a source that isn't them. Where that happens you have to take reasonable steps to make sure the person knows six things, including what you collected, why, and who will receive it.

In practice it bites on CRM enrichment, bought lists, referral streams and anything that quietly appends data to a customer record. There are exceptions — they already know, the information is publicly available, compliance isn't reasonably practicable — but you have to have thought about it. The health sector got the same change on the same date, through HIPC Amendment No. 2.

02

The Biometric Processing Privacy Code 2025

Now in force as a code of practice, with no Australian equivalent in code form. If you run facial recognition, biometric time-and-attendance or voice ID, this is live New Zealand regulation that applies to you specifically and not by analogy to something else.

Worth checking whether the fingerprint reader on the staff room wall was ever assessed against it. Most were installed as an HR convenience, not as a privacy decision.

03

NZISM, and why it's probably not about you

The New Zealand Information Security Manual, currently version 3.9 from November 2025, is a government-sector manual. Compliance with it is not required as a matter of law, and it only reaches you if you supply government under a formal agreement — at which point it flows down through the contract. Anyone marketing "NZISM compliance" to a small business is selling you somebody else's obligation.

For general security the New Zealand reference point is the NCSC's 10 Critical Controls. The NCSC absorbed CERT NZ in July 2024. There are no maturity levels attached and no compliance regime — more on the cyber security page.

What we do about it

Make the controls real and the evidence findable.

Compliance work goes wrong in one of two directions. Either it produces a folder of policies nobody has read, or it produces technical changes nobody can evidence. You need both halves to line up.

Privacy Act and APP 11 readiness

APP 11 is the one about taking reasonable steps to protect the personal information you hold. We work out what personal information you actually have and where it lives — which is nearly always more places than anyone expects — then put real access controls, encryption and retention around it. Then we write down what we did, because "reasonable steps" you can't demonstrate are not much use to you after the fact.

Privacy Act 2020 and IPP 5 readiness

IPP 5 is storage and security: reasonable safeguards against loss, misuse and unauthorised access. We work out what personal information you actually hold and where it lives — nearly always more places than anyone expects — then put real access controls, encryption and retention around it, and write down what we did. The Manage My Health finding turned on exactly this principle, and on whether the safeguards could be shown to have been adequate at the time.

A breach plan you've actually rehearsed

A breach response plan in a drawer is a document. A breach response plan you've run as a tabletop exercise is a control. We sit your leadership team in a room for ninety minutes with a realistic scenario and find out who makes the call, who rings the lawyer, who talks to staff, and how long it takes you to work out what was taken. The first run is always messy. That's the point of doing it on a Tuesday instead of during an actual incident.

My Health Record security and access policy

If your practice connects to Australia's My Health Record you need a written security and access policy, and it needs to match what your practice management system is actually configured to do. We reconcile the two, which is usually where the gap is.

Where your data sits, and what the Act actually says

This is the first question every New Zealand client asks us, so here is the honest answer. The Privacy Commissioner's guidance is explicit that where a provider holds information as your agent under section 11 — for safekeeping or processing on your instructions, not for its own purposes — that is generally not a cross-border disclosure under IPP 12. In the Commissioner's words, "you'll be responsible for the personal information that you put in the cloud – not the cloud service provider".

Read that carefully, because it is not the win some providers pretend. It does not move the obligation off you. It moves it from "is this lawful" to "is this well governed", and you stay accountable for IPP 5 either way. So we tell you plainly where the data sits, put model contract clauses in place using the Commissioner's own agreement builder and decision tree, and let you make the call. Health and government clients often have onshore hosting requirements that have nothing to do with the Privacy Act, and those still apply.

Accreditation evidence packs

Accreditation surveyors ask for evidence, not assurances. We assemble the technical half of the pack — access logs, backup and restore records, patching reports, user account reviews, device encryption status — and keep it current so the next cycle isn't a scramble.

Tracking pixels and marketing tech

The June 2026 findings over pixels on health websites should make every practice with a booking page nervous. We audit what your site and booking forms send to third parties, tell you in plain English what data is leaving, and help you shut off the bits that shouldn't be. Your marketing agency probably installed these with good intentions and no privacy review.

What your website sends, and where it goes

Every third-party script on your site is a collection point you did not document and a recipient you did not name. Booking pages and enquiry forms are the ones worth checking first, because what they capture is often more sensitive than the rest of the site combined. We audit what leaves, tell you in plain English who receives it, and help you shut off the parts that shouldn't be there. Your marketing agency installed most of it with good intentions and no privacy review.

Customer security questionnaires

Increasingly the privacy questions and the security questions arrive on the same form. We answer them for you, accurately, and flag what we can't yet answer. More on how that works on the cyber security page.

Where we stop

We're not lawyers and none of this is legal advice. We're an IT company that has read the guidance carefully and works with businesses who have these obligations every day. That's genuinely useful, and it is not the same thing as a legal opinion.

For anything contentious — whether a particular breach meets the serious harm threshold, what your contracts oblige you to do, whether to notify — you want a privacy lawyer, and we'll happily work alongside one. What we bring is the other half: making the technical controls real, and making the evidence findable when someone asks for it.

If we don't know something, we'll tell you we don't know it. There's a lot of confident nonsense talked about privacy law by people selling IT.

Not sure which obligations are yours?

Start with a conversation about what personal information you hold and where it lives. If the answer is that you have less exposure than you feared, we'll tell you that and you can get on with your day.