New Zealand
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
New Zealand is one of the easiest rich countries to send data out of. The privacy law lets personal information go abroad once you have any one of six simple grounds, and the regulator says that using an overseas cloud provider as your supplier usually does not count as sending data abroad at all. The regulator is real, staffed and issuing decisions, but it cannot fine you. The traps are in tax records and government data, not in privacy law.
Data governance in New Zealand
The eight things that decide how you handle data about people in New Zealand. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The Privacy Act 2020 reaches an overseas business that is carrying on business in New Zealand, even if it has no office, no staff and no bank account here. There is no size or revenue floor to duck under. You do not need to appoint a local representative, but every organisation covered by the law must name at least one privacy officer, and that person may sit overseas.
The extraterritorial reach was one of the headline changes from the Privacy Act 1993 to the Privacy Act 2020, which commenced on 1 December 2020. We could not open the statute text itself: New Zealand's official legislation site sits behind an automated-traffic challenge that blocks machine fetching, so the exact wording of the application provision is recorded in the unconfirmed list rather than quoted here. The regulator's own guidance is the basis for the scope statement, and the Privacy Commissioner has publicly pushed the same point at overseas-owned businesses operating here, telling them that a privacy policy written to another country's law is not compliance.
Sources
- Official sourceOffice of the Privacy CommissionerComparing the Privacy Acts 1993 and 2020
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerCompliant, but not in New Zealand — Privacy Commissioner blog, 15 August 2025
privacy.org.nz
“to make sure they meet their privacy obligations their policies need to reflect the Privacy Act 2020, which is the relevant New Zealand law.”
Link checked 18 August 2026
- Official sourceParliamentary Counsel OfficePrivacy Act 2020 (2020 No 31) — official consolidated text
legislation.govt.nz
Link checked 18 August 2026
Where the data is allowed to live
For most businesses, yes, and with very little effort. Personal information may go overseas if any one of six grounds applies, and the usual one is a contract in which the receiver promises comparable protection. There is a bigger point most people miss: the regulator says that handing data to an overseas cloud provider that acts as your supplier is not a disclosure at all, so the cross-border rule does not even switch on. Three areas override this: tax and business records, government data, and health and biometric information.
Sector by sector, checked on 18 August 2026. BANKING — open. The Reserve Bank's outsourcing policy for large banks turns on control, not geography, and says in terms that a required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, roughly six billion United States dollars. PAYMENTS, INSURANCE, SECURITIES — no localisation rule found, checked 18 August 2026, confidence medium. We could not reach the securities regulator's site from this environment, so the securities and insurance position is recorded as unverified rather than as a clean negative. GOVERNMENT AND PUBLIC SECTOR — the strictest area. Cabinet policy allows a public cloud service, onshore or offshore, only for information classified RESTRICTED or below, and pushes agencies to move RESTRICTED information onshore over time where a suitable New Zealand service exists. Anything more sensitive than RESTRICTED may not go into public cloud at all. The government security manual also tells agencies they should not buy offshore technology services from countries New Zealand has no security agreement with. TAX AND BUSINESS RECORDS, ALL INDUSTRIES — a genuine residency default. Records must be kept at a place in New Zealand unless the tax authority has authorised otherwise. HEALTH — governed by a separate binding code with its own version of the cross-border rule. Extra care applies but no hard wall was found. BIOMETRICS — a separate binding code issued in 2025 adds a proportionality test before you may process biometric information at all. TELECOM — the network security regime run by the national cyber agency regulates changes to public telecommunications networks. No data-residency requirement was found in the material we could open, checked 18 August 2026, confidence low. GAMBLING — a new licensed online casino regime is being built. Detailed operator obligations, including any record-location rules, were still unpublished at the date of this record. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE — no separate localisation rule found, checked 18 August 2026, confidence low.
Sources
- Official sourceOffice of the Privacy CommissionerDisclosing personal information outside New Zealand
privacy.org.nz
“in most circumstances, no – you aren't required by law to enter into such an agreement”
Link checked 18 August 2026
- Official sourceGovernment Chief Digital Officer, Department of Internal AffairsCloud First policy — Cabinet requirement
digital.govt.nz
“Must only store data classified as RESTRICTED or below in a public cloud service, whether it's hosted onshore or offshore.”
Link checked 18 August 2026
- Official sourceReserve Bank of New ZealandOutsourcing Policy (BS11), September 2022
rbnz.govt.nz
“This requirement does not mean that the system must be located in New Zealand”
Link checked 18 August 2026
- Official sourceInland RevenueRetention of business records in electronic format and application to store records offshore
taxtechnical.ird.govt.nz
“at a place in New Zealand”
Link checked 18 August 2026
Sending data out of the country
For personal information, pick one of six grounds and you are done. No government approval, no filing, no registration. The common route is a contract in which the overseas receiver promises comparable protection, and the regulator publishes free model clauses you can drop into an agreement. For tax and business records the model is the opposite way round: New Zealand is the default and you need permission to store them abroad.
The six grounds under the cross-border principle are: the person authorises it after being told the protections may not be comparable; the receiver does business in New Zealand and is itself caught by the Act; the receiver is subject to privacy laws that overall give comparable safeguards; the receiver signs up to a binding scheme named in regulations; the receiver is in a country named in regulations; or you reasonably believe the receiver is required to protect the information to a comparable standard, typically by contract. Two of those six are gates that were built and never opened. We found no order naming any country and no order naming any binding scheme, checked 18 August 2026. Treat the country route and the scheme route as unavailable and plan on the contract route. Separately, the regulator holds a power to serve a transfer prohibition notice stopping a specific flow of personal information out of New Zealand. It is a targeted blocking power rather than a country blacklist, and we found no evidence of it being used. The tax records model is an approval model with a published allowlist. Inland Revenue names third-party providers approved to hold New Zealand taxpayer electronic records offshore, and the list has roughly thirty names on it including several mainstream accounting and payroll platforms. If your provider is on that list you need no separate approval. If it is not, you apply in writing.
Sources
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 12 — disclosure outside New Zealand
privacy.org.nz
“subject to privacy laws that, overall, provide comparable safeguards”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerTransfer of personal information outside New Zealand — Part 8 and the transfer prohibition notice
privacy.org.nz
Link checked 18 August 2026
- Official sourceInland RevenueThird party providers approved to store taxpayer electronic records offshore
taxtechnical.ird.govt.nz
“Taxpayers who store their business records with these approved organisations do not need to obtain approval under section 22(2BA) to store their business records outside of New Zealand.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Office of the Privacy Commissioner, and it is genuinely working. It is staffed, it has a serving Commissioner, and it published formal decisions as recently as March 2026, compliance notices in December 2025 and a public inquiry report in June 2025. The catch is the toolkit: it cannot hand out large fines. The biggest cash penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars, and it is a criminal fine imposed by a court, not by the regulator.
Observable evidence of activity, all from the regulator's own site: a decision that a lost memory stick was a notifiable breach, dated 31 March 2026; a decision naming two supermarket operators for a collection breach, dated 17 December 2025; decisions in July 2025 about an enforcement officer misusing personal information and a finance business failing to recognise a fraud incident as a notifiable breach; a public inquiry report into a supermarket group's facial recognition trial published 4 June 2025; and compliance notices arising from the Manage My Health inquiry against both the platform and the national health agency in 2026. The office publicly warns of delays because demand for its services is high, which is itself evidence of a working caseload rather than a dormant body. What the regulator can actually do: issue a compliance notice requiring an organisation to fix something, issue an access direction requiring release of information, serve a transfer prohibition notice, run a public inquiry, and refer a complaint on to the Human Rights Review Tribunal, which can award damages to the affected individual. There is no percentage-of-turnover fine and no administrative penalty regime. Sector regulators operate alongside it. The Reserve Bank supervises bank outsourcing, Inland Revenue polices record storage, the Department of Internal Affairs is building the online casino licensing regime, the Government Chief Digital Officer sets cloud policy for public agencies, and the National Cyber Security Centre regulates telecommunications network security. All are functioning.
Sources
- Official sourceOffice of the Privacy CommissionerDecision notes — Office of the Privacy Commissioner
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerPublic inquiries — including the Foodstuffs North Island facial recognition inquiry, 4 June 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerManage My Health inquiry, phase one — compliance notices issued to Manage My Health and Health New Zealand
privacy.org.nz
“failed in their responsibilities to have reasonable security safeguards”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a clear floor and a vague ceiling. The floor most businesses hit is seven years for tax and business records, and those records must sit in New Zealand unless Inland Revenue has approved otherwise. The ceiling is a principle, not a date: you must not keep personal information for longer than you need it for a purpose you may lawfully use it for. When the two collide, the floor wins, because keeping records that another law requires you to keep is itself a lawful purpose.
Verified floor: seven tax years for business records, including electronic ones, extendable by the Commissioner of Inland Revenue to ten years in specified circumstances or during an audit or investigation. The ceiling is set by the retention principle in the privacy law, which sets no fixed period at all. It is a necessity test, applied case by case, and it is one of the few New Zealand obligations that genuinely requires an organisation to think rather than to look up a number. Public sector bodies face the reverse problem: they may not simply delete. Public records are subject to a separate archives regime that controls disposal. We could not open the archives authority's guidance pages from this environment, so the interaction between the retention principle and the public records regime is recorded as unverified. Other sector floors commonly cited in New Zealand practice — anti-money-laundering records, employment wage and time records, and the ten-year rule for health information — could not be verified against a government source during this run and are listed in the unconfirmed section rather than asserted here.
Sources
- Official sourceInland RevenueRecord keeping — Inland Revenue
ird.govt.nz
“Keep all your records (including those in electronic form) for at least 7 tax years.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 9 — retention of personal information
privacy.org.nz
“An agency that holds personal information must not keep that information for longer than is required for the purposes for which the information may lawfully be used.”
Link checked 18 August 2026
- Official sourceInland RevenueSPS 21/02 — Retention of business records in electronic format and application to store records offshore, 6 May 2021
taxtechnical.ird.govt.nz
Link checked 18 August 2026
If something goes wrong
There is only one hard clock, and it has no hours on it. If a privacy breach has caused or is likely to cause anyone serious harm, you must tell the Privacy Commissioner and the affected people as soon as you are practically able. There is no fixed deadline in hours or days. Reports go through the regulator's online tool. For most private businesses that is the only mandatory report, which makes New Zealand unusually simple compared with countries that stack three overlapping deadlines on top of each other.
Serious harm is judged on a list that includes physical harm, financial fraud, identity theft, psychological injury, loss of employment, blackmail, kidnapping and threats to life. The regulator's guidance is to call the police first if harm to a person looks imminent, then notify. What is NOT a second clock, for most organisations: reporting a cyber incident to the national cyber agency is voluntary in New Zealand, not mandatory. There is no general six-hour or twenty-four-hour cyber reporting duty of the kind India, Singapore or the European Union impose. Where additional clocks do exist they are narrow and we could not pin their deadlines down from official sources during this run. Telecommunications network operators have duties under the network security regime administered by the National Cyber Security Centre, which centres on notifying proposed network changes rather than on incident hours. Licensed financial institutions have their own supervisory notification duties. Both are listed as unverified. Failing to notify is itself an offence and has been the subject of a formal decision: in September 2024 the regulator publicly recorded a care provider taking two years to report a notifiable breach.
Sources
- Official sourceOffice of the Privacy CommissionerPrivacy breaches — when and how to notify
privacy.org.nz
“has caused (or is likely to cause) anyone serious harm”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerDecision notes — PBN23505 (two-year delay in reporting a notifiable breach, 24 September 2024) and PBN/3791 (31 March 2026)
privacy.org.nz
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre, Government Communications Security BureauRegulations and standards — National Cyber Security Centre
ncsc.govt.nz
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: your overseas cloud provider probably is not a cross-border transfer at all, so the paperwork everyone builds is often the wrong paperwork — and you stay fully liable for what that provider does. Two: your tax and business records are supposed to live in New Zealand unless Inland Revenue said otherwise. Three: two of the six ways to send data abroad rely on lists the government has never published. Four: the fines are tiny but the individual can sue you separately. Five: there is no special age of digital consent for children, so the ordinary rules apply to a nine-year-old.
1. THE AGENT RULE. The regulator's own guidance says that where an overseas service provider is acting as your agent you remain the holder of the information and the cross-border principle is not triggered. This is the single most consequential and least understood feature of New Zealand privacy law. It cuts both ways: you save a contract exercise, but you cannot point at the vendor when things go wrong, and you must still meet the security principle for everything they do. 2. TAX RECORDS DEFAULT TO NEW ZEALAND. Business records must be kept at a place in New Zealand unless the Commissioner of Inland Revenue authorises offshore storage. Most people discover this after they have already migrated an accounting system. The escape hatch is that Inland Revenue publishes a list of approved offshore storage providers, and if your provider is on it you need nothing further. Check the list before you migrate, not after. 3. TWO EMPTY LISTS. The cross-border principle offers a route based on the recipient being in a country named in regulations, and another based on the recipient joining a binding scheme named in regulations. We found no order populating either, checked 18 August 2026. Do not design a transfer programme around them. 4. THE MONEY IS NOT WHERE YOU EXPECT. The maximum penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars, and it is a court-imposed criminal fine for specific offences such as misleading an organisation to obtain someone else's information. The real exposure is the Human Rights Review Tribunal, which can award compensation to the individual, plus a compliance notice that forces you to change how you operate. 5. NO CHILDREN'S AGE THRESHOLD FOUND. We found no separate age of digital consent and no separate children's data regime in New Zealand privacy law, checked 18 August 2026. That is the opposite of a comfort: it means nothing shields you, and the regulator has made children's privacy a declared focus area, with a public survey putting children's privacy on social media as the leading public concern at seventy-one per cent. 6. GOVERNMENT BUYERS BRING THEIR OWN CEILING. If you sell to a New Zealand public agency, the constraint is not privacy law, it is the cloud classification rule. Nothing above RESTRICTED goes into a public cloud, and agencies are being nudged to move RESTRICTED information onshore over time. That is a procurement blocker, not a legal one, and it does not appear in any privacy summary.
Sources
- Official sourceOffice of the Privacy CommissionerDisclosing personal information outside New Zealand — the agent rule
privacy.org.nz
“you aren't required by law to enter into such an agreement”
Link checked 18 August 2026
- Official sourceInland RevenueRecord keeping — offshore and cloud storage
ird.govt.nz
“If you store your records off-shore (including cloud computing), make sure either you or your cloud service provider has our approval.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerChildren and young people policy project
privacy.org.nz
Link checked 18 August 2026
- Official sourceGovernment Chief Digital OfficerCloud jurisdictional risk guidance, 14 August 2024
digital.govt.nz
“over time, host RESTRICTED information in a New Zealand-based data centre, where a suitable onshore service exists”
Link checked 18 August 2026
What's changing next
The big privacy change already landed: from 1 May 2026 you must tell people when you collect their information from somebody else rather than from them. The next dated event is gambling. Online casino operators that did not apply for a licence must stop serving New Zealanders from 1 December 2026, with the licensed regime running from 2027. A general election on 7 November 2026 could change direction on all of it.
DATED AND CERTAIN 1 May 2026 — a new principle requiring you to tell people when their information was collected indirectly came into force. The regulator amended its binding codes in March 2026 to match and ran targeted guidance consultation in April 2026. This one already bites. 14 August 2026 — expressions of interest for online casino licences closed. September 2026 — the licence auction. October 2026 — licence applications open. 1 December 2026 — operators that did not apply must cease serving New Zealand. 2027 — the licensed regime fully operational. Up to fifteen licences, each up to three years, no operator holding more than three. Detailed compliance rules, including any record-location requirements, were promised for mid-2026 and were not published in a form we could verify at the date of this record. 7 November 2026 — general election. STATUS UNCERTAIN The Biometric Processing Privacy Code 2025 is in force as a binding code. We could not verify its exact commencement date or the transition deadline for organisations already using biometrics; both are in the unconfirmed list. The Customer and Product Data Act 2025 sets up New Zealand's consumer data right, starting with banking. We could not verify the commencement dates of the banking designation regulations. DORMANT SWITCHES — powers that already exist and can change the picture with no consultation 1. The Privacy Commissioner can serve a transfer prohibition notice stopping a specific flow of personal information out of New Zealand. No public use found. 2. The government can name countries, and separately name binding schemes, as approved routes for sending data abroad. Both powers appear unused. Using them would loosen, not tighten. 3. Inland Revenue can add to or remove names from its approved offshore record storage list. A removal would strand every taxpayer relying on that provider. 4. The cloud classification ceiling for public agencies is Cabinet policy, not legislation, and can be changed by Cabinet alone. EUROPEAN UNION ADEQUACY — stable. New Zealand's adequacy finding was maintained in January 2024 and the regulator continues six-monthly supplementary reporting to the European Commission, the twenty-second of which was filed in December 2025. Nothing suggests it is at risk, but it is the one dependency that would change New Zealand's value as a data destination overnight if it lapsed.
Sources
- Official sourceOffice of the Privacy CommissionerHealth Information Privacy Code Amendment No 2, March 2026 — reflecting principle 3A
privacy.org.nz
“in force from 1 May 2026”
Link checked 18 August 2026
- Official sourceDepartment of Internal AffairsOnline casino gambling — information for providers
dia.govt.nz
“Finalised regulations and guidance on how to comply will be published in mid-2026.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerReports on New Zealand adequacy to the European Commission — 22nd supplementary report, December 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceMinistry of Business, Innovation and EmploymentConsumer data right and the Customer and Product Data Act 2025
mbie.govt.nz
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud First policy (Cabinet requirement), with the Cloud jurisdictional risk guidance and the New Zealand Information Security Manual
Government policy document · New Zealand Information Security Manual version 3.9, November 2025
The hardest wall in New Zealand, and it is policy rather than statute. Public agencies may only put information classified RESTRICTED or below into a public cloud, whether that cloud is in New Zealand or overseas. Anything more sensitive stays out of public cloud entirely. Offshore hosting of the permitted classifications needs a documented risk assessment signed off by the chief executive.
Enforced by Government Chief Digital Officer
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Keep the data in the countryA ceiling rather than a border: only information classified RESTRICTED or below may go into a public cloud at all, onshore or offshore. Agencies should over time host RESTRICTED information in a New Zealand data centre where a suitable onshore service exists.
- Assess high-risk projectsA risk assessment is required before adopting any public cloud service, covering the destination country's lawful access framework, legal institutions and privacy protections.
- Prove the data stays under local controlCloud risks must be formally accepted by the agency head or chief executive and by the agency's accreditation authority.
- Hold a security certificateThe security manual advises agencies should not buy offshore technology services from countries New Zealand has no bilateral or multilateral security agreement with.
Sources
- Official sourceGovernment Chief Digital Officer, Department of Internal AffairsCloud First policy — Cabinet requirement, updated 19 December 2025
digital.govt.nz
“Must only store data classified as RESTRICTED or below in a public cloud service, whether it's hosted onshore or offshore.”
Link checked 18 August 2026
- Official sourceGovernment Chief Digital OfficerCloud jurisdictional risk guidance, 14 August 2024
digital.govt.nz
“make adoption decisions on a case-by-case basis following a risk assessment”
Link checked 18 August 2026
- Official sourceGovernment Communications Security BureauNew Zealand Information Security Manual, version 3.9, November 2025
nzism.gcsb.govt.nz
“SHOULD NOT engage industry for the provision of off-site information technology services and functions in countries that New Zealand does not have a multilateral or bilateral security agreement with”
Link checked 18 August 2026
Outsourcing Policy (BS11)
Licence condition · BS11, September 2022 version, imposed through conditions of registration
Checked and found to be a wall that is not there. New Zealand's bank outsourcing policy turns on control, not geography, and states in terms that the required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, about six billion United States dollars, and gave those banks six years to comply.
Enforced by Reserve Bank of New Zealand
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contract — applies at: New Zealand-incorporated banks with net liabilities above NZD 10 billion, about USD 6 billionThe bank must have legal and practical control over the back-up system and the associated data, whether that system is here or abroad.
- Register or notifyOutsourcing arrangements are approved through application forms lodged with the Reserve Bank, including an exempt list, a pre-approved functions list and a back-up capability form.
What it costs if you get it wrong
- Loss of your licenceBreach of a condition of registration
Sources
- Official sourceReserve Bank of New ZealandOutsourcing Policy (BS11), September 2022
rbnz.govt.nz
“This requirement does not mean that the system must be located in New Zealand”
Link checked 18 August 2026
- Official sourceReserve Bank of New ZealandBanking Supervision Handbook — policy documents for registered banks
rbnz.govt.nz
Link checked 18 August 2026
Health Information Privacy Code 2020
Statutory code of practice · Amendment No 1, May 2022; Amendment No 2, March 2026
Health information in New Zealand is governed by a binding code that sits on top of the general privacy law, covering providers, the accident compensation scheme, the health ministry and health insurers. It was amended in March 2026 to add the new indirect-collection notification duty from 1 May 2026. This is the sector where the regulator has been most visibly active.
Enforced by Office of the Privacy Commissioner
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Explicit consent
What it makes you do
- Put a transfer safeguard in placeThe code has its own rule 12 modelled on the general cross-border principle. We were unable to open the rule text, so any divergence from the general principle is unverified.
- Tell people what you do — from 1 May 2026Amendment No 2, made in March 2026, brings the new indirect-collection notification duty into the health code.
- Secure the dataEnforced in practice. The Privacy Commissioner found in 2026 that both a patient portal operator and the national health agency failed to have reasonable security safeguards, and issued compliance notices.
What it costs if you get it wrong
- Order to stopCompliance notice for failing to have reasonable security safeguards
Sources
- Official sourceOffice of the Privacy CommissionerHealth Information Privacy Code 2020
privacy.org.nz
“in force from 1 May 2026”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerManage My Health inquiry — phase one report and compliance notices
privacy.org.nz
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Privacy Act 2020
Act of parliament · 2020 No 31
New Zealand's general privacy law. Light on cross-border restriction: personal information may leave once any one of six grounds is met, and the regulator's own guidance says using an overseas cloud provider as your agent does not trigger the rule at all. Breach notification is mandatory but has no deadline in hours. The maximum fine is about six thousand United States dollars, so the real risk is a compliance notice or an individual's claim, not a penalty.
Enforced by Office of the Privacy Commissioner
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent, Nothing required
What it makes you do
- Tell people what you do
- Tell people what you do — from 1 May 2026New principle 3A. Where you collect someone's information from a source other than that person, you must tell them as soon as is reasonably practicable after collection. Wide list of exceptions, including where the person already knows and where the information is publicly available.
- Let people see their data
- Let people correct their data
- Secure the data
- Delete data after a periodNo fixed period. You must not keep personal information longer than needed for a purpose you may lawfully use it for.
- Report breaches to the regulatorNo deadline in hours. As soon as practicable after becoming aware, where serious harm has been or is likely to be caused.
- Tell affected peopleSame trigger and same open-ended timing as the regulator notification.
- Put a transfer safeguard in placePrinciple 12. Not triggered where the overseas provider is your agent rather than an independent recipient.
- Appoint a data protection officerCalled a privacy officer. Every organisation must have at least one. No requirement that the person be in New Zealand.
What it costs if you get it wrong
- Criminal liability: NZD 10,000 — about $6 thousandOffences including misleading an organisation to obtain another person's information, and obstructing the Commissioner
- Claims by individualsAn affected individual may be awarded compensation by the Human Rights Review Tribunal
- Order to stopCompliance notice, access direction, or transfer prohibition notice stopping a specific overseas flow
Sources
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 12 — disclosure of personal information outside New Zealand
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 3A — collection of information from another source
privacy.org.nz
“as soon as is reasonably practicable after the information has been collected”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerPrivacy breaches
privacy.org.nz
Link checked 18 August 2026
- Official sourceParliamentary Counsel OfficePrivacy Act 2020 — official consolidated text
legislation.govt.nz
Link checked 18 August 2026
Tax Administration Act 1994, section 22, applied through Standard Practice Statement 21/02
Act of parliament · Tax Administration Act 1994 s 22(2BA)(b) and s 22(8)(a); SPS 21/02
The residency rule almost nobody mentions. New Zealand business and tax records must by default be kept at a place in New Zealand. They may go offshore, including to cloud services, only if Inland Revenue has authorised it or your storage provider is on Inland Revenue's published approved list. Records must be kept for at least seven tax years.
Enforced by Inland Revenue
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryDefault position is that records are kept at a place in New Zealand. Offshore storage needs the Commissioner's authorisation, or a storage provider already on Inland Revenue's approved list.
- Keep data for a minimum period — 7 yearsSeven tax years. Extendable to ten years in specified circumstances or during an audit or investigation.
- Register or notifyA storage provider may apply once on behalf of all its customers. Roughly thirty providers are currently approved, including several mainstream accounting and payroll platforms.
Sources
- Official sourceInland RevenueRecord keeping — Inland Revenue
ird.govt.nz
“If you store your records off-shore (including cloud computing), make sure either you or your cloud service provider has our approval.”
Link checked 18 August 2026
- Official sourceInland RevenueThird party providers approved to store taxpayer electronic records offshore
taxtechnical.ird.govt.nz
“Taxpayers who store their business records with these approved organisations do not need to obtain approval under section 22(2BA) to store their business records outside of New Zealand.”
Link checked 18 August 2026
- Official sourceInland RevenueSPS 21/02 — Retention of business records in electronic format and application to store records offshore, 6 May 2021
taxtechnical.ird.govt.nz
Link checked 18 August 2026
Biometric Processing Privacy Code 2025
Statutory code of practice
A binding code issued in 2025 that sits over any use of face, fingerprint or voice recognition. It adds a proportionality test before you may process biometric information at all, on top of the ordinary privacy rules. Its exact commencement and transition dates could not be verified during this run and are listed as unconfirmed.
Enforced by Office of the Privacy Commissioner
Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Explicit consent
What it makes you do
- Assess high-risk projectsThe code requires organisations to weigh the benefit of biometric processing against the privacy cost before starting.
- Tell people what you doSpecific transparency duties about biometric collection.
Sources
- Official sourceOffice of the Privacy CommissionerCodes of practice — including the Biometric Processing Privacy Code 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerFoodstuffs North Island facial recognition technology inquiry, 4 June 2025
privacy.org.nz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact wording of the Privacy Act 2020 on which overseas organisations are caught, and on the transfer prohibition notice power
New Zealand's official legislation site sits behind an automated-traffic challenge that returns an empty response to every machine request, on every URL form we tried. Every statutory claim in this record therefore rests on the regulator's own restatement of the law rather than on the statute text.
That no country and no binding scheme has ever been prescribed by regulation under the cross-border principle
This is a negative. The regulator's own page on the principle lists both routes but names nothing, and we found no order in council populating either, checked 18 August 2026. We cannot prove no order exists.
The commencement date and the transition deadline of the Biometric Processing Privacy Code 2025
The regulator's index of codes confirms the code exists and is in force, but every dedicated page URL we tried returned not-found. The rule is therefore rated low confidence.
Whether the Public Records Act 2005 requires the Chief Archivist's authorisation before a public agency stores public records offshore
Archives New Zealand's guidance pages are disallowed to automated access by its own robots file and the statute site is unreachable. This is a commonly cited New Zealand rule that we could not stand up, and it would materially change the government sector picture if true.
Localisation or record-location rules in payments, insurance and securities
The Financial Markets Authority's site refused every request from this environment. We found no localisation rule for these sectors, but the check is incomplete rather than clean.
Whether the online casino gambling regime will require player data, accounts or servers to be held in New Zealand
The Department of Internal Affairs states that finalised regulations and compliance guidance were due in mid-2026. The detailed operator obligations were not published in a form we could open on 18 August 2026. This is the single most likely place for a new New Zealand localisation rule to appear before December 2026.
Retention floors for anti-money-laundering records, employment wage and time records, and health information
Widely stated in practice as five years, seven years and ten years respectively, but every government page we tried for each returned not-found or refused access. Not asserted here.
Whether the telecommunications network security regime imposes any incident reporting deadline in hours, or any requirement that network data stay in New Zealand
The National Cyber Security Centre's overview confirms it regulates network change proposals but gives no deadlines or location requirements, and the statute is unreachable.
The date Inland Revenue last updated its approved offshore storage provider list
The page shows a last-updated date of 11 March 2013 but names providers that did not exist under those names until 2024, so the displayed date is unreliable. Check the list itself before relying on any single entry.
Commencement dates for the Customer and Product Data Act 2025 banking designation regulations
The responsible ministry's page describes the framework but the timeline document was not reachable.
60-day cadence. Two things drive it. The online casino gambling regime has hard dates through December 2026 and its detailed operator rules, including any record-location requirement, were still unpublished at the date of this record. And several dormant switches can move without consultation: the regulator's transfer prohibition notice power, the unused powers to name approved countries and binding schemes, and Inland Revenue's ability to add or remove names from its offshore storage allowlist.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
New Zealand versus
Compare