New Zealand
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in New Zealand — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
New Zealand is one of the easiest rich countries to send data out of. Personal information can go abroad once you meet any one of six simple grounds. The regulator says that using an overseas cloud provider as your supplier usually does not count as sending data abroad at all. The regulator is real, staffed and issuing decisions, but it cannot fine you. The traps are in tax records and government data, not in privacy law.
Data governance in New Zealand
The eight things that decide how you handle data about people in New Zealand. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The Privacy Act 2020 reaches an overseas business that is carrying on business in New Zealand. It applies even if you have no office, no staff and no bank account here. There is no size or revenue floor to duck under. You do not need to appoint a local representative. But every organisation covered by the law must name at least one privacy officer, and that person may sit overseas.
The Privacy Act 2020 started on 1 December 2020. One of the biggest changes from the Privacy Act 1993 was that the law now applies even if you have no office in New Zealand. We could not open the statute text itself. New Zealand's official legislation site sits behind an automated-traffic challenge that blocks machine fetching. So the exact wording of the section setting out who is covered is recorded in the unconfirmed list rather than quoted here. The scope statement rests on the regulator's own guidance. The Privacy Commissioner has publicly pushed the same point at overseas-owned businesses operating here. He has told them that a privacy policy written to another country's law is not compliance.
Sources
- Official sourceOffice of the Privacy CommissionerComparing the Privacy Acts 1993 and 2020
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerCompliant, but not in New Zealand — Privacy Commissioner blog, 15 August 2025
privacy.org.nz
“to make sure they meet their privacy obligations their policies need to reflect the Privacy Act 2020, which is the relevant New Zealand law.”
Link checked 18 August 2026
- Official sourceParliamentary Counsel OfficePrivacy Act 2020 (2020 No 31) — official consolidated text
legislation.govt.nz
Link checked 18 August 2026
Where the data is allowed to live
For most businesses, yes, and with very little effort. Personal information may go overseas if any one of six grounds applies. The usual one is a contract in which the receiver promises comparable protection. There is a bigger point most people miss. The regulator says that handing data to an overseas cloud provider acting as your supplier is not a disclosure at all. So the cross-border rule does not even switch on. Three areas override this: tax and business records, government data, and health and biometric information.
Sector by sector, checked on 18 August 2026. BANKING. Open. The Reserve Bank's outsourcing policy for large banks turns on control, not geography. It says in terms that a required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, roughly six billion United States dollars. PAYMENTS, INSURANCE, SECURITIES. We found no rule about where data must sit, checked 18 August 2026, confidence medium. We could not reach the securities regulator's site from this environment. So the securities and insurance position is recorded as unverified rather than as a clean negative. GOVERNMENT AND PUBLIC SECTOR. The strictest area. Cabinet policy allows a public cloud service, in New Zealand or overseas, only for information classified RESTRICTED or below. It pushes agencies to move RESTRICTED information into New Zealand over time, where a suitable New Zealand service exists. Anything more sensitive than RESTRICTED may not go into public cloud at all. The government security manual also tells agencies they should not buy offshore technology services from countries New Zealand has no security agreement with. TAX AND BUSINESS RECORDS, ALL INDUSTRIES. A real rule that data must stay in the country. Records must be kept at a place in New Zealand unless the tax authority has allowed otherwise. HEALTH. Governed by a separate binding code with its own version of the cross-border rule. Extra care applies, but we found no outright ban. BIOMETRICS. A separate binding code issued in 2025 adds a proportionality test before you may use biometric information at all. TELECOM. The national cyber agency regulates changes to public telecommunications networks. We found no rule about where data must sit in the material we could open, checked 18 August 2026, confidence low. GAMBLING. A new licensed online casino scheme is being built. Detailed duties for operators, including any rules on where records sit, were still unpublished at the date of this record. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE. We found no separate rule about where data must sit, checked 18 August 2026, confidence low.
Sources
- Official sourceOffice of the Privacy CommissionerDisclosing personal information outside New Zealand
privacy.org.nz
“in most circumstances, no – you aren't required by law to enter into such an agreement”
Link checked 18 August 2026
- Official sourceGovernment Chief Digital Officer, Department of Internal AffairsCloud First policy — Cabinet requirement
digital.govt.nz
“Must only store data classified as RESTRICTED or below in a public cloud service, whether it's hosted onshore or offshore.”
Link checked 18 August 2026
- Official sourceReserve Bank of New ZealandOutsourcing Policy (BS11), September 2022
rbnz.govt.nz
“This requirement does not mean that the system must be located in New Zealand”
Link checked 18 August 2026
- Official sourceInland RevenueRetention of business records in electronic format and application to store records offshore
taxtechnical.ird.govt.nz
“at a place in New Zealand”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
For personal information, pick one of six grounds and you are done. There is no government approval, no filing and no registration. The common route is a contract in which the overseas receiver promises comparable protection. The regulator publishes free model clauses you can drop into an agreement. For tax and business records the model is the opposite way round. New Zealand is the default, and you need permission to store them abroad.
- Ways to send data out:
- Standard contract clauses · Official 'this country is safe' decision · Explicit consent · Nothing required · Government sign-off needed
The six grounds under the cross-border principle are these. The person agrees after being told the protections may not be comparable. Or the receiver does business in New Zealand and is itself caught by the Act. Or the receiver is subject to privacy laws that overall give comparable safeguards. Or the receiver signs up to a binding scheme named in regulations. Or the receiver is in a country named in regulations. Or you reasonably believe the receiver must protect the information to a comparable standard, usually by contract. Two of those six routes do not work, because the lists behind them are empty. We found no order naming any country, and no order naming any binding scheme, checked 18 August 2026. Treat the country route and the scheme route as unavailable, and plan on the contract route. Separately, the regulator can serve a transfer prohibition notice. That stops a specific flow of personal information out of New Zealand. It targets one flow rather than banning a country, and we found no evidence of it being used. The tax records model is different. You need approval, and there is a published list of approved providers. Inland Revenue names third-party providers approved to hold New Zealand taxpayer electronic records offshore. The list has roughly thirty names on it, including several mainstream accounting and payroll platforms. If your provider is on that list, you need no separate approval. If it is not, you apply in writing.
Sources
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 12 — disclosure outside New Zealand
privacy.org.nz
“subject to privacy laws that, overall, provide comparable safeguards”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerTransfer of personal information outside New Zealand — Part 8 and the transfer prohibition notice
privacy.org.nz
Link checked 18 August 2026
- Official sourceInland RevenueThird party providers approved to store taxpayer electronic records offshore
taxtechnical.ird.govt.nz
“Taxpayers who store their business records with these approved organisations do not need to obtain approval under section 22(2BA) to store their business records outside of New Zealand.”
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The Office of the Privacy Commissioner enforces the rules, and it is really working. It is staffed, it has a serving Commissioner, and it published formal decisions as recently as March 2026. It issued compliance notices in December 2025 and a public inquiry report in June 2025. The catch is its toolkit. It cannot hand out large fines. The biggest cash penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars. That is a criminal fine imposed by a court, not by the regulator.
- What it costs if you get it wrong:
- Claims by individuals · Order to stop
Evidence of activity, all from the regulator's own site. A decision that a lost memory stick was a notifiable breach, dated 31 March 2026. A decision naming two supermarket operators for a collection breach, dated 17 December 2025. Decisions in July 2025 about an enforcement officer misusing personal information, and about a finance business failing to recognise a fraud incident as a notifiable breach. A public inquiry report into a supermarket group's facial recognition trial, published 4 June 2025. Compliance notices from the Manage My Health inquiry, against both the platform and the national health agency, in 2026. The office publicly warns of delays because demand for its services is high. That is itself evidence of a working caseload rather than an idle body. Here is what the regulator can actually do. It can issue a compliance notice requiring an organisation to fix something. It can issue an access direction requiring release of information. It can serve a transfer prohibition notice. It can run a public inquiry. And it can refer a complaint on to the Human Rights Review Tribunal. That tribunal can award damages to the person affected. There is no fine based on a percentage of turnover, and no system of administrative penalties. Sector regulators work alongside it. The Reserve Bank supervises bank outsourcing. Inland Revenue polices record storage. The Department of Internal Affairs is building the online casino licensing scheme. The Government Chief Digital Officer sets cloud policy for public agencies. The National Cyber Security Centre regulates telecommunications network security. All are functioning.
Sources
- Official sourceOffice of the Privacy CommissionerDecision notes — Office of the Privacy Commissioner
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerPublic inquiries — including the Foodstuffs North Island facial recognition inquiry, 4 June 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerManage My Health inquiry, phase one — compliance notices issued to Manage My Health and Health New Zealand
privacy.org.nz
“failed in their responsibilities to have reasonable security safeguards”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a clear floor and a vague ceiling. The floor most businesses hit is seven years for tax and business records. Those records must sit in New Zealand unless Inland Revenue has approved otherwise. The ceiling is a principle, not a date. You must not keep personal information for longer than you need it for a purpose you may lawfully use it for. When the two collide, the floor wins. Keeping records that another law requires you to keep is itself a lawful purpose.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
The floor we verified: seven tax years for business records, including electronic ones. The Commissioner of Inland Revenue can extend that to ten years in specified circumstances, or during an audit or investigation. The ceiling comes from the retention principle in the privacy law, which sets no fixed period at all. It is a necessity test, applied case by case. It is one of the few New Zealand duties that requires you to think rather than to look up a number. Public sector bodies face the reverse problem. They may not simply delete. Public records are covered by separate archives rules that control disposal. We could not open the archives authority's guidance pages, so we could not confirm how the retention principle interacts with the public records rules. Other floors commonly quoted in New Zealand are anti-money-laundering records, employment wage and time records, and the ten-year rule for health information. We could not confirm any of them against a government source, so they are listed in the unconfirmed section rather than asserted here.
Sources
- Official sourceInland RevenueRecord keeping — Inland Revenue
ird.govt.nz
“Keep all your records (including those in electronic form) for at least 7 tax years.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 9 — retention of personal information
privacy.org.nz
“An agency that holds personal information must not keep that information for longer than is required for the purposes for which the information may lawfully be used.”
Link checked 18 August 2026
- Official sourceInland RevenueSPS 21/02 — Retention of business records in electronic format and application to store records offshore, 6 May 2021
taxtechnical.ird.govt.nz
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There is only one hard clock, and it has no hours on it. Has a privacy breach caused, or is it likely to cause, anyone serious harm? Then you must tell the Privacy Commissioner and the affected people as soon as you are practically able. There is no fixed deadline in hours or days. Reports go through the regulator's online tool. For most private businesses that is the only report you must make. That makes New Zealand unusually simple, compared with countries that stack three overlapping deadlines on top of each other.
- What you have to do here:
- Report breaches to the regulator · Tell affected people
Serious harm is judged on a list. It includes physical harm, financial fraud, identity theft, psychological injury, loss of employment, blackmail, kidnapping and threats to life. The regulator's guidance is to call the police first if harm to a person looks imminent, then notify. There is no second clock for most organisations. Reporting a cyber incident to the national cyber agency is voluntary in New Zealand, not compulsory. There is no general six-hour or twenty-four-hour cyber reporting duty of the kind India, Singapore or the European Union impose. Where extra clocks do exist they are narrow, and we could not confirm their deadlines from official sources. Telecommunications network operators have duties under the network security rules run by the National Cyber Security Centre. Those focus on notifying proposed network changes rather than on incident hours. Licensed financial institutions have their own supervisory notification duties. Both are listed as unverified. Failing to notify is itself an offence, and it has been the subject of a formal decision. In September 2024 the regulator publicly recorded a care provider taking two years to report a notifiable breach.
Sources
- Official sourceOffice of the Privacy CommissionerPrivacy breaches — when and how to notify
privacy.org.nz
“has caused (or is likely to cause) anyone serious harm”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerDecision notes — PBN23505 (two-year delay in reporting a notifiable breach, 24 September 2024) and PBN/3791 (31 March 2026)
privacy.org.nz
Link checked 18 August 2026
- Official sourceNational Cyber Security Centre, Government Communications Security BureauRegulations and standards — National Cyber Security Centre
ncsc.govt.nz
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One: your overseas cloud provider probably is not a cross-border transfer at all. So the paperwork everyone builds is often the wrong paperwork, and you stay fully liable for what that provider does. Two: your tax and business records are supposed to live in New Zealand unless Inland Revenue said otherwise. Three: two of the six ways to send data abroad rely on lists the government has never published. Four: the fines are tiny, but the person affected can sue you separately. Five: there is no special age of digital consent for children, so the ordinary rules apply to a nine-year-old.
- What you have to do here:
- Secure the data · Written vendor contract
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
1. THE SUPPLIER RULE. The regulator's own guidance says that where an overseas service provider acts as your agent, you remain the holder of the information. The cross-border principle is then not triggered. This is the most important and least understood feature of New Zealand privacy law. You save yourself a contract exercise. But you cannot point at the vendor when things go wrong, and you must still meet the security principle for everything they do. 2. TAX RECORDS DEFAULT TO NEW ZEALAND. Business records must be kept at a place in New Zealand, unless the Commissioner of Inland Revenue allows offshore storage. Most people discover this after they have already moved an accounting system. There is a way out. Inland Revenue publishes a list of approved offshore storage providers. If your provider is on it, you need nothing further. Check the list before you migrate, not after. 3. TWO EMPTY LISTS. The cross-border principle offers a route based on the receiver being in a country named in regulations. It offers another based on the receiver joining a binding scheme named in regulations. We found no order filling either list, checked 18 August 2026. Do not design a transfer programme around them. 4. THE MONEY IS NOT WHERE YOU EXPECT. The maximum penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars. It is a court-imposed criminal fine, for specific offences such as misleading an organisation to obtain someone else's information. The real exposure is the Human Rights Review Tribunal, which can award compensation to the person affected. Add to that a compliance notice that forces you to change how you operate. 5. NO AGE THRESHOLD FOR CHILDREN. We found no separate age of digital consent, and no separate set of children's data rules in New Zealand privacy law, checked 18 August 2026. That is not a comfort. It means nothing shields you. The regulator has made children's privacy a declared focus area. A public survey put children's privacy on social media as the leading public concern, at seventy-one per cent. 6. GOVERNMENT BUYERS BRING THEIR OWN CEILING. If you sell to a New Zealand public agency, the limit is not privacy law. It is the cloud classification rule. Nothing above RESTRICTED goes into a public cloud, and agencies are being nudged to move RESTRICTED information into New Zealand over time. That is a buying blocker, not a legal one, and it does not appear in any privacy summary.
Sources
- Official sourceOffice of the Privacy CommissionerDisclosing personal information outside New Zealand — the agent rule
privacy.org.nz
“you aren't required by law to enter into such an agreement”
Link checked 18 August 2026
- Official sourceInland RevenueRecord keeping — offshore and cloud storage
ird.govt.nz
“If you store your records off-shore (including cloud computing), make sure either you or your cloud service provider has our approval.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerChildren and young people policy project
privacy.org.nz
Link checked 18 August 2026
- Official sourceGovernment Chief Digital OfficerCloud jurisdictional risk guidance, 14 August 2024
digital.govt.nz
“over time, host RESTRICTED information in a New Zealand-based data centre, where a suitable onshore service exists”
Link checked 18 August 2026
What's changing next
The big privacy change already landed. From 1 May 2026 you must tell people when you collect their information from somebody else rather than from them. The next dated event is gambling. Online casino operators that did not apply for a licence must stop serving New Zealanders from 1 December 2026. The licensed scheme runs from 2027. A general election on 7 November 2026 could change direction on all of it.
DATED AND CERTAIN 1 May 2026. A new principle came into force. You must tell people when their information was collected from someone other than them. The regulator amended its binding codes in March 2026 to match, and ran targeted guidance consultation in April 2026. This one already applies. 14 August 2026. Expressions of interest for online casino licences closed. September 2026. The licence auction. October 2026. Licence applications open. 1 December 2026. Operators that did not apply must stop serving New Zealand. 2027. The licensed scheme fully operational. Up to fifteen licences, each up to three years, with no operator holding more than three. Detailed compliance rules, including any rules on where records sit, were promised for mid-2026. They were not published in a form we could verify at the date of this record. 7 November 2026. General election. STATUS UNCERTAIN The Biometric Processing Privacy Code 2025 is in force as a binding code. We could not confirm its exact start date, or the deadline for organisations already using biometrics. Both are in the unconfirmed list. The Customer and Product Data Act 2025 sets up New Zealand's consumer data right, starting with banking. We could not confirm the start dates of the banking designation regulations. POWERS THAT ALREADY EXIST AND CAN CHANGE THINGS WITH NO CONSULTATION 1. The Privacy Commissioner can serve a transfer prohibition notice, stopping a specific flow of personal information out of New Zealand. We found no public use of it. 2. The government can name countries, and separately name binding schemes, as approved routes for sending data abroad. Both powers appear unused. Using them would loosen the rules, not tighten them. 3. Inland Revenue can add names to, or remove names from, its approved offshore record storage list. A removal would strand every taxpayer relying on that provider. 4. The cloud classification ceiling for public agencies is Cabinet policy, not legislation. Cabinet can change it alone. EUROPE'S DECISION ON NEW ZEALAND. Stable. Europe's official decision that New Zealand is safe enough was maintained in January 2024. The regulator keeps filing six-monthly supplementary reports to the European Commission. The twenty-second was filed in December 2025. Nothing suggests it is at risk. But it is the one dependency that would change New Zealand's value as a data destination overnight if it lapsed.
Sources
- Official sourceOffice of the Privacy CommissionerHealth Information Privacy Code Amendment No 2, March 2026 — reflecting principle 3A
privacy.org.nz
“in force from 1 May 2026”
Link checked 18 August 2026
- Official sourceDepartment of Internal AffairsOnline casino gambling — information for providers
dia.govt.nz
“Finalised regulations and guidance on how to comply will be published in mid-2026.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerReports on New Zealand adequacy to the European Commission — 22nd supplementary report, December 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceMinistry of Business, Innovation and EmploymentConsumer data right and the Customer and Product Data Act 2025
mbie.govt.nz
Link checked 18 August 2026
What to do: Diarise 1 December 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Cloud First policy (Cabinet requirement), with the Cloud jurisdictional risk guidance and the New Zealand Information Security Manual · New Zealand Information Security Manual version 3.9, November 2025 · Government policy document
The strictest rule in New Zealand, and it is policy rather than law. Public agencies may only put information classified RESTRICTED or below into a public cloud. That is true whether the cloud is in New Zealand or overseas. Anything more sensitive stays out of public cloud entirely. Offshore hosting of the permitted classifications needs a written risk assessment signed off by the chief executive.
Enforced by Government Chief Digital Officer
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Keep the data in the countryThis is a ceiling rather than a border. Only information classified RESTRICTED or below may go into a public cloud at all, in New Zealand or overseas. Over time, agencies should host RESTRICTED information in a New Zealand data centre where a suitable local service exists.
- Assess high-risk projectsYou need a risk assessment before adopting any public cloud service. It must cover the destination country's rules on lawful access, its legal institutions and its privacy protections.
- Prove the data stays under local controlCloud risks must be formally accepted by the agency head or chief executive and by the agency's accreditation authority.
- Hold a security certificateThe security manual advises agencies should not buy offshore technology services from countries New Zealand has no bilateral or multilateral security agreement with.
Sources
- Official sourceGovernment Chief Digital Officer, Department of Internal AffairsCloud First policy — Cabinet requirement, updated 19 December 2025
digital.govt.nz
“Must only store data classified as RESTRICTED or below in a public cloud service, whether it's hosted onshore or offshore.”
Link checked 18 August 2026
- Official sourceGovernment Chief Digital OfficerCloud jurisdictional risk guidance, 14 August 2024
digital.govt.nz
“make adoption decisions on a case-by-case basis following a risk assessment”
Link checked 18 August 2026
- Official sourceGovernment Communications Security BureauNew Zealand Information Security Manual, version 3.9, November 2025
nzism.gcsb.govt.nz
“SHOULD NOT engage industry for the provision of off-site information technology services and functions in countries that New Zealand does not have a multilateral or bilateral security agreement with”
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Outsourcing Policy (BS11) · BS11, September 2022 version, imposed through conditions of registration · Licence condition
There is no rule here that data must stay in New Zealand. New Zealand's bank outsourcing policy turns on control, not geography. It states in terms that the required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, about six billion United States dollars. Those banks were given six years to comply.
Enforced by Reserve Bank of New Zealand
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contract — applies at: New Zealand-incorporated banks with net liabilities above NZD 10 billion, about USD 6 billionThe bank must have legal and practical control over the back-up system and the associated data, whether that system is here or abroad.
- Register or notifyOutsourcing arrangements are approved through application forms lodged with the Reserve Bank, including an exempt list, a pre-approved functions list and a back-up capability form.
What it costs if you get it wrong
- Loss of your licenceBreach of a condition of registration
Sources
- Official sourceReserve Bank of New ZealandOutsourcing Policy (BS11), September 2022
rbnz.govt.nz
“This requirement does not mean that the system must be located in New Zealand”
Link checked 18 August 2026
- Official sourceReserve Bank of New ZealandBanking Supervision Handbook — policy documents for registered banks
rbnz.govt.nz
Link checked 18 August 2026
Insurance rules
Official name: Health Information Privacy Code 2020 · Amendment No 1, May 2022; Amendment No 2, March 2026 · Statutory code of practice
Health information in New Zealand is governed by a binding code that sits on top of the general privacy law. It covers providers, the accident compensation scheme, the health ministry and health insurers. It was amended in March 2026 to add the new indirect-collection notification duty from 1 May 2026. This is the sector where the regulator has been most visibly active.
Enforced by Office of the Privacy Commissioner
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Explicit consent
What you have to do
- Put a transfer safeguard in placeThe code has its own rule 12, modelled on the general cross-border principle. We could not open the rule text. So we could not confirm whether it differs from the general principle.
- Tell people what you do — from 1 May 2026Amendment No 2, made in March 2026, brings the new indirect-collection notification duty into the health code.
- Secure the dataEnforced for real. In 2026 the Privacy Commissioner found that a patient portal operator and the national health agency both failed to have reasonable security safeguards. It issued compliance notices.
What it costs if you get it wrong
- Order to stopCompliance notice for failing to have reasonable security safeguards
Sources
- Official sourceOffice of the Privacy CommissionerHealth Information Privacy Code 2020
privacy.org.nz
“in force from 1 May 2026”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerManage My Health inquiry — phase one report and compliance notices
privacy.org.nz
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Cloud and outsourcing rules
Official name: Privacy Act 2020 · 2020 No 31 · Act of parliament
New Zealand's general privacy law. It puts few limits on sending data abroad. Personal information may leave once any one of six grounds is met. The regulator's own guidance says that using an overseas cloud provider as your agent does not trigger the rule at all. Breach notification is compulsory but has no deadline in hours. The maximum fine is about six thousand United States dollars. So the real risk is a compliance notice, or a claim by the person affected, not a penalty.
Enforced by Office of the Privacy Commissioner
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent, Nothing required
What you have to do
- Tell people what you do
- Tell people what you do — from 1 May 2026New principle 3A. Where you collect someone's information from a source other than that person, you must tell them as soon as is reasonably practicable after collection. Wide list of exceptions, including where the person already knows and where the information is publicly available.
- Let people see their data
- Let people correct their data
- Secure the data
- Delete data after a periodNo fixed period. You must not keep personal information longer than needed for a purpose you may lawfully use it for.
- Report breaches to the regulatorNo deadline in hours. As soon as practicable after becoming aware, where serious harm has been or is likely to be caused.
- Tell affected peopleSame trigger and same open-ended timing as the regulator notification.
- Put a transfer safeguard in placePrinciple 12. Not triggered where the overseas provider is your agent rather than an independent recipient.
- Appoint a data protection officerCalled a privacy officer. Every organisation must have at least one. No requirement that the person be in New Zealand.
What it costs if you get it wrong
- Criminal liability: NZD 10,000 — about $6 thousandOffences including misleading an organisation to obtain another person's information, and obstructing the Commissioner
- Claims by individualsAn affected individual may be awarded compensation by the Human Rights Review Tribunal
- Order to stopCompliance notice, access direction, or transfer prohibition notice stopping a specific overseas flow
Sources
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 12 — disclosure of personal information outside New Zealand
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerInformation privacy principle 3A — collection of information from another source
privacy.org.nz
“as soon as is reasonably practicable after the information has been collected”
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerPrivacy breaches
privacy.org.nz
Link checked 18 August 2026
- Official sourceParliamentary Counsel OfficePrivacy Act 2020 — official consolidated text
legislation.govt.nz
Link checked 18 August 2026
Personal data must stay in the country
Official name: Tax Administration Act 1994, section 22, applied through Standard Practice Statement 21/02 · Tax Administration Act 1994 s 22(2BA)(b) and s 22(8)(a); SPS 21/02 · Act of parliament
The location rule almost nobody mentions. New Zealand business and tax records must by default be kept at a place in New Zealand. They may go offshore, including to cloud services, in two cases only. Inland Revenue has allowed it. Or your storage provider is on Inland Revenue's published approved list. Records must be kept for at least seven tax years.
Enforced by Inland Revenue
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryDefault position is that records are kept at a place in New Zealand. Offshore storage needs the Commissioner's authorisation, or a storage provider already on Inland Revenue's approved list.
- Keep data for a minimum period — 7 yearsSeven tax years. Extendable to ten years in specified circumstances or during an audit or investigation.
- Register or notifyA storage provider may apply once on behalf of all its customers. Roughly thirty providers are currently approved, including several mainstream accounting and payroll platforms.
Sources
- Official sourceInland RevenueRecord keeping — Inland Revenue
ird.govt.nz
“If you store your records off-shore (including cloud computing), make sure either you or your cloud service provider has our approval.”
Link checked 18 August 2026
- Official sourceInland RevenueThird party providers approved to store taxpayer electronic records offshore
taxtechnical.ird.govt.nz
“Taxpayers who store their business records with these approved organisations do not need to obtain approval under section 22(2BA) to store their business records outside of New Zealand.”
Link checked 18 August 2026
- Official sourceInland RevenueSPS 21/02 — Retention of business records in electronic format and application to store records offshore, 6 May 2021
taxtechnical.ird.govt.nz
Link checked 18 August 2026
Biometric data rules
Official name: Biometric Processing Privacy Code 2025 · Statutory code of practice
A binding code issued in 2025 that covers any use of face, fingerprint or voice recognition. It adds a proportionality test before you may use biometric information at all, on top of the ordinary privacy rules. We could not confirm its exact start date or its transition dates. Those are listed as unconfirmed.
Enforced by Office of the Privacy Commissioner
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Explicit consent
What you have to do
- Assess high-risk projectsThe code requires you to weigh the benefit of using biometrics against the privacy cost before you start.
- Tell people what you doSpecific transparency duties about biometric collection.
Sources
- Official sourceOffice of the Privacy CommissionerCodes of practice — including the Biometric Processing Privacy Code 2025
privacy.org.nz
Link checked 18 August 2026
- Official sourceOffice of the Privacy CommissionerFoodstuffs North Island facial recognition technology inquiry, 4 June 2025
privacy.org.nz
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact wording of the Privacy Act 2020 on which overseas organisations are caught, and on the transfer prohibition notice power
We could not confirm anything against the statute text. New Zealand's official legislation site blocks automated requests, on every address we tried. Every claim about the law in this record rests on the regulator's own restatement of it. Check the legislation site yourself before you rely on exact wording.
That no country and no binding scheme has ever been prescribed by regulation under the cross-border principle
We found no country and no binding scheme named in regulations, checked 18 August 2026. The regulator's own page on the principle lists both routes but names nothing. We cannot prove no order exists, so check before you plan around either route.
The commencement date and the transition deadline of the Biometric Processing Privacy Code 2025
We could not confirm the details of this code against a government source. The regulator's index of codes confirms the code exists and is in force. But every dedicated page we tried was missing. We rate the rule low confidence.
Whether the Public Records Act 2005 requires the Chief Archivist's authorisation before a public agency stores public records offshore
We could not confirm New Zealand's rules on offshore storage and disposal of public records. Archives New Zealand blocks automated access to its guidance pages, and the statute site is unreachable. This rule is commonly quoted. If you sell to the public sector, check it with Archives New Zealand before you rely on it.
Localisation or record-location rules in payments, insurance and securities
We could not confirm the position for payments, insurance and securities. The Financial Markets Authority's site refused every request from this environment. We found no rule requiring data to stay in New Zealand, but the check is incomplete. If you work in these industries, check with the regulator.
Whether the online casino gambling regime will require player data, accounts or servers to be held in New Zealand
We could not confirm the detailed rules for online casino operators. The Department of Internal Affairs states that finalised regulations and compliance guidance were due in mid-2026. They were not published in a form we could open on 18 August 2026. This is the most likely place for a new New Zealand location rule to appear before December 2026.
Retention floors for anti-money-laundering records, employment wage and time records, and health information
We could not confirm these retention periods. They are widely quoted as five years, seven years and ten years respectively. Every government page we tried for each was missing or refused access. We do not assert them here. Check with the relevant regulator.
Whether the telecommunications network security regime imposes any incident reporting deadline in hours, or any requirement that network data stay in New Zealand
We could not confirm any deadlines or location requirements for telecommunications network operators. The National Cyber Security Centre's overview confirms it regulates network change proposals, but gives no deadlines. The statute is unreachable.
The date Inland Revenue last updated its approved offshore storage provider list
We could not confirm when Inland Revenue's approved provider list was last updated. The page shows a last-updated date of 11 March 2013, but it names providers that did not exist under those names until 2024. So the displayed date is unreliable. Check the list itself before relying on any single entry.
Commencement dates for the Customer and Product Data Act 2025 banking designation regulations
We could not confirm the timetable. The responsible ministry's page describes the scheme, but the timeline document was not reachable.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.