Skip to the content
Global Data RulesData governance rules, country by country

New Zealand

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: LowEnforcement: Active

New Zealand is one of the easiest rich countries to send data out of. The privacy law lets personal information go abroad once you have any one of six simple grounds, and the regulator says that using an overseas cloud provider as your supplier usually does not count as sending data abroad at all. The regulator is real, staffed and issuing decisions, but it cannot fine you. The traps are in tax records and government data, not in privacy law.

Data governance in New Zealand

The eight things that decide how you handle data about people in New Zealand. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The Privacy Act 2020 reaches an overseas business that is carrying on business in New Zealand, even if it has no office, no staff and no bank account here. There is no size or revenue floor to duck under. You do not need to appoint a local representative, but every organisation covered by the law must name at least one privacy officer, and that person may sit overseas.

Medium confidenceNational rulesAppoint a data protection officer

Where the data is allowed to live

For most businesses, yes, and with very little effort. Personal information may go overseas if any one of six grounds applies, and the usual one is a contract in which the receiver promises comparable protection. There is a bigger point most people miss: the regulator says that handing data to an overseas cloud provider that acts as your supplier is not a disclosure at all, so the cross-border rule does not even switch on. Three areas override this: tax and business records, government data, and health and biometric information.

Medium confidenceDepends on your industryBlocklistGovernmentHealth and social careBanking

Sending data out of the country

For personal information, pick one of six grounds and you are done. No government approval, no filing, no registration. The common route is a contract in which the overseas receiver promises comparable protection, and the regulator publishes free model clauses you can drop into an agreement. For tax and business records the model is the opposite way round: New Zealand is the default and you need permission to store them abroad.

Medium confidenceBlocklistStandard contract clausesOfficial 'this country is safe' decisionExplicit consentNothing requiredGovernment sign-off needed

The regulator, and whether it actually acts

The Office of the Privacy Commissioner, and it is genuinely working. It is staffed, it has a serving Commissioner, and it published formal decisions as recently as March 2026, compliance notices in December 2025 and a public inquiry report in June 2025. The catch is the toolkit: it cannot hand out large fines. The biggest cash penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars, and it is a criminal fine imposed by a court, not by the regulator.

High confidenceActiveClaims by individualsOrder to stop

How long you must keep it — and when to delete it

There is a clear floor and a vague ceiling. The floor most businesses hit is seven years for tax and business records, and those records must sit in New Zealand unless Inland Revenue has approved otherwise. The ceiling is a principle, not a date: you must not keep personal information for longer than you need it for a purpose you may lawfully use it for. When the two collide, the floor wins, because keeping records that another law requires you to keep is itself a lawful purpose.

Medium confidenceKeep data for a minimum periodDelete data after a period

If something goes wrong

There is only one hard clock, and it has no hours on it. If a privacy breach has caused or is likely to cause anyone serious harm, you must tell the Privacy Commissioner and the affected people as soon as you are practically able. There is no fixed deadline in hours or days. Reports go through the regulator's online tool. For most private businesses that is the only mandatory report, which makes New Zealand unusually simple compared with countries that stack three overlapping deadlines on top of each other.

High confidenceReport breaches to the regulatorTell affected people

What catches people out

Five things that are not in the summary. One: your overseas cloud provider probably is not a cross-border transfer at all, so the paperwork everyone builds is often the wrong paperwork — and you stay fully liable for what that provider does. Two: your tax and business records are supposed to live in New Zealand unless Inland Revenue said otherwise. Three: two of the six ways to send data abroad rely on lists the government has never published. Four: the fines are tiny but the individual can sue you separately. Five: there is no special age of digital consent for children, so the ordinary rules apply to a nine-year-old.

Medium confidenceSecure the dataWritten vendor contractCriminal liabilityClaims by individualsKeep the data in the country

What's changing next

The big privacy change already landed: from 1 May 2026 you must tell people when you collect their information from somebody else rather than from them. The next dated event is gambling. Online casino operators that did not apply for a licence must stop serving New Zealanders from 1 December 2026, with the licensed regime running from 2027. A general election on 7 November 2026 could change direction on all of it.

Medium confidenceIn forceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Cloud First policy (Cabinet requirement), with the Cloud jurisdictional risk guidance and the New Zealand Information Security Manual

Government policy document · New Zealand Information Security Manual version 3.9, November 2025

In forceYes, with paperwork

The hardest wall in New Zealand, and it is policy rather than statute. Public agencies may only put information classified RESTRICTED or below into a public cloud, whether that cloud is in New Zealand or overseas. Anything more sensitive stays out of public cloud entirely. Offshore hosting of the permitted classifications needs a documented risk assessment signed off by the chief executive.

In force since 14 August 2024

Enforced by Government Chief Digital Officer

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

High confidence
Banking

Outsourcing Policy (BS11)

Licence condition · BS11, September 2022 version, imposed through conditions of registration

In forceYes — store it anywhere

Checked and found to be a wall that is not there. New Zealand's bank outsourcing policy turns on control, not geography, and states in terms that the required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, about six billion United States dollars, and gave those banks six years to comply.

In force since 1 October 2017But only enforceable from 1 October 2023

Enforced by Reserve Bank of New Zealand

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Health and social care

Health Information Privacy Code 2020

Statutory code of practice · Amendment No 1, May 2022; Amendment No 2, March 2026

In forceYes, with paperwork

Health information in New Zealand is governed by a binding code that sits on top of the general privacy law, covering providers, the accident compensation scheme, the health ministry and health insurers. It was amended in March 2026 to add the new indirect-collection notification duty from 1 May 2026. This is the sector where the regulator has been most visibly active.

In force since 1 December 2020

Enforced by Office of the Privacy Commissioner

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Explicit consent

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Privacy Act 2020

Act of parliament · 2020 No 31

In forceYes, with paperwork

New Zealand's general privacy law. Light on cross-border restriction: personal information may leave once any one of six grounds is met, and the regulator's own guidance says using an overseas cloud provider as your agent does not trigger the rule at all. Breach notification is mandatory but has no deadline in hours. The maximum fine is about six thousand United States dollars, so the real risk is a compliance notice or an individual's claim, not a penalty.

In force since 1 December 2020

Enforced by Office of the Privacy Commissioner

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent, Nothing required

Medium confidence

Tax Administration Act 1994, section 22, applied through Standard Practice Statement 21/02

Act of parliament · Tax Administration Act 1994 s 22(2BA)(b) and s 22(8)(a); SPS 21/02

In forceYes, with paperwork

The residency rule almost nobody mentions. New Zealand business and tax records must by default be kept at a place in New Zealand. They may go offshore, including to cloud services, only if Inland Revenue has authorised it or your storage provider is on Inland Revenue's published approved list. Records must be kept for at least seven tax years.

In force since 1 January 1994But only enforceable from 6 May 2021

Enforced by Inland Revenue

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Biometric Processing Privacy Code 2025

Statutory code of practice

In forceYes, with paperwork

A binding code issued in 2025 that sits over any use of face, fingerprint or voice recognition. It adds a proportionality test before you may process biometric information at all, on top of the ordinary privacy rules. Its exact commencement and transition dates could not be verified during this run and are listed as unconfirmed.

Enforced by Office of the Privacy Commissioner

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Standard contract clauses, Explicit consent

Low confidence

Who you would hear from

  • Te Mana Mātāpono Matatapu

    General privacy law, binding codes of practice for health, credit reporting, telecommunications and biometrics

    Fully operational and visibly busy. Commissioner Michael Webster in post. Published decision notes through 31 March 2026, compliance notices in December 2025 and 2026, and a public inquiry report in June 2025. Warns of service delays because demand is high. Cannot impose administrative fines: its tools are compliance notices, access directions, transfer prohibition notices, public inquiries and referral to the Human Rights Review Tribunal.

  • Te Tari Taake

    Tax and business record retention and offshore storage approvals

    Maintains a published list of third-party providers approved to hold New Zealand taxpayer electronic records offshore.

  • Te Pūtea Matua

    Bank prudential supervision, including outsourcing

    Was itself the subject of a compliance notice from the Privacy Commissioner in September 2021 after a cyber attack.

  • Cloud policy and standards for public sector agencies

  • Telecommunications network security regulation and the New Zealand Information Security Manual

    Runs the network security regulatory functions for public telecommunications networks, including assessing proposed network changes. General cyber incident reporting to it is voluntary.

  • Te Tari Taiwhenua

    Gambling regulation including the new online casino licensing regime, and anti-money-laundering supervision for some sectors

  • Te Rua Mahara o te Kāwanatanga

    Public sector recordkeeping and disposal authorities

    Its guidance pages block automated access, so its rules on offshore storage and disposal of public records could not be verified during this run.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact wording of the Privacy Act 2020 on which overseas organisations are caught, and on the transfer prohibition notice power

    New Zealand's official legislation site sits behind an automated-traffic challenge that returns an empty response to every machine request, on every URL form we tried. Every statutory claim in this record therefore rests on the regulator's own restatement of the law rather than on the statute text.

  • That no country and no binding scheme has ever been prescribed by regulation under the cross-border principle

    This is a negative. The regulator's own page on the principle lists both routes but names nothing, and we found no order in council populating either, checked 18 August 2026. We cannot prove no order exists.

  • The commencement date and the transition deadline of the Biometric Processing Privacy Code 2025

    The regulator's index of codes confirms the code exists and is in force, but every dedicated page URL we tried returned not-found. The rule is therefore rated low confidence.

  • Whether the Public Records Act 2005 requires the Chief Archivist's authorisation before a public agency stores public records offshore

    Archives New Zealand's guidance pages are disallowed to automated access by its own robots file and the statute site is unreachable. This is a commonly cited New Zealand rule that we could not stand up, and it would materially change the government sector picture if true.

  • Localisation or record-location rules in payments, insurance and securities

    The Financial Markets Authority's site refused every request from this environment. We found no localisation rule for these sectors, but the check is incomplete rather than clean.

  • Whether the online casino gambling regime will require player data, accounts or servers to be held in New Zealand

    The Department of Internal Affairs states that finalised regulations and compliance guidance were due in mid-2026. The detailed operator obligations were not published in a form we could open on 18 August 2026. This is the single most likely place for a new New Zealand localisation rule to appear before December 2026.

  • Retention floors for anti-money-laundering records, employment wage and time records, and health information

    Widely stated in practice as five years, seven years and ten years respectively, but every government page we tried for each returned not-found or refused access. Not asserted here.

  • Whether the telecommunications network security regime imposes any incident reporting deadline in hours, or any requirement that network data stay in New Zealand

    The National Cyber Security Centre's overview confirms it regulates network change proposals but gives no deadlines or location requirements, and the statute is unreachable.

  • The date Inland Revenue last updated its approved offshore storage provider list

    The page shows a last-updated date of 11 March 2013 but names providers that did not exist under those names until 2024, so the displayed date is unreliable. Check the list itself before relying on any single entry.

  • Commencement dates for the Customer and Product Data Act 2025 banking designation regulations

    The responsible ministry's page describes the framework but the timeline document was not reachable.

60-day cadence. Two things drive it. The online casino gambling regime has hard dates through December 2026 and its detailed operator rules, including any record-location requirement, were still unpublished at the date of this record. And several dormant switches can move without consultation: the regulator's transfer prohibition notice power, the unused powers to name approved countries and binding schemes, and Inland Revenue's ability to add or remove names from its offshore storage allowlist.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

New Zealand versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.