Skip to the content
Global Data RulesData governance rules, country by country

New Zealand

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in New Zealand — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: LowEnforcement: Active

New Zealand is one of the easiest rich countries to send data out of. Personal information can go abroad once you meet any one of six simple grounds. The regulator says that using an overseas cloud provider as your supplier usually does not count as sending data abroad at all. The regulator is real, staffed and issuing decisions, but it cannot fine you. The traps are in tax records and government data, not in privacy law.

Data governance in New Zealand

The eight things that decide how you handle data about people in New Zealand. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The Privacy Act 2020 reaches an overseas business that is carrying on business in New Zealand. It applies even if you have no office, no staff and no bank account here. There is no size or revenue floor to duck under. You do not need to appoint a local representative. But every organisation covered by the law must name at least one privacy officer, and that person may sit overseas.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

For most businesses, yes, and with very little effort. Personal information may go overseas if any one of six grounds applies. The usual one is a contract in which the receiver promises comparable protection. There is a bigger point most people miss. The regulator says that handing data to an overseas cloud provider acting as your supplier is not a disclosure at all. So the cross-border rule does not even switch on. Three areas override this: tax and business records, government data, and health and biometric information.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

For personal information, pick one of six grounds and you are done. There is no government approval, no filing and no registration. The common route is a contract in which the overseas receiver promises comparable protection. The regulator publishes free model clauses you can drop into an agreement. For tax and business records the model is the opposite way round. New Zealand is the default, and you need permission to store them abroad.

Ways to send data out:
Standard contract clauses · Official 'this country is safe' decision · Explicit consent · Nothing required · Government sign-off needed

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The Office of the Privacy Commissioner enforces the rules, and it is really working. It is staffed, it has a serving Commissioner, and it published formal decisions as recently as March 2026. It issued compliance notices in December 2025 and a public inquiry report in June 2025. The catch is its toolkit. It cannot hand out large fines. The biggest cash penalty in the privacy law is ten thousand New Zealand dollars, about six thousand United States dollars. That is a criminal fine imposed by a court, not by the regulator.

What it costs if you get it wrong:
Claims by individuals · Order to stop

How long you must keep it — and when to delete it

There is a clear floor and a vague ceiling. The floor most businesses hit is seven years for tax and business records. Those records must sit in New Zealand unless Inland Revenue has approved otherwise. The ceiling is a principle, not a date. You must not keep personal information for longer than you need it for a purpose you may lawfully use it for. When the two collide, the floor wins. Keeping records that another law requires you to keep is itself a lawful purpose.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There is only one hard clock, and it has no hours on it. Has a privacy breach caused, or is it likely to cause, anyone serious harm? Then you must tell the Privacy Commissioner and the affected people as soon as you are practically able. There is no fixed deadline in hours or days. Reports go through the regulator's online tool. For most private businesses that is the only report you must make. That makes New Zealand unusually simple, compared with countries that stack three overlapping deadlines on top of each other.

What you have to do here:
Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: your overseas cloud provider probably is not a cross-border transfer at all. So the paperwork everyone builds is often the wrong paperwork, and you stay fully liable for what that provider does. Two: your tax and business records are supposed to live in New Zealand unless Inland Revenue said otherwise. Three: two of the six ways to send data abroad rely on lists the government has never published. Four: the fines are tiny, but the person affected can sue you separately. Five: there is no special age of digital consent for children, so the ordinary rules apply to a nine-year-old.

What you have to do here:
Secure the data · Written vendor contract
What it costs if you get it wrong:
Criminal liability · Claims by individuals
Not fully verified — see “What we're not sure about” below.

What's changing next

The big privacy change already landed. From 1 May 2026 you must tell people when you collect their information from somebody else rather than from them. The next dated event is gambling. Online casino operators that did not apply for a licence must stop serving New Zealanders from 1 December 2026. The licensed scheme runs from 2027. A general election on 7 November 2026 could change direction on all of it.

What to do: Diarise 1 December 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Cloud First policy (Cabinet requirement), with the Cloud jurisdictional risk guidance and the New Zealand Information Security Manual · New Zealand Information Security Manual version 3.9, November 2025 · Government policy document

In forceYes, with paperwork

The strictest rule in New Zealand, and it is policy rather than law. Public agencies may only put information classified RESTRICTED or below into a public cloud. That is true whether the cloud is in New Zealand or overseas. Anything more sensitive stays out of public cloud entirely. Offshore hosting of the permitted classifications needs a written risk assessment signed off by the chief executive.

In force since 14 August 2024

Enforced by Government Chief Digital Officer

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Banking

Cloud and outsourcing rules (Banking)

Official name: Outsourcing Policy (BS11) · BS11, September 2022 version, imposed through conditions of registration · Licence condition

In forceYes — store it anywhere

There is no rule here that data must stay in New Zealand. New Zealand's bank outsourcing policy turns on control, not geography. It states in terms that the required system does not have to be located in New Zealand. It applies only to New Zealand-incorporated banks with net liabilities above ten billion New Zealand dollars, about six billion United States dollars. Those banks were given six years to comply.

In force since 1 October 2017Enforced from 1 October 2023

Enforced by Reserve Bank of New Zealand

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Health and social care

Insurance rules

Official name: Health Information Privacy Code 2020 · Amendment No 1, May 2022; Amendment No 2, March 2026 · Statutory code of practice

In forceYes, with paperwork

Health information in New Zealand is governed by a binding code that sits on top of the general privacy law. It covers providers, the accident compensation scheme, the health ministry and health insurers. It was amended in March 2026 to add the new indirect-collection notification duty from 1 May 2026. This is the sector where the regulator has been most visibly active.

In force since 1 December 2020

Enforced by Office of the Privacy Commissioner

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Explicit consent

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Cloud and outsourcing rules

Official name: Privacy Act 2020 · 2020 No 31 · Act of parliament

In forceYes, with paperwork

New Zealand's general privacy law. It puts few limits on sending data abroad. Personal information may leave once any one of six grounds is met. The regulator's own guidance says that using an overseas cloud provider as your agent does not trigger the rule at all. Breach notification is compulsory but has no deadline in hours. The maximum fine is about six thousand United States dollars. So the real risk is a compliance notice, or a claim by the person affected, not a penalty.

In force since 1 December 2020

Enforced by Office of the Privacy Commissioner

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Official 'this country is safe' decision, Explicit consent, Nothing required

Not fully verified — see “What we're not sure about” below.

Personal data must stay in the country

Official name: Tax Administration Act 1994, section 22, applied through Standard Practice Statement 21/02 · Tax Administration Act 1994 s 22(2BA)(b) and s 22(8)(a); SPS 21/02 · Act of parliament

In forceYes, with paperwork

The location rule almost nobody mentions. New Zealand business and tax records must by default be kept at a place in New Zealand. They may go offshore, including to cloud services, in two cases only. Inland Revenue has allowed it. Or your storage provider is on Inland Revenue's published approved list. Records must be kept for at least seven tax years.

In force since 1 January 1994Enforced from 6 May 2021

Enforced by Inland Revenue

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Biometric data rules

Official name: Biometric Processing Privacy Code 2025 · Statutory code of practice

In forceYes, with paperwork

A binding code issued in 2025 that covers any use of face, fingerprint or voice recognition. It adds a proportionality test before you may use biometric information at all, on top of the ordinary privacy rules. We could not confirm its exact start date or its transition dates. Those are listed as unconfirmed.

Enforced by Office of the Privacy Commissioner

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Standard contract clauses, Explicit consent

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Te Mana Mātāpono Matatapu

    General privacy law, binding codes of practice for health, credit reporting, telecommunications and biometrics

    Fully operational and visibly busy. Commissioner Michael Webster is in post. It published decision notes through 31 March 2026, compliance notices in December 2025 and 2026, and a public inquiry report in June 2025. It warns of service delays because demand is high. It cannot impose administrative fines. Its tools are compliance notices, access directions, transfer prohibition notices, public inquiries, and referral to the Human Rights Review Tribunal.

  • Te Tari Taake

    Tax and business record retention and offshore storage approvals

    Maintains a published list of third-party providers approved to hold New Zealand taxpayer electronic records offshore.

  • Te Pūtea Matua

    Bank prudential supervision, including outsourcing

    Was itself the subject of a compliance notice from the Privacy Commissioner in September 2021 after a cyber attack.

  • Cloud policy and standards for public sector agencies

  • Telecommunications network security regulation and the New Zealand Information Security Manual

    Runs the network security regulatory functions for public telecommunications networks, including assessing proposed network changes. General cyber incident reporting to it is voluntary.

  • Te Tari Taiwhenua

    Gambling regulation including the new online casino licensing regime, and anti-money-laundering supervision for some sectors

  • Te Rua Mahara o te Kāwanatanga

    Public sector recordkeeping and disposal authorities

    Its guidance pages block automated access. So we could not confirm its rules on offshore storage and disposal of public records.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact wording of the Privacy Act 2020 on which overseas organisations are caught, and on the transfer prohibition notice power

    We could not confirm anything against the statute text. New Zealand's official legislation site blocks automated requests, on every address we tried. Every claim about the law in this record rests on the regulator's own restatement of it. Check the legislation site yourself before you rely on exact wording.

  • That no country and no binding scheme has ever been prescribed by regulation under the cross-border principle

    We found no country and no binding scheme named in regulations, checked 18 August 2026. The regulator's own page on the principle lists both routes but names nothing. We cannot prove no order exists, so check before you plan around either route.

  • The commencement date and the transition deadline of the Biometric Processing Privacy Code 2025

    We could not confirm the details of this code against a government source. The regulator's index of codes confirms the code exists and is in force. But every dedicated page we tried was missing. We rate the rule low confidence.

  • Whether the Public Records Act 2005 requires the Chief Archivist's authorisation before a public agency stores public records offshore

    We could not confirm New Zealand's rules on offshore storage and disposal of public records. Archives New Zealand blocks automated access to its guidance pages, and the statute site is unreachable. This rule is commonly quoted. If you sell to the public sector, check it with Archives New Zealand before you rely on it.

  • Localisation or record-location rules in payments, insurance and securities

    We could not confirm the position for payments, insurance and securities. The Financial Markets Authority's site refused every request from this environment. We found no rule requiring data to stay in New Zealand, but the check is incomplete. If you work in these industries, check with the regulator.

  • Whether the online casino gambling regime will require player data, accounts or servers to be held in New Zealand

    We could not confirm the detailed rules for online casino operators. The Department of Internal Affairs states that finalised regulations and compliance guidance were due in mid-2026. They were not published in a form we could open on 18 August 2026. This is the most likely place for a new New Zealand location rule to appear before December 2026.

  • Retention floors for anti-money-laundering records, employment wage and time records, and health information

    We could not confirm these retention periods. They are widely quoted as five years, seven years and ten years respectively. Every government page we tried for each was missing or refused access. We do not assert them here. Check with the relevant regulator.

  • Whether the telecommunications network security regime imposes any incident reporting deadline in hours, or any requirement that network data stay in New Zealand

    We could not confirm any deadlines or location requirements for telecommunications network operators. The National Cyber Security Centre's overview confirms it regulates network change proposals, but gives no deadlines. The statute is unreachable.

  • The date Inland Revenue last updated its approved offshore storage provider list

    We could not confirm when Inland Revenue's approved provider list was last updated. The page shows a last-updated date of 11 March 2013, but it names providers that did not exist under those names until 2024. So the displayed date is unreliable. Check the list itself before relying on any single entry.

  • Commencement dates for the Customer and Product Data Act 2025 banking designation regulations

    We could not confirm the timetable. The responsible ministry's page describes the scheme, but the timeline document was not reachable.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.