Customer and Product Data Bill – Select Committee reports back
The Economic Development, Science and Innovation Committee has released its report on the CPD Bill.

On 23 December last year – while most of us were frantically shopping and trying to avoid hearing Mariah Carey – the Economic Development, Science and Innovation Committee managed to release its report on the CPD Bill.
The Committee’s recommendations are relatively limited in scope, and the core aspects of the Bill remain firmly intact. However, there are some important proposed changes:
Derived Data. The Committee has recommended excluding any reference to “derived data” from the Bill. Derived data is data that is wholly or partly derived from designated customer data, and the Bill had initially provided for requirements for the use, modification or disclosure of derived data (as well as customer data) by data requesters to be included in regulations. Similar provisions in the Australian Consumer Data Right have proved difficult to implement and detracted from uptake, so many will see this recommendation as a big win. Interestingly, the Committee considered that the protections already provided by the Privacy Act meant that these provisions were unnecessary. This shows a desire to avoid creating a ‘two-tier’ system, where CPD data is subject to a layer of more onerous obligations under the legislation.
New Defence for Data Holders. The Committee has recommended adding a new defence for data holders for claims against them based on the data holder providing data to another person. This provides that it is a defence if the data holder proves they, in compliance or purported compliance with the Bill, provided data in good faith and (in certain circumstances) they took reasonable precautions and exercised due diligence. This was added to address possible scenarios where, by complying with their obligations in the Bill, data holders become inadvertently exposed to liability (e.g. where an accredited requestor is hacked and requests customer data).
Approved Standards Bodies. The Committee has recommended that MBIE should be able to approve one or more outside organisations to have a principal role in developing standards and supporting services for the CPD regime on MBIE’s behalf. The key beneficiary of these provisions is likely to be the Payments NZ ‘API Centre’, which is currently managing New Zealand’s industry-led open banking programme (although it will likely need some changes to its governance structure given that Payments NZ is bank-owned). Notably, the Committee has also proposed that levies collected from data holders and recipients under the Act could be used to fund any such standards body.
Accreditation Criteria. The initial Bill left the criteria for accreditation of data requestors to be determined by regulation. The Committee has recommended that some core high-level criteria should be entrenched in the primary legislation itself. They are: (1) the directors and senior managers are of “good character”, (2) the entity has “adequate security safeguards” in relation to the data they receive, and (3)the entity is capable of effectively complying with its obligations under the Act and there is no reason to believe they are likely to contravene them.
Simplifying the Regime. There are also a range of recommendations aimed at removing complexity and compliance cost from the regime – including removing various policy, reporting and record keeping obligations on data holders and requesters. The Committee has also proposed removing a provision of the Bill which prevented data holders and requesters from imposing penalties or enforcing rights against customers if they had contravened a duty under the Act.
The scope and substance of the Committee’s recommendations reflect the submissions and advice received during the Select Committee process. They are generally aimed at improving the workability of the regime in some key areas, while acknowledging the legislation as a whole is in good shape.
We can expect smooth progress of the Bill through the remainder of the Parliamentary process – and a lot of work to be done this year in drafting the regulations and standards required to activate the CPD regime by the ambitious deadline of December 2025.
You can find our Deep Dive guide to the Bill here – we’ll be continuing our updates throughout 2025.
Services in this insight
From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business
Space Law in New Zealand — Signals from the ground
Cyber security changes flagged for New Zealand
The four Cs of successful fintech partnerships
New rule 3A introduced to the Biometric Processing Privacy Code
IPP3A is nearly in force – What agencies need to know
OPC shifts public enquiries online – What agencies should do now
AI as a confidante? Legal privilege and the ever-increasing use of AI
New Therapeutic and Health Advertising Code – What you need to know
Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia
Consumer law update 2025
Open banking launches in New Zealand
Is fair something to fear? The Government announces beefed-up Fair Trading Act
Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta
Open banking almost live
Why New Zealand businesses should care about the EU Data Act
Product labelling changes flagged for New Zealand
Biometric Processing Privacy Code 2025 introduced to New Zealand
Open banking regulations released for consultation
Ten tips for buy-side M&A success
A recipe for disaster – Is caramel a copyright work?
Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)
Important changes made to the Privacy Act
New Zealand may ban social media for young users
Customer and Product Data Act update – Open banking officially on the way
Tips from the trenches – Your AI policy cheat sheet
Significant regulatory reform proposed for New Zealand media
Security guidance released for emerging tech companies
Customer and Product Data Bill – Select Committee reports back
Consumer law update 2024
New Zealand’s Artist Resale Royalty is ready to go
The shape of coffee – “Moccona” vs “Vittoria”
New Zealand’s Copyright Act gets a sense of humour
WIPO’s traditional knowledge treaty is adopted
Doing business in the Middle East
AI and advertising – What producers need to know
Seven contract clauses every freelancer needs
Baby Reindeer – When truth is stranger than fiction?
Our comments on the Biometric Processing Privacy Code
Therapeutic Products Act to be repealed this year
Is End-to-End to end?
Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement
Lawyers and Generative AI – New NZ Law Society guidance released
Facing the future – A biometrics code of practice for New Zealand?
Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?
Five Eyes release the Five Principles to Secure Innovation
The copyright conundrum with generative AI
Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools
Political advertising on social media: sludge or copyright quagmire?
Privacy Amendment Bill introduced to Parliament
New Data Privacy Framework: Meta gets a lifeline
The long and winding road to royalties
Implications of the Supreme Court’s “new debt” approach in Mainzeal
EU gets closer to AI laws
UK Supreme Court puts Quincecare ‘duty’ back in its box
A Deep Dive into The Customer and Product Data Bill
Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data
New NZ-UK Free Trade Agreement signals tech, media and IP law changes
Ditch the fax! Tips for building a tech-savvy law firm
The Incorporated Societies Act 2022 – what you need to know for your society
Common myths about copyright online
Artificial artist, or artificial plagiarist?
Big boost to gaming
Is your product “AI powered”?
The latest on New Zealand’s Consumer Data Right
Space Law in New Zealand
You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law
Open Banking is coming – through the Consumer Data Right
Massive SEC Fines for Companies Using Text and Instant Messaging
One Act to Rule Them All
A Legal Guide to Kicking SaaS
Potential changes to the Privacy Act 2020
NZ's Social Media "Code of Practice" Launched
Are you being unfair?
Are you legal?
Power Up 2022
A new Companies Office levy is one step closer
Has Paramount Pictures gone maverick?
From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners
I'm back, baby
Retail Payment System Act 2022 now in force
Paying the price for getting privacy wrong
Can AI be an inventor?
Finfluencer Crackdown
TIN Fintech Insights Report Launch
Britain seeks to regulate 'Big Tech'
Disclosure of personal information - how to, not don't do
The Spice May Flow, But The Copyright Doesn’t
Sound Recording Ownership (Taylor's Version)
The Lowdown (and Lockdown) on Summer Clerkships
Building Blocks of Trust
Firm News | Legal Rankings
Buy Now, Regulate Soon
Ten simple things
Funding the Future
Cyber Security for Start-ups
Fit for purchase
The Screen Industry Workers Bill
UK/New Zealand Trade Deal Takes Flight
Palmer v Alalääkkölä
Other articles you
might like
Hudson Gavin Martin was delighted to once again author the New Zealand chapter of Lexology In Depth: Space Law.
The Government’s new Cyber Security Strategy 2026–2030 and Action Plan 2026–2027 signal a renewed push to strengthen New Zealand’s resilience to digital threats.
IPP3A is almost here, and agencies that collect personal information indirectly need to prepare.







.jpg)







