Important changes made to the Privacy Act

New Zealand’s Privacy Act 2020 amended to include the indirect collection of personal information.

Important changes made to the Privacy ActImportant changes made to the Privacy Act
Category
Insight | General
Insight
|
General
Published Date
5
June 2025
Reading Time

Key changes to New Zealand’s Privacy Act 2020 (the Act) have recently been passed by Parliament. The most significant change is the introduction of a new Information Privacy Principle – IPP3A – which specifically addresses the indirect collection of personal information. Several technical amendments have also been made to address minor issues that have arisen since the Act first came into force.

The Office of the Privacy Commissioner (OPC) has released guidance on IPP3A (the Guidance) for public consultation. The Guidance is only a draft but gives some insight into how IPP3A will be enforced.

IPP3A

Under the Act, agencies were required to notify individuals when collecting personal information directly from them (IPP3), but there was no requirement for notification when information was collected from other sources (indirectly). As such, individuals could be unaware that an agency held and used their personal information, and this lack of transparency meant they were unable to exercise their rights to access, correct, or object to the use of their information.

IPP3A now requires agencies to take reasonable steps to notify individuals when their personal information is collected indirectly, unless one of the listed exceptions apply. The rule will only apply to personal information collected from 1 May 2026.

This change helps align New Zealand’s privacy law with international best practice and supports the country’s ongoing EU adequacy status, which facilitates the free flow of personal data from the European Union to New Zealand. IPP3A also brings New Zealand into line with the Australian legal position.

Notification requirements

As we have discussed before, new IPP3A is largely based on existing IPP3. The notification must include:

• The fact that the information has been collected;

• The name and address of the agency collecting and holding the information;

• The purposes for which the information is being collected;

• The recipients of the information;

• Whether the collection is authorised or required by law; and

• The individual’s rights of access to, and correction of, the information.

Notifications must be specific and clear. The OPC expects agencies to use plain language and, where possible, to name the third parties involved (more on this later).

Timing of notification

An agency is required to inform an individual as soon as reasonably practical after the information has been collected, unless the notification steps have already been taken.

The Guidance states that what is reasonably practical will “depend on the circumstances of the indirect collection, taking into consideration the available knowledge, cost, and effort involved”. For example, if an agency would need to hire additional staff to meet the notification requirements within two weeks but could notify with existing staff within four weeks, then what is reasonably practical would be to notify within four weeks.

Exceptions

There are practical exceptions to the notification requirement, such as when the individual is already aware of the collection, when compliance would be impractical or undermine the purpose of collection, where there is no prejudice to the individual from non-notification, or where information is anonymised, or used for statistical purposes. These exceptions are the same that apply in respect of IPP3.

IPP3A also introduces additional exceptions specifically for indirect collections. These apply in a more limited way, and include when an agency collects personal information for archiving purposes, and notification is likely to seriously impair achievement of this; where compliance would prejudice the security or defence of New Zealand, or the international relations of the Government of New Zealand; and where informing the individual concerned would cause a serious threat to public health or safety, or to the health or safety of another individual.

The Guidance notes that once an agency can no longer rely on an exception, it should notify the individual that it has collected their information indirectly. Agencies therefore need to be regularly assessing the situation as it evolves to determine whether an exception continues to apply.

Intermediaries

An important practical exception to IPP3A is when the individual has already been notified of the indirect collection. For example, if one agency (the disclosing agency) collects personal information directly from an individual and shares it with another agency (the collecting agency), the collecting agency does not need to comply with IPP3A if the disclosing agency has already informed the individual of the indirect collection.

The Guidance gives a clear steer on what is required to rely on this exception:

• If the disclosing agency is to be responsible for the notification requirements, it will need to be specific about who is indirectly collecting the personal information i.e., by naming specific organisations or companies rather than just describing a type or class of agency. For example, it is not sufficient to say, “we may share your information with a credit reporting agency”. However, if the disclosing agency knows that in certain situations it will always share information with specific agencies, it can notify individuals generally of the circumstances in which it would always send information to those agencies.

• The collecting agency will need to have a “sound basis” for believing the disclosing agency has informed the individual. This should be based on evidence rather than an assumption. One way to ensure this is to make the notification requirements part of the contractual arrangement i.e., both agencies agree that the organisation that originally collects the information from the individual concerned will make them aware of the required information, so that the collecting agency does not need to notify them again.

• The collecting agency will still need to have “reasonable grounds” to believe that the disclosing agency is in fact informing individuals as required. This could be achieved by receiving and filing a copy of a form signed by an individual, or through regular contract reporting requirements.

Note also that if an agency is using a third party provider (e.g., an IT service provider) that does not collect and use the information for its own purposes, then section 11 of the Act will continue to apply, and the agency will remain responsible for complying with IPP3A (not the third party).

IPP3A checklist

So, what should organisations do to prepare for IPP3A?

Understand data collection practices

Organisations should first audit their data collection practices to identify all instances where personal information is collected from sources other than the individual (e.g., from third parties or public records) and to understand whether (and how) individuals are notified of the indirect collection.

Assess whether exceptions apply

When there is indirect collection, organisations should assess whether there are any exceptions to IPP3A notification that they can rely on. This is a technical area, so agencies need to stay updated with the OPC’s evolving guidance and should consider taking legal advice.

When relying on an exception, agencies should document their decisions and reasoning as this may be scrutinised later by the OPC. The intention of IPP3A is to give people more information and control over who has their personal information, and we can expect the OPC to assess exceptions through this lens. The Guidance reflects the OPC’s general view that even though an organisation may not be required to notify individuals of indirect collection, that doesn’t mean it shouldn’t notify anyway.

Remember that agencies cannot automatically rely indefinitely on an exception to notification. Agencies need to have operational processes to regularly assess whether an exception continues to apply and to act to meet the notification requirements if circumstances change.

Review and update third party contracts

If an organisation receives indirect collection from an intermediary agency, it should confirm that the intermediary is contractually obligated to:

• Provide all necessary notifications to the individuals concerned; and

• Supply the organisation with enough information to reasonably conclude that IPP3A compliance obligations are being met. This could include copies of signed forms or consent documents, periodic compliance reports, or regular audits.

Businesses that manage data on behalf of clients (e.g., cloud or IT service providers) should ensure their contracts specify that responsibility for notifications to customers remains with the client to avoid doubt. Where such businesses also use client data for their own purposes (e.g., improving their products or services), then they will need to also ensure that the client is contractually obligated as set out above.  

Develop notification processes

Where there is no statutory exception, agencies will need to develop procedures to notify individuals either before indirect collection or as soon as reasonably practical after. Remember that what is reasonably practical will depend on the circumstances of the indirect collection, weighing up the cost, effort, and available knowledge. Inconvenience, expense, or administrative burden do not automatically mean notification is “not reasonably practical”.

Organisations need to ensure that notifications cover all the required details (fact of collection, purpose, recipients, agency name and address, legal basis, and rights of access/correction). It should be explained in plain language, where possible. Automated notifications can ensure consistency and timeliness.

Review and update privacy policies

Agencies should review and update their privacy policies to ensure they clearly explain indirect collection practices, specifying what information is collected, the purposes, and who it will be shared with. Remember the requirement for specificity – based on the Guidance, organisations need to be explicit about the type of information and the intended recipients, including naming third party organisations.

This may be an area where the Guidance is refined following public consultation, as this level of specificity is a material change to the way privacy statements are currently prepared. Constantly updating notifications to change the specifics could present significant administrative cost for organisations with large-scale or complex data environments. Overly frequent or duplicate notifications might also reduce the effectiveness of privacy communications and increase “notification fatigue” among individuals.

Implement training

Many organisations will benefit from giving updated training to their people about the new requirement and the specific steps needed for compliance. This will likely include training on identifying when indirect collection occurs and how to handle exceptions. The OPC has said it will take a risk-based approach to enforcement of IPP3A, focusing on the impact of non-notification and the agency’s efforts to comply.

Meet the deadline

The new requirements are planned to take effect from 1 May 2026 (an extension from the original 1 June 2025 commencement date), so there is time for organisations to review and update their systems and processes.

The Guidance itself is open for public consultation until 25 June 2025.

Putting privacy principles into practice often involves navigating complex issues. We’re here to help – contact us anytime for support.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore.

There are no services for this current insight. Take a look at our services page for more information on our different offerings.
Previous Article
Next Article

Consultation opens on New Zealand's payment services regulation

Modern slavery regulation on the way – Is your business ready?

From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business

Space Law in New Zealand — Signals from the ground

Cyber security changes flagged for New Zealand

The four Cs of successful fintech partnerships

New rule 3A introduced to the Biometric Processing Privacy Code

IPP3A is nearly in force – What agencies need to know

OPC shifts public enquiries online – What agencies should do now

AI as a confidante? Legal privilege and the ever-increasing use of AI

New Therapeutic and Health Advertising Code – What you need to know

Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia

Consumer law update 2025

Open banking launches in New Zealand

Is fair something to fear? The Government announces beefed-up Fair Trading Act

Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta

Open banking almost live

Why New Zealand businesses should care about the EU Data Act

Product labelling changes flagged for New Zealand

Biometric Processing Privacy Code 2025 introduced to New Zealand

Open banking regulations released for consultation

Ten tips for buy-side M&A success

A recipe for disaster – Is caramel a copyright work?

Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)

Important changes made to the Privacy Act

New Zealand may ban social media for young users

Customer and Product Data Act update – Open banking officially on the way

Tips from the trenches – Your AI policy cheat sheet

Significant regulatory reform proposed for New Zealand media

Security guidance released for emerging tech companies

Customer and Product Data Bill – Select Committee reports back

Consumer law update 2024

New Zealand’s Artist Resale Royalty is ready to go

The shape of coffee – “Moccona” vs “Vittoria”

New Zealand’s Copyright Act gets a sense of humour

WIPO’s traditional knowledge treaty is adopted

Doing business in the Middle East

AI and advertising – What producers need to know

Seven contract clauses every freelancer needs

Baby Reindeer – When truth is stranger than fiction?

Our comments on the Biometric Processing Privacy Code

Therapeutic Products Act to be repealed this year

Is End-to-End to end?

Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement

Lawyers and Generative AI – New NZ Law Society guidance released

Facing the future – A biometrics code of practice for New Zealand?

Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?

Five Eyes release the Five Principles to Secure Innovation

The copyright conundrum with generative AI

Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools

Political advertising on social media: sludge or copyright quagmire?

Privacy Amendment Bill introduced to Parliament

New Data Privacy Framework: Meta gets a lifeline

The long and winding road to royalties

Implications of the Supreme Court’s “new debt” approach in Mainzeal

EU gets closer to AI laws

UK Supreme Court puts Quincecare ‘duty’ back in its box

A Deep Dive into The Customer and Product Data Bill

Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data

New NZ-UK Free Trade Agreement signals tech, media and IP law changes

Ditch the fax! Tips for building a tech-savvy law firm

The Incorporated Societies Act 2022 – what you need to know for your society

Common myths about copyright online

Artificial artist, or artificial plagiarist?

Big boost to gaming

Is your product “AI powered”?

The latest on New Zealand’s Consumer Data Right

Space Law in New Zealand

You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law

Open Banking is coming – through the Consumer Data Right

Massive SEC Fines for Companies Using Text and Instant Messaging

One Act to Rule Them All

A Legal Guide to Kicking SaaS

Potential changes to the Privacy Act 2020

NZ's Social Media "Code of Practice" Launched

Are you being unfair?

A new Companies Office levy is one step closer

Has Paramount Pictures gone maverick?

From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners

Retail Payment System Act 2022 now in force

Paying the price for getting privacy wrong

Can AI be an inventor?

Finfluencer Crackdown

TIN Fintech Insights Report Launch

Britain seeks to regulate 'Big Tech'

Disclosure of personal information - how to, not don't do

The Spice May Flow, But The Copyright Doesn’t

Sound Recording Ownership (Taylor's Version)

The Lowdown (and Lockdown) on Summer Clerkships

Building Blocks of Trust

Firm News | Legal Rankings

Buy Now, Regulate Soon

Ten simple things

Funding the Future

Cyber Security for Start-ups

Fit for purchase

The Screen Industry Workers Bill

Other articles you
might like

Modern slavery regulation on the way – Is your business ready?
6
May 2026

New modern slavery legislation is progressing through Parliament and is now open for public consultation.

Luiz Buck

Luiz Buck

Senior Associate

Space Law in New Zealand — Signals from the ground
28
April 2026

Hudson Gavin Martin was delighted to once again author the New Zealand chapter of Lexology In Depth: Space Law.

Lisa Paz

Lisa Paz

Senior Associate

Cyber security changes flagged for New Zealand
13
April 2026

The Government’s new Cyber Security Strategy 2026–2030 and Action Plan 2026–2027 signal a renewed push to strengthen New Zealand’s resilience to digital threats.

Luiz Buck

Luiz Buck

Senior Associate

Simon Martin

Simon Martin

Partner