New rule 3A introduced to the Biometric Processing Privacy Code

New rule 3A means individuals must be notified about indirect collection under the Biometric Processing Privacy Code 2025.

New rule 3A introduced to the Biometric Processing Privacy CodeNew rule 3A introduced to the Biometric Processing Privacy Code
Category
Insight | Tech
Insight
|
Tech
Published Date
1
April 2026
Reading Time

The Office of the Privacy Commissioner (OPC) has now settled how Information Privacy Principle 3A (IPP3A) will be incorporated into the Biometric Processing Privacy Code 2025 (the Code): through a new rule 3A dealing with indirect collection. This is an important development for agencies using biometric information for biometric processing, because it confirms that compliance does not stop at the point of direct capture.

New IPP3A applies from 1 May 2026 to personal information collected indirectly. In broad terms, where an agency collects personal information from someone other than the individual concerned, it must take reasonable steps, as soon as reasonably practicable after collection, to ensure the individual is aware of specified matters unless an exception applies. IPP3A does not apply to personal information collected indirectly before 1 May 2026. You can read more about IPP3A here.

New rule 3A

The OPC has now incorporated this indirect collection notification concept into the Code through a new rule 3A.

The Code already replaces the Information Privacy Principles in the Privacy Act 2020 with 13 targeted rules for biometric information, including a rule 3 that requires agencies to tell people about the collection of biometric information for the purpose of biometric processing where the biometric information is collected directly from the individual. Biometric information is regarded as highly sensitive personal information because it is closely connected to identity, may be difficult or impossible to replace if compromised, and can create broader concerns about surveillance, exclusion and fairness. You can read more about the Code here.

Rule 3A is being added to the Code to reflect IPP3A but will be modified to align with the existing rules and exceptions in the Code. The aim is clarity and consistency – agencies will have biometric-specific notification rules for both direct and indirect collection. So, for biometric deployments:

• Direct collection (e.g., an employer enrolling employees into a biometric verification access system operated by the employer) will be governed by rule 3.

• Indirect collection (e.g., a shared workspace business receiving biometric templates collected by an employer cohabiting in the shared workspace to enrol its employees into a biometric verification access system operated by the shared workspace business) will be governed by rule 3A.

In practice, rule 3A narrows IPP3A to make it fit with rule 3 of the Code, which is itself stricter than IPP3, especially as to the content and presentation of notices.

In particular, rule 3A of the Code does not include the full set of statutory exceptions available in IPP3A. The “not reasonably practicable”, “publicly available information”, “no prejudice to the individual” and “information used in a form where individual not identifiable” exceptions have been excluded from rule 3A. Agencies will also need to comply with the extra notification matters that are required by rule 3(1) and 3(2) of the Code compared with IPP3/IPP3A (such as whether there is any available alternative option).

Operationalising rule 3A

In practice, there may be situations where both IPP3A and rule 3A are relevant, and agencies will have to decide how to comply when the statutory frameworks do not fully align.

This could arise, for example, in a commercial scenario involving the use of a multi-party biometric identification system. Agencies could be subject to rule 3A of the Code for their biometric processing activities (i.e., indirectly collecting biometric information for the purpose of biometric processing) and subject to IPP3A for any indirect collection of other personal information (e.g., the names of individuals). In that scenario, agencies would have to apply one framework to the non-biometric processing components of the process (full IPP3A) and apply a different, narrower framework to the biometric processing components (rule 3A), even if both sets of information travel through the same technical pipelines and are presented to individuals in a single privacy notice.

This fragmentation may make it harder for agencies to design a coherent and efficient notification strategy. Agencies may still present a single privacy notice, but that notice must satisfy the IPP3A requirements for non-biometric processing and the Code’s more specific biometric-notification requirements where biometric processing is involved.

In these data-sharing arrangements, agencies cannot assume that the direct collector’s privacy notice solves the issue for everyone downstream. The logic of IPP3A, reflected in new rule 3A, is that the agency collecting the information indirectly bears the obligation of notification, and must be satisfied that the individual has been made aware of the relevant matters unless a recognised exception can properly be relied on. If the downstream indirect collector wants to rely on an upstream notice to satisfy the “previously been made aware” exception, it must have a sound evidential basis for concluding that the earlier notice made the individual aware of all the required matters (including the specific recipient and purposes).

Timing

The amendment to the Code to add rule 3A applies from 1 May 2026, which aligns with the commencement of IPP3A itself. However, the existing transition period for agencies already using biometric processing to become compliant with the Code remains until 3 August 2026.

The OPC’s position is that this means that:

• Agencies that started biometric processing after 3 November 2025 – when the Code took effect – must comply with rule 3A on 1 May 2026.

• Agencies that started biometric processing before or on 3 November 2025 must comply with rule 3A on 3 August 2026.

As with IPP3A, to give effect to rule 3A agencies will need to map biometric data flows carefully to identify where biometric information for biometric processing is collected directly, where it is received indirectly, which parties are acting only as service providers, and what notifications travel through which systems. Agencies will also need to review their privacy notices, check whether contractual arrangements support compliance with rule 3A and assess carefully whether any statutory exceptions apply.

Please contact our team if your organisation needs advice on complying with rule 3A.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

There are no services for this current insight. Take a look at our services page for more information on our different offerings.

Services in this insight

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore.

There are no services for this current insight. Take a look at our services page for more information on our different offerings.
Previous Article
Next Article

From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business

Space Law in New Zealand — Signals from the ground

Cyber security changes flagged for New Zealand

The four Cs of successful fintech partnerships

New rule 3A introduced to the Biometric Processing Privacy Code

IPP3A is nearly in force – What agencies need to know

OPC shifts public enquiries online – What agencies should do now

AI as a confidante? Legal privilege and the ever-increasing use of AI

New Therapeutic and Health Advertising Code – What you need to know

Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia

Consumer law update 2025

Open banking launches in New Zealand

Is fair something to fear? The Government announces beefed-up Fair Trading Act

Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta

Open banking almost live

Why New Zealand businesses should care about the EU Data Act

Product labelling changes flagged for New Zealand

Biometric Processing Privacy Code 2025 introduced to New Zealand

Open banking regulations released for consultation

Ten tips for buy-side M&A success

A recipe for disaster – Is caramel a copyright work?

Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)

Important changes made to the Privacy Act

New Zealand may ban social media for young users

Customer and Product Data Act update – Open banking officially on the way

Tips from the trenches – Your AI policy cheat sheet

Significant regulatory reform proposed for New Zealand media

Security guidance released for emerging tech companies

Customer and Product Data Bill – Select Committee reports back

Consumer law update 2024

New Zealand’s Artist Resale Royalty is ready to go

The shape of coffee – “Moccona” vs “Vittoria”

New Zealand’s Copyright Act gets a sense of humour

WIPO’s traditional knowledge treaty is adopted

Doing business in the Middle East

AI and advertising – What producers need to know

Seven contract clauses every freelancer needs

Baby Reindeer – When truth is stranger than fiction?

Our comments on the Biometric Processing Privacy Code

Therapeutic Products Act to be repealed this year

Is End-to-End to end?

Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement

Lawyers and Generative AI – New NZ Law Society guidance released

Facing the future – A biometrics code of practice for New Zealand?

Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?

Five Eyes release the Five Principles to Secure Innovation

The copyright conundrum with generative AI

Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools

Political advertising on social media: sludge or copyright quagmire?

Privacy Amendment Bill introduced to Parliament

New Data Privacy Framework: Meta gets a lifeline

The long and winding road to royalties

Implications of the Supreme Court’s “new debt” approach in Mainzeal

EU gets closer to AI laws

UK Supreme Court puts Quincecare ‘duty’ back in its box

A Deep Dive into The Customer and Product Data Bill

Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data

New NZ-UK Free Trade Agreement signals tech, media and IP law changes

Ditch the fax! Tips for building a tech-savvy law firm

The Incorporated Societies Act 2022 – what you need to know for your society

Common myths about copyright online

Artificial artist, or artificial plagiarist?

Big boost to gaming

Is your product “AI powered”?

The latest on New Zealand’s Consumer Data Right

Space Law in New Zealand

You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law

Open Banking is coming – through the Consumer Data Right

Massive SEC Fines for Companies Using Text and Instant Messaging

One Act to Rule Them All

A Legal Guide to Kicking SaaS

Potential changes to the Privacy Act 2020

NZ's Social Media "Code of Practice" Launched

Are you being unfair?

A new Companies Office levy is one step closer

Has Paramount Pictures gone maverick?

From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners

Retail Payment System Act 2022 now in force

Paying the price for getting privacy wrong

Can AI be an inventor?

Finfluencer Crackdown

TIN Fintech Insights Report Launch

Britain seeks to regulate 'Big Tech'

Disclosure of personal information - how to, not don't do

The Spice May Flow, But The Copyright Doesn’t

Sound Recording Ownership (Taylor's Version)

The Lowdown (and Lockdown) on Summer Clerkships

Building Blocks of Trust

Firm News | Legal Rankings

Buy Now, Regulate Soon

Ten simple things

Funding the Future

Cyber Security for Start-ups

Fit for purchase

The Screen Industry Workers Bill

UK/New Zealand Trade Deal Takes Flight

Palmer v Alalääkkölä

Other articles you
might like

The four Cs of successful fintech partnerships
2
April 2026

Negotiating a fintech partnership agreement is not a zero sum game.

Andrew Dentice

Partner

Open banking launches in New Zealand
2
December 2025

The official commencement of open banking in New Zealand is a significant milestone for the local industry.

Andrew Dentice

Partner

Kyra Vince

Special Counsel – Knowledge

New Data Privacy Framework: Meta gets a lifeline
1
September 2023

The European Commission has now adopted an adequacy decision for an EU-US Data Privacy Framework, adding a new twist to an ongoing tale.

Andrew Dentice

Partner