A recent NZ Tribunal ruling shows privacy risk is not just about data breaches. Over-collection, misuse and biased decisions based on outdated information can cause real harm. What NZ businesses need to know.
Stay informed about the Children's Privacy Code and its impact on NZ businesses. Discover why the Children's Privacy Code is crucial for your compliance.
The Biometric Processing Privacy Code 2025 is now law under the Privacy Act. It introduces a specific and enforceable set of rules for any organisation in New Zealand using biometric technologies such as facial recognition, voice ID, fingerprints, or similar tools to identify, verify, or categorise individuals.Key Dates • The Code comes into force on 3 November 2025 • Organisations already using biometric systems must comply by 3 August 2026 This Code substitutes the 13 standard privacy princi
A finance business recently found itself under scrutiny after a fraud incident exposed significant gaps in its privacy practices, including a failure to notify the Privacy Commissioner as required under the Privacy Act.A caller pretending to be a customer was able to mislead staff, access the customer’s account, and make unauthorised changes and transactions. Not once, but multiple times. Even though the customer raised repeated concerns that someone was accessing and using their personal inform
A recent case from the NZ Privacy Commissioner, Case Note 329275 [2025] NZ Priv Cmr 2, is a timely reminder that good intentions do not always equal lawful use.A company took a photo of a short-term employee during their factory work. The employee believed the photo was for internal use only. Two years later, after they had left the country, they discovered their image was being used widely in public marketing, including on the side of the building, in shopping centres, and in the company’s annu
From 1 May 2026, agencies that collect personal information indirectly will need to notify individuals, unless an exception applies. The draft guidance is open for consultation until 25 June 2025.What stands out is how clear the OPC is about what compliance looks like.For example, the Guidance states:▶️ A bank is collecting the information and plans to send it on to a financial services company. The bank needs to tell the individual the name of the company it is sending the information to.... It
As a parent, it was heartbreaking to read how sensitive personal information was accessed and shared in ways that directly led to harm, including physical violence. And this is just a “snapshot” of what was reported.The reality is this: you can’t bolt privacy on after the fact.You need to build a culture that treats privacy as a layer of protection, not a layer of red tape. Without that mindset, even the best policies and procedures will fail.What stood out to me most was the quote that some soc
Great to hear from Michael Webster, New Zealand’s Privacy Commissioner, at the Buddle Findlay event a few weeks ago. He covered key privacy challenges, including: • Recent breaches and lessons learned. • IPP5 expectations—security and third-party sharing. • Biometrics and the progress of the new Privacy Code. • GDPR adequacy status and its implications. • Employee browsing risks—a growing concern.On employee browsing, the Commissioner highlighted that this is an increasingly serious risk, especi
A few commercial clients have asked how to manage tariff risks in their contracts. Tariff uncertainty is creating real challenges for businesses, from rising costs to supply chain disruptions. Reviewing key contract terms now can help mitigate risk. Key provisions to review: • Force Majeure: May not cover tariffs unless clearly drafted. • Change in Law/Tax Clauses: Can adjust pricing or timelines if tariffs impact costs. • Termination Clauses: Consider exit options for tariff-driven price incre