A recent NZ Tribunal ruling shows privacy risk is not just about data breaches. Over-collection, misuse and biased decisions based on outdated information can cause real harm. What NZ businesses need to know.
Stay informed about the Children's Privacy Code and its impact on NZ businesses. Discover why the Children's Privacy Code is crucial for your compliance.
A recent case from the NZ Privacy Commissioner, Case Note 329275 [2025] NZ Priv Cmr 2, is a timely reminder that good intentions do not always equal lawful use.A company took a photo of a short-term employee during their factory work. The employee believed the photo was for internal use only. Two years later, after they had left the country, they discovered their image was being used widely in public marketing, including on the side of the building, in shopping centres, and in the company’s annu
From 1 May 2026, agencies that collect personal information indirectly will need to notify individuals, unless an exception applies. The draft guidance is open for consultation until 25 June 2025.What stands out is how clear the OPC is about what compliance looks like.For example, the Guidance states:▶️ A bank is collecting the information and plans to send it on to a financial services company. The bank needs to tell the individual the name of the company it is sending the information to.... It
As a parent, it was heartbreaking to read how sensitive personal information was accessed and shared in ways that directly led to harm, including physical violence. And this is just a “snapshot” of what was reported.The reality is this: you can’t bolt privacy on after the fact.You need to build a culture that treats privacy as a layer of protection, not a layer of red tape. Without that mindset, even the best policies and procedures will fail.What stood out to me most was the quote that some soc
Great to hear from Michael Webster, New Zealand’s Privacy Commissioner, at the Buddle Findlay event a few weeks ago. He covered key privacy challenges, including: • Recent breaches and lessons learned. • IPP5 expectations—security and third-party sharing. • Biometrics and the progress of the new Privacy Code. • GDPR adequacy status and its implications. • Employee browsing risks—a growing concern.On employee browsing, the Commissioner highlighted that this is an increasingly serious risk, especi