Get in touch Frequently asked questions
Start with a
clear answer.
Plain English answers to common questions about privacy, biometrics, AI, data, intellectual property and information disputes in New Zealand.
Biometrics
03Can my New Zealand business collect biometric information from staff or customers?+
Potentially, but the Biometric Processing Privacy Code 2025 now applies. Before collecting or using biometric information, an organisation generally needs to establish a lawful purpose, test whether the processing is necessary and proportionate, consider less intrusive alternatives, provide the required notice and put appropriate safeguards in place. The answer depends on the proposed technology, purpose, setting and effect on people.
What did the Biometric Processing Privacy Code change?+
The Code introduced rules written specifically for biometric processing, including stronger necessity and proportionality requirements, detailed transparency obligations, limits on some uses and an express need to consider alternatives. It covers biometric identification and categorisation using features such as faces, fingerprints, voices and behavioural patterns. The transition period for existing users ended on 3 August 2026.
Do I need consent to use facial recognition in my business?+
Not in every case, but consent does not by itself make facial recognition lawful or proportionate. The organisation must still satisfy the Privacy Act and the Biometric Processing Privacy Code, including the purpose, necessity, proportionality, notification and safeguard requirements that apply to the particular use. A documented assessment should be completed before deployment.
Privacy & data
05What are the core obligations under the Privacy Act 2020?+
Most organisations must comply with the Information Privacy Principles across the lifecycle of personal information: collection, storage, use, disclosure, access, correction and disposal. Since 1 May 2026, IPP 3A also requires notification when personal information is collected indirectly, unless an exception applies. Organisations must appoint at least one Privacy Officer, respond to access and correction requests and notify the Privacy Commissioner and affected people when a privacy breach is notifiable.
Do I need to appoint a Privacy Officer?+
Yes. Every agency must have at least one Privacy Officer under the Privacy Act 2020. The role may be held by a staff member and does not have to be held by a lawyer. An external adviser can also support the function where an organisation needs additional capacity, specialist judgement or independence.
How does IPP 12 affect overseas data transfers?+
IPP 12 restricts disclosure of personal information to a foreign person or entity unless a permitted safeguard applies. Common routes include comparable privacy protection, a binding contractual commitment to comparable safeguards or the individual’s informed authorisation. The analysis depends on the facts, including whether an overseas cloud or service provider is acting only as your agent or is receiving the information for its own purposes.
What should a New Zealand data sharing agreement include?+
It should state the purpose and authority for sharing, the information in scope, permitted uses, security standards, breach responsibilities, access and audit rights, retention or deletion requirements, liability settings and what happens at the end of the arrangement. The contract should reflect the real information flow rather than relying on generic wording.
When does a commercial contract need a data processing agreement?+
A separate data processing schedule is often useful when a supplier processes personal information for a customer, including SaaS, outsourcing, payroll, customer support and AI services. It should deal with permitted processing, security, incidents, subprocessors, overseas handling, audit, deletion and liability. Whether it needs to be a separate document depends on the structure of the main agreement.
AI
04What does responsible AI mean for a New Zealand business?+
It means having a documented way to decide when AI may be used, how risk is assessed, who is accountable, what human oversight is required and how performance is monitored. Existing privacy, consumer, human rights, contractual and negligence law can apply even without a single general AI statute.
How does the Privacy Act 2020 apply to AI?+
If an AI system is trained on, receives or produces personal information, the Information Privacy Principles may apply to the collection, accuracy, security, use, disclosure and retention of that information. Organisations remain responsible for understanding what their tools and vendors do with personal information and for setting appropriate contractual and operational controls.
What should an AI governance framework include?+
A workable framework should define what counts as AI, assign ownership, tier uses by risk, require proportionate assessment before deployment and establish monitoring, escalation and retirement processes. It should also address staff use of general purpose tools, procurement, data handling, output checking, record keeping and incident response.
Do contracts with AI vendors need special clauses?+
Usually. Relevant clauses may cover rights in inputs and outputs, use of customer data for model training, confidentiality, security, transparency about model changes, accuracy and human review, intellectual property infringement, incident notification, audit rights, subcontracting and liability. The priorities depend on the tool and the decision it supports.
Assessments
08What is a privacy maturity assessment?+
It is a structured review of how well an organisation manages privacy across governance, people, processes, systems and assurance. Unlike a privacy impact assessment for a particular initiative, a maturity assessment looks across the organisation, identifies gaps and produces a prioritised improvement roadmap.
Why should my business consider a privacy maturity assessment?+
It gives leadership an independent view of current privacy risk, helps prioritise investment and creates a clear plan for improvement. It can also help answer assurance questions from boards, regulators, insurers, major customers and transaction partners, particularly in health, financial services and other sectors that handle large amounts of information.
Why have a lawyer lead a privacy maturity assessment?+
A lawyer can connect operational findings to the legal risks under the Privacy Act, contracts and related obligations. Where the assessment is commissioned and conducted for the purpose of obtaining legal advice, legal professional privilege may also apply to some communications or work product. Privilege depends on the context and should be structured deliberately rather than assumed.
What does a privacy maturity assessment cover?+
A full review commonly covers governance and accountability, policies, notices and consent, data inventory and lifecycle management, security and breach response, individual rights, vendor management, training, monitoring and assurance. The output should distinguish legal risk from operational improvement and turn both into a practical action plan.
How long does a privacy maturity assessment take?+
For a small or medium sized organisation, a focused assessment often takes around four to six weeks from scoping to final report. Timing depends on organisational size, complexity, the number of interviews and the quality of existing documentation. Scope, timing and deliverables can be agreed at the outset.
When does my business need a privacy impact assessment?+
New Zealand law does not impose a general PIA requirement for every project, but the Privacy Commissioner expects organisations to use PIAs for new or higher risk information practices. Biometrics, AI, profiling, sensitive information, major data sharing and new overseas arrangements are common triggers. Some specific regimes, including the Biometric Processing Privacy Code, impose more particular assessment obligations.
What does a useful privacy impact assessment cover?+
It maps the information flows, tests the proposal against the applicable privacy rules, considers the effects on people, examines necessity and alternatives, identifies safeguards and records who accepted any remaining risk. The result should support a sound decision, not simply complete a checklist.
Should we do the PIA internally or bring in an external lawyer?+
A capable internal team can often manage a straightforward assessment with lower risk. Independent specialist support is useful for biometrics, AI, sensitive information, novel uses, complex sharing, contentious projects or any matter likely to receive regulatory or public scrutiny. External counsel can work alongside the project team while testing assumptions and strengthening the final decision record.
IP & disputes
02What intellectual property work does O’Brien Legal do?+
The practice covers both commercial IP and strategy or enforcement. That includes ownership and chain of title reviews, copyright and trade mark advice, licensing, assignments, development and collaboration agreements, commercialisation, brand protection strategy, infringement analysis, cease and desist correspondence, negotiated resolutions and litigation strategy with specialist counsel where needed.
Can O’Brien Legal help when a dispute has already started?+
Yes. O’Brien Legal advises on complex contractual disputes, including substantial construction claims, as well as breach of confidence, privacy, data, technology, intellectual property, defamation and reputation matters. Rachel also advises on privacy issues arising within employment and relationship property disputes. The work can include case strategy, evidence preservation, urgent correspondence, negotiations, settlement and working with specialist barristers when court proceedings or urgent relief are required.
Working with O’Brien Legal
01Does O’Brien Legal use AI and modern legal technology?+
Yes. Where appropriate, O’Brien Legal uses carefully selected AI and modern legal technology to support research, document analysis, drafting and efficient delivery. Technology supports the work. Rachel remains responsible for the legal analysis and advice, with confidentiality, privacy and professional obligations kept at the centre of each matter.
These answers provide general information only and are not legal advice. The position may depend on the facts and may change as the law and regulatory guidance develop.