Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Step 1: Audit your data collection points
- Step 2: Identify what you collect and why
- Step 3: Check sharing, storage, and overseas disclosure
- Step 4: Set out access and correction rights
- Step 5: Cover complaints and internal responsibility
- Step 6: Align the policy with your real documents and systems
- Common mistakes New Zealand businesses make
- How often should you update a privacy policy?
- Key Takeaways
Many New Zealand businesses collect personal information long before they realise they need to explain what they are doing with it. A website contact form, online checkout, mailing list signup, recruitment page, customer support inbox, or staff records system can all trigger privacy obligations. The common mistakes are usually simple, but costly: copying an overseas privacy policy that does not match New Zealand law, using vague wording that does not reflect actual business practices, or forgetting to cover third party apps, payment providers, and cloud software.
A privacy policy is not just website filler. It is one of the clearest ways to show customers, clients, suppliers, and staff how your business handles personal information. If your policy says one thing and your systems do another, that gap can create compliance issues, complaints, and trust problems. Here’s what creating a privacy policy for businesses in New Zealand usually involves, when you need one, what should go into it, and where founders often get caught before they launch online, collect leads, or sign up to new software.
Overview
A New Zealand privacy policy should accurately explain what personal information your business collects, why you collect it, how you use and store it, who you share it with, and how people can access or correct their information. The main legal framework is the Privacy Act 2020, but your policy should also fit the way your business actually operates across your website, contracts, marketing, hiring, and customer service.
- Identify every place your business collects personal information, including online forms, checkout pages, email enquiries, recruitment, and offline records.
- Match your policy to your real practices, not a generic overseas template.
- Explain collection purposes clearly, including customer service, account setup, fulfilment, marketing, recruitment, and legal compliance where relevant.
- State whether information is shared with payment providers, IT platforms, couriers, advisers, or offshore service providers.
- Include a clear process for access, correction, and privacy complaints.
- Review the policy whenever you add a new app, sales channel, loyalty programme, or marketing process.
What Creating a Privacy Policy Means For New Zealand Businesses
Creating a privacy policy means documenting, in plain English, how your business handles personal information and making sure that statement reflects your day to day operations.
For New Zealand businesses, the key legal context is the Privacy Act 2020. That Act sets out privacy principles covering collection, use, storage, access, correction, and disclosure of personal information. A privacy policy is not the whole of your compliance, but it is often the public facing explanation of how you meet those obligations.
If you are trying to start a business in New Zealand, privacy can show up earlier than expected. Founders often focus on registration, business structure, branding, contracts, and trade mark issues first. Those all matter, but privacy usually appears the moment you build a website, collect customer enquiries, hire staff, run digital ads, or start selling online.
A good privacy policy should answer practical questions people actually have, such as:
- What information are you collecting about me?
- Why do you need it?
- Will you send me marketing?
- Who else gets access to it?
- Is my information sent overseas through your software providers?
- How do I ask for a copy or correct a mistake?
That matters for more than legal compliance. If a potential customer is deciding whether to buy from a new online store, book a service, sign up for a platform, or submit a quote request, a clear privacy policy can support trust. If the policy is missing, clearly copied from another market, or inconsistent with your checkout and email practices, people notice.
What counts as personal information?
Personal information is broadly any information about an identifiable individual. For a small business, that can include obvious details like names and email addresses, but also information that founders sometimes overlook.
- Phone numbers and physical addresses
- Payment and billing details
- Customer order history
- IP addresses or device information where it can relate to an identifiable person
- Support correspondence
- CCTV footage
- Employee records and job applicant information
- Health or dietary information for certain services or events
The main risk is assuming privacy only matters for tech companies or large platforms. A café taking online orders, a tradie using a quote form, a consultant storing client notes, or an eCommerce brand using retargeting tools may all need a properly drafted privacy policy and, in some cases, a cookie policy.
Why a website policy is not enough on its own
A privacy policy often sits on a website, but your obligations do not stop there. Your business should also think about collection notices, internal processes, staff training, software settings, supplier terms, and incident response.
This is where founders often get caught. They publish a policy, then later add a new CRM, email platform, booking system, loyalty app, or offshore contractor without updating anything. The result is a policy that no longer matches reality.
If you collect personal information through contracts, forms, social media messaging, events, phone calls, or in person transactions, those channels should align with what the policy says.
When This Issue Comes Up
Privacy policy work usually comes up when a business starts collecting information in a new way, or when growth makes informal practices too risky.
For many founders, that first moment is launching online. You may be building a website, setting up a Shopify store, adding newsletter signup fields, or integrating payment and delivery systems. Even a simple contact form can mean you need to explain what happens to the information submitted.
It also comes up before you sign a contract with a software provider. Many cloud tools collect, host, analyse, or transfer customer information. If your business uses offshore platforms for email marketing, file storage, analytics, customer support, or payroll, your privacy documentation should deal with those arrangements.
Common trigger points
- You are launching a website or app.
- You are selling online and collecting customer account, payment, or delivery details.
- You are building a mailing list or running promotions.
- You are hiring staff or contractors and collecting applicant information.
- You are introducing CCTV, access control, or visitor logs.
- You are expanding into a new industry with tighter privacy expectations, such as health, education, or financial services.
- You are responding to a customer complaint or data incident.
- You are preparing for investment, due diligence, or a sale process and need your documents in order.
Privacy issues can also surface when you update your business structure or operational model. For example, if you move from a sole trader setup to a company, add a franchise style network, or start using third party fulfilment providers, your data flows can change. Your policy should change too.
Different industries will face different privacy risks. A recruitment business may collect CVs, referee comments, and identity records. A clinic may handle more sensitive information. A SaaS business may process customer data through multiple integrations. A retail brand may collect behavioural data for marketing. The policy should reflect the specific legal requirements and practical reality of that business.
Privacy can overlap with other business legal issues as well. If you are preparing website terms, customer terms, employment agreements, contractor agreements, or marketing content, the promises in those documents should not conflict with your privacy wording. The same applies if you are promoting your brand and protecting it with a trade mark. Trust and transparency matter across the whole customer journey, not just on a standalone privacy page.
Practical Steps And Common Mistakes
The best way to create a privacy policy is to map what your business actually does first, then draft the policy around those facts.
Step 1: Audit your data collection points
Start with a practical review before you spend money on setup or publish a policy. List every point where your business receives personal information.
- Website contact forms
- Checkout pages and customer accounts
- Email enquiries
- Phone calls and customer support tickets
- Newsletter signup forms
- Social media lead forms and direct messages
- Recruitment forms and CV submissions
- In person forms, waivers, and sign in sheets
- CCTV and security systems
- Supplier and contractor onboarding records
This step helps you avoid a common problem, a policy that only covers website visitors when the business actually collects much more.
Step 2: Identify what you collect and why
Your policy should explain the categories of personal information you collect and the reasons for collecting them. Keep the wording specific enough to be meaningful, but flexible enough to reflect real operations.
Typical collection purposes can include:
- Providing products or services
- Processing orders and payments
- Arranging delivery or bookings
- Managing accounts and customer support
- Sending service updates
- Marketing, where permitted and consistent with your practices
- Recruitment and HR administration
- Meeting legal obligations
- Improving systems, security, and user experience
Avoid broad statements that say you collect information for “any business purpose” or “as required”. Those phrases often create more uncertainty than protection.
Step 3: Check sharing, storage, and overseas disclosure
Many New Zealand businesses rely on third party providers. Your website host, cloud storage system, payment gateway, email platform, payroll software, booking app, analytics tool, or CRM may all receive or hold personal information.
Your policy should say, in clear terms, whether information is shared with service providers and whether it may be stored or processed outside New Zealand. That does not mean listing every tool in technical detail, but it does mean being honest about the categories of recipients and the fact of offshore handling where relevant.
This area is easy to miss when founders use plug and play software. A business may think it stores data “locally” because the team works in New Zealand, even though the software provider hosts information in Australia, the United States, Singapore, or elsewhere.
Step 4: Set out access and correction rights
People generally have rights to request access to their personal information and ask for corrections. Your privacy policy should explain how they can contact your business about those requests.
Keep this practical. Use a clear contact point, explain that you may need to verify identity, and make sure someone in the business is responsible for handling requests. A policy is only useful if your team can follow it in practice.
Step 5: Cover complaints and internal responsibility
Your policy should tell people how to raise privacy concerns. It should also name the role or team responsible for privacy issues, even if that is simply the business owner or operations manager in a smaller company.
If your business experiences a privacy incident, confusion over internal responsibility can make the response slower and riskier. Deciding this in advance is much easier than sorting it out after a complaint arrives.
Step 6: Align the policy with your real documents and systems
A privacy policy should not sit in isolation. Review your related business documents and workflows so they do not contradict each other.
- Website terms
- Customer contracts or customer terms
- Subscription or platform terms
- Employment agreements and onboarding forms
- Contractor agreements
- Supplier arrangements involving customer data
- Marketing consent processes
- Internal data retention and security practices
For example, if your sign up form says customers will receive promotional emails, your policy should address marketing use. If your contracts promise confidentiality or restricted data use, your privacy wording should support that promise.
Common mistakes New Zealand businesses make
The most common privacy policy mistakes are not usually dramatic. They are everyday shortcuts that create legal and commercial problems later.
- Using an Australian, UK, or US template without adapting it to New Zealand law and business practice.
- Describing data practices that the business does not actually follow.
- Failing to mention third party service providers or offshore storage.
- Forgetting staff, contractor, or recruitment information.
- Collecting more information than needed without a clear reason.
- Publishing a policy once and never reviewing it.
- Ignoring cookies, analytics, or marketing tracking where those tools are relevant.
- Leaving out clear contact details for access, correction, or complaints.
Another mistake is treating privacy as a one off website task. If your business grows, launches a new sales channel, enters a regulated industry, or changes software, your privacy settings, contracts, and policy all need a second look.
How often should you update a privacy policy?
You should review your privacy policy whenever your data practices change in a meaningful way. For many SMEs, an annual review is sensible, with additional updates when there is a new website feature, a new software platform, a marketing shift, or a business restructure.
This is particularly relevant before you launch online in a new market, before you onboard a new provider, or before due diligence with an investor or purchaser. A stale policy can become a red flag quickly.
FAQs
Do all New Zealand businesses need a privacy policy?
Not every business is legally required to publish a standalone privacy policy in every circumstance, but if your business collects personal information, having a clear policy is usually a sensible and expected part of compliance. For most businesses with a website, staff, customers, or digital systems, it is a practical necessity.
Can I copy a privacy policy from another business?
No, that is risky. A copied policy may not match your actual practices, your software setup, or New Zealand legal context. The main issue is not wording style, it is accuracy.
What should a privacy policy include?
It should usually cover what personal information you collect, how you collect it, why you collect it, how you use it, who you share it with, whether it is stored or processed overseas, how people can access or correct it, and how to make a complaint.
Do I need to mention offshore cloud providers?
If personal information is stored or processed overseas through your business systems, your policy should deal with that clearly. Many SMEs use offshore providers without realising it, so this is worth checking before you publish.
Is a privacy policy enough to comply with privacy law?
No. A privacy policy is only one part of privacy compliance. Your actual collection practices, internal processes, staff handling, security measures, and response to requests or incidents also matter.
Key Takeaways
- Creating a privacy policy for businesses in New Zealand means explaining, accurately and clearly, how your business collects, uses, stores, and shares personal information.
- The Privacy Act 2020 is the core legal framework, but your policy also needs to fit your website, contracts, marketing, recruitment, and software tools.
- Founders often get caught by generic templates, undeclared third party apps, offshore data storage, and policies that no longer match actual business practice.
- A useful privacy policy should cover collection points, purposes, sharing, overseas disclosure, access and correction rights, and complaint handling.
- Privacy should be reviewed alongside business structure changes, online selling setups, customer terms, employment documents, and other legal requirements.
- Regular reviews matter, especially before you sign a new provider agreement, expand your operations, or change the way you collect customer data.
If your business is dealing with creating a privacy policy and wants help with privacy compliance, website terms, customer contracts, or software and data handling issues, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








