Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- Scope of processing
- Instructions and use restrictions
- Security standards
- Subprocessors and outsourcing chains
- Offshore disclosure and cross border access
- Privacy breach notification and incident response
- Assistance with access, correction and retention requests
- Liability, indemnities and practical remedies
Common Mistakes With Processing Contract
- Accepting standard terms without mapping the data flow
- Assuming a privacy policy solves the supplier issue
- Missing hidden rights to use data for the provider’s own benefit
- Overlooking subcontractors and support access
- Failing to align the contract with internal practice
- Ignoring contract renewal and exit terms
FAQs
- Does every New Zealand business need a separate processing contract?
- Is a processing contract only relevant for large tech companies?
- What if the supplier says its terms cannot be changed?
- Do offshore providers automatically breach New Zealand privacy rules?
- What should be in a processing contract at minimum?
- Key Takeaways
If your business shares customer, employee or user data with a software provider, payroll platform, marketing agency or outsourced support team, you may need a processing contract in place before you sign. A common mistake is assuming the supplier’s standard terms already cover privacy law. Another is focusing only on price and features, while missing where the data is stored, who can access it, and what happens if there is a privacy breach. A third is relying on a sales promise that the provider is “fully compliant” without checking what the contract actually says.
For New Zealand businesses, those gaps can create real risk. If another business handles personal information for you, your privacy obligations do not disappear just because the data sits in someone else’s system. This guide explains what a processing contract is, when you are likely to need one, what legal issues to review before you accept the provider’s standard terms, and the mistakes founders and SMEs commonly make when outsourcing data handling.
Overview
A processing contract is the agreement that sets out how one party may handle personal information on behalf of another. In practice, it matters whenever your business uses a third party to collect, store, analyse, host, transmit or otherwise process personal information for a business purpose.
For New Zealand businesses, the key question is not just whether a provider touches data, but what control you keep, what instructions apply, and whether the contract properly allocates privacy, security and breach response obligations.
- Identify whether the provider is handling personal information on your behalf, rather than using it for its own separate purposes.
- Check what categories of information are involved, such as customer details, employee records, payment data, health information or behavioural data.
- Review where the data is stored or accessed, especially if information may be transferred or accessed offshore.
- Confirm the contract limits use of the data to your instructions and the agreed services.
- Look for clear clauses on security measures, subcontractors, breach notification, deletion or return of data, and audit or information rights.
- Make sure the practical setup matches the paperwork, including permissions in the software, internal policies and staff access controls.
What Processing Contract Means For New Zealand Businesses
A processing contract is usually needed when another provider handles personal information for your business under your instructions. It is the document that turns vague privacy assurances into binding obligations.
In plain English, this comes up when you engage third parties such as:
- cloud software providers
- CRM or email marketing platforms
- payroll processors
- IT managed service providers
- customer support outsourcers
- data analytics consultants
- document storage providers
- recruitment or HR software vendors
Not every service agreement will use the label “data processing agreement” or “DPA”. Some providers build the relevant terms into their master services agreement, SaaS agreement or privacy schedule. The label matters less than the substance.
The legal purpose is straightforward. Your business may still be responsible for how personal information is handled under the Privacy Act 2020, even if a third party carries out the day to day processing. That means you should be confident the provider can only use the information in authorised ways, keeps it secure, and tells you quickly if something goes wrong.
When a separate processing contract is usually sensible
You should strongly consider a separate processing contract, or at least a detailed processing schedule, where the provider has ongoing or significant access to personal information. This is especially true before you sign a contract for software or outsourcing services that will touch a large volume of customer or employee data.
Common founder moments include:
- before you sign with a new payroll bureau that will hold employee tax and bank details
- before you accept the provider’s standard terms for a CRM that stores all your sales leads and customer notes
- before you rely on a verbal promise from a developer that offshore support staff will only access data “when needed”
- before you move files from local systems into a hosted cloud platform
- before you outsource customer service and give the provider access to your ticketing system
Why New Zealand privacy law still matters when someone else processes the data
Your obligations under New Zealand privacy law are not outsourced away. If your business collected the information and decides why it is being used, you generally still need to make sure that use is lawful, transparent and secure.
That is why a processing contract should do more than say the provider will comply with “applicable law”. That wording is often too general to help when there is a data incident, a customer access request, or a dispute about who approved a new use of the data.
A better contract usually spells out:
- what information is being processed
- what the provider is allowed to do with it
- who can access it
- where it can be stored or accessed from
- what security standards apply
- when the provider must tell you about an issue
- how data is returned, deleted or retained at the end of the arrangement
Controller and processor style roles, without the jargon overload
Many businesses use the language of “controller” and “processor”, even though New Zealand law does not always frame responsibilities in exactly the same way as some overseas regimes.
The useful practical distinction is this: if your business decides the purpose of handling the information, and a service provider handles it for you, you should treat that provider relationship as one that needs clear processing terms.
Things become more complicated where the supplier also uses the information for its own purposes, such as product development, platform analytics, benchmarking or direct marketing. That does not automatically make the arrangement unlawful, but it means you need to look closely at what rights you are giving away and whether your own privacy notice and customer communications line up with those uses.
Legal Issues To Check Before You Sign
The most important legal step is to read beyond the sales summary and test whether the contract actually controls the provider’s use of personal information. This is where founders often get caught, especially when the provider says the terms are “non negotiable”.
Scope of processing
The contract should clearly describe what the provider is doing with the data. If the wording is broad enough to cover almost any use, your business may be taking on unnecessary risk.
Check whether the agreement identifies:
- the categories of personal information involved
- the people affected, such as customers, employees, contractors or app users
- the purpose of the processing
- how long the processing will continue
- whether the provider may create derived data, reports or analytics from the information
If the provider wants a right to use data for service improvement or analytics, the clause should be specific. You want to know whether data is anonymised, aggregated, identifiable, retained indefinitely, or shared with other group companies.
Instructions and use restrictions
A proper processing contract should say the provider only processes personal information on your documented instructions, except where law requires otherwise. Without that restriction, the supplier may have room to use the information in ways your business did not expect.
This matters in practical situations such as:
- a marketing platform using your customer list to improve its own audience models
- a software vendor mining support tickets to train tools unrelated to your account
- an outsourced admin team downloading information into separate spreadsheets for convenience
If a use is not necessary for the service, question it before you sign.
Security standards
The contract should say more than “reasonable security”. Reasonable can mean very different things to different providers.
Look for clauses dealing with:
- access controls and user permissions
- encryption in transit and at rest, where relevant
- multi factor authentication
- logging and monitoring
- staff confidentiality obligations
- security testing and patch management
- physical security for hosted infrastructure, where applicable
You do not always need every technical measure written in full detail, but the contract should give you enough comfort that security is not just a marketing statement. High risk information, such as health details or children’s data, usually justifies tighter drafting.
Subprocessors and outsourcing chains
If your provider uses subcontractors, you need to know about it before you sign. Many SaaS and managed service providers rely on multiple subprocessors for hosting, support, communications, backup and analytics.
The contract should address:
- whether subprocessors are allowed at all
- how you are notified about new subprocessors
- whether you have any right to object in higher risk cases
- whether the provider remains fully responsible for subcontractor acts and omissions
- where those subprocessors are located
This issue often gets missed when the main supplier appears to be based in New Zealand but the actual infrastructure or support team is elsewhere.
Offshore disclosure and cross border access
If information is stored overseas, or can be accessed from overseas, cross border privacy issues arise. For New Zealand businesses, that can affect the privacy notices you give individuals, the steps you take to assess the recipient, and the terms you require in the contract.
Before you accept the provider’s standard terms, confirm:
- the countries where data will be stored
- the countries from which support staff can access it
- whether the provider can move data between regions without notice
- what legal protections apply in those locations
- whether your own customer facing privacy materials need updating
This is not just a technical issue. It affects how transparent your business is with the people whose information you collect.
Privacy breach notification and incident response
If there is a security incident, speed matters. A vague promise to notify you “promptly” may not be enough if your business needs to investigate, contain the issue and decide whether notification obligations arise.
A stronger clause usually covers:
- how quickly the provider must notify you after becoming aware of a breach or suspected breach
- what information they must provide initially
- their duty to investigate, contain and remediate
- their obligation to preserve evidence and logs
- who communicates with affected individuals and regulators
- who bears the cost of remediation where the provider caused the issue
Before you rely on a verbal promise that the provider has “never had a breach”, check the contract wording instead.
Assistance with access, correction and retention requests
Your business may receive requests from individuals who want access to their personal information or want it corrected. The provider should be required to help you respond within a workable timeframe.
The contract should also deal with retention and deletion. Some providers keep backup copies or archived data long after the commercial relationship ends. That may be operationally necessary in some cases, but it should be transparent and limited.
Liability, indemnities and practical remedies
The main risk is not just whether the provider breached the contract, but whether you can recover meaningful loss if they do. Standard supplier terms often cap liability at a very low amount, sometimes just a few months of fees.
That may be commercially acceptable for a low risk tool. It is often harder to justify where the provider handles sensitive information or has broad system access. Before you sign, consider whether the liability clauses and privacy risk match the likely disruption of a breach, and the cost of notifying affected people, investigating the issue and restoring operations.
Common Mistakes With Processing Contract
The most common mistake is treating the processing contract as a technical annex that does not need business review. In reality, it often decides who carries the privacy risk when something goes wrong.
Accepting standard terms without mapping the data flow
Many SMEs sign software or outsourcing terms without first working out what information will be uploaded, who will have admin rights and whether overseas access is switched on by default. That creates a mismatch between what the business thinks it bought and what the provider is actually permitted to do.
Even a short internal data map helps. Identify what data enters the system, who uses it, whether it includes special categories of information, and what integrations are turned on.
Assuming a privacy policy solves the supplier issue
Your customer facing privacy statement is not a substitute for a processing contract. A privacy policy explains your handling of information to individuals. It does not bind a supplier to security standards, notification timeframes or deletion obligations.
Businesses often discover this gap after a problem arises and the vendor contract says almost nothing useful about data handling.
Missing hidden rights to use data for the provider’s own benefit
Suppliers sometimes include broad rights to use customer data for analytics, service improvement, machine learning or business operations. Those rights may be buried in schedules or product specific terms.
That does not always mean you should walk away. It does mean you should ask direct questions, such as:
- Is the provider using identifiable or de identified data?
- Can they combine your data with other customers’ data?
- Will they keep the information after termination?
- Can you opt out of secondary uses?
- Do your own disclosures to customers or employees cover that use?
Overlooking subcontractors and support access
This is where founders often get caught. The contract may look fine at a high level, but the provider’s support model allows multiple subcontractors or offshore teams to access live data. If that is not visible before you sign, your risk assessment is incomplete.
Ask for the current list of subprocessors or equivalent supplier list. Check whether the provider can change that list unilaterally.
Failing to align the contract with internal practice
A well drafted processing contract still falls short if your team gives broad access rights to staff, exports data unnecessarily, or keeps duplicate records forever. The legal document and the operational setup need to match.
Practical alignment usually means:
- limiting user permissions inside the platform
- turning off unnecessary integrations
- setting retention periods
- training staff on approved uses of the system
- keeping a clear internal owner for vendor privacy issues
Ignoring contract renewal and exit terms
Privacy risk does not end at signing. Auto renewal clauses, changing product terms and messy exit processes can leave your data sitting in a system longer than expected.
Before you sign, look at what happens when the contract ends. You want a realistic process for exporting your data, confirming deletion, and dealing with residual backups or legally required retention.
FAQs
Does every New Zealand business need a separate processing contract?
No. Some lower risk supplier arrangements may be adequately covered in a main service agreement if the privacy and data handling clauses are detailed enough. The key issue is whether the contract properly controls how the provider handles personal information on your behalf.
Is a processing contract only relevant for large tech companies?
No. Small businesses often need one too, especially where they use cloud software, outsourced payroll, external IT support, marketing platforms or offshore service providers. SMEs can face the same privacy risks as larger organisations, even with smaller volumes of data.
What if the supplier says its terms cannot be changed?
That is common, especially with large software vendors. You can still review the terms carefully, assess whether the risk is acceptable, ask targeted questions, request side wording for higher risk points, and make an informed decision before you accept the provider’s standard terms.
Do offshore providers automatically breach New Zealand privacy rules?
No. Offshore storage or access is not automatically unlawful. But it does require proper review of how the data is protected, what the provider can do with it, and whether your own privacy disclosures and internal processes reflect the cross border arrangement.
What should be in a processing contract at minimum?
At minimum, it should address the purpose of processing, limits on use, security measures, subcontracting, breach notification, assistance with privacy requests, and deletion or return of data at the end of the relationship. Higher risk arrangements usually need more detailed drafting.
Key Takeaways
- A processing contract is usually needed where a third party handles personal information for your business under your instructions.
- For New Zealand businesses, privacy obligations do not disappear just because a supplier stores or accesses the data.
- Before you sign, check scope of use, security standards, subprocessors, offshore access, breach notification, retention and deletion, and liability settings.
- Do not rely on marketing claims or verbal assurances. The contract should clearly set out what the provider can and cannot do.
- The best processing terms are matched with practical internal controls, such as restricted access, data mapping and clear vendor management.
If you want help with supplier terms, privacy obligations, cross border data issues, breach response clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
When should you formalise this?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








