Database Right in New Zealand: Ownership and Protecting Business Data

Alex Solo
byAlex Solo11 min read

Business data often becomes valuable long before founders realise it. Customer lists, supplier records, pricing history, product catalogues, usage logs and lead databases can take months or years to build, yet many businesses assume they automatically “own” all of it in the same way they own stock or equipment. That is where people get caught.

Common mistakes include assuming New Zealand has a standalone database right like the UK or EU, forgetting to deal with ownership in contractor agreements, and collecting personal information without thinking about privacy rules. Another frequent problem is spending money on software or data scraping before checking what rights sit with the platform, staff member or external developer.

This guide answers the practical questions founders and SMEs ask most often: whether database right exists in New Zealand, who can own business data, how copyright, contract and confidentiality law may protect a database, and what steps make your data easier to control before you sign a contract, launch online, or share information with a third party.

Overview

New Zealand does not have a separate, standalone “database right” in the way some overseas jurisdictions do. For New Zealand businesses, protection usually comes from a mix of copyright, confidentiality, contract terms, privacy compliance, trade secrets and technical controls.

  • Check whether your database contains original selection, arrangement or structure that may attract copyright.
  • Confirm who created the database, employee, founder, contractor or software provider, and whether ownership has been assigned in writing.
  • Separate personal information from non-personal business data and comply with the Privacy Act 2020 when collecting, storing and using it.
  • Use contracts with staff, contractors, customers and suppliers to deal with ownership, permitted use, access, extraction and return of data.
  • Protect commercially sensitive information with confidentiality terms, access controls, security settings and clear internal processes.
  • Review third party platform terms before you scrape, export, licence, share or monetise data.

What Database Right Means For New Zealand Businesses

The short answer is that New Zealand businesses should not assume a special statutory database right exists. If your business relies on a customer database, inventory system, pricing archive or data-driven product, your legal position usually depends on other rights instead.

Is there a database right in New Zealand?

New Zealand law does not generally recognise a standalone database right equivalent to the sui generis database right seen in some other countries. That matters because a founder reading UK materials may think the act of investing time and money in collecting data automatically creates a separate legal right over the contents. In New Zealand, that is not a safe assumption.

This does not mean your database is unprotected. It means the protection analysis is more layered. You need to ask what exactly you are trying to protect:

  • the data itself
  • the way the database is structured or arranged
  • the software behind it
  • personal information inside it
  • confidential business know-how revealed by it
  • your contractual control over access and use

Sometimes, yes. Copyright may protect the original compilation, selection or arrangement of information, rather than the bare facts themselves. Facts such as a customer’s name, a market price or a product dimension are not usually owned just because you recorded them. But the original way those facts are chosen, organised and presented may attract copyright if the legal threshold is met.

For example, a carefully designed subscription database with bespoke categories, tags, search logic and metadata fields may have stronger copyright arguments than a plain list copied from public sources into a spreadsheet. A large amount of effort alone does not guarantee copyright protection. The question is not only how much work was done, but whether the work produced something sufficiently original.

Who owns the database your business uses?

Ownership depends heavily on who created the material and what the contract says. This is where founders often get caught, especially when a contractor builds the CRM, a freelancer compiles the mailing list, or a software company hosts the information.

Ownership commonly turns on whether the database was created by:

  • an employee in the course of employment
  • a founder before the company was incorporated
  • an independent contractor or consultant
  • a software developer using their own systems and templates
  • a third party platform that grants access but keeps underlying rights

If a founder built valuable data assets before company setup, those rights may not automatically sit with the company later. Before you invest in branding, raise capital or sign a sale agreement, it is worth checking whether the company actually owns the data assets it relies on.

What about personal information?

If your database contains customer, employee or user information, privacy law becomes central. The Privacy Act 2020 affects how you collect, store, use, disclose and retain personal information. Even if your business has strong contractual rights over a database, that does not remove privacy obligations.

This matters for businesses selling online, software businesses building analytics tools, agencies managing client lists, and retailers using loyalty or email marketing data. You need a lawful and transparent approach to collection and use. You should also have a clear privacy policy and think about access requests, correction requests, security safeguards and whether information is being shared overseas.

When This Issue Comes Up

Database ownership issues usually appear at moments of growth, outsourcing or dispute. The main risk is that a database becomes commercially important before anyone has clearly documented who owns it and who can use it.

When a contractor or developer creates the system

A common founder moment is paying a developer to build an internal platform, app backend or CRM extension, then later discovering the code, schema or exported data is not clearly assigned to the business. The contractor may believe they own the intellectual property they created unless there is a written assignment or licence.

Before you sign a contract with a developer or data consultant, check whether it deals with:

  • ownership of the database structure and contents
  • ownership of source code and custom integrations
  • rights to export data in a usable format
  • ongoing access if the relationship ends
  • limits on the contractor reusing your data or system design

When founders build data assets before company setup

Many startups start informally. A founder collects leads, supplier contacts, customer feedback and pricing intelligence before deciding on business structure or completing Companies Office registration. Later, the business incorporates and assumes all those materials belong to the new company.

That assumption can create problems in investment, due diligence and co-founder disputes. If the company is meant to own the database, the transfer should be properly documented. That is especially important before you bring on investors, issue shares, or negotiate a sale.

When staff leave with lists or records

Sales teams, account managers and operations staff often have practical access to the most valuable data in the business. Trouble starts when an employee leaves and takes client records, pricing sheets, supplier lists or prospect notes to a new employer or competing venture.

New Zealand businesses usually rely on employment contracts, confidentiality obligations, intellectual property clauses and internal access controls in this situation. If your contracts are vague and everyone uses personal devices or unsupervised cloud tools, recovery becomes much harder.

When using third party platforms and marketplaces

A business might build up years of customer interactions on an ecommerce platform, booking system, SaaS tool or marketplace. The business may assume that because it entered the data, it controls all future use of it. In reality, platform terms can restrict scraping, extraction, resale, migration or analytics use.

Before you spend money on setup or migration, review the terms on:

  • who owns uploaded content and user-generated data
  • what export rights you have
  • whether the provider can analyse or aggregate your data
  • what happens on termination
  • whether the data is stored or processed offshore

When buying or selling a business

In an acquisition, the database is often one of the main assets being bought. But “customer database” can mean very different things in practice. Does the seller have the right to transfer it? Does it include personal information collected for a specific purpose? Are there marketing consents? Are there restrictions under platform contracts or customer terms?

These questions matter before you sign. A sale agreement should identify what data assets are included, what rights go with them, and what warranties the seller gives about ownership, compliance and use.

Practical Steps And Common Mistakes

New Zealand businesses protect database value best when they combine legal documents, privacy compliance and practical controls. Relying on one tool alone is usually not enough.

1. Identify what your business is actually protecting

Do not treat all data as one asset. A customer email list, a proprietary classification system, a product catalogue and backend code may each have different legal treatment.

Map out:

  • the raw information in the database
  • the selection and arrangement of that information
  • the software or schema that stores it
  • any personal information included
  • any confidential insights, models or pricing patterns revealed by it

This exercise sounds basic, but it helps you choose the right contracts and protection strategy.

2. Put ownership beyond doubt in contracts

The most practical protection for many SMEs is a well-drafted contract. This applies to founder arrangements, contractor agreements, software development agreements, employment agreements, platform terms and sale documents.

Clauses often need to cover:

  • who owns newly created databases and related intellectual property
  • whether rights are assigned immediately or licensed
  • who can access, extract, edit, copy or re-use the data
  • what happens when the relationship ends
  • return, deletion or transfer obligations
  • confidentiality and non-disclosure obligations

A frequent mistake is relying on a generic services agreement that says nothing about data ownership. Another is assuming payment alone transfers intellectual property. It often does not.

3. Get privacy settings and disclosures right

If your database contains personal information, your legal focus should include privacy from the start. That means thinking about what you collect, why you collect it, how long you keep it, and who you share it with.

At a practical level, many businesses should review:

  • privacy collection statements
  • website or app privacy policies
  • customer terms dealing with data use
  • internal retention and deletion practices
  • security access permissions
  • overseas storage or service providers

A common mistake is building a rich marketing database from customer interactions without giving clear notice about analytics, remarketing, profiling or data sharing. Another is retaining old information indefinitely because it might be useful later.

4. Treat confidential business information separately

Even where copyright is uncertain, confidentiality can still be powerful. Supplier margins, pricing logic, prospect scoring, deal pipelines and usage trends may be commercially sensitive even if they are not protected as copyright works.

Confidentiality protection works better when the business acts consistently. Limit access to those who need it. Mark sensitive materials appropriately. Use internal policies. Remove access promptly when staff or contractors leave. If your conduct treats the database as casual or public, it becomes harder to argue later that it was confidential.

5. Check your rights before scraping or importing data

Businesses sometimes assume publicly visible information is free to collect and commercialise. That is risky. Website terms, copyright issues, trade mark concerns, confidentiality issues and privacy law can all be relevant depending on the source and use.

Before you launch online with a data-heavy product, think about:

  • whether the source terms prohibit scraping or automated extraction
  • whether the material includes personal information
  • whether the copied structure or content may infringe copyright
  • whether your marketing about the dataset could mislead under fair trading rules
  • whether customers will expect proof that you can lawfully supply the data

This is especially relevant for price comparison tools, lead generation services, AI training datasets, recruitment platforms and aggregators.

6. Plan for exits, disputes and migration

Database problems often surface only when relationships end. A business wants to change platforms, terminate a developer, remove a co-founder, or sell part of the company. If the contract does not deal with migration and exit, the other party may have leverage.

Good planning usually covers format, timing, cooperation, deletion and verification. You want to know that the business can extract its data cleanly and continue operating without an argument over access.

Common mistakes founders make

Some mistakes appear again and again across startups and SMEs:

  • assuming New Zealand has a separate database right that automatically protects investment in data collection
  • failing to assign rights from contractors, founders or consultants
  • using software or marketplaces without checking export and ownership clauses
  • mixing personal information and general business data without proper privacy processes
  • giving broad access to sensitive records with no clear offboarding steps
  • describing a database as “owned” in investor or sale discussions before verifying the legal position

If your business is scaling, selling online or building a data-driven product, these issues are worth sorting out early. It is easier to set up ownership and usage rights now than to fix gaps during a dispute or due diligence process.

FAQs

Does New Zealand have a standalone database right?

No. New Zealand does not generally have a separate statutory database right like some overseas jurisdictions. Protection usually depends on copyright, contract, confidentiality, privacy compliance and related rights.

Can my business own a customer database?

Often yes, but ownership depends on how the database was created, who created it, what contracts say, and whether personal information rules affect how it can be used or transferred. Do not assume ownership without checking the documents.

Usually not the bare facts themselves. Copyright may protect the original compilation, selection or arrangement of information, depending on the circumstances.

What if a contractor built our CRM or data system?

You should check the services agreement straight away. If there is no clear intellectual property assignment or licence dealing with the database, code and exports, the contractor may still hold important rights.

Can I sell a database when I sell my business?

Sometimes, but you need to confirm that the business has the right to transfer it and that any personal information was collected and can be used in a way that allows the transfer. Sale documents should address ownership, compliance and permitted use clearly.

Key Takeaways

  • New Zealand does not usually provide a standalone database right, so businesses should rely on a mix of copyright, contracts, confidentiality and privacy compliance.
  • Ownership of a database depends on who created it and what written agreements say, especially where founders, employees, contractors or software providers are involved.
  • Personal information inside a database brings Privacy Act 2020 obligations that sit alongside any intellectual property or contractual rights.
  • Platform terms, software agreements and sale documents can heavily affect access, export, use and transfer rights.
  • The safest approach is to document ownership early, control access carefully and review data rights before you sign a contract, invest in setup or share information with third parties.

If your business is dealing with database right and wants help with contractor IP clauses, privacy compliance, software and platform agreements, or business sale data issues, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.