Setting Up an Electronic Communications Policy for NZ Workplaces

If your team uses email, messaging apps, cloud storage, mobile phones, video calls or social media, you already have electronic communications risks, whether you have a policy or not. Many New Zealand businesses leave this too vague, copy a policy from overseas, or focus only on misconduct without dealing with privacy, monitoring, data handling and practical day to day use. Another common mistake is treating informal tools like WhatsApp, Slack, text messages or personal devices as if they sit outside the business.

A good electronic communications policy does more than tell staff not to send inappropriate emails. It sets clear rules for business communications, helps protect confidential information, supports fair expectations around monitoring, and reduces disputes when something goes wrong. This guide explains what an effective workplace electronic communications policy should cover in New Zealand, when you need one, the legal issues to think about, and the mistakes that most often cause trouble for employers before a problem turns into a privacy complaint, disciplinary issue or reputational mess.

Overview

An electronic communications policy sets the rules for how workers use business systems and digital channels at work. In New Zealand, the policy should line up with employment obligations, privacy requirements and the real tools your team actually uses, not just your formal IT systems.

A workable policy also helps you show that expectations were clearly communicated before you rely on them in a disciplinary process or internal investigation.

  • Define which systems, devices and channels the policy covers, including email, chat apps, phones, cloud platforms, social media and personal devices used for work.
  • Explain acceptable use, limited personal use, confidentiality and security expectations in plain language.
  • Set out whether and how monitoring may occur, and be transparent about the reasons for it.
  • Address privacy, collection and handling of personal information, and access to workplace messages or records.
  • Link the policy to employment agreements, disciplinary processes and other workplace policies.
  • Cover practical issues such as remote work, offboarding, password security, scams and use of AI tools where relevant.
  • Train staff and managers so the policy is applied consistently, not only after an incident.

What To Creating an Effective Electronic Communications Policy for Workplaces Means For New Zealand Businesses

For a New Zealand business, this means creating a policy that matches your actual operations and gives staff fair, clear notice about what is expected when they communicate electronically for work.

There is no single statute called an electronic communications policy law. Instead, the issue sits across employment law, privacy law, confidentiality obligations, health and safety considerations in some contexts, and your own contractual arrangements with staff and contractors.

Why this matters for employers

Electronic communications create a record. That can help your business, but it can also expose internal disputes, privacy failings, poor customer handling, misuse of confidential information and inconsistent management decisions.

When expectations are unclear, employers often struggle to respond fairly. A manager may assume emails are company property and can be searched at any time, while a worker may expect some level of privacy in personal use or private messaging on a work device. This gap is where disputes start.

What laws and obligations usually sit behind the policy

Your policy should be drafted with several legal themes in mind:

  • Employment obligations, including acting fairly and reasonably, giving clear expectations, and following a proper process if misconduct is alleged.
  • The Privacy Act 2020, especially where your business collects, stores, accesses or discloses personal information through workplace systems.
  • Good faith duties in employment relationships, including transparency about monitoring and workplace expectations.
  • Confidentiality and intellectual property protections, especially where staff handle client information, pricing, product plans or internal documents.
  • Cybersecurity and data handling obligations under client contracts, supplier agreements or industry standards.
  • Record keeping needs where communications form part of business decisions, customer instructions, approvals or complaints.

What the policy should usually cover

A useful policy is not just a list of bans. It should answer the practical questions your team actually faces on a normal Tuesday.

Most businesses should consider including:

  • Which people are covered, such as employees, contractors, temporary staff and interns.
  • Which systems are covered, such as company email, messaging platforms, CRM notes, shared drives, video meeting tools and business social media accounts.
  • Whether staff can use personal devices for work, and if so, what security controls apply.
  • Whether limited personal use is allowed, and what counts as unacceptable use.
  • Rules on respectful communications, bullying, harassment, discriminatory content and inappropriate jokes or images.
  • Rules on phishing, suspicious links, file sharing, passwords, multi factor authentication and reporting cyber incidents.
  • How confidential information must be handled, including forwarding restrictions and use of external storage or AI tools.
  • Whether the business may monitor usage, access messages or review logs, and the reasons for doing so.
  • What happens when someone leaves, including return of devices, transfer of access and retention of business records.

Policies are not stand alone documents

Your electronic communications policy should work with your employment agreements and other workplace documents. If your employment agreement says little about confidentiality, device return, intellectual property or use of business systems, the policy may not carry as much weight as you expect.

This is also where founders often get caught. They adopt a policy after a problem arises, but they have not checked whether existing staff were properly notified, whether the policy can be updated under the employment agreement, or whether the business has been applying the rules consistently.

When This Issue Comes Up

This issue usually comes up when a business grows beyond informal habits and needs clear rules before a mistake, complaint or security incident forces the problem.

Many businesses first think about an electronic communications policy after someone sends confidential material to the wrong person, posts something inappropriate online, uses a personal device to store customer information, or leaves the business with key account access still active.

Common founder and manager moments

  • You hire your first employees and realise everyone is using different apps to talk to customers.
  • You move to hybrid or remote work and need rules around personal devices, home networks and file sharing.
  • You onboard a contractor who needs access to internal systems and client information.
  • You start storing more customer or employee data in cloud tools and need privacy controls.
  • You discover staff have been using unofficial messaging apps for business decisions.
  • You want to investigate suspected misconduct, but you are not sure what access to messages is fair and lawful.
  • You have no process for offboarding, and former workers still have access to email, drives or social accounts.
  • You are dealing with online reputational issues caused by staff comments or unauthorised posts.

Businesses with higher risk exposure

Some sectors need more detailed controls because the information handled is more sensitive or the communication volume is high.

Examples include:

  • Professional services firms handling confidential client files and advice.
  • Health related businesses managing sensitive personal information.
  • Recruitment, HR and education businesses handling candidate or student records.
  • Ecommerce and service businesses managing customer complaints and online reviews.
  • Tech companies where source code, product roadmaps and access credentials need tight protection.
  • Franchise, multi site or field based businesses where staff rely heavily on mobile devices and messaging apps.

Before you sign or roll out new systems

You should also deal with this before you sign major software contracts, before you spend money on setup for a bring your own device model, or before you move customer communications onto a new platform. Technology decisions often create legal consequences around privacy, record access, data retention and employee expectations.

If you are expanding, restructuring or setting up a company in New Zealand with a distributed team, this policy is one of the practical documents that supports your wider employment and privacy framework. It sits alongside choices about business structure, registration, trade mark protection, customer terms, contractor agreements and internal privacy processes.

Practical Steps And Common Mistakes

The best policy is specific, realistic and consistently applied. A short document that reflects your real systems is often better than a long template that nobody follows.

1. Map the tools your business actually uses

Start with facts, not assumptions. List every channel staff use for work, whether formally approved or not.

  • Email platforms.
  • Team chat tools.
  • Text messages and phone calls.
  • Video conferencing platforms.
  • Shared drives and document systems.
  • Project management tools.
  • CRM notes and ticketing systems.
  • Social media accounts.
  • Personal devices used for business.
  • AI assistants or automated messaging tools.

If your policy ignores unofficial tools, it will not solve the real risk.

2. Decide what personal use is allowed

Most businesses allow some limited personal use, but many policies avoid saying so. That creates unnecessary confusion.

If limited personal use is acceptable, say what the boundaries are. For example:

  • Use must be occasional and reasonable.
  • It must not interfere with work duties.
  • It must not breach security rules.
  • It must not involve offensive, unlawful or discriminatory content.
  • It must not create significant storage, cost or reputational issues for the business.

Staff are more likely to follow rules that reflect real life.

3. Be careful with monitoring language

You can often monitor business systems to some extent, but the main mistake is acting as if broad hidden surveillance is risk free. Transparency matters.

Your policy should explain:

  • What kinds of monitoring may occur, such as security logging, access reviews, email audits or device management.
  • Why monitoring may occur, such as cybersecurity, policy compliance, business continuity or investigating specific concerns.
  • Who can authorise access and under what circumstances.
  • How information gathered through monitoring will be handled.

Overly aggressive wording can create distrust and may not sit well with privacy expectations or good faith obligations. On the other hand, vague wording can make later investigations harder.

4. Cover privacy and personal information properly

If communications contain personal information about staff, customers or suppliers, your business should handle that information consistently with the Privacy Act 2020.

That usually means thinking about:

  • Why the information is being collected.
  • Who can access it.
  • How long it is retained.
  • How it is secured.
  • When it may be disclosed internally or externally.
  • How privacy requests or complaints will be managed.

An electronic communications policy is not a substitute for a privacy policy or internal privacy process, but it should align with them.

5. Deal with confidentiality in practical terms

Telling staff to keep information confidential is not enough if the policy does not explain what that means in practice.

Spell out common situations, such as:

  • Forwarding client emails to personal accounts.
  • Saving business files on unapproved apps.
  • Sharing screenshots from internal chats.
  • Using confidential material in AI prompts or third party tools.
  • Posting work discussions or customer details on social media.
  • Taking contact lists or sales pipelines when leaving the business.

This is especially important where your contracts with customers or suppliers include confidentiality clauses or data handling obligations.

A policy buried in a shared drive is not much use. Staff should receive it when they start, understand it, and know where to go with questions.

Your process should include:

  • Providing the policy at onboarding.
  • Training managers on how to apply it fairly.
  • Refreshing the policy when systems change.
  • Recording acknowledgment where appropriate.
  • Removing access promptly when someone leaves.
  • Checking that business records are retained and devices are returned.

7. Make sure disciplinary language is fair

You can state that breaches may lead to disciplinary action, but avoid wording that suggests automatic dismissal for every breach. Employment issues in New Zealand require a fair and reasonable process based on the actual facts.

If a serious issue arises, the policy should support, not replace, a proper investigation and consultation process.

Common mistakes businesses make

  • Using a UK or Australian template without adapting it for New Zealand privacy and employment context.
  • Writing a policy that only covers email while the team mainly uses chat apps and mobiles.
  • Claiming the business can access everything at any time without limits or process.
  • Forgetting contractors, casual staff or temporary workers who also use business systems.
  • Failing to align the policy with employment agreements, privacy documents and IT settings.
  • Ignoring social media and external messaging where client communications actually happen.
  • Not addressing remote work or personal device use.
  • Trying to rely on a policy that staff were never trained on or did not receive.

What a good policy rollout looks like

For most SMEs, a sensible rollout is staged. First, confirm your business structure and internal decision makers, then finalise employment and contractor documents, then match the policy to your systems and privacy processes. After that, train your team and review the policy as the business changes.

This is particularly useful if you are growing fast, selling online, managing customer support across multiple channels, or dealing with industry legal requirements that depend on secure records and controlled communications.

FAQs

Do New Zealand businesses legally need an electronic communications policy?

Not every business is expressly required by a single law to have one, but most employers should have one in practice. It helps meet employment, privacy, confidentiality and risk management needs, especially once staff use digital tools for work.

Can an employer read employee emails or messages?

Sometimes, but not without care. Access depends on the system used, the reason for access, the employee's expectations, what your policy says, and whether the approach is fair and consistent with privacy obligations.

Should the policy cover personal devices used for work?

Yes. If staff use their own phones or laptops for business, the policy should address security, access, storage of business information, what happens when employment ends, and the limits of any monitoring.

Is a policy enough on its own if there is a misconduct issue?

No. A policy helps set expectations, but you still need to follow a fair employment process before making disciplinary decisions. The policy is only one part of the picture.

How often should the policy be reviewed?

Review it whenever your systems, work practices or privacy risks change, and otherwise on a regular cycle. A policy written before remote work, cloud collaboration or AI tools became common may now be out of date.

Key Takeaways

  • An electronic communications policy helps New Zealand businesses set clear rules for email, messaging, devices, cloud tools and social media used for work.
  • The policy should reflect New Zealand employment and privacy obligations, especially around fair expectations, monitoring and handling personal information.
  • Your document should match the systems your team really uses, including personal devices, unofficial chat tools and remote work arrangements.
  • Clear rules on confidentiality, security, acceptable use, monitoring and offboarding reduce disputes and make incidents easier to manage.
  • The policy works best when it aligns with employment agreements, privacy documents, contracts and practical training for managers and staff.
  • Copying an overseas template or relying on vague rules is where many SMEs get caught.

If your business is dealing with creating an effective electronic communications policy for workplaces and wants help with workplace policies, privacy compliance, employment agreements, and confidentiality protections, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.