Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map the personal information you handle
- 2. Check your privacy notices and collection statements
- 3. Review contracts for privacy promises
- 4. Examine offshore disclosure and access
- 5. Test your security controls in plain business terms
- 6. Have a workable privacy breach response process
- 7. Check retention and deletion practices
- 8. Align sales, marketing and operations
- 9. Keep records that support your answers
- Key Takeaways
When a customer, investor, enterprise buyer or business partner asks privacy questions about your business, the pressure usually hits just before a contract is signed.
Founders often make the same mistakes: assuming a website privacy policy is enough, giving broad assurances about data security without checking internal practice, or overlooking what their software providers and offshore tools are doing with personal information. Those gaps can slow a deal, weaken trust, or expose your business to Privacy Act problems later.
A vendor privacy due diligence review is really a test of whether your business can explain, document and stand behind the way it handles personal information. This guide covers what New Zealand businesses should expect, when these reviews come up, the main legal and practical issues to check, and how to avoid common errors before you sign.
Overview
A vendor privacy due diligence review asks whether your business collects, uses, stores, shares and secures personal information in a lawful and commercially sensible way. In New Zealand, the key legal framework is the Privacy Act 2020, but buyers and commercial customers will usually look beyond bare legal compliance and ask whether your day to day practices match what your contracts, policies and sales team say.
- What personal information you collect, and why you need it
- Whether you have clear privacy notices and customer-facing disclosures
- How consent, notifications and collection practices work in reality
- Which staff, contractors and service providers can access the data
- Whether information is stored or accessed outside New Zealand
- What security controls, access restrictions and incident response steps you use
- How long you keep information, and how you delete or anonymise it
- What your contracts say about privacy, confidentiality and data handling
- Whether you have had any privacy complaints, breaches or regulator contact
- How marketing, analytics and cookies line up with your public statements
What Vendor Privacy Due Diligence Review Means For New Zealand Businesses
The practical meaning is simple: another party wants evidence that your business can be trusted with personal information before they buy from you, invest in you, or integrate with your systems.
For many SMEs, this comes as a spreadsheet questionnaire, procurement checklist, contract schedule or due diligence request list. For a startup selling software, payroll support, recruitment services, health technology, education tools, e-commerce services or managed business operations, privacy questions can become one of the main commercial hurdles.
Why privacy due diligence matters
Privacy is no longer just an internal compliance issue. It affects sales cycles, enterprise procurement, fundraising, strategic partnerships and exit planning. If your business cannot explain how it handles personal information, a customer may delay signing, ask for heavier contractual warranties, or decide the risk is too high.
In a business sale or investment process, weak privacy practices can also reduce value. Buyers want to know whether they are inheriting hidden liabilities, such as poor collection notices, insecure systems, unsupported staff access practices, or undocumented offshore data transfers.
The New Zealand legal baseline
New Zealand businesses that handle personal information need to comply with the Privacy Act 2020. That includes the Information Privacy Principles, which govern matters such as collection, use, disclosure, storage, access and correction. The law can also apply where an overseas business carries on business in New Zealand.
In a vendor privacy due diligence review, the questions usually map back to practical themes under that framework, including:
- Whether you only collect information for a lawful and necessary business purpose
- Whether people are told what is being collected, why, and who will receive it
- Whether information is protected by reasonable security safeguards
- Whether data is accurate, up to date and not misleadingly used
- Whether people can access and correct their information where required
- Whether disclosure and overseas sharing are handled properly
- Whether notifiable privacy breaches are recognised and escalated
Depending on your sector, other obligations may sit alongside privacy. A business in fintech, health, education, HR, logistics or marketing may face contractual security requirements, confidentiality duties, industry rules or customer procurement standards that go further than the minimum legal baseline.
What reviewers are really testing
Most due diligence requests are not looking for perfect paperwork. They are testing consistency. The buyer or customer wants to know whether your legal documents, technical setup, sales promises and staff behaviour all line up.
This is where founders often get caught. A privacy policy may say one thing, while the product team uses extra analytics tools, the customer success team exports data into spreadsheets, and offshore contractors can access records without a clear process. None of that necessarily means the business is failing, but it does mean the due diligence response needs to be honest, specific and fixed where needed.
Common documents requested
Before you sign a contract or enter a formal diligence phase, expect requests for documents such as:
- Your privacy policy and internal privacy procedures
- Customer terms, supplier agreements and confidentiality clauses
- Data processing schedules or service descriptions
- Information security policies and access control records
- Breach response or incident management procedures
- Records of subcontractors and cloud providers
- Details of offshore hosting or support access
- Any past privacy complaints, disputes or security incidents
- Retention and deletion policies
- Marketing and cookie disclosures for your website or app
If you do not have all of these documents, that does not automatically stop a deal. It does mean you should know what exists, what is missing, and what explanations can be given without overpromising.
When This Issue Comes Up
Vendor privacy due diligence usually appears at the point where the commercial relationship becomes real, when a customer is about to onboard, an investor is getting serious, or a buyer starts reviewing your business before acquisition.
Enterprise customer onboarding
Large New Zealand organisations often send privacy and security questionnaires to suppliers before procurement approval. This is common where your service handles customer records, staff data, contact lists, payment details, or usage data.
A small SaaS provider may think it is only selling workflow software, then realise the platform stores names, email addresses, job titles, internal notes and uploaded documents. From the customer's perspective, that is a privacy issue even if your product is not marketed as a data service.
Investment and fundraising
Investors increasingly ask whether a startup has basic privacy compliance in place, especially if growth depends on collecting user data or integrating with third party platforms. Poor privacy hygiene can raise concerns about regulatory exposure, reputational damage and future enterprise sales friction.
Questions often arise before term sheets are finalised or before diligence deepens. This is a good moment to tidy up your documentation, because privacy gaps found during fundraising can slow momentum at exactly the wrong time.
Business sales and acquisitions
In an acquisition, privacy due diligence becomes broader. The buyer is not just reviewing your customer promises. They are looking at inherited risk across your datasets, contracts, software stack and historical incidents.
If your business plans to sell in the future, privacy records should not be treated as an afterthought. Missing records, unclear data ownership, or contradictory contracts can become price or warranty issues later.
Supplier and platform reviews
This issue also comes up when you rely on other vendors. If your own cloud providers, support platforms, CRM systems, payment tools or offshore contractors process personal information, your customer may expect you to understand that supply chain.
You may be asked:
- Who hosts the data
- Which subcontractors have access
- Whether data leaves New Zealand
- What security certifications or controls are in place
- How incidents are notified and managed
If you cannot answer those questions, you may struggle to complete your own vendor privacy due diligence review.
Website, app and marketing changes
Privacy diligence does not only happen during large deals. It often surfaces when a business launches online, adds behavioural analytics, starts using a new marketing automation platform, or expands its online ordering system.
Before you spend money on setup, it is worth checking whether your collection notices, terms, cookies, CRM settings and internal access permissions match the way the business actually operates. Fixing this early is easier than rewriting everything under procurement pressure.
Practical Steps And Common Mistakes
The best way to prepare is to map your data handling from start to finish, then compare that reality against your contracts, policies and customer promises.
1. Map the personal information you handle
You need a clear picture of what your business collects and where it goes. That means more than customer sign up forms. It includes support tickets, staff handling, integrations, backups, spreadsheets and marketing tools.
Your data map should cover:
- What information you collect
- Where it comes from
- Why you collect it
- Where it is stored
- Who can access it
- Whether it is shared with third parties
- How long you keep it
- How it is deleted or anonymised
Common mistake: businesses answer diligence questions based on the product design, not actual operations. If the support team downloads CSV files or contractors view live data, that must be captured too.
2. Check your privacy notices and collection statements
Your public-facing privacy material should explain in plain English what information you collect, why you collect it, and what people can expect. For New Zealand businesses, this needs to align with how information is actually collected and used.
Review whether your privacy wording covers:
- Website and app data collection
- Customer account information
- Marketing communications and analytics
- Third party sharing
- Overseas storage or access
- Access and correction rights
- Complaint or contact channels
Common mistake: copying a generic privacy policy that mentions tools and practices your business does not use, while missing the tools and practices it does use.
3. Review contracts for privacy promises
Sales contracts, master service agreements, supplier terms and procurement schedules often contain privacy obligations that are stricter than your internal systems can support. This is where legal and operational mismatch creates risk.
Before you sign, check whether your contracts promise things such as:
- Data storage only in a particular country
- Immediate breach notification timeframes
- Use restrictions on data and metadata
- Approval rights for subcontractors
- Specific deletion periods on termination
- Audit rights or security reporting commitments
- Detailed confidentiality and staff screening obligations
Common mistake: accepting enterprise customer paper without checking whether your existing software vendors, hosting setup or support workflows can meet those obligations.
4. Examine offshore disclosure and access
Many New Zealand businesses use software hosted overseas or allow offshore support access. That can be workable, but it needs to be identified and handled properly.
Questions to ask include:
- Which providers store or process information offshore
- Whether overseas support staff can access live records
- What contractual protections are in place
- Whether customer notices mention overseas disclosure or storage where relevant
- Whether any data localisation commitments have already been made to customers
Common mistake: assuming cloud hosting is a pure technical issue. In due diligence, it is a legal and commercial issue too.
5. Test your security controls in plain business terms
Reviewers often ask detailed security questions, but they are usually trying to understand basic risk management. If your answer is full of marketing language and thin on specifics, confidence drops fast.
Be ready to explain matters such as:
- Role-based access controls
- Multi-factor authentication
- Password management
- Device and endpoint controls
- Logging and monitoring
- Backup practices
- Staff training
- How leavers lose access
- How incidents are escalated internally
Common mistake: saying the business uses industry standard security without being able to describe what that means in practice.
6. Have a workable privacy breach response process
A notifiable privacy breach can trigger legal obligations in New Zealand. Even where a breach is not notifiable, customers will want to know whether your team can recognise an issue quickly and respond sensibly.
Your process should address:
- Who staff report incidents to
- How incidents are assessed
- When legal input is needed
- When customers or affected individuals may need to be told
- How records are kept
- How systems and communications are contained
Common mistake: relying on informal Slack messages or ad hoc decisions during an incident. Under pressure, that usually creates delay and confusion.
7. Check retention and deletion practices
Businesses often collect data faster than they retire it. Due diligence reviewers may ask how long information is kept and whether deletion happens at the end of a contract.
Look for mismatches between what your documents say and what systems allow. For example, a contract may promise deletion within 30 days, while backups, archive accounts or exported reports remain available for much longer.
Common mistake: treating deletion as only a product feature issue. It usually touches contracts, operations, backups and customer communications.
8. Align sales, marketing and operations
Your legal documents are only part of the picture. Privacy promises are also made in demos, procurement calls, pitch decks, proposal documents and onboarding materials.
Make sure teams know what they can and cannot say about:
- Where data is stored
- Whether data is used for product improvement or analytics
- Who can access information
- Whether subcontractors are involved
- How long information is retained
- How quickly incidents are notified
Common mistake: the sales team promising bespoke privacy outcomes before operations or legal have checked whether they are achievable.
9. Keep records that support your answers
A good response is easier when your business keeps a central record of key privacy information. This does not need to be overly formal for every SME, but it should be organised enough to support procurement and deal questions.
Useful records include:
- A current list of systems handling personal information
- A list of third party providers and subcontractors
- Current policies and procedures
- Contract templates and customer-specific data terms
- Incident logs and resolution notes
- Staff training records
- Retention and deletion settings
This is also where business structure and governance matter. If your company setup is informal, contractor arrangements are undocumented, or ownership of customer data is unclear, privacy due diligence can expose broader contractual issues as well.
FAQs
Does every New Zealand business need a vendor privacy due diligence review?
No, not in a formal sense. But any business that handles personal information may face privacy questions from customers, investors, partners or buyers, especially before you sign a contract with a larger organisation.
Is a privacy policy enough to satisfy due diligence?
No. A privacy policy is only one piece of the picture. Reviewers usually want to know whether your contracts, internal processes, software tools, security controls and actual staff practices match that policy.
What if we use overseas software providers?
That is common for New Zealand businesses, but you should know which providers are involved, what data they handle, where access occurs, and what customer disclosures or contractual protections are needed.
Can a privacy issue stop a customer deal?
Yes. Privacy gaps can delay procurement, lead to tougher contract terms, or cause a customer to choose another supplier if they are not comfortable with the risk.
Should startups deal with this before fundraising or enterprise sales?
Yes. Cleaning up privacy notices, contracts, vendor arrangements and basic security records before diligence starts is usually faster and cheaper than trying to fix everything under deal pressure.
Key Takeaways
- A vendor privacy due diligence review checks whether your business can clearly explain and support how it handles personal information.
- For New Zealand businesses, the Privacy Act 2020 is the legal baseline, but enterprise customers and buyers often expect more detailed operational answers.
- The main issues are data mapping, privacy notices, contracts, offshore access, security controls, breach response, and retention and deletion practices.
- Founders often get into trouble when public statements, sales promises and day to day operations do not match.
- Preparing early, before you sign, can reduce deal delays and help your business respond with confidence.
If your business is dealing with vendor privacy due diligence review and wants help with privacy policies, customer contracts, supplier data terms, breach response planning, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
When should you formalise this?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.






