Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map your data before you draft anything
- 2. Explain your purposes in plain language
- 3. Be specific about sharing and service providers
- 4. Match the notice to your forms and workflows
- 5. Cover access and correction rights properly
- 6. Take extra care with sensitive information
- 7. Review related documents, not just the privacy notice
- Common mistakes training providers make
- What a well drafted notice usually includes
- Key Takeaways
If you run a training business in New Zealand, your privacy notice is not just a formality. It is often the first place learners, parents, clients, staff and funders look to understand what you do with personal information. Many training providers make the same mistakes: copying a generic overseas policy, collecting more information than they actually need, or forgetting to explain how enrolment data, attendance records, online learning data and marketing details are used.
Those gaps can create real problems before you sign supply contracts, before you spend money on a new learning platform, or before you launch an online course. A weak privacy notice can lead to complaints, confusion about consent, and difficult questions when someone asks for access to their information.
This guide explains what a privacy notice for New Zealand training providers should cover, when you need one, how the Privacy Act 2020 affects your day to day operations, and the practical steps that help you avoid the mistakes founders and growing providers often make.
Overview
A privacy notice tells people what personal information your training business collects, why you collect it, who you share it with, and how they can access or correct it. For New Zealand training providers, it should match how enrolments, course delivery, student support, assessments, websites and marketing actually work in practice.
- Identify every point where you collect personal information, including enquiry forms, enrolments, assessments, websites, events and recruitment.
- Explain your purposes in plain English, such as administering courses, confirming attendance, issuing certificates, handling payments and sending updates.
- Describe who receives the information, including service providers, learning management systems, payment platforms, industry bodies or government agencies where relevant.
- Set out how people can request access to their information or ask for corrections.
- Check whether you collect sensitive information, such as health or accessibility information, and explain that separately and carefully.
- Review whether any information is stored or accessed overseas.
- Make sure your privacy notice aligns with your enrolment terms, staff documents, website forms and internal processes.
What Privacy Notice Training Providers Means For New Zealand Businesses
For a New Zealand training provider, a privacy notice is a practical transparency document required by the way privacy law works. It should tell people, at or before the time of collection where possible, what happens to their information.
Under the Privacy Act 2020, organisations that collect personal information need to comply with the information privacy principles. One of the most relevant for training providers is the duty to be open about collection. If you ask learners, tutors, employees or corporate clients for information, you generally need to explain why you need it, what you will do with it, and what rights they have.
That matters because training businesses often collect a broad mix of information across different settings. A private training establishment, workplace trainer, coaching business, compliance training provider or online education platform may collect:
- names, addresses, phone numbers and email addresses
- dates of birth and identity details
- emergency contact information
- attendance and participation records
- assessment results and certificates
- billing and payment information
- employment history or qualification records
- photos, videos or class recordings
- website usage data and marketing preferences
- health, accessibility or learning support information
The legal issue is not only what you collect, but whether your explanation matches the real use of that information. This is where founders often get caught. A provider may say it collects information for enrolment purposes, but then also uses that same information for newsletters, case studies, referral marketing or third party platform analytics without saying so clearly.
A privacy notice for training providers in New Zealand also needs to reflect the type of business you run. If you are looking to start a training business in New Zealand, privacy should sit alongside your other setup issues, such as:
- choosing a business structure, such as a company or sole trader model
- registering the company through the Companies Office if you incorporate
- checking your business name and whether you should apply for a trade mark
- putting customer contracts and enrolment terms in place
- reviewing website terms if you are selling online courses
- working out sector specific education or industry requirements
- setting up staff and contractor agreements
Your privacy notice is not the only document you need, but it is one of the most visible. A learner may never read your internal data handling process, but they are far more likely to see your website privacy statement, enrolment form notice or sign up page wording.
What counts as personal information?
Personal information means information about an identifiable individual. It is wider than many business owners expect. A person's name and email address obviously count, but so can class notes, a recorded webinar where a participant is visible, an IP address linked to an account, a support request, or an assessor comment attached to a named learner.
If your business can reasonably connect the information to a person, treat it as personal information and draft your notice accordingly.
Why training providers need extra care
Training businesses often sit in the middle of several relationships at once. You may deal with individual learners, a corporate customer paying for staff training, tutors delivering sessions, software providers hosting content, and regulators or industry bodies requiring records.
That makes it easy for privacy messaging to become vague. Your notice should explain the different flows of information clearly. If an employer books training for its staff, for example, you may need to tell participants whether attendance or completion information will be reported back to that employer.
When This Issue Comes Up
Privacy notice issues usually show up at collection points, platform changes and growth moments. If your process changes, your notice usually needs to change too.
Many providers first think about privacy when they are building a website. That is one trigger, but not the only one. You should review your privacy notice whenever your business starts collecting information in a new way or for a new purpose.
Common founder moments
The need for a clear privacy notice often comes up in these situations:
- before you launch online and start collecting enquiry or enrolment details through your website
- before you sign a contract with a corporate client that requires learner reporting
- before you spend money on setup for a new learning management system or video platform
- when you start recording webinars or in person sessions
- when you add marketing automation or customer relationship management tools
- when you expand from in person teaching to online delivery
- when you begin collecting accessibility, medical or wellbeing information to support learners
- when you hire staff or engage contractors and collect personnel records
- when you decide to use learner testimonials, photographs or case studies in promotions
Each of these moments changes the privacy picture. A one page statement that worked for a small in person workshop business may no longer be enough once you are taking registrations online, issuing digital credentials and using offshore software.
Online training and selling online courses
If you sell training online, your privacy position becomes more layered. You may collect billing details, account logins, learning progress, discussion forum content, device data and marketing preferences, all through different tools.
That means your privacy notice should work with your broader online terms and customer terms. If your course includes subscriptions, automatic renewals, membership communities or recorded sessions, your documentation should line up. The privacy notice tells users what happens to their information, while your terms explain the commercial relationship.
Working with children or younger learners
If your training business works with school age learners or young people, take extra care with collection notices and communications. The Privacy Act still applies, but the practical question is whether your wording is clear enough for the audience and whether parents or guardians should also be informed, depending on the context.
You should also think carefully before using photos, recordings or student success stories in marketing. A broad statement hidden in a website footer is unlikely to be enough where the use is sensitive or unexpected.
Corporate training arrangements
In workplace training, employers often expect reports on attendance, completion and performance. This can be legitimate, but it should not come as a surprise to the individual participant.
Your contracts with the business client should say what reporting is included. Your privacy notice should also explain what information will be shared back to the employer, and why. If there are optional extras, such as post course surveys or behavioural profiling tools, those should be addressed clearly rather than folded into a general statement.
Practical Steps And Common Mistakes
The best privacy notice is accurate, specific and easy to follow. It should describe what your training business actually does, not what a generic template says a business might do.
1. Map your data before you draft anything
Start by listing every place you collect personal information. Most providers have more collection points than they realise.
Look at:
- website contact forms
- course registration forms
- checkout pages
- email marketing sign ups
- in person sign in sheets
- assessment submissions
- video conferencing tools
- learning management systems
- surveys and feedback forms
- staff recruitment forms
- contractor onboarding forms
If you do not map collection points first, your privacy notice will usually miss something important.
2. Explain your purposes in plain language
People should be able to understand why you are collecting their information without decoding legal jargon. "For business purposes" is too vague. "To process your enrolment, deliver your course, issue your certificate, communicate with you about class changes, and manage payment" is much better.
If you have several distinct purposes, separate them. For example:
- course administration
- identity verification
- assessment and certification
- customer support
- marketing communications
- reporting to an employer or funding body where applicable
- improving courses and platforms
Where a purpose is optional, say that clearly. Marketing is the most common example. If someone gives you their email to enrol in a course, that does not always mean they expect ongoing promotional messages unrelated to that enrolment.
3. Be specific about sharing and service providers
Most training providers use third party platforms. The main risk is pretending you do not. If personal information passes through payment systems, course hosting tools, email platforms, cloud storage or webinar software, your notice should say so in a clear way.
You do not need to overload the notice with technical detail, but you should be honest about categories of recipients, such as:
- technology and software providers
- payment processors
- trainers, assessors and support staff
- employers who have booked training for their staff
- government agencies or regulators where disclosure is required or authorised by law
- professional advisers and service providers
If information is stored or accessed outside New Zealand, that deserves special attention. Cross border disclosure needs care under New Zealand privacy law, and your contracts with providers may need review before you sign.
4. Match the notice to your forms and workflows
A privacy notice is only useful if your forms, sign up pages and staff processes match it. If your enrolment form asks for dietary requirements, health information or emergency contacts, your notice should explain why that information is needed and who can access it.
This is also where consent language can go wrong. Businesses often use one broad tick box for everything, including mandatory course administration and optional marketing. Those are different issues. Your form design should reflect that difference.
5. Cover access and correction rights properly
Your notice should tell people how they can request access to their personal information or ask for corrections. Keep the process practical. Give a contact point, explain that requests may need verification, and make sure someone in the business knows how to handle them.
Training providers sometimes forget that assessment records, attendance records and communication logs may all fall within an access request. Before you print forms or scale your systems, decide how those records are stored and retrieved.
6. Take extra care with sensitive information
Some training businesses collect information that deserves additional caution, even if the Privacy Act does not use the same category labels found in some overseas laws. Health details, disability support needs, cultural or wellbeing information, identification documents and disciplinary records can all be especially sensitive.
If you collect this type of information, ask yourself:
- do we really need it for this course or service
- who inside the business needs access
- how long should we keep it
- what should the notice say so people are not surprised
- do our contracts and internal processes match what we are telling people
7. Review related documents, not just the privacy notice
Privacy problems rarely sit in one document alone. The notice should align with your enrolment terms, website terms, staff privacy wording, contractor agreements, client contracts and internal data handling procedures.
For example, if your corporate training agreement promises detailed participant reporting to a client, but your learner privacy notice says nothing about that reporting, you have a mismatch. The same issue can arise if your marketing team wants to use photos and testimonials but your enrolment process never clearly raises that use.
Common mistakes training providers make
These issues come up often:
- using a copied overseas privacy policy that refers to laws or rights that do not fit New Zealand
- describing data collection in broad generic terms with no reference to training activities
- failing to mention recording of classes, webinars or assessments
- bundling marketing consent into compulsory enrolment wording
- forgetting to mention employer reporting in workplace training
- collecting health or support information without explaining why
- not updating the notice after switching software platforms or expanding services
- treating a privacy notice as a website footer only, instead of a collection notice used at key points
A good rule is simple: if a learner, employee or client would be surprised to discover a use or disclosure of their information, your privacy notice probably needs work.
What a well drafted notice usually includes
Most New Zealand training providers will want their privacy notice to address:
- who the business is and how to contact it
- what personal information is collected
- how the information is collected
- the reasons for collection
- what happens if the information is not provided, where relevant
- who the information may be shared with
- whether information may be disclosed overseas
- how the information is stored and protected at a high level
- how people can access or correct their information
- how complaints or privacy questions can be raised
The drafting should reflect your size and activities. A small specialist training consultancy may need a shorter notice than a provider with online accounts, multiple trainers, assessments, recordings and employer reporting. Shorter is not always better if it leaves out real practices.
FAQs
Do all New Zealand training providers need a privacy notice?
Most do. If your business collects personal information from learners, clients, staff or website users, you should have a privacy notice or collection notice that explains what you collect and why.
Is a website privacy policy enough on its own?
Usually not. A website privacy statement helps, but training providers often also need privacy wording on enrolment forms, event registrations, recorded session notices or staff documents so people are informed at the right time.
Do we need to mention online platforms and overseas software providers?
Yes, if those providers handle personal information. You should explain the categories of service providers you use and review whether any overseas disclosure issues need to be addressed.
Can we use learner information for marketing if we collected it for enrolment?
Sometimes, but you should not assume enrolment automatically covers ongoing marketing. Your notice and forms should clearly explain any marketing use, and your communications should be consistent with New Zealand privacy and marketing rules.
What if an employer pays for staff training?
You should be clear about what participant information will be shared back to the employer, such as attendance or completion status. That should be covered in both your client arrangements and your participant facing privacy wording.
Key Takeaways
- A privacy notice for New Zealand training providers should explain, in plain English, what personal information you collect, why you collect it, who you share it with and how people can access or correct it.
- Your notice should match the reality of your enrolment process, learning platforms, assessments, marketing activity, employer reporting and staff handling practices.
- Privacy issues commonly arise before you launch online, before you sign a client contract, before you adopt new software and before you collect sensitive learner information.
- Generic copied policies are a common mistake. Training providers need wording tailored to class recordings, certifications, attendance reporting, online delivery and support information.
- Your privacy notice should line up with related documents, including website terms, enrolment terms, client contracts, contractor agreements and internal processes.
- Regular reviews matter, especially when your business grows, changes software, expands services or starts selling online courses.
If your business is dealing with privacy notice training providers and wants help with privacy notices, enrolment terms, online platform contracts, and data handling compliance, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
When should you formalise this?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







