Privacy Statements for New Zealand Businesses: What They Are and When You Need One

Alex Solo
byAlex Solo12 min read

A lot of New Zealand businesses collect personal information long before they realise they need to explain what happens to it. You might have a website contact form, take online bookings, run email marketing, use CCTV, collect customer details at a market stall, or ask job applicants to send CVs. Common mistakes include copying a generic overseas privacy statement, hiding it in hard-to-find wording, or saying you collect data “just in case” without a real business reason. Another frequent issue is forgetting that your actual day to day practices need to match what your statement says.

A privacy statement is not just website filler. It is part of how you tell customers, staff, contractors and other individuals what personal information you collect, why you collect it, how you use it, and who you share it with. For many businesses, this is a basic transparency step under New Zealand privacy law. Here’s what a privacy statement does, when you are likely to need one, and the practical points to sort out before you launch online, roll out a new system, or sign up with a third party software provider.

Overview

A privacy statement is a plain language notice that explains your business’s personal information practices. In New Zealand, if your business collects personal information, you should usually have a clear privacy statement available at the point people deal with you, especially online or wherever you gather information directly.

The right statement depends on what your business actually collects and how it uses that information. A one size fits all template often misses important details and can create compliance problems if it does not reflect your real processes.

  • Identify what personal information your business collects, from customers, staff, contractors, website visitors and job applicants.
  • Check why you collect each type of information and whether you genuinely need it.
  • Explain how information is stored, used, disclosed and retained.
  • Make sure people know how they can access or correct their information.
  • Review whether any information is sent overseas through cloud software, payment tools or service providers.
  • Match your privacy statement to your actual systems, contracts and internal practices.
  • Put the statement where people will see it before they hand over their details.

What Privacy Statement Means For New Zealand Businesses

A privacy statement tells people, in practical terms, what your business does with their personal information. It helps you meet transparency obligations and sets expectations before someone gives you their details.

Under the Privacy Act 2020, New Zealand businesses that collect personal information generally need to make certain information known to the people concerned. This often includes why the information is being collected, who will receive it, whether providing it is compulsory or voluntary, and what rights the person has to access and correct their information.

For many businesses, the privacy statement is where those points are pulled together in a clear and usable format. It is not necessarily the only step you need to take, but it is often the most visible one.

What counts as personal information?

Personal information is any information about an identifiable individual. It is broader than many founders expect. It can include obvious items like a customer’s name, email address, phone number and delivery address, but it can also include less obvious data if it can identify someone directly or indirectly.

Examples can include:

  • customer account details
  • booking information
  • IP addresses and device data where linked to an individual
  • CCTV footage
  • employee records
  • job applications and interview notes
  • health or dietary information collected for services or events
  • complaint records and correspondence

Is a privacy statement the same as a privacy policy?

Not always, but people often use the terms interchangeably. In practice, a business may have an internal privacy policy that guides staff on how to handle personal information, and a public facing privacy statement that explains those practices to customers and other individuals.

Some businesses combine both ideas into a single public document. The key point is that your outward facing statement should be accurate, understandable and tailored to the information you actually collect.

Why this matters for small businesses too

A common misconception is that privacy documents are only for larger companies or tech businesses. That is not right. A sole trader, startup, online store, consultancy, gym, clinic, recruitment business, hospitality venue or trades business can all collect personal information in ways that trigger privacy obligations.

This issue often appears early. Founders start a business in New Zealand, choose a business structure, complete registration, set up a website, get a trade mark underway, and sort out customer terms or contracts with booking software or payment platforms. Privacy can be left until later, but customer data collection usually starts on day one.

The main risk is not just legal non compliance. A weak or inaccurate privacy statement can also create trust issues, lead to complaints, and expose a gap between what your business says and what it actually does.

What a good privacy statement usually covers

A useful privacy statement should reflect the real customer journey and the systems behind it. It will usually address:

  • what information you collect
  • how you collect it, such as through forms, purchases, cookies, phone calls or in person interactions
  • why you collect it
  • whether people must provide it and what happens if they do not
  • who you share it with, such as payment providers, IT vendors, couriers or professional advisers
  • whether it is stored or processed overseas
  • how individuals can request access or correction
  • how to contact your business about privacy concerns

If your statement says you only use information for one purpose, but your marketing team later uses it for another purpose, that mismatch can become a problem. The wording should be specific enough to be meaningful, without boxing your business into statements that are too narrow or unrealistic.

When This Issue Comes Up

You usually need a privacy statement when your business starts collecting personal information, especially through a website, app, booking system, employment process or customer onboarding form. In practice, that means many businesses need one earlier than they think.

When you launch online

If your business has a website that collects names, emails, phone numbers, payment details, enquiry information or marketing sign ups, you should have a privacy statement available before people submit their information. This applies whether you are selling products, offering services, taking bookings or just inviting enquiries.

Selling online raises a few related issues too. Alongside privacy, founders often need to sort out website terms, consumer law compliance, payment processes, supplier agreements and trade mark protection. Your privacy statement should work with those documents, not contradict them.

When you collect information in person

Privacy statements are not only for websites. You may need one if you collect customer details:

  • at a market stall
  • through paper forms
  • at events or promotions
  • through loyalty programmes
  • in a clinic, studio, office or retail store
  • when visitors are recorded on CCTV

In these situations, the notice may be shorter or presented differently, but people should still know what you are collecting and why.

When you hire staff or contractors

Recruitment and employment processes often involve sensitive personal information. If your business asks applicants for CVs, referee details, identity documents or health related information, you should explain how that information will be used and stored.

This point is easy to miss when you are moving quickly to make a first hire. Before you sign employment contracts or a contractor agreement, make sure your internal practices for handling applicant and worker data line up with what you tell people.

When you use third party platforms

Many SMEs rely on cloud systems for email marketing, payroll, customer relationship management, ecommerce, booking systems, accounting tools and file storage. These tools may store or process personal information outside New Zealand.

That does not automatically mean you cannot use them. But your privacy statement and your contracts with providers should accurately reflect what happens to the data. This is where founders often get caught, especially when they install multiple tools over time without reviewing their privacy wording.

When your business collects sensitive information

If your business handles more sensitive categories of information, you need to be especially careful. That may include health information, identity documents, financial details, children’s information, or records connected to vulnerable customers.

Examples include:

  • a fitness business collecting injury or medical details
  • a childcare provider collecting parent and child information
  • a professional services firm holding identification documents for verification
  • a hospitality business collecting dietary needs for events

More sensitive information generally calls for clearer explanations, stronger internal controls and better staff awareness.

When you change your business model

A privacy statement is not a once only exercise. You should review it when your business changes direction, adopts new software, expands into a new market, introduces online sales, launches a mobile app, or starts new marketing activities.

For example, a founder may start as a local service business, then add online booking, digital advertising, customer accounts and email campaigns. Each step changes the data picture. If the statement does not evolve too, it can become outdated quickly.

Practical Steps And Common Mistakes

The most practical way to prepare a privacy statement is to map what your business actually does with personal information first, then write the statement around that reality. Legal wording should follow your operations, not the other way around.

Step 1: Map your data collection points

Start with the places where your business receives personal information. Look at the full lifecycle, not just your website. Check:

  • contact forms and email enquiries
  • checkout pages and payment tools
  • booking systems and client intake forms
  • paper forms used in store or on site
  • job application channels
  • customer support messages
  • marketing sign ups and promotions
  • CCTV and security systems

This exercise often shows that the business collects more information than the owner realises. It can also reveal duplicate collection, unnecessary questions or systems that do not speak to each other.

Step 2: Decide what you actually need

Your business should only collect personal information where there is a genuine business purpose. Founders sometimes ask for extra fields because they might be useful later. That approach creates risk.

For each data point, ask:

  • why do we need this information?
  • when do we collect it?
  • who in the business uses it?
  • how long do we keep it?
  • what happens if we do not collect it?

If you cannot answer those questions clearly, reconsider whether you should be collecting that information at all.

Step 3: Match the statement to your systems and contracts

Your privacy statement should align with the tools and agreements your business uses. If your ecommerce store shares customer data with a fulfilment provider, your statement should say that. If a software vendor hosts data overseas, your statement should deal with that too.

Before you sign a contract with a software provider, check what the provider says about storage, processing, subcontractors and security. Your customer facing statement should not promise something your vendors do not support.

Step 4: Put the statement where people will see it

A privacy statement is most useful when people can access it at the time they provide their information. For websites, that usually means placing it where forms, account registration or checkout processes appear. For in person collection, it may mean a printed notice, intake form wording, signage or a digital form displayed on a tablet.

Visibility matters. Hiding the statement in fine print or making it hard to find undermines the point of giving notice.

Step 5: Train the people who handle information

Even a well drafted privacy statement can fail in practice if staff do not follow it. Customer service teams, managers, sales staff and recruiters should understand the basics of what information the business collects, who can access it, and how requests for access or correction should be handled.

This matters most in growing businesses, where processes become informal and responsibilities are spread across a small team.

Common mistake: copying a foreign template

A United States, Australian or European template may refer to different laws, rights or terminology. It can also include concepts that do not fit how your New Zealand business operates.

A copied template often creates two problems:

  • it leaves out key details relevant to your actual systems
  • it includes promises or legal references that do not apply to your business

That mismatch can confuse customers and make internal compliance harder.

Common mistake: treating cookies and analytics as an afterthought

Businesses often focus on obvious customer details and forget website analytics, tracking tools and marketing pixels. If your site collects behavioural information or uses tools that profile visitors for advertising or performance tracking, your privacy statement should address this in a clear and accurate way.

This is especially relevant for businesses selling online, running digital campaigns, or using customer relationship software to follow up leads.

Common mistake: saying too little or too much

A vague statement that says you collect information “to improve services” is often not helpful enough. On the other hand, an overly broad statement that claims you may use information for almost any purpose can damage trust and may not reflect fair collection practice.

The goal is plain language that is specific to your business. A customer should be able to read it and understand what will happen to their information in normal business terms.

Common mistake: forgetting access and correction rights

People generally have rights to ask for access to personal information you hold about them and to request correction. Your privacy statement should tell them how to make that request and who to contact.

If your business receives a request and has no process for responding, delays and confusion can follow. This is worth sorting out before you spend money on setup for a new customer platform or outsourced admin team.

Common mistake: not reviewing the statement as the business grows

Startups and SMEs change fast. A privacy statement that was fine when you only took email enquiries may no longer work once you add online sales, loyalty programmes, app integrations or a team of staff.

Review the statement whenever you:

  • launch a new product or service
  • start using a new software platform
  • expand your marketing activity
  • collect new categories of information
  • hire staff and introduce HR systems
  • share data with new service providers

A review can often be bundled with other legal housekeeping, such as updating contracts, checking website terms, confirming business name use, or reviewing trade mark filings and branding.

FAQs

Does every New Zealand business need a privacy statement?

Not every business needs the same type of document, but if your business collects personal information, a clear privacy statement is usually a sensible and often necessary step. Most businesses with websites, booking systems, customer records or recruitment processes should have one.

Do I only need a privacy statement for my website?

No. You may also need privacy wording for paper forms, email collection, recruitment, CCTV, in person sign ups or other offline collection methods. The key issue is whether you are collecting personal information, not just where it happens.

Can I use a free template?

You can start from a template, but it needs to be tailored carefully. A generic template often fails to reflect your actual data practices, third party software, overseas storage arrangements or industry specific collection. That can create more work later.

What if I use overseas software providers?

You should understand where personal information goes, what the provider does with it, and whether your privacy statement explains that clearly. The fact that data is processed offshore is not something to ignore, especially if multiple systems are involved.

How often should I update my privacy statement?

Review it whenever your business changes how it collects, uses, stores or shares personal information. A yearly check is also sensible for many SMEs, particularly if you are growing, selling online, hiring staff or adopting new software.

Key Takeaways

  • A privacy statement explains how your New Zealand business collects, uses, stores and shares personal information.
  • If you collect personal information through a website, booking system, recruitment process, in person form or CCTV, you will often need a clear privacy statement.
  • Your statement should reflect real business practices, not generic template wording copied from another market.
  • It should cover what information you collect, why you collect it, who receives it, whether it may go overseas, and how people can access or correct their information.
  • Founders should review privacy wording when launching online, adopting new software, expanding marketing, hiring staff or changing business operations.
  • The document should sit alongside your other legal foundations, including contracts, website terms, consumer compliance, branding and business structure decisions.

If your business is dealing with privacy statement and wants help with privacy wording, website terms, software provider contracts, compliance reviews, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.