Private Information: Legal Obligations, Privacy and Data Security

Alex Solo
byAlex Solo11 min read

Private information is easy to collect and surprisingly easy to mishandle. Many New Zealand businesses assume privacy rules only apply to large tech companies, rely on a copied privacy policy that does not match what they actually do, or store customer and staff data in shared systems without clear access controls. Those mistakes can lead to complaints, loss of trust, contract problems, and in some cases mandatory steps after a privacy breach.

For startups and SMEs, the issue usually appears in ordinary founder moments, when you launch online, hire staff, sign with a software provider, run marketing campaigns, or ask customers for more data than you really need. The legal risk is not just hacking. It is also poor collection practices, weak internal processes, and saying one thing in your privacy notice while doing another.

This guide explains what counts as private information in New Zealand, when your obligations arise, the main privacy and data security rules to think about, and the practical steps that help businesses avoid common mistakes before they become expensive problems.

Overview

New Zealand businesses that collect, use, store or share personal information need to handle it lawfully, transparently and securely. The Privacy Act 2020 applies widely, and the main question is usually not whether the law applies, but whether your current practices match what the law expects and what your contracts, website and internal processes say.

A sensible starting point is to map what information you collect, why you collect it, who can access it, where it is stored, and what you would do if something goes wrong.

  • Identify what private information your business holds about customers, staff, contractors and suppliers.
  • Check whether you really need each category of information you collect.
  • Make sure your collection statements and privacy policy reflect what you actually do.
  • Limit access to information internally and use appropriate security measures.
  • Review contracts with software providers, marketing platforms and other service providers.
  • Set up a clear process for privacy requests, corrections and complaints.
  • Prepare for privacy breaches, including when notification may be required.
  • Take extra care if information is sent, stored or accessed overseas.

What Private Information Means For New Zealand Businesses

Private information usually means personal information, that is, information about an identifiable individual. For most businesses, that covers far more than names and email addresses.

If someone can be identified directly or indirectly from the information you hold, you should treat it as personal information and handle it carefully. In practice, this often includes customer records, employee files, website account details, job applications, device identifiers, CCTV footage, support call notes, and payment-related information handled through your systems.

What counts as personal information

The category is broad. A single piece of data might identify a person on its own, or it might become identifying when combined with other information your business already has.

  • Name, address, email address and phone number.
  • Date of birth, identification details and customer account numbers.
  • Employment records, payroll details and performance notes.
  • Health information, accessibility needs or leave information.
  • IP addresses, online identifiers and website usage data linked to an account.
  • Recorded calls, chat logs, CCTV footage and complaint records.
  • Photos, video, voice recordings and biometric data.

Some information is more sensitive than others. Health details, disciplinary records, identity documents and children’s information generally require closer handling because the harm from misuse is usually higher.

What the Privacy Act expects

The Privacy Act 2020 sets out information privacy principles. These principles cover the full information lifecycle, from collection through to storage, use, disclosure, access and correction.

For business owners, the practical message is simple: collect information for a genuine business purpose, tell people what is happening, keep the information safe, do not use it for unrelated purposes without a proper basis, and give people access to their information where required.

This also means your privacy documents cannot be treated as a box-ticking exercise. If your website says you only use data for order fulfilment, but your team later uploads customer lists to unrelated marketing tools or shares them with another business, the legal and reputational risk rises quickly.

Why this matters even for small businesses

Small businesses often think privacy obligations are lighter because the team is small or the customer list is modest. That is where founders often get caught. A small e-commerce business can still hold hundreds of addresses, payment-adjacent details, support messages and marketing preferences. A professional services firm may hold passports, bank details and confidential client records.

The main risk is not only regulatory attention. It is also losing a client, breaching a commercial contract, delaying a sale process, or dealing with avoidable clean-up work after a staff member downloads data into the wrong spreadsheet or sends information to the wrong recipient.

When This Issue Comes Up

Private information issues come up early and often, usually before the business realises it is dealing with privacy law in a serious way.

Most founders first face the issue when setting up systems. You choose an e-commerce platform, a CRM, payroll software, cloud storage, help desk tools, analytics, email marketing systems and security settings. Each of those choices can affect what information you collect, where it goes, who can access it and what your legal documents need to say.

Common founder moments

  • Before you launch online and start collecting customer names, contact details and payment information.
  • Before you hire staff and gather CVs, references, bank details and emergency contacts.
  • Before you sign a contract with a software provider that stores business and customer data.
  • Before you spend money on setup for CCTV, access control systems or device monitoring tools.
  • Before you send marketing emails or create audience lists from customer data.
  • Before you ask customers for identity documents, health details or other sensitive information.
  • Before you share data with contractors, offshore support teams or related businesses.
  • Before a sale, investment round or due diligence process where data handling is scrutinised.

Examples across different business types

An online retailer may collect delivery addresses, account passwords, returns history and shopping behaviour. A healthcare-adjacent startup may handle highly sensitive health and wellness information. A SaaS company may process end-user data on behalf of business customers, which creates both privacy obligations and contract risk.

A café with online ordering might think it only holds basic customer details, but it may also collect staff records, CCTV footage, allergen notes, loyalty information and third-party delivery platform data. A professional services firm might hold passport scans for verification, engagement records, payment information and confidential commercial documents.

The issue also appears when you expand. If you start a business in New Zealand and later sell online overseas, use overseas cloud systems, or engage offshore contractors, you need to think carefully about how information moves across borders and what your customers have been told.

Commercial documents that often connect to privacy

Privacy is rarely a standalone issue. It often sits inside wider commercial paperwork and business setup decisions.

  • Website terms and app terms.
  • Privacy policies and collection statements.
  • Employment agreements and workplace policies.
  • Contractor agreements and confidentiality clauses.
  • Software and SaaS customer contracts.
  • Supplier agreements and outsourcing arrangements.
  • Terms for promotions, memberships or loyalty programmes.
  • Sale and investment documents during due diligence.

That is why privacy should be considered alongside contracts, business structure, brand protection, trade mark planning and your broader compliance setup, not only as an IT problem.

Practical Steps And Common Mistakes

The best privacy approach is usually simple: collect less, say clearly what you are doing, secure what you keep, and make sure your team follows the same process every time.

1. Map your data before you write documents

A privacy policy should describe reality, not guess at it. Before you draft or update anything, map the personal information your business handles.

For each category of information, record:

  • What the information is.
  • Why you collect it.
  • How you collect it.
  • Where it is stored.
  • Who has access.
  • Who it is shared with.
  • How long you keep it.
  • How it is deleted or de-identified.

This exercise often reveals duplicate systems, unnecessary collection, old staff access, and software tools the business forgot it was using.

2. Only collect what you actually need

Businesses often ask for more information than the job requires. That creates extra risk without adding much value.

If you run an online store, you may need delivery details and contact information, but not necessarily date of birth. If you recruit casually, you may need enough information to assess suitability, but not broad background material before it is justified. If you offer a digital service, collect only the data needed to deliver and improve the service, rather than taking every field your platform makes available by default.

3. Be transparent at the point of collection

People should understand what is happening when they hand over their information. This usually means having a privacy policy, but it can also require clear wording on forms, sign-up pages, booking tools, HR processes and support channels.

Your notices should align with your actual practices on matters such as:

  • The purpose of collection.
  • Whether providing the information is optional or required.
  • What happens if the person does not provide it.
  • Who the information may be shared with.
  • Whether information may be stored or accessed overseas.
  • How a person can request access or correction.

A common mistake is using generic language that looks polished but says very little. Another is failing to update notices when the business adds new tools or uses data in new ways.

4. Set access controls and security that fit the risk

Data security is not just a technical issue for developers. It is a management issue. The right measures depend on the sensitivity of the information and the size and complexity of the business, but every business should have a baseline.

  • Use strong passwords and multi-factor authentication.
  • Restrict access based on role, not convenience.
  • Remove access promptly when staff leave or change roles.
  • Use secure devices and keep software updated.
  • Train staff to spot phishing, misdirected emails and social engineering.
  • Back up important systems and test recovery processes.
  • Secure physical files, laptops and portable devices.
  • Review whether sensitive information needs encryption or extra controls.

One of the most common small business mistakes is keeping everything accessible to everyone because the team is trusted and small. Trust is not a substitute for process.

5. Review overseas storage and service providers

Many New Zealand businesses use cloud platforms hosted overseas or support teams in other countries. That can be perfectly workable, but you need to understand where information is going and whether your arrangements are appropriate.

Before you sign a contract with a provider, check:

  • Where data is stored and from where it can be accessed.
  • What security measures the provider offers.
  • Whether subcontractors are involved.
  • What the provider can do with your data.
  • How breaches are handled and reported.
  • How data is returned or deleted when the contract ends.

This is also where businesses often need contracts that clearly allocate responsibilities, especially if you process information for clients or rely on a third party to process information for you.

6. Prepare for privacy requests and complaints

People may ask what information you hold about them or request correction. If your business has no process, these requests can become messy and inconsistent.

Nominate who handles privacy queries. Keep a simple internal process for verifying identity, locating relevant records, responding within a reasonable timeframe, and recording what was done. If a request relates to information spread across email, CRM notes and third-party platforms, your team should know where to look.

7. Have a privacy breach plan

A privacy breach can be malicious, accidental or internal. The breach might involve hacking, but it can also be a lost laptop, an email sent to the wrong customer, or a public folder left open.

Your plan should cover:

  • How staff escalate a suspected breach immediately.
  • Who investigates and who makes decisions.
  • How to contain the issue.
  • How to assess likely harm.
  • When legal advice may be needed.
  • When affected people and the Privacy Commissioner may need to be notified.
  • How the incident is documented and reviewed.

Mandatory notification can apply where a breach causes serious harm or is likely to do so. The exact assessment depends on the circumstances, so it is worth getting advice quickly if an incident occurs.

Common mistakes New Zealand businesses make

  • Copying a privacy policy from another business without matching it to actual operations.
  • Collecting sensitive information because a form template includes the field.
  • Letting former staff retain system access.
  • Using customer data for new marketing activity without checking what customers were told.
  • Storing personal information in unsecured spreadsheets or shared drives.
  • Failing to document internal processes for requests, complaints and breaches.
  • Assuming the software provider is solely responsible for privacy compliance.
  • Ignoring privacy due diligence when fundraising, selling the business or onboarding enterprise clients.

Founders should also remember that privacy overlaps with other legal obligations. Marketing claims about security and confidentiality can raise Fair Trading Act issues if they are misleading. Confidential information clauses in contracts may sit alongside privacy obligations. Employment contracts and contractor arrangements should also support your internal controls.

FAQs

Do all New Zealand businesses need a privacy policy?

Not every business is subject to the exact same practical requirements, but if you collect personal information, a clear privacy policy is often a sensible and expected step. It helps meet transparency obligations and is commonly expected by customers, platforms, commercial partners and enterprise clients.

What is the difference between privacy and data security?

Privacy is about how personal information is collected, used, disclosed and managed. Data security is about the measures you use to protect that information from loss, misuse, unauthorised access or disclosure. You generally need both.

Can I store customer information overseas?

Often yes, but you should understand where the data goes, what safeguards apply, and whether your privacy materials accurately describe the arrangement. Overseas hosting and access should be reviewed carefully before you sign and before you rely on the provider.

What should I do if my business has a privacy breach?

Act quickly to contain the issue, assess what information was affected, evaluate the risk of harm, and document your response. Some breaches may need to be notified to the Privacy Commissioner and affected individuals, especially where serious harm is likely.

Does employee information count as private information?

Yes. Staff records, payroll details, health information, performance notes, recruitment records and emergency contact details can all be personal information. Employers should treat employee data with the same level of care as customer information, adjusted for context.

Key Takeaways

  • Private information usually means personal information about an identifiable individual, and most New Zealand businesses handle it more often than they think.
  • The Privacy Act 2020 affects how you collect, use, store, disclose and respond to requests about personal information.
  • Privacy issues arise in everyday business decisions, especially when launching online, hiring staff, signing software contracts, marketing to customers and expanding overseas.
  • A workable privacy setup starts with mapping your data, limiting collection, being transparent, controlling access, reviewing suppliers and preparing for breaches.
  • Common mistakes include copied policies, unnecessary collection, weak access controls, inconsistent internal processes and mismatch between documents and real practices.
  • Privacy should be considered alongside contracts, website terms, employment documents, outsourcing arrangements and broader compliance planning.

If your business is dealing with private information and wants help with privacy policies, data handling contracts, breach response planning, compliance reviews, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.