Records of Processing Activities for New Zealand Businesses

Alex Solo
byAlex Solo12 min read

If your business collects customer details, staff records, website analytics, supplier contacts or marketing data, you are already processing personal information, whether you call it that or not. A common mistake is assuming privacy compliance starts and ends with a website privacy policy. Another is keeping data in five different systems without any clear record of what is stored, why it is there, who can access it, or when it should be deleted. A third is signing up to offshore software before checking where personal information goes.

Records of processing activities help fix those problems. They give you a practical map of your data handling so you can answer basic but important questions before you sign a contract, before you launch online, and before a privacy issue turns into a scramble. For New Zealand businesses, this guide explains what records of processing activities are, when they matter, how to create them in a sensible way, and the mistakes that most often cause trouble.

Overview

Records of processing activities are internal records that show what personal information your business collects, why you collect it, where it is stored, who you share it with, and how long you keep it. They are not just a box-ticking exercise. They help you manage Privacy Act obligations, respond to access or correction requests, assess overseas providers, and reduce confusion inside your team.

  • Identify each category of personal information your business handles, such as customer contact details, employee files, payment information and marketing lists.
  • Record why the information is collected and the business purpose for using it.
  • List where the data comes from, where it is stored, and which systems or service providers receive it.
  • Note any overseas storage, access or disclosure arrangements.
  • Set retention periods and practical deletion or archival rules.
  • Assign internal responsibility so the record stays current when your systems or processes change.

What Records of Processing Activities Means For New Zealand Businesses

For a New Zealand business, records of processing activities means having a clear internal record of your personal information handling across the business, not just on paper but in a way your team can actually use.

New Zealand's Privacy Act 2020 does not prescribe a single mandatory template for all businesses called a record of processing activities in the same way some overseas regimes do. But the practical expectation is similar. If your business handles personal information, you should know what you hold, why you hold it, where it sits, and what safeguards apply. Without that, it is difficult to comply with core privacy obligations.

This issue matters because privacy compliance is operational. You cannot give an accurate privacy policy or privacy collection notice, assess a new software provider, handle a request for access, or respond to a notifiable privacy breach if nobody has mapped the data flow first.

What these records usually include

A useful record of processing activities usually includes the main facts about each processing activity, rather than broad statements that are too vague to help. For example, instead of saying “we collect customer data”, the record should break that down into real business activities.

  • The type of activity, such as onboarding customers, sending email marketing, managing employees, processing payroll, handling online orders, or running support tickets.
  • The categories of personal information involved, such as names, phone numbers, addresses, device data, employment history, bank account details, or identification documents.
  • The source of the information, such as the individual, a website form, a recruitment platform, a referral partner, or a third party service provider.
  • The purpose of the activity, such as fulfilling orders, verifying identity, managing a contract, paying staff, or complying with legal obligations.
  • The systems used to store or process the information, such as a CRM, cloud drive, payroll software, helpdesk platform, accounting tool or email platform.
  • Who can access the information internally and which external providers receive it.
  • Whether information is disclosed or accessible overseas.
  • How long the information is kept and how it is deleted, anonymised or archived.
  • Any particular security controls or higher-risk features, such as sensitive information, children’s information, or large-scale marketing profiles.

Why this matters even for smaller businesses

Small and medium businesses often assume formal data mapping is only for larger companies. That is where founders often get caught. A five-person business can still hold employee records, customer databases, website enquiry data, CCTV footage, email archives and mailing lists across multiple systems.

The main risk is not just a regulator asking for paperwork. The practical risk is making bad decisions because no one has a complete picture. You might duplicate data across platforms, keep old applicant records for too long, give a contractor wider access than needed, or promise something in your privacy collection notice that does not match what your systems actually do.

These records do not sit in isolation. They support several parts of a sensible compliance setup.

  • Privacy transparency, because your collection notices and privacy policy need to reflect actual data handling.
  • Commercial contracts, because you should understand what customer or staff data is affected before you sign with a SaaS provider, marketing agency or outsourced administrator.
  • Security planning, because you need to know which systems contain the highest-risk information.
  • Employment documentation, because staff handling personal information should have clear responsibilities and confidentiality expectations in their employment contracts.
  • Incident response, because a privacy breach response is much faster when the business already knows what data sits where.

For startups, this becomes especially relevant when you start a business in New Zealand with a digital product, sell online, hire your first staff member, or expand into a new industry with tighter privacy expectations such as health-adjacent services, education technology, recruitment or financial administration.

When This Issue Comes Up

Records of processing activities usually become urgent at moments of change, when a business is about to add a new system, launch a new service, or deal with a privacy problem under time pressure.

In practice, founders tend to think about this too late. They spend money on setup, subscriptions and outsourcing first, then try to reverse engineer where personal information is flowing.

Before you launch online

If you are selling online or collecting leads through a website, you should document the data flow before launch. This includes website forms, newsletter tools, cookies or analytics, payment processors, customer accounts and support channels.

This is also the point where privacy disclosures, customer terms and supplier agreements start intersecting. If your site says one thing about data use but your software stack does another, your documents are already out of step.

Before you sign with software or service providers

Any time you adopt a CRM, payroll platform, booking system, cloud host, outsourced HR provider or marketing platform, records of processing activities should be updated. That gives you a proper basis for asking the right questions before you sign.

  • What personal information will the provider handle?
  • Will they store or access information outside New Zealand?
  • Who within your team will have access?
  • Does the provider need all of that information, or only part of it?
  • What happens to the data when the contract ends?

This is where commercial terms and privacy risk overlap. A contract may deal with service levels and pricing, but if it does not align with your actual data handling, you can still be exposed.

When you hire staff or engage contractors

Employee and contractor onboarding creates new data streams quickly. You begin collecting identification details, contact information, payroll records, emergency contacts, performance information and sometimes health-related information.

If your business uses shared drives, messaging apps or informal processes, these records can spread widely without anyone noticing. A proper processing record helps you decide what should be stored centrally, what should be restricted, and what should not be kept at all.

When you expand, restructure or seek investment

Investors, acquirers and commercial partners often want confidence that your data practices are under control. They may not ask specifically for a document called a record of processing activities, but they will ask questions that depend on one.

  • What personal information does the business rely on?
  • Are there any high-risk data sets?
  • Which third parties process that information?
  • Are privacy notices and internal practices aligned?
  • Are there unresolved issues around retention, security or offshore disclosures?

If you cannot answer those questions clearly, due diligence slows down and trust drops.

After a complaint, access request or privacy incident

This is the most expensive time to discover you do not know your own systems. If an individual asks for access to their information, asks for correction, or complains about disclosure, you need to know where relevant records are likely to sit.

The same applies if a staff member sends information to the wrong recipient, a laptop is lost, or an online platform is compromised. Records of processing activities do not prevent every breach, but they make response faster and more accurate.

Practical Steps And Common Mistakes

The best approach is to build a working data map that reflects how your business actually operates, then connect it to your privacy documents, contracts and internal procedures.

You do not need a complicated enterprise system to do this. Most startups and SMEs can start with a structured internal register, as long as it is specific, current and owned by someone.

Step 1: List your real-world processing activities

Start with business functions, not legal labels. Think about the moments where personal information enters, moves through, or leaves your business.

  • Customer enquiries and lead capture.
  • Online ordering and payment processing.
  • Account creation and login management.
  • Customer support and complaint handling.
  • Email marketing and promotions.
  • Recruitment and applicant screening.
  • Employment administration and payroll.
  • Supplier or contractor management where individuals are identified.
  • CCTV, access control or visitor management if used.

This gives you a manageable structure. From there, document what information is involved in each activity.

Step 2: Match each activity to a business purpose

Every data set should have a clear reason for being collected and used. “Because the system collects it automatically” is not a good enough reason. If you cannot explain the purpose, that usually points to overcollection or poor system design.

Be careful with secondary uses. For example, customer contact details collected to fulfil an order are not automatically fair game for unrelated marketing or profiling without proper transparency and a lawful basis for that use.

Step 3: Trace the systems and recipients

Founders often underestimate how many vendors touch their data. A single website enquiry might pass through your site host, form provider, CRM, email platform and internal inbox.

Your record should identify:

  • The platform or location where the information is first collected.
  • Where it is stored after collection.
  • Which team members or departments can access it.
  • Which outside providers process, host or receive it.
  • Whether those providers are in New Zealand or offshore.

This step is especially important before you sign contracts with software providers or agencies. It can also affect what you need to say in your privacy policy or privacy collection notices.

Step 4: Set retention and deletion rules

One of the most common mistakes is keeping everything forever because deletion feels risky or inconvenient. In reality, indefinite retention creates its own risk. Old data is harder to secure, harder to search, and easier to misuse.

Your records should note how long information is kept and what happens at the end of that period. Some records need to be retained for legal or operational reasons. Others should be deleted, anonymised or archived under controlled access. Where retention touches tax or accounting requirements, speak with your accountant or tax adviser as well.

A processing record is only useful if it informs the rest of your business setup. Once your record exists, compare it against your current documents and internal arrangements.

  • Privacy policy and collection statements.
  • Customer terms and platform terms.
  • Supplier contracts and SaaS terms.
  • Employment agreements, policies and confidentiality obligations.
  • Internal access controls and approval processes.
  • Breach response procedures.

This is also a good time to check whether your business structure and decision-making lines are clear. Startups often have founders, contractors and advisers all using the same systems without a formal access owner. That can create confusion about responsibility.

Common mistakes New Zealand businesses make

The most common mistakes are practical, not technical. They usually come from speed, growth and disconnected systems.

  • Treating a privacy policy as the whole privacy programme.
  • Copying overseas templates that do not match New Zealand operations or legal context.
  • Recording data categories too broadly, so the register is not useful in practice.
  • Forgetting employee, applicant and contractor information.
  • Ignoring offshore access because the software “just works in the cloud”.
  • Keeping old mailing lists, CVs or support records indefinitely.
  • Failing to update the register after changing software, outsourcing functions or launching new features.
  • Leaving ownership unclear, so nobody maintains the record.

Privacy records are not your only setup task, but they connect with several others. When you start a business in New Zealand, founders often focus on registration, business structure, branding and trade mark issues first. Those matter, but data handling should be sorted early too, especially if your business is digital, service-based, or marketing-heavy.

For example, an online retailer may need customer terms, supplier agreements and privacy disclosures that all line up with the same data flow. A recruitment business may need stronger internal controls around candidate records. A software startup may need to check how user analytics, account data and support logs are handled before scaling. An education provider may need to be more careful about student information and parent contact details.

The record of processing activities acts like a central reference point. It helps your contracts, privacy wording and operational decisions stay consistent as the business grows.

FAQs

Do New Zealand businesses legally need records of processing activities?

There is no one-size-fits-all statutory form that every New Zealand business must maintain under that exact name. But keeping an internal record of how personal information is processed is a sensible and often necessary way to meet privacy obligations in practice.

What size business should create one?

Any business that regularly handles personal information should consider it. Even a small company with a website, customer list, employees and cloud software can benefit from a simple but accurate processing register.

Is a privacy policy the same thing as a record of processing activities?

No. A privacy policy explains to individuals how your business handles personal information. A record of processing activities is an internal operational document that maps what really happens behind the scenes.

What if we use overseas software providers?

You should document that clearly. Record what information the provider can access, where data may be stored or disclosed, and whether your contracts and privacy disclosures reflect that arrangement.

How often should the record be updated?

Update it whenever your business changes how it collects, uses, stores or shares personal information. At a minimum, review it regularly and again before you launch online, hire new teams, add new systems, or sign major provider contracts.

Key Takeaways

  • Records of processing activities give your business a practical map of what personal information you handle, why you handle it, and where it goes.
  • They are especially useful before you sign with software providers, launch online, hire staff, expand into new services or respond to a privacy issue.
  • A good record should cover data categories, purposes, systems, access, recipients, offshore arrangements, retention and deletion.
  • Common mistakes include relying only on a privacy policy, forgetting employee data, ignoring cloud providers, and never updating the record after business changes.
  • Your processing record should align with your privacy wording, contracts, internal policies and access controls.
  • If your business is dealing with records of processing activities and wants help with privacy policies, supplier contracts, data handling reviews, and internal compliance documents, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.