Selling Customer Data in New Zealand: Privacy Law Issues for Businesses

Alex Solo
byAlex Solo11 min read

Many businesses treat customer data like a commercial asset, then get caught when a deal is already on the table.

The common mistakes are usually the same: assuming a privacy policy gives broad permission to sell information, signing a buyer's standard terms without checking who is responsible for privacy compliance, and thinking de-identified data is always safe to trade. In New Zealand, those assumptions can create real legal and commercial risk.

If you are considering selling data, licensing a customer database, sharing user information as part of a business sale, or entering a data monetisation arrangement, the legal question is not just whether the deal makes money. You also need to check what you originally told customers, whether the disclosure is authorised under the Privacy Act 2020, what your contract says about liability, and whether the transfer could be misleading or unfair in the wider business context. Here is what to sort out before you sign.

Overview

Selling customer information in New Zealand is not automatically unlawful, but it is heavily constrained by privacy law, your contractual promises, and the way the data was collected. The main risk is not only regulatory attention, but also losing customer trust, breaching partner agreements, or inheriting liability through a poorly drafted contract.

  • Identify exactly what data is being sold, licensed, disclosed, or shared, and whether it is personal information.
  • Check what customers were told at the point of collection, including any privacy notices, terms, consent wording, and sales materials.
  • Assess whether the proposed disclosure is permitted under the Privacy Act 2020, including any limits on use, disclosure, and overseas transfer.
  • Review contracts with buyers, service providers, funders, and commercial partners for restrictions, warranties, indemnities, and ownership issues.
  • Test whether the data is truly anonymised, or whether individuals could still be identified directly or indirectly.
  • Plan how you will document the transaction, allocate risk, handle complaints, and respond if customers object.

What Selling Data Means For New Zealand Businesses

Selling data can mean several different things, and the label matters less than the substance. If personal information changes hands for commercial value, the privacy issues usually follow whether you call it a sale, licence, partnership, data sharing arrangement, customer list transfer, or business asset deal.

Personal information is broader than many founders expect

Under the Privacy Act 2020, personal information generally means information about an identifiable individual. That can include obvious identifiers such as names, phone numbers and email addresses, but it can also include purchase history, location records, device identifiers, account behaviour, and profile information if a person can be identified from that data on its own or when combined with other information.

This is where businesses often get caught. A spreadsheet without names may still be personal information if the buyer can match the records back to real people. A loyalty database, app usage record, lead list, or customer segmentation file can all raise privacy issues even if the data feels commercial rather than sensitive.

A business sale is different from a standalone data deal, but not risk free

If you sell your whole business, customer data may transfer as part of the assets. That does not mean privacy concerns disappear. You still need to ask whether the transfer is consistent with the original purpose of collection, what customers were told, and whether the buyer will use the data in a materially different way.

A standalone deal is usually riskier. Selling a customer list to a third party for its own marketing, analytics, or product development is more likely to fall outside what customers reasonably expected when they handed over their details.

Many business owners focus only on whether they have consent. That matters, but it is not the whole picture. The Privacy Act also looks at purpose, transparency, fairness, storage, access, correction, and disclosure limits.

If your privacy notice said you collect information to fulfil orders and provide support, that does not automatically give you a free hand to monetise the database later. If your sign-up page was vague, buried key wording, or did not mention onward disclosure clearly enough, relying on implied permission can be risky.

Some data products are sold in aggregated or de-identified form. That can reduce privacy risk, but only if the information is genuinely no longer about identifiable individuals. If a buyer can re-identify users by combining the dataset with other information, the legal and reputational issue may remain.

Before you rely on a verbal promise that the buyer will not attempt re-identification, put the restriction into the contract. You should also define what standard of anonymisation has been applied and who bears the risk if that process fails.

The core legal question is whether you have the right to disclose the data for this specific deal, on these terms, to this recipient, for this use. The answer usually sits across several documents rather than one neat clause.

1. What did you tell customers when you collected the data?

Your first stop is the collection point. Look at sign-up forms, app screens, lead forms, account creation pages, campaign landing pages, order processes, and any privacy collection notice or statement in force at the time the data was collected.

Check whether those materials clearly covered:

  • why the information was collected
  • who it might be shared with
  • whether it could be sold, licensed, or transferred
  • whether the recipient could use it for its own purposes
  • whether the information could be sent overseas

If your wording only covered internal use, service delivery, or trusted suppliers acting for you, that may not support a third party acquiring the data for its own commercial benefit.

2. Is the disclosure allowed under the Privacy Act 2020?

The Privacy Act sets rules around how agencies collect, use, and disclose personal information. A business will usually need to consider whether the proposed disclosure fits the purpose for which the information was obtained, whether an exception applies, and whether the disclosure would be unfair or beyond reasonable customer expectations.

In practical terms, ask:

  • is the new use closely connected to the original reason for collection
  • would a customer reasonably expect this disclosure
  • do you have clear consent, and was it informed and specific enough
  • are there any sensitive categories of information that increase the risk
  • does the buyer intend to use the data in a way you did not originally explain

If the answer is uncertain, the deal needs more work before you sign. That may mean changing the structure, narrowing the dataset, seeking updated permissions, or deciding not to proceed.

3. Are there overseas disclosure issues?

If the buyer, processor, or related group entity is outside New Zealand, cross-border disclosure rules may apply. This matters even where the commercial deal is signed locally but the data will be stored, analysed, or accessed offshore.

Before you accept the provider's standard terms, check:

  • where the data will be stored and accessed
  • whether the recipient is subject to comparable privacy safeguards
  • what promises the buyer is giving about compliance and onward transfers
  • what you told customers about overseas disclosure

Cross-border issues are easy to miss when a buyer says it has a global platform. The legal risk sits with the actual data flow, not just the local sales contact.

4. Who owns the data, and who can use it after the deal?

Ownership of data is often discussed casually, but the legal rights are usually contractual rather than absolute. Your rights may depend on terms with customers, terms with software vendors, joint venture arrangements, reseller agreements, or white label deals.

For example, a platform provider may claim rights in usage data. A commercial partner may restrict use of shared customer records. A franchise or distribution agreement may control who owns leads generated in the relationship. If you ignore those documents, you may promise the buyer rights you do not actually hold.

The sale agreement should spell out:

  • what dataset is included
  • whether the deal is a sale, licence, or limited-use disclosure
  • what the buyer can do with the information
  • whether the seller can continue using the data
  • what happens to derived insights, models, and analytics outputs
  • whether re-identification, resale, or onward disclosure is prohibited

5. What warranties and indemnities are you giving?

This is often where founders take on more risk than they realise. A buyer may ask you to warrant that all data was collected lawfully, all required consents were obtained, every notice was compliant, and no complaint or breach has occurred. Those promises may be too broad if your records are messy or your historic wording changed over time.

Look closely at:

  • warranties about lawful collection, use, and disclosure
  • indemnities for privacy claims, complaints, regulator action, and third party losses
  • caps on liability and exclusions for indirect loss
  • knowledge qualifiers, time limits, and materiality thresholds
  • obligations to assist with complaints, access requests, or correction requests after completion

If the buyer wants a wide indemnity, make sure the deal price justifies that risk. You may need a narrower warranty set, disclosures against the warranties, or a clear liability cap.

6. Could the deal be misleading or damage customer trust?

Privacy risk is not the only issue. If your marketing said customer information would never be shared, or suggested strict confidentiality that is inconsistent with the proposed deal, you may create Fair Trading Act risk as well as contract risk. The problem is sharper where customer trust is part of your brand.

Even if a disclosure can be argued to fit a legal exception, the practical fallout may still be serious. Complaints, churn, and investor concerns can follow a transaction that feels inconsistent with what customers thought they signed up for.

7. What records and process will you need if something goes wrong?

A data transaction should not be documented only through the main commercial agreement. Keep a clear internal record of the legal basis for disclosure, what dataset was transferred, what customer-facing wording was relied on, and what restrictions were imposed on the recipient.

This helps if you later need to answer:

  • a customer complaint
  • a request for access or correction
  • a buyer dispute about data quality or lawfulness
  • questions from the Office of the Privacy Commissioner

Common Mistakes With Selling Data

The most common mistakes happen when a business treats customer information like a normal asset sale and skips the privacy analysis. That shortcut can turn a simple revenue opportunity into a contract dispute or reputational problem.

Relying on an old privacy policy

A policy written years ago may not match how your business actually collects and uses data now. It may also be too general to support a new monetisation arrangement. If you have changed systems, channels, products, or customer types, your old wording may not carry the weight you want it to.

Founders often discover this only when buyer due diligence starts. If the buyer asks for historic versions of your privacy notices and collection wording, you need to know exactly what was in place for the relevant records.

Assuming a list can be sold because it was expensive to build

The money you spent acquiring leads does not decide whether you can sell them. The legal question is whether the information can be disclosed in the way proposed. A valuable CRM is not automatically a transferable asset in the same way as stock or equipment.

Using vague contract language

Terms like data sharing, commercial use, business purposes, or partner use can be too broad to protect either side. If the contract does not define the permitted use, security expectations, complaint handling, and onward transfer restrictions, arguments often follow.

This matters before you sign a contract with an analytics buyer, ad-tech partner, or industry participant who wants broad reuse rights. The more valuable the data, the more precise the contract drafting needs to be.

Forgetting about third party restrictions

Your software, marketplace, payment, white label, or channel partner contracts may limit how customer information can be used. Some agreements prohibit independent commercial exploitation of data gathered through the service. Others say data belongs to the platform or can only be used to provide the contracted service.

If you promise a buyer unrestricted rights without checking those terms first, you may breach another contract the moment the deal completes.

Calling data anonymous without testing re-identification risk

Removing names is not enough. Small datasets, location data, unusual transaction patterns, and niche industry records can make re-identification easier than expected. This is especially true for startups and SMEs with narrow customer groups.

Before you spend money on setup for a data product, test whether the dataset can be matched back to individuals with reasonable effort. If the answer is yes, treat it as personal information unless proper expert advice supports a different conclusion.

Ignoring customer communications after the deal

Some transactions need a clear communication plan. Even where consent is not the only legal basis, customers may expect notice of a business transfer or a material change in how their data will be used. Silence can make an already sensitive transaction harder to defend.

Overpromising on compliance in due diligence

Sellers sometimes answer due diligence questions too confidently because they want the deal to move. If your records are incomplete, say so and deal with it in the contract. A carefully drafted disclosure schedule is usually better than an unrealistic warranty that everything has always been fully compliant.

FAQs

Can my business sell its customer list in New Zealand?

Sometimes, but not automatically. You need to check whether the customer list contains personal information, what customers were told when it was collected, and whether the proposed disclosure is allowed under the Privacy Act 2020 and your contracts.

Not in every case, but consent is often a major issue. If the sale or disclosure goes beyond the original purpose of collection or what customers reasonably expected, relying on consent or updating your permissions may be necessary.

Is anonymised data safe to sell?

Only if individuals are no longer identifiable in practice. If a buyer could re-identify people from the dataset alone or with other available information, privacy obligations may still apply.

What if I am selling my whole business?

Customer data may transfer with the business, but you still need to assess privacy disclosures, contract terms, and how the buyer will use the information after completion. A business sale is not a blanket exemption.

What should be in a data sale agreement?

The agreement should clearly define the dataset, permitted use, privacy compliance responsibilities, security obligations, restrictions on resale and re-identification, warranties, indemnities, liability limits, and post-completion complaint handling.

Key Takeaways

  • Selling data in New Zealand is a legal and commercial issue, not just a pricing exercise.
  • The key question is whether the proposed disclosure fits what customers were told and what the Privacy Act 2020 allows.
  • Customer lists, usage records, and de-identified datasets can still count as personal information or create privacy risk.
  • Before you sign, review collection wording, privacy notices, partner agreements, overseas transfer issues, and the buyer's intended use.
  • Your contract should define the dataset, permitted uses, restrictions, security standards, warranties, indemnities, and liability caps with care.
  • Founders often get caught by old privacy wording, third party contract limits, and assumptions that anonymisation solves everything.

If you want help with privacy compliance, contract drafting, warranty and indemnity risk, overseas disclosure issues, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.