Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- 1. What personal information is being transferred?
- 2. Who is sending and receiving the information?
- 3. Do the clauses provide comparable safeguards?
- 4. Does the contract line up with your privacy disclosures?
- 5. What happens if there is a privacy breach?
- 6. Are audit and information rights realistic?
- 7. What law governs the clause set?
FAQs
- Are standard contractual clauses mandatory in New Zealand?
- Can I rely on my overseas software provider's standard data processing addendum?
- Is an NDA enough for sending personal information overseas?
- Do I need customer consent every time data goes offshore?
- What if the provider refuses to change its global terms?
- Key Takeaways
Sending personal information offshore is routine for New Zealand businesses, but the legal risk often gets missed until a customer asks where their data sits, a procurement team sends over a privacy schedule, or an overseas software provider insists on its own transfer terms. Common mistakes include assuming a global SaaS provider has already handled New Zealand privacy compliance, copying overseas clauses that do not fit local law, and signing data transfer wording that says more than your business can actually do in practice.
The key question is simple: when personal information leaves New Zealand, what contractual protections should be in place, and are standard contractual clauses the right tool? The answer depends on who is sending the data, where it is going, what security and onward transfer protections apply, and whether the receiving party is really acting as your processor, your service provider, or as an independent controller of the information.
This guide explains how standard contractual clauses for international data transfers fit into the New Zealand Privacy Act 2020, what founders and SMEs should look for before signing, and where businesses commonly get caught.
Overview
New Zealand law does not prescribe one mandatory set of standard contractual clauses in the same way some overseas regimes do, but contracts still play a central role when your business discloses personal information to an overseas recipient. In practice, contractual clauses are often used to show that the overseas party must protect the information in a way that provides comparable safeguards to the New Zealand Privacy Act 2020.
- Whether the information being transferred is personal information under the Privacy Act 2020.
- Who the overseas recipient is, and whether it is a related company, cloud provider, outsourcing partner, or customer.
- Whether the overseas recipient is already subject to privacy laws that provide comparable safeguards.
- What contractual promises the recipient gives about use, storage, security, access, correction, breach response, and onward disclosure.
- Whether the contract matches what actually happens operationally, including hosting locations, subprocessors, and support access from other countries.
- What your customer contracts, privacy policy, and internal practices say about offshore storage and access.
When New Zealand Businesses Use NDAs
Businesses usually use standard contractual clauses for international data transfers when they are disclosing personal information to an overseas party and need enforceable privacy protections in the contract before they sign.
The heading here says NDAs because businesses often think confidentiality agreements will solve the problem. They usually do not. An NDA can help with secrecy, but international data transfers involve a different set of issues, including privacy law obligations, individual rights, security controls, breach notification processes, and restrictions on further disclosure. If personal information is involved, you often need more than a standard confidentiality clause.
Common founder situations
These clauses often come up in very practical moments, such as before you accept the provider's standard terms for software, payroll, customer support, analytics, CRM, document storage, or offshore development services.
- A New Zealand retailer uses a customer support platform with staff based in Australia, the Philippines, and the United States.
- A health or wellness business stores appointment and client information with an overseas booking provider.
- A SaaS company shares user data with an offshore hosting, email, or payment-related vendor.
- A professional services firm outsources document review, bookkeeping support, or IT administration to an overseas contractor.
- A New Zealand parent company shares employee or customer information with a related company overseas.
- A supplier receives a large enterprise customer contract requiring cross-border data transfer clauses before work begins.
Why contracts matter under New Zealand law
The Privacy Act 2020 places limits on disclosure of personal information outside New Zealand. A New Zealand agency generally needs a lawful basis for the disclosure, and in many cases must be satisfied that the overseas recipient is subject to safeguards that are comparable to those in the Privacy Act, or that another permitted basis applies.
Contract terms are often the most practical way to support that assessment. They can require the overseas recipient to protect the information, limit what it can do with it, and cooperate if an individual asks for access or correction. They can also deal with the less glamorous but very important issues, such as deletion, return of data, security incidents, and who is responsible if a subprocessor in another country gets involved.
This is where businesses often get caught. A vendor may offer a polished data processing addendum based on overseas law, but it may be written around concepts, rights, or liability settings that do not fit the Privacy Act 2020 or your customer commitments. The label sounds safe, but the actual wording may leave gaps.
Are there official New Zealand SCCs?
New Zealand does not currently have one universal set of mandatory statutory standard contractual clauses equivalent to the European Union model. That means businesses often use customised data transfer clauses, data processing agreements, vendor privacy schedules, or internationally drafted SCC-style terms adapted for New Zealand use.
That flexibility is useful, but it also means there is no shortcut in simply pasting in a foreign template. The document still needs to match the transfer, the parties, and the Privacy Act framework.
Legal Issues To Check Before You Sign
Before you sign a cross-border data transfer contract, the main legal task is to confirm that the wording actually supports lawful disclosure under New Zealand privacy law and reflects how the data flows in real life.
1. What personal information is being transferred?
Start with the data itself. Some businesses sign transfer clauses without ever defining the information that is leaving New Zealand.
Your contract should clearly describe the categories of personal information involved, such as:
- customer names, contact details, and order history
- employee payroll, leave, and performance information
- user account details and activity logs
- special categories of sensitive business information, if relevant to your operations
- support tickets, recordings, or uploaded documents
The more sensitive the information, the more carefully the transfer should be assessed. A generic line saying “data” is rarely enough.
2. Who is sending and receiving the information?
You need the contract to identify the legal entities, not just the brand name on a website. This matters because an offshore transfer may involve one contracting entity, another hosting entity, and several subprocessors in other countries.
Check:
- the full legal name of the overseas recipient
- whether the recipient acts only on your instructions or also uses data for its own purposes
- whether related companies will access the information
- whether subcontractors or subprocessors are involved
- which countries may be used for storage, support, or backup access
Before you rely on a verbal promise that data stays in one country, make sure the contract says so, or says exactly when other jurisdictions can be used.
3. Do the clauses provide comparable safeguards?
The contract should impose privacy protections that are genuinely comparable to core New Zealand privacy expectations. The exact wording can vary, but the practical protections matter more than the title of the document.
Look for clauses covering:
- use of personal information only for agreed purposes
- limits on disclosure to third parties
- reasonable security safeguards
- assistance with access and correction requests
- notification and cooperation if there is a privacy incident or breach
- return or deletion of information at the end of the engagement
- flow-down obligations to subprocessors
- rights to receive information about compliance or security measures
If the overseas party can use the information broadly for product improvement, marketing, analytics across customers, or its own independent business purposes, the arrangement may not function like a simple processor relationship. That changes the legal risk and should be reviewed carefully.
4. Does the contract line up with your privacy disclosures?
Your customer-facing privacy statement and internal data practices should match the transfer arrangement. If your privacy policy says information may be stored or accessed overseas, the contract should not contradict that. If your enterprise customers require prior notice or consent for offshore transfers, your vendor contract should support that commitment.
Mismatches create avoidable problems. A business can have a decent vendor clause set but still face trouble because sales teams promised local-only storage, or the privacy policy was silent on offshore access.
5. What happens if there is a privacy breach?
Breach response wording often looks fine until there is an actual incident. Then founders discover the vendor only promises to notify “without undue delay”, gives no investigation assistance, and excludes almost all liability.
Before you sign, check the contract for:
- clear notice timing for actual or suspected incidents
- what details the recipient must provide
- who manages communications with affected individuals and regulators
- what containment and remediation support is required
- whether the recipient must preserve evidence and cooperate
- liability allocation for breaches caused by the recipient or its subprocessors
This matters even more if you hold customer data on behalf of other businesses. Your own downstream contract may require fast notice, and you need enough upstream protection from the overseas provider to meet those obligations.
6. Are audit and information rights realistic?
Many templates include broad audit rights that a major software vendor will never accept. Others offer no verification rights at all. The better approach is practical evidence of compliance.
That could include security summaries, independent certifications, questionnaire responses, subprocessor lists, and notice of material changes. The goal is not to win a perfect clause that nobody will sign. The goal is to get enough contractual comfort to assess and manage the transfer responsibly.
7. What law governs the clause set?
Governing law and dispute clauses matter, but they should not distract from the privacy substance. A contract governed by another country's law can still contain useful transfer protections, but you should check whether any definitions or compliance promises assume a foreign legal regime that does not map neatly onto New Zealand requirements.
This is a common issue where an overseas template is built around foreign concepts such as controller, processor, restricted transfer, or data subject rights in a very specific statutory form. Those concepts may still be workable, but they often need careful adaptation.
Common NDA Mistakes
The most common mistake is treating a cross-border data transfer as a simple confidentiality issue when it really requires privacy-specific contractual protection.
Using an NDA instead of a data transfer clause
An NDA usually says confidential information must not be disclosed. That is not enough for personal information. It may say nothing about access requests, deletion, breach notification, subprocessors, offshore hosting locations, or use restrictions that align with privacy law.
If personal information is leaving New Zealand, founders should assume an NDA alone is not the right document unless the privacy points are built in separately.
Copying EU or US terms without checking New Zealand fit
Foreign templates can be useful starting points, but not all imported wording works well in New Zealand. Some clauses over-promise rights your business cannot operationally support. Others rely on legal tests or regulator guidance from another jurisdiction and leave gaps against the Privacy Act 2020.
A clause set should be tailored to the actual transfer, not chosen just because a large overseas provider uses it globally.
Ignoring onward transfers
The first overseas recipient is not always the end of the story. Data may then move to hosting providers, support teams, AI tools, analytics services, or backup vendors in other countries.
Check whether the contract:
- requires approval or notice before new subprocessors are added
- imposes equivalent obligations on those subprocessors
- identifies the countries involved
- gives you options if you object to a new subprocessor
If onward transfers are invisible in the paperwork, the real data exposure may be much wider than expected.
Accepting broad vendor limitations of liability
Many standard terms cap liability at a small amount or exclude indirect loss so broadly that the protection becomes thin in a real incident. You may not be able to negotiate every point, but you should understand the gap before you sign.
This is especially relevant where your own customer contract pushes higher privacy obligations down onto you. If the upstream and downstream positions do not line up, your business can end up carrying the risk in the middle.
Promising localisation you cannot verify
Some businesses tell customers their data is stored in New Zealand or Australia, but the provider's support personnel, backups, or subprocessors still access the information from elsewhere. That can create privacy compliance issues and Fair Trading Act concerns if the statement is misleading.
Before you rely on a vendor marketing page, confirm the actual contractual position and operational model.
Failing to document the decision
Even where a transfer is lawful, businesses often keep no internal record of why they were comfortable with the overseas disclosure. If a customer later asks questions, the team scrambles to reconstruct the reasoning.
A simple internal assessment can help record:
- what data is transferred
- why the transfer is needed
- which countries and recipients are involved
- what contractual safeguards apply
- what residual risks remain
- what customer disclosures or consents are relevant
That kind of record is practical, not bureaucratic. It helps legal, procurement, privacy, and operations stay aligned.
FAQs
Are standard contractual clauses mandatory in New Zealand?
No. New Zealand does not currently prescribe one mandatory universal set of standard contractual clauses for all international data transfers. Contracts are still commonly used to show the overseas recipient must protect personal information with safeguards comparable to those expected under the Privacy Act 2020.
Can I rely on my overseas software provider's standard data processing addendum?
Sometimes, but not automatically. You should check whether the addendum covers offshore disclosure, subprocessor use, breach response, access and correction assistance, and use restrictions in a way that works for your New Zealand obligations and your customer contracts.
Is an NDA enough for sending personal information overseas?
Usually not. An NDA focuses on confidentiality, while cross-border personal information transfers usually need broader privacy protections and operational commitments.
Do I need customer consent every time data goes offshore?
Not necessarily. Consent may be relevant in some cases, but it is not the only pathway. The Privacy Act framework looks at whether the overseas recipient is subject to comparable safeguards or whether another permitted basis applies. The correct approach depends on the transfer and the surrounding documentation.
What if the provider refuses to change its global terms?
You still need to assess the risk before you sign. That may mean accepting the terms with eyes open, negotiating a side letter, adjusting your own customer commitments, changing how much personal information is shared, or choosing another provider if the gap is too large.
Key Takeaways
- New Zealand does not have one mandatory statutory SCC template for all offshore transfers, but contracts remain a key way to protect personal information sent overseas.
- An NDA alone is usually not enough where personal information is involved. Privacy-specific clauses matter.
- Before you sign, identify the data, the legal entities, the countries involved, and any subprocessors or onward transfers.
- The clause set should cover use limits, security, access and correction support, breach response, deletion or return, and subprocessor obligations.
- Foreign templates can help, but they should be checked against the Privacy Act 2020 and your actual operational setup.
- Your privacy policy, customer contracts, and vendor terms should all say compatible things about offshore storage and access.
- Keep a short internal record of why the transfer is permitted and what safeguards you relied on.
If you want help with cross-border privacy terms, data processing agreements, vendor contract risk, and Privacy Act 2020 compliance, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







