Consent Forms for NZ Businesses: Privacy, Compliance and Common Mistakes

Alex Solo
byAlex Solo11 min read

A lot of New Zealand businesses collect personal information long before they realise they need to think carefully about consent. That usually happens when a website sign-up form goes live, a marketing list starts growing, or a business begins collecting health details, ID documents, photos, location data, or customer preferences.

The common mistakes are usually the same: using vague wording, bundling several permissions into one tick box, and assuming silence or pre-ticked boxes count as valid consent.

Those mistakes create more than a drafting problem. They can lead to misleading marketing practices, privacy complaints, poor customer trust, and internal confusion about what your business is actually allowed to do with the information it holds. This guide answers what consent forms are really for, when New Zealand businesses need them, how they fit with the Privacy Act 2020, and what practical steps matter before you launch online, collect sensitive information, or ask customers to agree to data use.

Overview

A consent form is only useful if it clearly matches the way your business collects, uses, stores, and shares personal information. In New Zealand, consent often sits alongside broader privacy obligations, so a form on its own is not enough if your collection process is unclear or unfair.

The real question is not whether you have a form. The real question is whether the person understands what they are agreeing to, and whether your business can prove that agreement later.

  • Identify exactly what personal information you are collecting and why you need it.
  • Work out whether consent is actually required, or whether another lawful basis for collection applies.
  • Separate different permissions, such as service delivery, marketing, use of images, and disclosure to third parties.
  • Use plain language so customers, users, patients, or clients can make a real choice.
  • Keep records showing when consent was given, what wording was used, and how a person can withdraw it.
  • Make sure your privacy policy, website forms, app flows, contracts, and staff processes all say the same thing.

For most businesses, understanding consent forms means knowing that consent is not a magic fix. It is one part of a lawful and transparent data handling process.

Under the Privacy Act 2020, businesses generally need to collect personal information for a lawful purpose connected with their functions or activities, and the collection must be necessary for that purpose. People should usually know why the information is being collected, who will receive it, whether providing it is compulsory or voluntary, and what happens if they do not provide it.

That means a consent form often works together with a privacy collection statement or privacy policy. The form records permission for a specific act. The privacy documents explain the broader handling of personal information.

A business can tell people what it is doing with data without necessarily asking for consent to every step. For example, if you need a customer’s delivery address to send an order, that may be an obvious and necessary part of providing the service. You still need to tell the customer what you are collecting and why, but separate consent for the delivery itself may not be the main issue.

Consent becomes more important where the use is optional, unexpected, sensitive, or higher risk. Common examples include:

  • sending direct marketing emails or text messages
  • using customer photos or testimonials in advertising
  • collecting health information, biometric information, or identity documents
  • sharing data with third party platforms or partner businesses beyond what a customer would reasonably expect
  • recording calls or meetings for training or quality purposes
  • tracking user behaviour through apps, cookies, or similar technologies in a way that is not obvious

A valid consent process should give the person a real choice, enough information to decide, and a clear way to say yes or no. If your form is confusing, hidden inside dense customer terms, or bundled into a take-it-or-leave-it process where the extra use is not necessary, the consent may be challenged.

In practice, good consent forms are:

  • specific, so each permission covers a clearly described use
  • informed, so the person knows what they are agreeing to
  • voluntary, so the person is not pressured or misled
  • current, so old permissions are not stretched to cover new activities
  • recorded, so your business can show what happened if a complaint arises

Why This Matters Beyond Privacy Law

The risk is not only a privacy complaint. Consent language also affects your broader business compliance. If your sign-up process suggests a customer is only joining a waitlist, but you then add them to a promotional mailing list, that can raise Fair Trading Act issues because your representations about the sign-up process may be misleading.

Consent can also affect contracts and customer disputes. If your service agreement says one thing, your app screen says another, and your internal staff script says something else, your business creates avoidable confusion. This is where founders often get caught, especially before they spend money on setup, online advertising, or outsourced software.

When This Issue Comes Up

Consent form issues usually come up at growth points, when a business adds a new channel, gathers more detailed customer information, or starts using data in a new way.

Website And App Sign Ups

If you are selling online, running a SaaS platform, or collecting leads through a website, you may ask people to create accounts, join newsletters, book demos, or download resources. Each of those actions can involve different types of consent.

A common mistake is using one checkbox for everything. For example, a customer might need to agree to your core platform terms to create an account, but that does not automatically mean they have agreed to unrelated marketing, partner offers, or public use of their success story.

Health, Wellness, Education, And Care Services

Businesses in health, therapy, coaching, childcare, aged care support, and education often collect more sensitive information than standard retailers or consultants. If you are gathering medical details, wellbeing information, next-of-kin contacts, photos of children, or behavioural records, your forms need more care.

The wording should explain why the information is needed, who can access it, how long it may be kept, and whether any disclosures are required to third party software providers or specialist contractors.

Marketing Campaigns And Customer Testimonials

A customer may be happy to buy from you without wanting their photo, review, or first name used in advertising. That is why marketing consent should usually be separate from service delivery.

This often arises before you print brochures, launch social campaigns, or publish case studies. It also comes up when businesses run competitions, referral programmes, or influencer campaigns and want to reuse entrant data later.

Employment And Recruitment Processes

Businesses often focus on customer data and forget internal consent issues. Recruitment forms, background checks, staff profile pages, workplace photos, and emergency contact records all involve personal information.

Employers should be careful not to rely on consent where the power imbalance means the choice may not be fully voluntary. In employment settings, transparency, necessity, and carefully drafted employment contracts and workplace documents matter just as much as any signed form.

New Suppliers, Software, And Overseas Providers

The issue also comes up before you sign a contract with a CRM platform, analytics provider, cloud storage company, payroll system, or outsourced support team. If customer information is going into a third party system, your collection statements and consent wording need to reflect that reality.

Where information may be stored or accessed overseas, businesses should also consider cross-border disclosure obligations under New Zealand privacy law. A consent form should not promise local-only handling if your actual systems do something different.

Practical Steps And Common Mistakes

The best consent forms are built from your real data practices, not copied from a template that sounds legal but does not match your business.

Step 1: Map Your Data Before You Draft

Start with what your business actually does. Before you write a form, list:

  • what information you collect
  • where you collect it, such as website forms, in-store forms, calls, apps, or paper documents
  • why you collect it
  • who can access it internally
  • whether you share it with service providers or business partners
  • how long you keep it
  • how a person can correct or withdraw information or permissions

If you skip this step, the consent form usually ends up too broad or inaccurate.

Step 2: Separate The Permissions

Different uses should usually have different consent wording. This helps people understand the choice and helps your team administer it properly later.

For example, a form might need separate consent areas for:

  • receiving marketing emails
  • receiving SMS updates
  • sharing information with a delivery or booking platform
  • using a testimonial, image, or video for promotion
  • collecting sensitive information for service delivery
  • recording a call or consultation

Bundled consent is one of the most common drafting problems. It creates uncertainty about what the person actually agreed to.

Step 3: Use Plain Language

Your form should read like a real explanation, not a warning label. If a customer, patient, or applicant cannot tell what they are agreeing to after one read, the wording probably needs work.

Good plain language usually means:

  • short sentences
  • everyday terms instead of legal jargon
  • clear naming of third parties or categories of recipients
  • clear explanation of optional versus necessary data uses
  • clear instructions for withdrawing consent

Terms and conditions can still exist separately, but they should not carry hidden privacy permissions that a person would not reasonably expect.

Step 4: Match The Form To The User Experience

The wording on paper and the experience on screen need to match. If your mobile app presents one sentence and your backend stores a different version of the consent language, your records may be hard to rely on later.

This matters before you launch online, redesign your website, or integrate a new customer platform. Founders often approve legal wording, then a developer shortens the front-end prompt in a way that changes the meaning.

Step 5: Keep A Reliable Record

If a customer later says they never agreed, your business needs evidence. A good record usually includes:

  • the date and time consent was given
  • the wording shown at the time
  • the method used, such as web form, signed paper form, email reply, or recorded verbal confirmation
  • any updates or withdrawals
  • the account or file connected to that person

This is especially important for businesses with subscriptions, recurring services, or online marketing systems.

Step 6: Build A Withdrawal Process

Consent should not be treated as permanent just because someone once said yes. Your process should explain how a person can opt out, unsubscribe, revoke image use permissions, or ask questions about data handling.

If the withdrawal process is hard to find or difficult to use, the original consent process may look unfair in practice.

Common Mistakes New Zealand Businesses Make

Most consent problems come from poor implementation, not bad intentions. The mistakes that show up most often include:

  • using pre-ticked boxes
  • relying on silence or inactivity as consent
  • copying overseas wording that does not match New Zealand law or actual business practices
  • asking for consent that is wider than the business really needs
  • failing to update forms after changing software, suppliers, or marketing activities
  • burying important permissions in long website terms
  • telling staff one rule while customer-facing forms say another
  • keeping no audit trail of what the person agreed to

A consent form should rarely stand alone. It usually needs to line up with several other documents and processes, including:

  • your privacy policy
  • website terms or app terms
  • customer contracts or booking terms
  • employee privacy notices and workplace policies
  • supplier agreements with software and service providers
  • internal data retention and complaint-handling procedures

This is why businesses should review consent before they sign major vendor contracts, before they spend money on setup for a new platform, and before they scale a marketing campaign.

Industry Examples

A gym might need separate consent for membership administration, health disclosures relevant to training, direct marketing, and use of member images on social media.

An ecommerce store might only need basic collection details to fulfil orders, but should separately address newsletter consent, review publication, and any use of third party remarketing tools or cookies.

A clinic or wellness provider may need carefully drafted forms for sensitive health information, appointment reminders, telehealth platforms, and disclosure to specialists or administrative providers.

A software startup may need consent wording embedded across account creation, product analytics, beta testing, support call recording, and customer case studies. It also needs contracts with vendors and a business structure that supports proper internal accountability as the company grows.

FAQs

No. Not every data collection step requires a separate consent form. Many businesses still need clear privacy notices and transparent collection practices, even where formal consent is not the main legal basis for handling the information.

Can I use one checkbox for terms, privacy, and marketing?

Usually, that is risky. Where those items serve different purposes, separate acknowledgments or consents are generally clearer and easier to defend if a complaint arises.

Are pre-ticked boxes acceptable?

They are often a poor choice and can undermine whether consent was genuinely given. Active, clear agreement is safer than assuming consent from inaction.

What if I change how I use customer data later?

You should review whether your existing notices and consents still cover the new use. If the new use is materially different, unexpected, or more intrusive, fresh wording or a new consent process may be needed.

Not always. Electronic acceptance, recorded verbal consent, and other methods can work if the process is clear and your business keeps reliable records of what the person agreed to.

Key Takeaways

  • Consent forms work best when they reflect your actual data practices, not generic wording copied from elsewhere.
  • Under New Zealand privacy law, clear notice and fair collection practices matter alongside consent.
  • Separate optional permissions, such as marketing, testimonials, image use, and sensitive data collection, instead of bundling them together.
  • Use plain language, avoid pre-ticked boxes, and make withdrawal of consent easy.
  • Keep records showing when consent was given, what wording was used, and how your business acted on it.
  • Review consent wording whenever you add new software, change suppliers, sell online in new ways, or start using personal information for a new purpose.

If your business is dealing with understanding consent forms and wants help with privacy notices, customer sign-up wording, marketing consent processes, and supplier data clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.