Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Work out what personal information you really collect
- 2. Match each item of information to a real business purpose
- 3. Tell people what is happening with their information
- 4. Get consent where consent is the right basis, but do not rely on it carelessly
- 5. Limit access inside the business
- 6. Check surveillance and recording practices carefully
- 7. Build privacy into contracts and supplier arrangements
- 8. Prepare for privacy breaches
- Common mistakes founders make
- Key Takeaways
Privacy issues often catch business owners at the worst possible moment, after a staff member posts a customer photo, a marketing team reuses personal data without checking consent, or CCTV footage is shared more widely than anyone expected. A common mistake is assuming privacy only matters when there is a data breach. Another is thinking that if information was posted publicly, your business can use it however it likes. A third is treating privacy as just an IT issue, when many problems start in day to day sales, hiring, customer service, and marketing decisions.
For New Zealand businesses, invasion of privacy is not one single rule with one single label. The issue can arise through the Privacy Act 2020, misuse of personal information, intrusive monitoring, unauthorised collection, misleading statements about data use, or public disclosure that causes real harm. This guide explains what counts as invasion of privacy in practice, when the risk comes up for startups and SMEs, and what to fix before you sign contracts, launch campaigns, or spend money on setup.
Overview
In New Zealand, an invasion of privacy usually means a business has interfered with a person’s privacy in a way the law recognises as wrongful, unfair, or harmful. That can involve collecting personal information without a proper reason, using it for a different purpose, disclosing it without authority, keeping it insecure, or intruding into someone’s private affairs in a way that creates a real risk of harm.
- Whether the information is personal information about an identifiable person
- Why your business collected it, and whether that purpose was clear at the time
- Whether the collection method was fair, lawful, and not unreasonably intrusive
- Whether the person knew what would happen to their information
- Whether you used or disclosed the information for a new purpose without consent or another lawful basis
- Whether you kept the information secure and only for as long as needed
- Whether surveillance, recording, or publication intruded into a genuinely private situation
- Whether the action caused, or could cause, loss, distress, humiliation, or another form of harm
What Counts as Invasion of Privacy Means For New Zealand Businesses
For a New Zealand business, invasion of privacy usually means crossing the line between legitimate business use of information and unfair interference with a person’s private life or personal data.
The legal starting point is often the Privacy Act 2020. That Act regulates how agencies, including most businesses, collect, hold, use, and disclose personal information. Personal information means information about an identifiable individual. It does not need to be secret or highly sensitive to be protected.
A customer’s name, email address, order history, CCTV image, delivery instructions, health details, IP address in some contexts, job application, and staff performance notes can all raise privacy issues. The main question is not just what the information is, but what your business does with it.
Privacy is broader than a data breach
Many founders think privacy law only matters if hackers access their systems. A breach is one privacy problem, but it is not the whole picture.
Your business may invade privacy if it:
- collects more information than it reasonably needs
- collects information in a misleading or covert way
- uses customer details for unrelated marketing without proper notice or consent
- shares employee or customer information internally on a needlessly wide basis
- publishes photos, recordings, or stories that identify a person in a private or sensitive context
- retains old records without a clear reason
- fails to secure devices, cloud platforms, or files containing personal information
Collection, use, and disclosure are separate issues
A business can collect information lawfully but still create a privacy problem later. This is where founders often get caught.
For example, a gym may collect member photos for ID verification at sign up. That does not automatically allow the business to use those same photos in social media advertising. A medical-adjacent wellness service may collect health information to deliver services, but not to circulate client stories around the office for training unless there is a clear lawful basis and appropriate controls.
Each stage needs its own justification:
- collection, why you need the information
- use, what you will do with it
- disclosure, who else will receive it
- storage, how you will protect it
- retention, how long you will keep it
Invasion of privacy can also happen outside the Privacy Act
Some conduct may be described as invasion of privacy even where the issue is not just about database records or customer files. Intrusive surveillance, publishing private facts, or misusing images can create separate risk.
If a business records private conversations without proper authority, installs cameras in places where people expect privacy, or publicises sensitive personal details, the problem may involve privacy tort principles, employment law issues, contractual confidentiality, or misleading conduct concerns as well as Privacy Act obligations.
That matters because business risk is not limited to regulator complaints. You may also face:
- customer complaints and refund demands
- staff grievances or disciplinary disputes
- reputational damage
- loss of commercial trust
- contract disputes with clients or suppliers
Harm matters, but prevention matters more
Under New Zealand privacy law, harm is often relevant when assessing a complaint or notifiable privacy breach. Harm can include humiliation, significant distress, financial loss, identity fraud risk, or damage to someone’s rights or interests.
But waiting until harm is obvious is a mistake. Good privacy practice means checking your position before you launch online, before you hand data to a software provider, and before you roll out monitoring tools for staff or contractors.
When This Issue Comes Up
Privacy problems usually appear in ordinary business processes, not dramatic edge cases.
Most SMEs run into this issue when they start collecting more customer and staff data than they used to, especially as they move to online sales, remote work, cloud software, and targeted marketing.
Marketing and customer acquisition
This issue comes up when businesses use mailing lists, online tracking tools, testimonials, case studies, competitions, or social media content. A founder may assume that because a customer gave an email address during checkout, it can be used for broader promotional campaigns forever. That is not always right.
Risk points include:
- adding people to marketing lists without clear notice
- repurposing customer information for a campaign unrelated to the original transaction
- using customer photos or reviews without proper permission
- collecting excessive information through web forms
- making vague or inaccurate privacy statements
CCTV, recordings, and workplace monitoring
Many businesses install cameras for security, stock control, or health and safety reasons. The main risk is overreach.
Cameras in public facing retail areas may be easier to justify than cameras in staff break rooms, changing areas, or other locations where people reasonably expect privacy. Audio recording raises extra sensitivity. Covert monitoring is especially risky unless there is a very strong reason and the legal basis has been checked carefully.
Workplace monitoring can also create employment issues. Even if your concern is theft or productivity, you should not assume a broad right to watch, record, or track staff at any time. Policies, notice, proportionality, and purpose all matter.
Hiring and staff management
Recruitment often generates avoidable privacy issues because businesses collect large amounts of personal information before they have a clear process.
Examples include:
- asking applicants for information unrelated to the role
- keeping unsuccessful applicant files indefinitely
- circulating CVs widely inside the business
- checking social media in a misleading or excessive way
- sharing employee health or disciplinary information more broadly than necessary
Employee records are not exempt from privacy expectations just because they sit in an HR folder. The same basic questions still apply, why was this information collected, who needs access, and how long should it be kept?
Customer service and complaint handling
Customer support teams often handle invoices, addresses, order histories, recordings, and complaint files. Privacy risk increases when staff are trying to solve a problem quickly and share information too freely.
A common example is sending account information to the wrong person, discussing one customer’s dispute in a way another customer can hear, or posting screenshots of customer exchanges for training or internal chat without enough control.
Online platforms and third party providers
Many startups depend on ecommerce systems, CRM platforms, booking software, analytics tools, payroll systems, and offshore cloud storage. This issue comes up before you sign a contract with those providers, not after something goes wrong.
If your provider handles personal information on your behalf, you still need to understand:
- what data is collected and where it is stored
- who can access it
- whether it is transferred overseas
- what security commitments the provider makes
- what happens if there is a privacy breach
- how data is deleted when the contract ends
Practical Steps And Common Mistakes
The best way to avoid invading privacy is to map what personal information your business touches, why you need it, and who can see it before your systems and habits become hard to unwind.
That sounds simple, but most privacy trouble in small businesses comes from informal processes, recycled templates, and assumptions that no longer fit how the business actually operates.
1. Work out what personal information you really collect
Many businesses underestimate the range of personal information they hold. Do not just look at your main database.
Check all of the places where personal information may sit:
- website forms and landing pages
- email inboxes
- cloud drives and shared folders
- payment and booking systems
- CCTV systems
- HR files
- customer support platforms
- phones, laptops, and messaging apps
If you do not know what you hold, you cannot explain your practices clearly or secure the information properly.
2. Match each item of information to a real business purpose
If you cannot explain why you need a piece of information, you should question whether you should collect it at all.
Founders often ask for more than they need because a form template came that way or because it might be useful later. That is risky. Privacy law generally expects collection to be connected to a lawful and necessary business purpose.
For example, a florist taking online orders may need delivery details and contact information. It probably does not need a customer’s date of birth unless there is a clear reason. A small consultancy may need referee checks for a senior role, but only at the right stage of recruitment and with an appropriate process.
3. Tell people what is happening with their information
Clear notice is one of the simplest ways to reduce privacy risk. People should not have to guess what your business is collecting and why.
Your privacy documents and privacy collection notices should line up with what actually happens in the business. Common mistakes include copying a generic privacy policy, leaving out marketing use, ignoring CCTV, or failing to mention overseas service providers.
Good notice should cover matters such as:
- what information you collect
- why you collect it
- whether providing it is optional or required
- who you share it with
- how people can access or correct it
- how to contact your business about privacy concerns
4. Get consent where consent is the right basis, but do not rely on it carelessly
Consent can help, but it is not a magic fix. A buried clause in customer terms and conditions may not solve a privacy problem if the practice is still unfair, unclear, or broader than people would reasonably expect.
Consent works best when it is specific and meaningful, such as permission to use a customer testimonial with their name and image, or agreement to receive a certain kind of promotional content. If the use changes later, revisit the permission rather than stretching it.
5. Limit access inside the business
Not everyone in your business needs access to everything. Internal oversharing is one of the most common SME privacy failures.
Customer complaints, employee health information, payroll details, and sensitive commercial correspondence should be accessible only to the people who genuinely need them. This is partly a systems issue and partly a training issue.
6. Check surveillance and recording practices carefully
If your business uses cameras, call recording, GPS tracking, screenshots, or software monitoring, the detail matters.
Ask questions such as:
- what is the exact purpose of the monitoring
- is the monitoring proportionate to that purpose
- have people been told about it clearly
- is audio recording really necessary
- are you recording in a place where privacy expectations are higher
- how long are recordings kept
- who can review them
This is an area where founders should be especially careful before they spend money on setup, because the wrong system design can create legal and workplace issues from day one.
7. Build privacy into contracts and supplier arrangements
If a service provider stores, processes, or accesses personal information for you, your contract should deal with privacy and security clearly. A handshake understanding is not enough.
Commercial agreements should usually address:
- what data the provider can access
- what instructions they must follow
- confidentiality obligations
- security standards or minimum measures
- breach notification timing
- subcontracting limits
- data return or deletion at the end of the relationship
8. Prepare for privacy breaches
A privacy breach can happen through hacking, lost devices, misdirected emails, accidental publication, or staff error. The legal question is not only how the breach happened, but how your business responds.
You should have a practical process and data breach response plan for:
- identifying and containing the incident
- assessing likely harm
- deciding whether notification is required
- communicating with affected individuals
- documenting what happened and what changes were made
Common mistakes founders make
Most privacy trouble comes from ordinary shortcuts rather than deliberate misconduct.
- copying a privacy policy that does not match actual business practices
- using customer information for new marketing without checking the original purpose
- keeping data forever because storage is cheap
- assuming publicly available information is free to reuse
- letting all staff access shared folders containing personal information
- rolling out CCTV or call recording without proper notice
- forgetting privacy issues in contractor and software agreements
- treating privacy as an admin task instead of a business risk issue
FAQs
Is invasion of privacy the same as a breach of the Privacy Act?
Not always. A Privacy Act breach is one type of privacy problem, but invasion of privacy can also describe intrusive conduct such as unjustified surveillance or publication of private facts. In business settings, the issues often overlap.
Can my business use customer photos from social media?
Not automatically. Even if a photo is publicly visible, using it for marketing or commercial promotion can still create privacy, consent, intellectual property, and fair trading issues. Check permission first.
Does CCTV always count as an invasion of privacy?
No. CCTV can be lawful if it has a genuine purpose, is proportionate, and people are told about it appropriately. The risk increases if cameras are hidden, audio is recorded, or surveillance occurs in places where privacy expectations are higher.
What if a staff member shares personal information by mistake?
An accidental disclosure can still be a privacy breach. Your business should contain the problem quickly, assess the likely harm, keep a record of the incident, and consider whether affected people or the Privacy Commissioner need to be notified.
Do small businesses need a privacy policy?
In most cases, yes. If you collect personal information from customers, staff, contractors, or website users, a clear privacy policy and matching internal practices are usually a sensible baseline. The document should reflect what your business actually does, not generic wording.
Key Takeaways
- What counts as invasion of privacy depends on the facts, but it often involves unfair collection, misuse, unauthorised disclosure, intrusive monitoring, or weak protection of personal information.
- For New Zealand businesses, the Privacy Act 2020 is usually the starting point, but privacy risk can also involve employment issues, confidentiality, marketing practices, and publication of private material.
- This issue commonly arises in marketing, CCTV use, hiring, customer support, online platforms, and supplier arrangements.
- The safest approach is to collect only what you need, explain your practices clearly, limit internal access, secure information properly, and document privacy expectations in contracts and policies.
- Founders should review privacy settings and notices before they launch online, before they sign with software providers, and before they spend money on monitoring or recording systems.
If your business is dealing with what counts as invasion of privacy and wants help with privacy policies, supplier contracts, data breach response, or workplace monitoring issues, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







