Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Map the personal data your business actually holds
- Collect only what you actually need
- Tell people what you are doing
- Check your contracts with service providers
- Limit access inside your business
- Set retention rules and delete what you no longer need
- Prepare for access, correction, and breach issues
- Common mistakes New Zealand businesses make
- Key Takeaways
If you collect customer names, email addresses, delivery details, CVs, website analytics, or staff records, you are probably handling personal data, even if you do not think of your business as “data-driven”. A common mistake is assuming personal data only means highly sensitive material like passports or health records. Another is thinking information is not personal if it sits in a spreadsheet, a shared inbox, or a cloud app run by a third party. A third mistake is overlooking data that can identify someone indirectly, such as an IP address linked to an account, CCTV footage, or notes about a customer complaint.
For New Zealand businesses, the real question is not just what data you collect, but whether a person can be identified from it, either on its own or when combined with other information you hold. That affects your privacy policy, your staff processes, your supplier contracts, and what you should sort out before you launch online or sign up to a new software platform. This guide explains what counts as personal data in New Zealand, when the issue comes up in day to day business, and the practical steps that help you avoid common privacy mistakes.
Overview
In New Zealand, personal data is generally information about an identifiable individual. The term often used in the Privacy Act 2020 is “personal information”, but for most businesses the practical question is the same, can this information identify a real person directly or indirectly?
That includes obvious identifiers, but it can also extend to business records, digital identifiers, footage, opinions, and internal notes where a person can be worked out from the context.
- Whether the information identifies someone directly, such as by name or contact details
- Whether someone could be identified indirectly when the data is combined with other records
- Whether the information is about a customer, employee, contractor, supplier contact, or website user
- Whether the data is sensitive, such as health, financial, biometric, or children’s information
- Where the data is stored, who can access it, and whether third party providers handle it for you
- Why you are collecting it, how long you need it, and what you tell people about that collection
What Personal Data Means For New Zealand Businesses
For New Zealand businesses, personal data means information about an identifiable individual, and the definition is wider than many founders expect.
The Privacy Act 2020 uses the term “personal information”, which covers information about a living, identifiable individual. In practice, if the information points to a person, or could reasonably be linked back to them, treat it as personal data for your business processes.
Obvious examples of personal data
Some categories are straightforward. If you collect these, you are handling personal data:
- Full names
- Email addresses
- Phone numbers
- Residential or delivery addresses
- Date of birth
- Driver licence or passport details
- Bank account information tied to a person
- Photographs of identifiable people
- Employment records and CVs
This applies whether the information belongs to customers, employees, contractors, directors, sole traders, or job applicants.
Less obvious examples businesses often miss
This is where founders often get caught. Information does not need to be obviously private to count as personal data.
Examples that are often overlooked include:
- Customer support notes about a complaint or refund
- CCTV footage where a person can be recognised
- Website account usernames linked to a person
- IP addresses or device identifiers when they can be tied to an individual account or activity
- Booking history and purchase history linked to a person
- Performance notes about staff
- References for a candidate
- Slack, email, or CRM messages about a particular individual
- Recorded phone calls
- Location data from deliveries, apps, or fleet tools where an individual is identifiable
An internal note saying “customer was difficult and asked for a chargeback” can still be personal data if it is connected to a named account. The same goes for a spreadsheet with initials, if your team can easily work out who those initials refer to.
What about business contact details?
Business contact details can still be personal data if they identify an individual person.
For example, “sarah@company.co.nz” and a direct mobile number usually relate to an identifiable individual, even if used in a business setting. A generic email such as “accounts@company.co.nz” is less likely to be personal data on its own, unless your records clearly tie it to one specific person.
Can anonymised or aggregated data still be personal?
Truly anonymised data is generally not personal data, but many businesses overestimate how anonymous their records really are.
If you remove names but keep enough detail to identify someone, the data may still be personal. This often happens with small customer groups, staff reports, or location records. If one store manager can look at the data and know exactly which employee it refers to, it is not truly anonymous.
Aggregated data is safer where individuals cannot reasonably be identified. For example, a report showing total monthly sales by region, without any customer level detail, is less likely to be personal data.
Sensitive information needs extra care
The Privacy Act does not create one single special category list in the same way some overseas privacy laws do, but some information plainly carries higher risk and should be handled with more care.
That usually includes:
- Health information
- Financial information
- Identity documents
- Biometric data
- Children’s information
- Employment investigations and disciplinary records
- Criminal history information, where lawfully collected
The main risk is not just collection. It is collecting more than you need, keeping it too long, using it for a new purpose, or failing to secure it properly.
When This Issue Comes Up
Personal data questions come up much earlier than most businesses expect, often before you sign a contract or spend money on setup.
You do not need to be a tech platform to face privacy obligations. Almost every startup and SME in New Zealand handles personal data somewhere in its sales, hiring, marketing, or operations.
Customer sign ups and selling online
If you sell online, offer bookings, take enquiries, or run a mailing list, you are likely collecting personal data from day one.
Common examples include:
- Checkout details for deliveries
- Contact forms on your website
- Email marketing sign ups
- Account registrations
- Payment details processed through a provider
- Support tickets and chat logs
This is the point where your collection notices, privacy policy, website terms, and platform settings need to line up. Founders often copy a privacy policy from overseas without checking whether it fits New Zealand law or their actual data practices.
Hiring staff and contractors
Recruitment creates a large volume of personal data, often before the business has mature internal systems.
That can include:
- CVs and cover letters
- Interview notes
- Reference checks
- Right to work or identity documents
- Payroll and emergency contact details
- Performance and disciplinary records
If you are growing quickly, this is where retention problems often start. Businesses keep unsuccessful candidate files indefinitely or circulate interview notes too widely.
Using software providers and cloud tools
If your CRM, HR platform, email system, booking app, or analytics tool stores information about identifiable people, your business is still responsible for handling that data properly.
Many founders assume the software provider “covers privacy”. That is not enough. You still need to understand:
- What information goes into the tool
- Where that information is stored
- Who can access it
- Whether the provider can use it for its own purposes
- What happens if there is a security incident
This matters before you sign a SaaS contract, especially if overseas hosting or subcontractors are involved.
Marketing, analytics, and customer profiling
Marketing data often feels less sensitive, but it can still be personal data when linked to a person or account.
Examples include:
- Email open and click data tied to subscriber profiles
- Loyalty programmes
- Ad audiences uploaded from customer lists
- Purchase history used for recommendations
- Website behaviour connected to named users
If your business uses personal data to target offers, segment customers, or personalise communications, be clear about what you collect and how you use it.
Complaints, incidents, and dispute management
Businesses often gather sensitive and detailed records when something goes wrong.
Complaint files may include staff statements, customer messages, call recordings, delivery photos, or medical details linked to a service incident. These records still need controlled access, a lawful purpose, and sensible retention periods.
Practical Steps And Common Mistakes
The safest approach is to assume data is personal if an individual can reasonably be identified, then build your processes around that assumption.
You do not need a huge legal framework to start well. Most SMEs need a clear map of what they collect, why they collect it, who sees it, and what documents and contracts support that process.
Map the personal data your business actually holds
Start with what happens in real life, not with a template policy.
List the places where your business collects or stores personal data, such as:
- Your website forms
- Checkout pages
- Email inboxes
- Shared drives
- CRMs and spreadsheets
- HR folders
- Accounting or invoicing systems
- CCTV systems
- Staff phones and messaging platforms
This exercise often reveals hidden problems, especially duplicate records, unnecessary access, and old data no one meant to keep.
Collect only what you actually need
If a piece of information is not necessary for the service, contract, compliance task, or operational step, think carefully before asking for it.
Over-collection is one of the most common privacy mistakes. A simple example is asking for date of birth when an email address would do, or requesting ID documents for a low risk transaction that does not require them.
Tell people what you are doing
People should not have to guess why you are collecting their personal data.
Your privacy messaging should explain key points such as:
- What information you collect
- Why you collect it
- Who you may share it with
- Whether it may be stored or processed overseas
- How people can access or correct their information
That usually means having a privacy policy that matches your real practices, plus targeted collection notices in forms, onboarding documents, or recruitment processes where needed.
Check your contracts with service providers
If another business handles personal data for you, the contract should deal with privacy and security clearly.
Before you sign, look at issues such as:
- Who owns or controls the data
- What the provider is allowed to do with it
- Security commitments
- Confidentiality obligations
- Breach notification timing
- Deletion or return of data at the end of the contract
This is especially important for HR software, cloud storage, CRMs, payment systems, and outsourced support providers, and may require a data processing agreement or clear privacy clauses.
Limit access inside your business
Not every staff member needs access to every file.
Access controls reduce the risk of accidental disclosure and make it easier to show that your business treats personal data seriously. Keep sensitive HR files, identity documents, and complaint investigations restricted to the people who genuinely need them.
Set retention rules and delete what you no longer need
Keeping personal data forever is rarely a good default.
Retention should reflect your operational needs, legal obligations, and the type of information involved. Different records may need different treatment. A recruitment file, a marketing list, and a customer invoice history do not necessarily justify the same retention period.
If specific retention questions overlap with tax or accounting requirements, speak with your accountant or tax adviser on those aspects.
Prepare for access, correction, and breach issues
Privacy compliance is not just about collection. It is also about what happens when a person asks for their information, wants a correction, or there is a security incident.
Your team should know:
- Who handles privacy requests
- Where relevant records are stored
- How to verify the requester’s identity
- What to do if information has been sent to the wrong person
- When to escalate a possible privacy breach
Small businesses often have the right intentions but no internal process, which causes delay and confusion when a real issue arises.
Common mistakes New Zealand businesses make
Most privacy problems start with ordinary business shortcuts, not dramatic misconduct.
- Assuming “business information” is never personal data
- Collecting more information than the business needs
- Using customer data for a new purpose without checking the original collection basis
- Relying on overseas templates that do not reflect New Zealand law or actual business practices
- Giving broad staff access to HR, customer, or complaint records
- Storing personal data in informal channels with poor controls
- Keeping old CVs, customer lists, or archived exports indefinitely
- Signing supplier contracts without checking data handling terms
If any of these sound familiar, the answer is usually not to panic. It is to tidy up the process before the issue becomes a complaint, a breach, or a trust problem with customers and staff.
FAQs
Is a work email address personal data?
Usually, yes, if it identifies an individual, such as a named employee email address. A generic shared address is less likely to be personal data on its own.
Does personal data include information about sole traders?
Often, yes. If the information relates to an identifiable individual operating as a sole trader, it can still be personal data even though it is used for business purposes.
Are IP addresses and analytics data personal data?
They can be. If an IP address, device identifier, or analytics record can be linked to a person or account, treat it as personal data.
Do employee records count as personal data?
Yes. Payroll details, performance notes, emergency contacts, recruitment files, and disciplinary records can all be personal data.
If I use a third party platform, is privacy their problem?
No. The platform may have its own obligations, but your business still needs to understand what data is collected, how it is used, and what your contract says about handling and security.
Key Takeaways
- In New Zealand, personal data generally means information about an identifiable individual, whether direct or indirect.
- It includes more than names and ID documents, it can also cover business contact details, CCTV, internal notes, account history, and digital identifiers.
- The issue comes up across online sales, recruitment, software tools, marketing, and complaint handling.
- Founders should map the data they hold, collect only what they need, explain their practices clearly, and check supplier contracts carefully.
- Good privacy practice also means controlling internal access, setting retention rules, and preparing for information requests and data incidents.
- If your business is dealing with personal data and wants help with privacy policies, supplier contracts, data collection notices, breach response processes, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.





