Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
If your business is launching a new app, changing how customer data moves between systems, or rolling out AI tools, a Privacy Impact Assessment can save you from expensive mistakes. A lot of founders collect more personal information than they need, copy overseas privacy templates that do not fit New Zealand law, or leave privacy questions until after a product has been built. That is usually when problems show up, including unclear consent, poor data security decisions, or contracts that do not match how information is actually handled.
A Privacy Impact Assessment, often shortened to a PIA, is a practical way to spot privacy risks early and fix them before you sign a contract, spend money on setup, or launch online. This guide explains how to define PIA in plain English, when New Zealand businesses should use one, what it should cover, and the common mistakes that create legal and commercial risk.
Overview
A Privacy Impact Assessment is a structured review of how a project, product, process, or system will affect personal information and individual privacy. In New Zealand, it is not a one-size-fits-all legal form. It is a practical risk tool that helps a business work out what information it is collecting, why it needs it, who will see it, how long it will keep it, and whether the setup matches the Privacy Act 2020.
A good PIA does more than describe data flows. It helps decision-makers change the design, documents, contracts, and internal processes before the business is locked in.
- What personal information you are collecting, creating, storing, sharing, or deleting
- Why the information is needed, and whether you can collect less
- Which Privacy Act 2020 principles are most relevant to the project
- Whether individuals are being told clearly what happens to their information
- Who inside and outside the business can access the information
- What systems, vendors, or offshore providers are involved
- How security, retention, correction, and access requests will be handled
- What contracts, policies, notices, and internal approvals need updating
What Define Pia Means For New Zealand Businesses
To define PIA simply, it means assessing the privacy impact of a business decision before that decision creates a problem. For New Zealand businesses, that usually means documenting how personal information will be handled and checking whether the project is fair, transparent, and legally supportable.
A PIA is not just for large corporates or government agencies. Startups, online stores, SaaS businesses, professional service firms, healthcare-adjacent businesses, education providers, and employers can all need one when personal information is used in a new or riskier way.
What a PIA usually covers
A proper Privacy Impact Assessment usually brings together the legal, operational, and technical sides of a project. It should explain the project clearly enough that someone outside the team can understand what is changing and why privacy issues matter.
Most PIAs include:
- a description of the project or change
- the types of personal information involved
- where the information comes from
- the purpose of collection and use
- who the information is shared with
- whether any data is sent or accessed overseas
- the legal and practical risks
- steps to reduce those risks
- the decision on whether the project should proceed as planned, proceed with changes, or pause for further review
How the Privacy Act 2020 fits in
New Zealand's Privacy Act 2020 does not say every business must complete a PIA for every project. But the Act sets rules for collecting, using, storing, disclosing, and giving access to personal information. A PIA helps you test whether your project lines up with those rules in practice.
For example, a PIA can help you check whether your business is:
- collecting information for a lawful and necessary purpose
- telling people what they need to know at the point of collection
- keeping information secure against loss, misuse, or unauthorised access
- giving people a realistic way to access or correct their information
- retaining information only as long as needed
- disclosing information in ways people would reasonably expect, or where another legal basis applies
That matters because privacy compliance is rarely just about a policy on your website. It often depends on how your forms, customer journey, contracts, software settings, staff access permissions, and marketing practices actually work.
Why founders and SMEs should care
The main risk is not just a privacy complaint. A poor data setup can also slow down a product launch, spook enterprise customers during procurement, create issues in due diligence, and force a costly rebuild after contracts are signed.
This is where founders often get caught. The product team chooses a tool, the operations team signs up a vendor, and the privacy questions only come up when someone asks where the data sits, whether call recordings are kept, or how customer deletion requests will be handled.
A PIA gives you a cleaner answer to those questions. It also helps your business show that privacy was considered seriously, which can matter if a regulator, partner, investor, or customer later asks how risks were assessed.
When This Issue Comes Up
A Privacy Impact Assessment is most useful when your business is doing something new with personal information, especially where the change affects visibility, control, security, or scale. The best time to do it is before you sign a contract, before you lock in a system design, and before you spend money on setup that is hard to unwind.
Common business moments that trigger a PIA
PIAs commonly come up when a business is:
- launching a new app, website, platform, or customer portal
- introducing online ordering, online bookings, or account-based services
- collecting sensitive or higher-risk information, such as health details, identity documents, or location data
- adding customer analytics, behavioural tracking, or profiling tools
- using AI systems that process staff, customer, or supplier information
- moving data to a new cloud provider or software platform
- sharing information with a marketing agency, outsourced service provider, or related company
- sending or allowing access to personal information outside New Zealand
- changing employee monitoring, recruitment, or HR systems
- combining datasets that were originally collected for different purposes
Not every one of these scenarios creates the same level of risk. But they are all strong signs that a privacy review should happen.
Examples in day-to-day SME settings
An e-commerce business may add a loyalty programme that tracks purchase history, preferences, and birthdays. A PIA helps decide what fields are actually needed, what customers should be told, and whether the retention period makes sense.
A software startup may start recording support calls and feeding transcripts into an AI assistant. A PIA can identify whether customers were told about recording, whether there is a suitable use case for the transcript data, and whether the vendor terms give enough control over stored information.
A professional services firm may outsource document processing to an overseas provider. A PIA can flag cross-border disclosure issues, contractual controls, client confidentiality concerns, and whether the privacy notice or privacy policy needs updating.
An employer may introduce GPS tracking in work vehicles or new productivity monitoring software. A PIA helps test whether the monitoring is proportionate, whether staff have been informed properly, and whether the collected data is likely to be used fairly.
When a short internal review may be enough
Some low-risk changes may not need a lengthy formal document. If the project is minor and does not materially change what personal information is collected, who receives it, or how people are affected, a shorter internal assessment may be reasonable.
What matters is substance, not paperwork for its own sake. If there is a real privacy impact, the review should be detailed enough to identify and manage it.
Practical Steps And Common Mistakes
A useful PIA is specific to the actual project, not a recycled template. It should map what really happens to personal information from collection through to deletion, then turn the risks into clear actions for the team.
Practical steps to prepare a PIA
Start with the project itself. Write down what is changing, what the business wants to achieve, and which systems or providers are involved.
Then identify the personal information lifecycle. That usually includes:
- how information is collected
- what categories of information are involved
- who enters or uploads it
- where it is stored
- who can access it
- who it is shared with
- how long it is kept
- how it is corrected, exported, or deleted
Next, match that data flow against the legal and practical questions. Ask:
- Is each category of information actually needed for the stated purpose?
- Would customers, users, staff, or contractors reasonably expect this use?
- Are your collection statements and privacy policy clear enough?
- Do your supplier contracts reflect the way personal information will be handled?
- Is the level of security appropriate for the sensitivity of the information?
- Can your team respond if someone requests access or correction?
- Is there a process for detecting and escalating a privacy breach?
- Are there any high-risk features that should be removed or redesigned?
After that, assign actions and owners. A PIA is not finished when risks are listed. It is finished when the necessary contract updates, product changes, wording fixes, security steps, and internal approvals are allocated to real people with a timeframe.
Who should be involved
The right people are usually the ones who understand what actually happens, not just the ones approving the budget. Depending on the project, that might include:
- a founder or senior decision-maker
- operations or product leads
- IT or security personnel
- marketing or customer experience staff
- HR staff for workforce-related projects
- legal advisers where the risks are material or unclear
- key vendors who control parts of the data flow
If the assessment is done only by one team, important issues often get missed. Marketing may know what is promised to users, product may know what the system can do, and legal may know where the wording or contract position is weak. You usually need all three views.
Common mistakes businesses make
The most common mistake is doing the PIA too late. Once contracts are signed and systems are configured, changing the setup becomes slower and more expensive.
Another common mistake is treating the PIA like a privacy policy exercise. A policy matters, but it does not replace testing the actual collection points, settings, permissions, and workflows.
Businesses also get caught when they:
- collect information because a form can include it, not because it is necessary
- copy broad consent wording that does not match the real use of data
- assume a software provider has already handled all privacy issues
- forget to review cross-border access and disclosure arrangements
- leave retention periods undefined
- fail to line up customer-facing notices with internal practices
- ignore staff training, even though staff behaviour often causes the real risk
- write down risks but do not track whether fixes were implemented
How a PIA connects with other legal documents
A Privacy Impact Assessment often reveals that other legal documents need attention too. Depending on the project, your business may need to review or update:
- its privacy policy
- collection notices on forms, apps, and websites
- customer terms or platform terms
- supplier agreements or SaaS contracts
- data processing clauses and confidentiality terms
- employment policies or staff IT use policies
- incident response and breach reporting procedures
This is one reason PIAs are commercially useful. They do not sit in a drawer. They often point directly to contract, policy, and process gaps that would otherwise stay hidden until there is a complaint or negotiation problem.
What good looks like in practice
A good PIA is clear, current, and tied to decisions. It explains the project in plain English, identifies the real privacy risks, and records what the business will do about them.
If a regulator or major customer asked to see your reasoning, the document should show that the business considered data minimisation, transparency, security, access rights, vendor risk, and practical controls. It should also show who approved the final approach and when it will be reviewed again.
FAQs
Is a Privacy Impact Assessment mandatory in New Zealand?
Not in every case. New Zealand law does not require every business to complete a PIA for every activity, but it is often a sensible and expected step for projects involving new, sensitive, large-scale, or higher-risk uses of personal information.
What does define PIA mean in simple terms?
It means defining and assessing the privacy impact of a project before it goes live. In practice, that means working out how personal information will be handled, what the risks are, and what changes should be made to reduce those risks.
When should a business do a PIA?
The best time is early, before you sign a contract, before you build the final workflow, and before you launch online. A late-stage PIA is still better than none, but it usually gives you fewer practical options.
Who should prepare a PIA?
The people who understand the project should be involved, including operations, product, IT, and decision-makers. Legal input is often useful where the project is sensitive, uses offshore vendors, changes customer disclosures, or creates uncertainty under the Privacy Act 2020.
Does a PIA replace a privacy policy?
No. A PIA is an internal assessment tool. A privacy policy is an external explanation of how your business handles personal information. The two should align, but they serve different purposes.
Key Takeaways
- A Privacy Impact Assessment is a practical review of how a project affects personal information and privacy.
- To define PIA simply, it means identifying privacy risks early and deciding what to change before launch or implementation.
- In New Zealand, a PIA helps businesses test whether a new system, product, or process aligns with the Privacy Act 2020.
- PIAs are especially useful when introducing new technology, using AI, sharing data with vendors, handling sensitive information, or moving data offshore.
- The most effective PIAs are done early, involve the right internal teams, and lead to concrete action on contracts, notices, policies, and system settings.
- Common mistakes include using generic templates, collecting too much information, ignoring vendor risk, and leaving the assessment until after contracts are signed.
- If your business is dealing with define pia and wants help with privacy policies, supplier contracts, data sharing arrangements, or Privacy Act compliance, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







