When Can New Zealand Businesses Disclose Personal Information with Consent?

Alex Solo
byAlex Solo11 min read

Many New Zealand businesses know they need to be careful with personal information, but the real trouble starts when they want to share it with someone else. A customer says, “that’s fine”, a staff member ticks a box, or a supplier asks for a list of contacts, and suddenly the business assumes consent covers everything. That is where founders often get caught. Common mistakes include relying on vague verbal permission, collecting consent after the disclosure has already happened, and using information for a broader purpose than the person actually agreed to.

The Privacy Act 2020 does allow disclosure in some cases, and consent can be one of the clearest paths, but only if it is real, informed and tied to what you are actually doing. If you are collecting customer details, sharing information within a group of companies, using third party platforms, or sending information to a marketing or fulfilment provider, this is a practical issue worth getting right before you sign a contract or spend money on setup.

This guide explains what consent to disclosure of information means in New Zealand, when businesses can rely on it, where consent falls short, and what practical steps reduce your privacy risk.

Overview

Consent can support a lawful disclosure of personal information, but it is not a magic fix. Your business still needs to be clear about what information is being shared, who it is going to, why the disclosure is happening, and whether the person genuinely agreed.

A good consent process is specific, documented and easy to understand. A weak consent process usually fails because it is buried in general terms, bundled with unrelated permissions, or too vague to match the actual disclosure.

  • Work out exactly what personal information you want to disclose and why.
  • Check whether consent is the right legal basis, or whether another rule under the Privacy Act applies.
  • Make sure the person knows who will receive the information and what it will be used for.
  • Record when and how consent was given, and keep the wording used at the time.
  • Avoid broad or bundled consent that tries to cover future unknown disclosures.
  • Review your privacy policy, collection statements, contracts and internal processes so they match what your business actually does.

Consent means a person has agreed to your business disclosing their personal information, but that agreement needs to be meaningful. In practice, the safest approach is to treat consent as valid only where the individual understands the key facts and has a real choice.

Under the Privacy Act 2020, New Zealand businesses usually need to think about why personal information was collected in the first place and whether a later disclosure fits within that purpose or an allowed exception. Consent can sit alongside those rules. It is often most useful where the disclosure goes beyond what the person would reasonably expect, or where you want express permission for a particular use.

What counts as personal information?

Personal information is information about an identifiable individual. For a business, that can include:

  • customer names, addresses, email addresses and phone numbers
  • payment details and order history
  • employee or contractor records
  • health, insurance or support information
  • photos, recordings or location data
  • online account details and identifiers linked to a person

If the information can identify someone directly or indirectly, treat it carefully.

Consent is more likely to be valid where it is informed, specific and voluntary. The person should know what they are saying yes to, and the scope of that permission should match the actual disclosure.

That usually means your business should be able to answer:

  • what information will be disclosed
  • who will receive it
  • why the disclosure is happening
  • whether the recipient is in New Zealand or overseas
  • what the likely consequences are for the individual
  • whether saying no is a genuine option

A pre-ticked box, a hidden clause in long terms, or a general statement that information may be shared “from time to time” can be risky if it does not clearly cover the disclosure you later make.

Express consent is the stronger option. That is where the person clearly says yes, such as ticking an unchecked box, signing a form, replying by email, or accepting a clearly worded in-app request.

Implied consent can exist in some situations, but businesses should be careful with it. If a customer gives you a delivery address, they would usually expect you to share it with the courier. That is different from assuming they agree to their details being shared with unrelated marketing partners. If there is any doubt, ask directly.

Even where you have consent, your business still needs to handle the disclosure properly. Privacy compliance often overlaps with other areas of your business setup, including:

  • customer terms and conditions
  • supplier agreements and software contracts
  • employment contracts and related documents
  • data storage and security processes
  • cross border data arrangements
  • marketing practices under the Fair Trading Act and spam rules

This is why a privacy issue can quickly turn into a contracts and systems issue as well.

When This Issue Comes Up

Consent to disclosure of information usually becomes important at ordinary business moments, not only during a privacy complaint. The risk tends to appear when your business grows, adds new tools, outsources work, or starts using personal information in ways customers did not originally expect.

Sharing customer data with service providers

Many SMEs use payment processors, CRM platforms, booking systems, couriers, IT providers and marketing agencies. Some of these providers are simply handling information on your behalf. Others may use it for their own purposes or sit outside New Zealand.

Before you sign a contract with a new platform or provider, check whether your privacy wording and customer communications accurately describe that disclosure. If your collection statement says little more than “we may share information with trusted partners”, that may not be enough for a more sensitive or unexpected arrangement.

Disclosures within a group of companies

Founders sometimes assume they can freely move customer or employee information between related entities. That is not always safe. Separate companies are separate legal entities, even if the same people own them.

If one company collected the information, think carefully before another company uses it. The main questions are whether the person would reasonably expect that sharing, whether the original purpose covers it, and whether your consent wording or privacy notice actually says this happens.

Using testimonials, case studies and marketing content

Consent matters when you want to use someone’s name, image, comments or business story in promotional material. This is particularly relevant for agencies, software businesses, coaches, healthcare-adjacent services and professional service firms.

A customer who gave feedback to your support team has not automatically agreed to have that feedback published on your website, in ads or in social posts. Ask clearly, and keep a record of what uses they agreed to.

Disclosing employee and contractor information

Businesses often share employee or contractor information with payroll providers, benefit providers, clients, landlords, software systems or overseas parent companies. Some of these disclosures may be expected and necessary, but not all of them should be treated casually.

Employment and contractor documents should align with your internal privacy practices. A broad clause that says information may be shared “for business purposes” can be too loose if your real process is much more specific.

Sales, due diligence and business restructuring

If you are selling part of the business, raising capital, or entering a merger process, personal information often comes up during due diligence. Buyers and investors may want access to customer lists, staff records or support logs.

This is a point where founders need to slow down. You may be able to share some information in a controlled and de-identified form first, then disclose more only if needed and on proper terms. Consent may be relevant, but confidentiality arrangements, purpose limits and data minimisation are just as important.

Health, support or sensitive information

The more sensitive the information, the more careful your business should be. Health details, identity documents, financial hardship information, children’s information and complaint records deserve a higher standard of clarity.

In these situations, vague wording is especially risky. If you are collecting sensitive information, spell out any likely disclosure early, before the person hands over the data.

Practical Steps And Common Mistakes

The best way to handle consent is to build it into your collection, disclosure and record-keeping process from the start. Most privacy problems happen because a business grows faster than its paperwork and systems.

Your consent request should match the actual business activity. If you need permission to share information with a finance provider, logistics partner, related company or marketing platform, say so in plain English.

Strong wording usually includes:

  • the categories of information involved
  • the categories or names of recipients
  • the purpose of the disclosure
  • whether overseas disclosure may happen
  • any practical effect on the individual
  • how the person can withdraw consent, where that is workable

Avoid copying broad online template wording if it does not fit your real process. This is where founders often get caught after adding a new app, channel partner or outsourcing arrangement.

Bundled consent is a common problem. If one tick box covers account creation, marketing, third party disclosures and data analytics, the individual may not have given meaningful permission for each part.

Separate requests work better. For example, a customer might need to agree to your customer terms, while separately choosing whether you may share their details with a related company for cross-selling or use their testimonial in advertising.

Record the evidence

If your business later needs to show that consent was given, you need more than a general assumption. Keep records that show:

  • who gave the consent
  • when it was given
  • how it was given, such as online form, email or signed document
  • the exact wording presented at the time
  • any version history if your privacy wording changed

This matters if there is a complaint, an internal dispute, a data incident, or a question during a transaction.

Match your contracts to your privacy promises

Your privacy policy should not say one thing while your supplier contracts permit something broader. If a software provider can use data for its own analytics, product training or secondary purposes, your business needs to understand that before you start using the service.

Review contracts with:

  • software and cloud providers
  • marketing and lead generation agencies
  • courier and fulfilment partners
  • outsourced customer support providers
  • related entities handling shared data

Look for clauses dealing with purpose limits, confidentiality, sub-processors, overseas storage, security, and who is responsible if something goes wrong.

Watch overseas disclosures

If personal information is being disclosed outside New Zealand, extra care is needed. The legal position depends on the arrangement and destination, and your business should understand where data is going before you sign.

At a practical level, tell people if overseas recipients are involved where that is relevant to the disclosure. Also check whether your contracts and platform settings reflect what you are telling customers and staff.

Do not rely on silence or assumptions

A person’s failure to object is not always consent. Neither is a broad commercial relationship. If you plan to disclose information in a way the person may not expect, ask directly.

This issue often appears when businesses expand their marketing, partner with another brand, or reuse old customer data for a new initiative. Past contact does not automatically mean present permission.

Train the people who actually handle the data

Many privacy problems are operational rather than legal drafting problems. Sales staff, account managers, support teams and founders often make day to day disclosure decisions quickly.

Your internal process should make clear:

  • when staff can share personal information without escalation
  • when express consent is needed
  • how to verify identity before disclosing information
  • what to do if a customer withdraws consent or objects
  • who approves unusual or high-risk disclosures

Simple internal guidance can prevent costly mistakes.

Common mistakes New Zealand businesses make

The most common errors are not usually dramatic. They are small process gaps that create risk over time.

  • Using vague privacy wording that does not match actual disclosures.
  • Assuming related companies can freely share data with each other.
  • Publishing customer names, images or reviews without clear permission.
  • Failing to keep evidence of when consent was given.
  • Adding a new platform or offshore provider without updating privacy notices or contracts.
  • Collecting more information than needed and then trying to find uses for it later.
  • Treating employee and contractor information less carefully than customer information.

If any of those sound familiar, it is worth reviewing your process before the issue turns into a complaint or reputational problem.

FAQs

Sometimes, but written or recorded consent is much safer. Verbal consent can be hard to prove later and often lacks enough detail about the scope of the disclosure.

Not necessarily. A privacy policy helps with transparency, but it may not amount to clear consent for a specific disclosure, especially if the wording is broad or the disclosure is unexpected.

Can a business share information with an overseas software provider if the customer consented?

Consent may help, but it is not the only issue. You should also understand the cross border arrangement, check your contracts, and make sure your explanation to the individual is accurate.

In many situations, yes, at least for future disclosures. The practical effect depends on the arrangement and whether the disclosure is ongoing, already completed, or necessary to keep providing the service.

Not always. Some disclosures are expected for employment administration, but businesses should still be transparent and should not assume a broad employment clause covers every possible disclosure.

Key Takeaways

  • Consent to disclosure of information works best when it is specific, informed, voluntary and documented.
  • Your business should clearly explain what information will be shared, with whom, and for what purpose.
  • Vague, bundled or implied consent can be risky, especially for unexpected, sensitive or overseas disclosures.
  • Privacy notices, customer terms, employment documents and supplier contracts should all line up with your actual data practices.
  • Good record-keeping and staff training are just as important as the wording you use.
  • Before you sign a contract or roll out a new process, review whether your disclosure practices match what people were told when their information was collected.

If your business is dealing with consent to disclosure of information and wants help with privacy policies, customer consent wording, supplier contracts, and internal data handling processes, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.