When Does Your New Zealand Business Need a Privacy Officer?

Alex Solo
byAlex Solo11 min read

If your business collects customer details, staff records, website enquiries, or marketing data, privacy is already part of your day-to-day operations. A common mistake is assuming only large organisations need a privacy officer. Another is naming someone on paper, then giving them no authority, no training, and no process for dealing with complaints or data requests. A third is treating privacy as an IT issue only, when the real problems often start with staff habits, poor forms, unclear notices, or rushed responses to customers.

New Zealand law is fairly direct on this point: agencies generally need a privacy officer. For many startups and SMEs, the real question is not whether one is required, but who should do the job and what that person needs to handle in practice. This guide explains when your business needs a privacy officer, what the role means under New Zealand law, when the issue usually comes up for founders, and the practical steps that help you avoid avoidable privacy problems before you sign contracts, launch online, or scale your team.

Overview

Most New Zealand businesses and organisations that collect, hold, use, or disclose personal information should have at least one privacy officer. The role is not just a title, it is a practical responsibility for making sure privacy requests, complaints, and internal questions are handled properly.

  • Whether your business is an “agency” under the Privacy Act 2020
  • Who in your business is suitable to act as privacy officer
  • What authority, time, and training that person needs
  • How your business handles access requests, correction requests, and privacy complaints
  • Whether your privacy policy, staff practices, and supplier agreements line up with how you actually collect and use data
  • What to do if you collect information online, use overseas providers, or share data with contractors

What Privacy Officer Means For New Zealand Businesses

A privacy officer is the person responsible for helping your business meet its privacy obligations under New Zealand law.

Under the Privacy Act 2020, an agency must appoint a privacy officer. In practical terms, most businesses will fall within the definition of an agency. If you run a company, partnership, sole trader business, charity, club, or other organisation and you deal with personal information, you should assume this requirement applies unless you have specific advice saying otherwise.

Personal information is broad. It includes obvious items like names, email addresses, phone numbers, and employee files. It also includes information that can identify someone indirectly, such as booking records, customer complaint notes, CCTV footage linked to an individual, job application materials, loyalty data, and online account information.

What does the privacy officer actually do?

The privacy officer is not expected to personally manage every spreadsheet or approve every email campaign. The role is about oversight, coordination, and response.

In most SMEs, the privacy officer’s functions usually include:

  • Encouraging compliance with the Privacy Act and internal privacy processes
  • Dealing with requests from individuals who want access to or correction of their personal information
  • Working through privacy complaints
  • Acting as a contact point with the Office of the Privacy Commissioner where needed
  • Helping the business identify privacy risks in day-to-day operations
  • Making sure staff know what to do with personal information

This means the privacy officer needs enough visibility across the business to spot issues early. If your website captures leads, your payroll system stores staff information, and your customer service team keeps records of complaints, the privacy officer should understand how those pieces fit together.

Does the privacy officer have to be a specialist?

No, not usually. The law does not require every business to hire a dedicated privacy specialist.

For many startups and smaller businesses, a director, founder, office manager, operations lead, people and culture manager, or senior admin team member may take on the role. The better question is whether that person has the time, judgment, and authority to respond properly when privacy issues arise.

This is where founders often get caught. A business may appoint the most available person rather than the right person. If the nominated privacy officer cannot answer customer questions, cannot ask staff to change poor practices, or does not understand what information the business holds, the appointment may not help much in real life.

Can one person hold other roles too?

Yes. In a smaller business, the privacy officer often wears multiple hats.

That is normal, but there is still a practical limit. If the same person is already stretched across HR, contracts, compliance, and daily operations, privacy can easily become a task that gets handled only after something goes wrong. The main risk is delay. Privacy requests and complaints often have time-sensitive elements, so someone needs to be able to act promptly.

What if your business operates mostly online?

An online business is not exempt. In fact, online businesses often have more privacy touchpoints, not fewer.

If you sell online, run a subscription service, collect website analytics, use online forms, store customer accounts, or market by email or SMS, you are handling personal information in ways that create clear privacy obligations. A privacy officer helps make sure the legal side matches the practical setup, especially where your systems rely on third party platforms or overseas service providers.

When This Issue Comes Up

Most businesses should appoint a privacy officer early, ideally before they collect much personal information or launch systems that depend on it.

In practice, many founders only realise the issue exists when a customer asks for a copy of their data, a staff member raises a complaint, or a supplier questionnaire asks for the name of the business’s privacy contact. The better approach is to sort this out before the pressure point arrives.

When you start collecting customer information

The issue comes up as soon as your business collects identifiable information from customers, users, subscribers, or leads.

That can happen earlier than many founders expect, such as when you:

  • set up a website contact form
  • take online bookings or orders
  • build an email marketing list
  • use a CRM
  • record customer support conversations
  • collect addresses for delivery

If your business is preparing to launch online, privacy should sit alongside your customer terms, website disclosures, contracts, and trade mark planning, not as an afterthought.

When you hire staff or contractors

Employment information is personal information, so privacy obligations increase once you start building a team.

Before you hire, you may collect CVs, references, police vetting information where appropriate, right to work records, emergency contacts, and payroll details. After hiring, your business may hold leave information, performance notes, health information, disciplinary records, and device monitoring data. A privacy officer helps make sure that access to these records is limited and requests are handled correctly.

When a client or larger customer asks compliance questions

Privacy officer issues often surface during procurement or contract negotiations.

A larger customer may ask whether your business has a privacy officer, a privacy policy, a data breach response process, or rules about overseas data storage. This is common if you supply software, professional services, education services, health-related services, recruitment, marketing, or any offering that handles personal information for others.

If you are tendering for work or about to sign a service agreement, privacy readiness can affect whether the deal proceeds smoothly.

When you use third party software or offshore providers

Using cloud software, outsourced support, offshore developers, or international platforms can raise privacy questions quickly.

Your business may still be responsible for what happens to personal information even if another provider stores or processes it. A privacy officer should understand:

  • what platforms collect personal information
  • where data is stored
  • who can access it
  • whether the provider terms align with your customer promises
  • what happens if there is a security issue or service failure

When something goes wrong

A privacy breach is often the moment businesses discover they needed a clearer internal owner all along.

This might involve emailing the wrong attachment, exposing customer details through poor permissions, losing a laptop, sharing staff information inappropriately, or collecting data through a form without telling people how it would be used. At that point, the privacy officer becomes central to managing the response, assessing reporting obligations, and keeping records of what happened.

Practical Steps And Common Mistakes

The best privacy officer setup is simple, active, and matched to how your business actually operates.

You do not need a thick manual that nobody reads. You do need clear responsibility, workable procedures, and documents that reflect your real practices. Here’s what to sort out first.

Choose the right person

Your privacy officer should be someone who can ask questions across the business and get answers.

That usually means someone reasonably senior, organised, and trusted. They should be able to coordinate with founders, IT providers, HR, marketing, and customer-facing teams. If you appoint a junior staff member without support, you risk creating a role with responsibility but no practical power.

When deciding who should take the role, think about:

  • whether they understand how personal information flows through the business
  • whether they can respond to customers and staff confidently
  • whether they have enough time to manage requests and incidents
  • whether they can escalate issues before they become bigger problems

Document the appointment internally

The appointment does not need to be complicated, but it should be clear.

Record who the privacy officer is, what they are responsible for, who supports them, and where privacy requests should be sent. Make sure customer-facing and people-facing staff know who to contact. If nobody can identify the privacy officer when an issue arises, the appointment has not really been embedded.

Review what personal information you collect

You cannot manage privacy well if you do not know what information your business holds.

A practical data review should cover:

  • what personal information you collect from customers, website users, staff, and contractors
  • why you collect it
  • where it is stored
  • who can access it
  • how long you keep it
  • whether you share it with service providers or related entities

This exercise often reveals old forms, duplicated storage, excessive access permissions, or data collection that no longer has a clear purpose.

Make your privacy policy match reality

A privacy policy should describe what your business actually does, not what a template says.

One common mistake is copying a generic policy that does not match your systems, your marketing methods, or your customer journey. Another is publishing a policy that says the business only collects contact details, when in reality it also stores payment-related data, support records, employment information, or behavioural analytics.

Your privacy officer should check that your policy covers matters such as:

  • what information is collected
  • how it is collected
  • why it is used
  • whether it is disclosed to others
  • how people can request access or correction
  • how to contact the business about privacy concerns

Set a process for access and correction requests

People can ask for access to personal information your business holds about them, and they can ask for corrections.

If those requests arrive by email, social media, customer support chat, or through a staff manager, your team needs to know what to do next. A common error is informal handling, where one employee replies too quickly, another ignores the request, and no central record is kept.

Your process should cover:

  • who receives the request
  • how identity is checked where necessary
  • who gathers the relevant information
  • who reviews whether anything can or should be withheld under the law
  • how the response is recorded
  • what timeframe the business aims to meet

Prepare for privacy breaches

Every business that handles personal information should have a basic breach response process.

This does not need to be over-engineered for a small business, but it should be real. Your privacy officer should know who to contact internally, how to contain the issue, how to assess seriousness, and when legal advice may be needed. In some cases, a notifiable privacy breach may need to be reported.

Before you spend money on setup, fancy software is not always the first answer. Better staff habits, clearer access controls, and cleaner processes often reduce risk faster than a new tool does.

Train staff on the simple things

Most privacy problems start with ordinary behaviour, not dramatic cyber incidents.

Staff should understand basics such as:

  • only collecting information that is actually needed
  • not sharing customer or employee information casually
  • checking recipients before sending emails
  • using approved systems rather than personal accounts or devices where possible
  • escalating complaints and unusual requests quickly
  • keeping passwords and access details secure

This matters whether you run a retail business, a professional services firm, a software startup, a health-adjacent business, or an e-commerce store selling online across New Zealand.

Watch for these common mistakes

The most common privacy officer mistakes are practical rather than technical.

  • Assuming a tiny business does not need a privacy officer
  • Appointing someone but not giving them any actual role
  • Using a privacy policy that does not match business operations
  • Letting customer data sit across inboxes, spreadsheets, and old apps with no clear owner
  • Forgetting staff information is also covered by privacy rules
  • Signing supplier agreements without checking how personal information will be handled
  • Waiting until a complaint or breach to work out internal responsibilities

If your business is growing quickly, these issues often overlap with broader legal housekeeping such as contracts, employment contracts, online terms, intellectual property protection including trade mark planning, and choosing the right business structure. Privacy should sit alongside those decisions because each one can affect what information you collect and how you use it.

FAQs

Does every New Zealand business need a privacy officer?

Most do. The Privacy Act 2020 requires agencies to appoint a privacy officer, and most businesses will be agencies for this purpose.

Can a director or founder be the privacy officer?

Yes. In many startups and SMEs, a founder, director, or senior manager takes the role. The key issue is whether they have enough time and authority to do it properly.

Do I need to tell customers who the privacy officer is?

You should make it easy for people to contact your business about privacy matters. In practice, many businesses include a privacy contact point in their privacy policy or internal response process, whether that names the individual or the role.

What if we only collect basic contact details?

You are still handling personal information. Even basic contact details can trigger privacy obligations, especially if you use them for marketing, customer accounts, support, or staff management.

Is a privacy officer the same as a data security manager?

No. There can be overlap, but the privacy officer role is broader. It covers requests, complaints, compliance, and internal coordination, not just system security.

Key Takeaways

  • Most New Zealand businesses that handle personal information should appoint a privacy officer under the Privacy Act 2020.
  • The role is practical, not symbolic. The privacy officer should be able to manage requests, complaints, and internal privacy questions.
  • Small businesses do not usually need a dedicated specialist, but they do need someone with enough authority, time, and support.
  • The issue often comes up when you launch online, hire staff, answer client compliance questionnaires, use offshore software, or deal with a privacy incident.
  • Your privacy officer should help align your privacy policy, internal processes, staff training, and supplier arrangements with how your business actually handles personal information.
  • Common mistakes include assuming the role is optional, using generic policies, and waiting until a complaint or breach to get organised.

If your business is dealing with privacy officer and wants help with privacy policies, data handling processes, supplier contracts, or breach response planning, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.