Main laws

New Zealand Act

Customer and Product Data Act 2025

The Customer and Product Data Act 2025 creates New Zealand's framework for customer-controlled data sharing.

In force; sector duties depend on designationNew ZealandPlain-English guide6 practical checks

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • The Act does not make every New Zealand business a data holder.
  • Detailed duties are activated through sector designations, regulations and standards.

Likely relevant if

  • Businesses designated as data holders in a regulated sector
  • Fintechs and other providers seeking accreditation to receive customer-authorised data
  • Software and infrastructure providers supporting regulated data services

Check first

  • Confirm whether the business and data are covered by a sector designation
  • Provide designated customer or product data when a valid request must be honoured
  • Operate an electronic system that meets prescribed technical and performance requirements

What the Act builds

The Act creates the legal framework for a New Zealand customer data right. In a designated sector, a customer may be able to ask a data holder for specified data, authorise an accredited requestor to obtain it, or ask for a designated action to be performed.

The framework is intended to support services such as comparison, switching and account management. The Act supplies the legal structure, while designation regulations and standards determine much of the practical scope.

How a regulated request works

  1. Check coverage

    Confirm that the data holder, customer, data and requested service fall within the designation and rules.

  2. Verify the person

    Apply the required identity checks for the customer, secondary user or accredited requestor.

  3. Confirm authorisation

    Where an accredited requestor is involved, make sure customer authorisation is valid, controllable and capable of being ended.

  4. Provide or refuse lawfully

    Deliver the regulated service through the compliant system or rely on a permitted or required refusal ground.

  5. Keep the record

    Retain the records needed to explain what was requested, authorised and provided.

What this means for product design

Compliance will show up in the product itself. Authorisation language, identity checks, revocation controls, API performance, security and complaint routes all shape whether the service works lawfully.

A legal policy cannot repair a confusing or insecure customer journey after launch. Product, engineering, privacy, security and customer-support teams need one implementation plan.

Key points

  • Show customers what data or action they are authorising
  • Make it possible to control and end authorisation
  • Separate required identity checks from unnecessary data collection
  • Log requests, decisions, data transfers and service failures
  • Connect complaints and incidents to the right regulatory response

A sensible first readiness review

Key points

  • Confirm whether a current or proposed designation covers the business
  • List the systems that hold relevant customer and product data
  • Identify third parties involved in storage, identity, APIs or customer support
  • Test how authorisation is given, changed and withdrawn
  • Review security, complaints, records and incident escalation together
  • Assign an owner to monitor new designation regulations and standards

Common questions

Does the Act apply to every business that holds customer data?

No. The main regulated data-service duties depend on designation regulations that identify sectors, data holders, data and actions. A business should check its role and the relevant designation before assuming it is covered.

What is an accredited requestor?

It is a person approved under the Act to request regulated data services with a customer's authorisation. Accreditation can carry terms, conditions, renewal requirements and ongoing compliance duties.

Is this only a privacy law?

No. Privacy and security are central, but the Act also covers data access, designated actions, accreditation, technical standards, complaints, enforcement and civil remedies.

Related topics

How Sprintlaw can help

Update history

New18 July 2026

Customer and Product Data Act guide added

The library now explains New Zealand's customer-controlled data-sharing framework, including designation, authorisation, data-holder and accredited-requestor roles.