Under the Privacy Act 2020, an individual can request access to personal information an agency holds about them. Businesses receive these more often than they expect — frequently from a former employee, a customer in dispute, or someone contemplating a claim.
The obligation
Where an agency holds personal information about an individual, that individual is entitled to request access to it and to request correction.
Key features:
- The request does not have to be in a particular form or use the word “privacy”. A person asking what you have about them is making a request.
- You must respond as soon as reasonably practicable, and no later than 20 working days after receiving it.
- Extensions are possible in defined circumstances, and require you to notify the person within the original period.
- Charging is limited and generally not available for a first request from an individual about themselves.
Twenty working days is a month of real time. Businesses that do not have a process spend most of it locating information.
What is covered
Personal information about the requester, in whatever form and wherever held. That includes:
- Emails mentioning them, including internal discussion.
- File notes and meeting records.
- Performance and disciplinary records.
- CCTV footage of them.
- Text messages and instant messages.
- Notes in a CRM.
The scope surprises people. An internal email chain discussing an employee is their personal information, and they can ask for it.
This is worth knowing before writing the email rather than after. The practical guidance is simple: do not put anything in writing about a person that you would not be prepared to show them.
Grounds for withholding
Refusal grounds exist and they are specific rather than general. They include where disclosure would involve unwarranted disclosure of another person’s affairs, where it would breach legal professional privilege, where it would prejudice maintenance of the law, and where the information is evaluative material provided in confidence in defined circumstances.
Where you withhold, you must say so and give the reason. Blanket refusal without grounds is not available, and partial release with redactions is frequently the correct answer rather than refusing outright.
The other-person ground does a lot of work in practice. An email chain about a workplace complaint contains information about the complainant as well as the subject, and releasing it wholesale would disclose the complainant’s affairs.
Requests in a dispute
A substantial share of access requests arrive when a relationship has broken down — a personal grievance, a disciplinary process, a customer complaint heading toward a claim.
The request is valid regardless of motive. Refusing because you suspect the person is building a case is not a ground.
Take advice where a request arrives in a live dispute, because the interaction with privilege and with disclosure obligations in the proceeding needs handling. But respond within the timeframe rather than ignoring it.
Building a process before you need one
- Know where personal information lives. Most businesses cannot list every system holding it — accounting, payroll, CRM, email, cloud storage, CCTV, and spreadsheets on individual machines.
- Name someone responsible for handling requests.
- Diarise the 20 working day deadline from the day the request arrives.
- Search systematically, including email and messaging, not just the obvious file.
- Review before release for third-party information and other withholding grounds.
- Record what you released and what you withheld, and why.
Correction requests
An individual can also request correction of information they consider wrong. Where you decline, they can require a statement of the correction sought to be attached to the information.
That is a reasonable outcome in a genuine disagreement about facts, and it is better than a dispute about whether your record is accurate.
The enforcement context
The Office of the Privacy Commissioner received approximately 1,598 complaints in the year to 30 June 2025, with 67 percent of closed complaints resolved with some form of settlement.
Failure to respond to an access request within the timeframe is itself a common complaint ground, and it is entirely avoidable.
The Office of the Privacy Commissioner publishes guidance on access requests, withholding grounds and response templates free at privacy.org.nz.
Figures: Office of the Privacy Commissioner Annual Report, year ending 30 June 2025. General information only, not legal advice.








