Data governance sounds like an enterprise concern. The underlying question is one every business should be able to answer and most cannot: what information do we hold, where is it, why do we have it, and who can reach it?
Start with an inventory
List every system that holds information about people — customers, employees, suppliers, applicants. In a typical small business that includes:
- Accounting software.
- Payroll.
- CRM or customer database.
- Email, which is usually the largest and least controlled repository.
- Cloud file storage.
- Website and e-commerce platform.
- Marketing platform.
- Point of sale.
- CCTV.
- Spreadsheets on individual machines, which nobody counts and everyone has.
For each: what is held, why, who can access it, where it is stored, and how long it is kept.
Most businesses doing this for the first time find data they did not know they had, in systems nobody owns, accessible to people who no longer work there.
The Privacy Act framework
The Privacy Act 2020 sets information privacy principles governing collection, use, disclosure, storage and access. The practical obligations for a small business:
- Collect only what you need for a lawful purpose connected to your activities.
- Tell people what you are collecting, why, who will see it and their access rights.
- Use it only for the purpose it was collected for, or a directly related one.
- Keep it secure, with reasonable safeguards.
- Do not keep it longer than necessary.
- Provide access and correction when requested by the individual.
IPP 3A, in force since 1 May 2026, adds a notification obligation where personal information is collected indirectly — from a data broker, a marketing list, a related company or any third-party source. Businesses that buy prospect lists or enrich customer records now have a notification obligation they did not have before.
Retention is where most businesses are exposed
The default behaviour is to keep everything forever, because storage is cheap and deleting feels risky.
That is a liability. Data you hold unnecessarily is data that can be breached, that you must produce on an access request, and that you must secure.
Set retention periods by category, balancing legal requirements — seven years for tax records, six years for employment records, longer for building work — against the principle of not keeping personal information longer than needed. Then actually delete.
Unsuccessful job applicants are the clearest example. Most businesses hold applications from a decade ago for no purpose whatsoever.
Access control
Give people the access their role requires and no more. Remove access the day someone leaves — email, cloud services, shared drives, payment systems and any shared password they knew.
The inventory makes offboarding possible. Businesses without one routinely leave former employees with access for years.
Breach notification
Where a privacy breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable.
The failure mode is rarely the decision — it is that nobody recognised an incident as a privacy breach. A lost laptop, an email to the wrong distribution list, a misconfigured cloud folder and a departing employee copying a customer list are all candidates, and none look like a cyber attack to the person who notices first.
Write the decision path down beforehand, because the obligation runs while everyone is busy.
Third parties and offshore
Using a cloud provider is a disclosure of personal information, and you remain accountable for it. Where information goes offshore, obligations apply around ensuring comparable protections.
For each significant provider, establish: where data is stored, who at the provider can access it, whether your data is used to train their models, retention and deletion, and their breach notification commitments.
This is a contract question as much as a technical one, and the terms differ substantially between consumer and business tiers.
AI tools
Staff are using them. Entering customer personal information into a general-purpose AI tool is a disclosure, and you are accountable for it.
A short practical policy — which tools are approved, what may never be entered, that output is reviewed — works better than a prohibition that will be ignored and removes your visibility.
Using the data you hold
Beyond compliance, most businesses hold information they never use. Customer purchase history, product performance, enquiry sources and service failures are all available and rarely analysed.
The businesses that get value from data generally start with one question they want answered rather than with a platform.
The Office of the Privacy Commissioner publishes guidance, a breach notification tool and privacy statement templates free at privacy.org.nz, and the National Cyber Security Centre publishes security guidance.
General information only, not legal advice.








