Indirect Collection and IPP 3A: The Obligation on Bought Data

Share Article

In force since 1 May 2026, IPP 3A requires notification where personal information is collected from someone other than the individual.

The Privacy Amendment Act 2025 inserted a new information privacy principle — IPP 3A — into the Privacy Act 2020, in force since 1 May 2026.

It addresses a genuine gap, and it catches a common commercial practice.

The gap it closes

Principle 3 has always required agencies to tell people about collection when information is gathered directly from them — what is being collected, why, who will receive it, and their access and correction rights.

Nothing equivalent applied where information was collected indirectly. A business could buy a list, enrich its records from a third-party source, or receive data from a related company, and the individual would never know.

IPP 3A extends a notification obligation to that situation.

What triggers it

Collecting personal information about someone from a source other than that person. In commercial practice:

  • Purchasing marketing or prospect lists.
  • Enriching customer records from external data providers.
  • Receiving customer information from a partner, reseller or related company.
  • Obtaining information from a credit reporting agency.
  • Scraping publicly available sources to build a contact database.

Where it applies, you must take reasonable steps to notify the individual about matters including what you hold, where it came from, and what you intend to do with it.

Exceptions exist, and they are narrower than most businesses assume. The default position is that notification is required.

Bought lists now carry two problems

Purchasing a mailing list was already problematic under the Unsolicited Electronic Messages Act, which requires consent for commercial electronic messages. Consent given to someone else for their purposes is not consent given to you, and a vendor’s assurance that everyone opted in is not a defence you can rely on.

IPP 3A adds a privacy obligation on top. So a bought list creates:

  • A likely consent problem for sending anything, and
  • A notification obligation for holding the data at all.

The practical conclusion most businesses will reach is that building your own list is the only durable approach. It is slower and it works.

What to do about existing practice

  1. Identify indirect collection. Where does personal information in your systems come from? Most businesses have never mapped this and find sources they had forgotten.
  2. Update your privacy statement to cover indirect collection — categories of information, sources, and purposes.
  3. Build notification into the process. Where you routinely receive data from a partner, notification should happen as a matter of course rather than as an exception.
  4. Review supplier and partner agreements to establish who notifies, and on what basis they hold the information.
  5. Reconsider bought data against the combined obligations.

Where marketing and privacy meet

Electronic marketing requires consent, clear sender identification, and a functional unsubscribe honoured promptly. Consent can be express, inferred from an existing business relationship, or deemed where someone has conspicuously published a work address without a contrary statement and the message is relevant to their role.

That last category is narrower than it sounds — relevance to the person’s actual work role is required, so scraping addresses and sending unrelated marketing does not qualify.

The Act also prohibits using address-harvesting software or a harvested-address list for unsolicited commercial messages.

Records are the practical protection

For each contact, be able to show how the information was obtained, when, what the person was told, and their unsubscribe history. Most reputable email platforms record this automatically; businesses running lists out of spreadsheets generally cannot produce it.

The regulator is active

The Office of the Privacy Commissioner received approximately 1,598 complaints and 1,093 breach notifications in the year to 30 June 2025, and confirmed intent to issue compliance notices against two organisations in May 2026.

The Office publishes guidance on the information privacy principles, privacy statement templates and a breach notification tool free at privacy.org.nz. The Department of Internal Affairs publishes guidance on electronic messaging law.

Figures: Office of the Privacy Commissioner Annual Report, year ending 30 June 2025. IPP 3A in force 1 May 2026. General information only, not legal advice.

ads-2

Explore Business Topics

Whether you’re running a business, growing your career or simply staying informed, discover expert articles from New Zealand’s most important industries.

Accounting

Tax, bookkeeping, Xero, payroll and financial reporting.

Agriculture

Farming, agribusiness, horticulture, innovation and rural industry news.

Construction

Building, trades, regulations, projects and construction industry updates.

Engineering

Engineering innovation, infrastructure, manufacturing and technical expertise.

Finance

Business finance, investing, lending, insurance and economic insights.

Health

Healthcare, medical services, wellbeing, aged care and industry developments.

Law

Commercial law, employment law, property law and legal guidance.

Logistics

Supply chains, warehousing, fulfilment, freight and logistics solutions.

Property

Commercial property, real estate, investment and market trends.

Retail

Retail trends, eCommerce, customer experience and business growth.

Technology

Artificial intelligence, cybersecurity, software and digital transformation.

Transport

Road, rail, marine, aviation and transport industry developments.