The Privacy Act 2020 is still the governing privacy statute in New Zealand, but the obligations sitting underneath it have shifted twice in the past year. A new information privacy principle came into force on 1 May 2026, and organisations already using biometric systems face a compliance deadline of 3 August 2026. If neither of those dates is familiar, this is worth ten minutes.
IPP 3A: telling people when you did not collect from them
The Privacy Amendment Act 2025 inserted a new principle, IPP 3A, which came into force on 1 May 2026. It addresses a gap in the original scheme.
Principle 3 has always required agencies to tell people about collection when information is gathered directly from them. IPP 3A extends a notification obligation to information collected indirectly — from a data broker, a marketing list, a credit reporting agency, a related company, or any other third-party source.
In practice, if your business buys prospect lists, enriches customer records from external providers, or receives personal information from partners, you now need to notify the individuals concerned about matters including what you hold, where it came from and what you intend to do with it. There are exceptions, but they are narrower than most businesses assume, and the default position is that notification is required.
The Biometric Processing Privacy Code and the 3 August deadline
The Office of the Privacy Commissioner issued the Biometric Processing Privacy Code on 21 July 2025. It came into force on 3 November 2025 for new biometric collection, and organisations already processing biometric information were given until 3 August 2026 to bring existing activities into line.
The Code does not amend the Act. It modifies how the information privacy principles apply where an organisation collects biometric information for processing by an automated system. That framing matters, because it is broader than most people expect.
Biometric processing in this sense covers facial recognition, fingerprint and iris systems, voiceprint identification, and automated matching of physical characteristics. It reaches ordinary commercial situations: retailers running facial recognition for loss prevention, employers using fingerprint time clocks, buildings with biometric access control, and call centres using voice authentication.
The Code’s central requirement is a proportionality assessment. Before deploying biometric processing, an organisation must be satisfied the benefit is proportionate to the privacy intrusion, and must have genuinely considered whether a less intrusive alternative would achieve the same result. It also imposes specific notification and transparency obligations, and restricts certain uses outright.
What to check before 3 August
- Whether any system you operate performs automated biometric matching, including systems procured as a feature of something else — access control, rostering, security cameras with analytics.
- Whether a documented proportionality assessment exists, and whether it considered alternatives.
- Whether the signage and notice you give people actually describes biometric processing, or just says the area is under surveillance.
- Where the biometric data is stored, who can access it, how long it is kept, and what triggers deletion.
- What your vendor contract says about the vendor’s own use of the data.
Breach notification has not changed, and still catches people out
The notifiable privacy breach regime introduced with the Act remains in force. Where a breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware of it.
The failure mode is rarely the decision itself. It is that nobody in the organisation recognised an incident as a privacy breach quickly enough to make the decision at all. A lost laptop, an email sent to the wrong distribution list, a misconfigured cloud storage bucket and a departing employee copying a customer database are all candidates, and none of them look like a cyber incident to the person who notices first.
The practical position
For most businesses the required work is modest but not zero: update your privacy statement to cover indirect collection, run an honest inventory of anything doing biometric matching, and make sure the people who would first notice an incident know what to do with it.
The Office of the Privacy Commissioner publishes its guidance openly at privacy.org.nz, and it is written for a general audience rather than for lawyers. It is the right first stop before paying anyone for an opinion.
This article explains the current rules in general terms and is not legal advice. Requirements depend on your specific circumstances.








