Privacy compliance is frequently presented to small businesses as a documentation exercise. The Act does not require that. It requires you to handle personal information sensibly, and for most small businesses that fits on a page.
Know what you hold
List every system holding information about people — customers, employees, suppliers, applicants. In a typical small business:
- Accounting software and payroll.
- Customer database or CRM.
- Email, which is usually the largest and least controlled repository.
- Cloud file storage.
- Website and any e-commerce platform.
- Marketing platform.
- Point of sale.
- CCTV.
- Spreadsheets on individual machines, which nobody counts.
For each: what is held, why, who can access it, where it is stored, how long it is kept.
Most businesses doing this for the first time find data they did not know they had, accessible to people who no longer work there.
The principles, in practice
- Collect only what you need for a purpose connected to your activities.
- Tell people what you are collecting and why. A short privacy statement on your website and on forms covers most of it.
- Use it for that purpose, or one directly related.
- Keep it secure with reasonable safeguards.
- Do not keep it longer than necessary.
- Provide access and correction when someone asks — within 20 working days.
Security that actually matters
The controls that prevent most incidents are unglamorous:
- Multi-factor authentication, email first. Email resets every other password you own.
- Remove access the day someone leaves.
- Limit who can see what — health information and payroll should not be in a general folder.
- Automatic updates on everything.
- Tested backups.
- Delete what you no longer need, particularly unsuccessful job applications, which most businesses keep forever for no reason.
Know what to do if it gets out
Where a breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and affected individuals as soon as practicable.
The failure mode is not the decision — it is that nobody recognises an incident as a privacy breach fast enough to make it. Candidates that do not look like cyber attacks:
- An email to the wrong distribution list.
- A lost laptop or phone.
- A misconfigured cloud folder.
- A departing employee copying the customer list.
- Ransomware — assume data was taken as well as encrypted, because most now is.
Write down the decision path beforehand, and keep it somewhere not dependent on the systems that may be unavailable.
The Office received approximately 1,093 breach notifications and 1,598 complaints in the year to 30 June 2025, so this is a live regime rather than a theoretical one.
Two changes worth knowing
IPP 3A, in force since 1 May 2026, requires notification where you collect personal information indirectly — from a bought list, a data provider, a partner or a related company. If you buy prospect data, this applies to you.
The Biometric Processing Privacy Code transition period ended 3 August 2026. If you use fingerprint time clocks, facial recognition or any automated biometric matching, the Code now applies fully and requires a documented proportionality assessment.
Third parties
Using a cloud provider is a disclosure and you remain accountable. Where data goes offshore, obligations apply around ensuring comparable protections.
For each significant provider: where is data stored, who can access it, is your data used to train their models, and what are their breach notification commitments. The terms differ substantially between consumer and business tiers.
The same applies to AI tools, which staff are using whether or not there is a policy. A short position on which tools are approved and what may never be entered works better than a prohibition that will be ignored.
Where to look
The Office of the Privacy Commissioner publishes free privacy statement templates, guidance and an online breach notification tool at privacy.org.nz, written for a general audience. Its material is licensed for reuse with attribution.
Figures: Office of the Privacy Commissioner Annual Report, year ending 30 June 2025. General information only, not legal advice.








