The Privacy Act 2020
What the Act does
- The Privacy Act 2020 governs how businesses and other organisations collect, use, store, share and dispose of personal information.
- Personal information is information about an identifiable individual — a name, an address, a phone number, a customer record, a photograph or drone image that shows who someone is, a loyalty-card purchase history.
- It applies to every business, of any size, and it is regulated by the Office of the Privacy Commissioner (OPC).
The information privacy principles a business must follow
The Act sets out information privacy principles. The ones that most often decide a business question are:
- Collect only what you need, for a lawful purpose connected to your functions.
- Collect it directly from the person, wherever that is possible.
- Tell people what you are collecting, why, who will hold it, and their right to see and correct it.
- Notify indirect collection. Since 1 May 2026, principle IPP3A requires a business that collects someone's personal information from a source other than that person to take reasonable steps to make them aware of it, as soon as reasonably practicable.
- Collect it fairly — not by deception, and not unreasonably intrusively.
- Keep it secure, with reasonable safeguards against loss, misuse and unauthorised access.
- Let people access and correct their own information.
- Do not keep it longer than you need it for the purpose you collected it for.
- Use and disclose it only for the purpose it was collected for, unless an exception applies.
- Take care before sending it overseas — comparable protections must apply where the information is going.
Privacy breaches
- A privacy breach is unauthorised access to, or disclosure or loss of, personal information.
- If a breach has caused, or is likely to cause, serious harm, the business must notify the Privacy Commissioner and the affected people as soon as practicable. Failing to notify is itself an offence.
- Individuals can complain to the OPC, and complaints can go to the Human Rights Review Tribunal, which can award damages.
Why this matters commercially
- Businesses now collect far more personal information than they used to — loyalty schemes, apps, online orders, CCTV, drones, vehicle tracking, website analytics — often without deciding to.
- Every new technology that gathers data brings the business further under this Act, which is why a technology question in the exam is frequently a privacy question underneath.
- The real cost of a breach is trust: customers who believe their information is mishandled stop providing it, and stop buying.
How businesses respond
- Write a privacy policy setting out what is collected and why, and publish it.
- Write procedures implementing it: who may access the data, how long it is kept, how it is deleted, who responds to an access request.
- Collect less. Information the business does not hold cannot be breached — the cheapest control available.
- Delete promptly once the purpose is complete, and be able to show that deletion happened.
- Secure the data — access controls, encryption, staff training. Most breaches are human error, not attacks.
- Train staff, because the person who emails a spreadsheet to the wrong address is what a breach usually looks like.
- Have a breach response plan, so the notification decision is made against a prepared standard rather than in a panic.