What is NZPA?

The Privacy Act 2020 provides the rules in New Zealand for protecting personal information and puts responsibilities on agencies and organizations about how they must do that. For example, people have a right to know what information your agency holds about them and a right to ask you to correct it if they think it is wrong. It replaced the previous Privacy Act 1993 and introduced several significant changes to strengthen privacy protections for individuals.

Where does the NZPA apply?

It is relevant to any entity, whether public or private, that collects, stores, uses, or shares personal data within New Zealand. Additionally, the Act has extraterritorial reach, meaning it also applies to organizations based outside New Zealand if they are conducting business within the country or processing personal information about individuals located in New Zealand.

What are some possible reasons for NZPA penalties?

Sharing or allowing access to personal information without proper consent or a lawful basis is against NZPA. Other actions can lead to a penalty as well such as not taking reasonable steps to secure personal information from unauthorized access, loss, or misuse. Collecting personal information without informing individuals about why it is being collected, how it will be used, or who it will be shared with (breach of Principle 3 of the Act).

Who is liable for NZPA penalties?

The Act applies to all "agencies" handling personal information, including: businesses, government agencies, non-profits. However, individuals (e.g., employees or directors) can also face consequences for intentional or reckless breaches.

What are the NZPA penalties for
non-compliance?

Compliance Notices: Issued by the Privacy Commissioner to enforce corrective actions.
Fines: Up to NZD 10,000 (5,600+ USD) for failing to comply with a compliance notice or other principle of the Act.
Civil Litigation: Affected individuals can bring claims to the Human Rights Review Tribunal for damages, including emotional harm.

Get the APA checklist for Free

Improve the effectiveness of your compliance strategy now.

Download checklist
graphic of a white notepad page against a black background

Frequently Asked Questions

What is consent under NZPA?

Under New Zealand's Privacy Act 2020 (NZPA), consent refers to the freely given, informed, and specific agreement of an individual to the collection, use, or disclosure of their personal information. While the Act does not explicitly define "consent" in a legal sense, it emphasizes the need for transparency and fairness when handling personal data.

Consent is particularly important under NZPA in the following situations:
- When using personal information for secondary purposes beyond the original intent.
- When sharing personal information with third parties.
- For sensitive information.

What is the difference between GDPR and NZPA?

The General Data Protection Regulation (GDPR) and New Zealand’s Privacy Act 2020 (NZPA) share a focus on personal data protection but differ significantly in scope, enforcement, and requirements. GDPR applies across the EU and to organizations worldwide that process data of EU residents, while NZPA applies primarily to entities in New Zealand, with limited extraterritorial scope. GDPR mandates stricter rules for consent, requiring it to be explicit, informed, and unambiguous, whereas NZPA allows for implied consent in some cases.

How to make my Shopify store compliant with the NZPA?

To assure NZPA compliance for your business, start by implementing clear data protection policies and procedures. One of the easiest ways to simplify compliance is by using a Consent Management Platform (CMP) like Consentmo, which is designed specifically for Shopify stores. Our app helps you manage cookie consent, data requests, and user rights, verifying your store meets APA requirements without hassle.

I need more info on NZPA.

Make sure to check out our detailed blog post covering all important notes.

Is your site compliant?