Skip to content
TB
TeamBenchResources

NZ Privacy Act 2020: Content Compliance Guide

New Zealand's Privacy Act 2020 creates specific obligations for content that handles personal information. Learn how to review content for privacy compliance.

TeamBench· Content Quality PlatformFebruary 19, 20267 min read

The Privacy Act 2020 replaced New Zealand's Privacy Act 1993, introducing stronger protections for personal information and new enforcement powers for the Office of the Privacy Commissioner (OPC). The Act applies to every "agency" that collects, holds, uses, or discloses personal information, which includes businesses, government departments, not-for-profits, and individuals acting in a professional capacity. There is no small business exemption in New Zealand.

For content teams, the Privacy Act 2020 creates direct obligations about how personal information is collected through content (forms, surveys, sign-ups), how privacy practices are communicated (privacy statements and notices), how personal information appears in published content (case studies, testimonials, reports), and how direct marketing is conducted.

The Information Privacy Principles

The Privacy Act 2020 is structured around 13 Information Privacy Principles (IPPs) that govern the full lifecycle of personal information:

IPPTitleContent Relevance
IPP 1Purpose of collectionCollection notices must state why information is being collected
IPP 2Source of informationContent forms should collect directly from the individual where practicable
IPP 3Collection of informationCollection notices must explain what is collected and the consequences of not providing it
IPP 4Manner of collectionCollection must not be unfair, intrusive, or involve misleading content
IPP 5Storage and securityContent systems must protect personal information
IPP 6Access to personal informationIndividuals can request access to content containing their personal information
IPP 7Correction of personal informationIndividuals can request correction of inaccurate content
IPP 8AccuracyContent containing personal information must be accurate before use
IPP 9RetentionPersonal information in content should not be kept longer than necessary
IPP 10Limits on usePersonal information collected for one purpose must not be used in content for a different purpose
IPP 11Limits on disclosureContent must not disclose personal information beyond authorised purposes
IPP 12Disclosure of information outside NZCross-border content publishing must meet specific requirements
IPP 13Unique identifiersContent should not assign unique identifiers unless necessary

Key Changes from the 1993 Act

The Privacy Act 2020 introduced several significant changes that affect content practices:

Mandatory Breach Notification

Agencies must notify the Privacy Commissioner and affected individuals of privacy breaches that pose a risk of serious harm. This includes breaches involving content, such as:

  • Accidental publication of personal information in reports, newsletters, or website content
  • Data breaches in content management systems
  • Unauthorised access to content containing personal information
  • Misdirected emails or documents containing personal information

Cross-Border Disclosure (IPP 12)

The updated cross-border disclosure principle is particularly relevant for organisations that publish content internationally or use overseas content platforms. Personal information can only be disclosed to a foreign person or entity if:

  • The individual authorises the disclosure
  • The foreign recipient is subject to comparable privacy protections
  • The agency believes on reasonable grounds that the foreign recipient will protect the information consistently with the IPPs

This affects organisations using international content management systems, cloud hosting, email marketing platforms, and social media platforms.

Compliance Notices

The Privacy Commissioner gained the power to issue compliance notices directing agencies to take specific action to comply with the Act. This enforcement tool means content-related privacy failures can result in formal regulatory action, not just recommendations.

Increased Penalties

Offences under the Act can result in fines up to $10,000 for individuals. While these penalties may seem modest compared to other jurisdictions, the reputational impact of a Privacy Commissioner finding is often more significant than the financial penalty.

Content-Specific Privacy Obligations

Privacy Statements and Notices

Every point of personal information collection requires a privacy notice. For content teams, this means:

  • Website contact forms, newsletter sign-ups, and registration pages
  • Survey and feedback forms
  • Event registration pages
  • Customer account creation flows
  • Mobile app onboarding screens
  • Competition and promotion entries

Each notice must explain what information is being collected, why it is being collected (IPP 1), whether it is mandatory or voluntary, the consequences of not providing it (IPP 3), who the information may be shared with, and how to access and correct the information.

Published Content Containing Personal Information

When personal information appears in published content, teams must ensure:

  • Consent is current and specific: Consent given for one purpose does not extend to other purposes
  • De-identification is adequate: If full identification is unnecessary, use de-identified or aggregated data
  • Accuracy is verified: Personal information must be checked for accuracy before publication (IPP 8)
  • Retention is justified: Published content containing personal information should be reviewed and removed when no longer needed (IPP 9)

Direct Marketing

Direct marketing using personal information must comply with IPP 10 (limits on use) and IPP 11 (limits on disclosure). Key requirements:

  • Marketing must be within the purpose for which the information was collected, or the individual must have consented
  • Every marketing communication must include an opt-out mechanism
  • Opt-out requests must be actioned promptly
  • The Unsolicited Electronic Messages Act 2007 imposes additional requirements for electronic marketing

Building a Privacy Content Review Process

Pre-Publication Checklist

Before publishing any content that contains or collects personal information:

  • Purpose of any personal information collection is stated clearly
  • Privacy notice is present at each collection point
  • Consent has been obtained for any personal information included in content
  • Personal information is accurate and current
  • Content does not disclose personal information beyond consented purposes
  • Cross-border disclosure requirements are met if content is published internationally
  • De-identification has been applied where full identification is unnecessary

Periodic Review

  • Review privacy statements quarterly for accuracy and completeness
  • Audit published content for personal information that is no longer necessary
  • Check that opt-out mechanisms in marketing content are functioning
  • Verify that content management systems meet IPP 5 security requirements
  • Review cross-border data flows through content platforms against IPP 12

How Content Review Tools Support Privacy Compliance

Organisations produce large volumes of content that either contains personal information or collects it. Privacy compliance across this content requires systematic review that scales with content volume.

Content review platforms can check collection notices against IPP requirements, flag personal information appearing in published content without documented consent, assess privacy statements for completeness and plain language, identify cross-border disclosure issues in content workflows, and verify that marketing content includes required opt-out mechanisms. By configuring review criteria based on the Privacy Act 2020 and uploading OPC guidance into a knowledge base, teams can systematically review content for privacy compliance.

This provides a consistent first-pass review that catches common privacy issues before publication. It does not replace qualified privacy advice for complex information handling questions, but it helps content teams maintain baseline compliance across their published materials.


This article provides general information about the NZ Privacy Act 2020 and content compliance. It is not legal or privacy advice. Always consult the Office of the Privacy Commissioner for current guidance and seek qualified privacy advice for your specific situation.

privacy-act-2020opcpersonal-informationdata-privacycompliancenew-zealand

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required