🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
NZ v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-03

New Zealand

NZ schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 39 claims · 35 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
39Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

New Zealand's data-protection compliance perimeter tightened on two fronts this cycle. Information privacy principle 3A, introduced by the Privacy Amendment Act 2025, came into force on 1 May 2026, requiring agencies that collect personal information indirectly to take reasonable steps to notify the individual of specified matters; the new obligation applies only to information collected from that date forward. Separately, the Biometrics Processing Privacy Code, which came into force in November 2025 and governs purpose, sourcing, collection, storage, accessibility, retention, disclosure and use limitations for biometric information, saw its grace period for historical biometric processing expire on 3 August 2026, meaning agencies processing biometric information collected before the Code took effect are now expected to be in compliance rather than operating under transitional tolerance.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.

Primary frameworkPrivacy Act 2020 (NZ)
Traffic-light rationale — GreenComprehensive, currently-in-force omnibus statute with an active single regulator and confirmed EU adequacy; amber-tilt reserved for scope/registration sub-modules given absence of certain GDPR-analogous mechanics.

Sub-modules (5)

Regulator And AuthorityGreen

The OPC, led by Privacy Commissioner Michael Webster, is the statutory data protection authority referred to as 'the Commissioner' under the Act.

Claims (1):

  • The Privacy Act established the Office of the Privacy Commissioner of New Zealand (OPC), which acts as the data protection authority and is referred to as 'the Commissioner' within the Privacy Act and the Privacy Act 2020.

Act And InstrumentsGreen

Primary instruments are the Privacy Act 2020, Privacy Regulations 2020, and the Privacy Amendment Act 2025; the OPC also issues binding codes of practice with the force of law.

Claims (2):

  • On 1 December 2020, the OPC announced the entry into effect of the Privacy Act 2020, which repeals and replaces the 27-year-old Privacy Act 1993.
  • New Zealand's Privacy Amendment Act 2025 was signed into law and officially enacted after receiving Royal Assent on 23 September 2025, introducing new Information Privacy Principle 3A requiring notification when personal information is collected indirectly.

Material ScopeAmber

The Act protects 'personal information' held by public and private sector 'agencies'; unlike the GDPR it does not define special categories of data or clearly delineate types of processing caught.

Claims (1):

  • Unlike the GDPR, neither the Privacy Act 1993 nor the Privacy Act 2020 provide for special categories of data or clearly define what types of data processing fall under their scope.

Territorial ScopeGreen

The 2020 Act expanded territorial scope to overseas businesses/organisations 'carrying on business' in New Zealand even absent physical presence.

Claims (1):

  • The Privacy Act 2020 has expanded extraterritorial scope, encompassing overseas businesses or organisations that 'carry on business' in New Zealand even if they do not have a physical presence in the country.

Regulator Registration And FilingAmber

No general registration or filing regime for controllers/agencies was identified; the Act relies on principles-based compliance rather than registration.

Absence provenance: unavailable. Searched: New Zealand Privacy Act controller registration requirement, OPC registration filing obligation.

Category narrative88 words

New Zealand's data-protection regime is anchored in the Privacy Act 2020, which repealed and replaced the Privacy Act 1993 and entered into force 1 December 2020, overseen by the Office of the Privacy Commissioner (OPC). The regime is principles-based (13 Information Privacy Principles), has extraterritorial reach for overseas agencies 'carrying on business' in NZ, and was amended in 2025 (Privacy Amendment Act 2025, Royal Assent 23 September 2025) to add IPP3A on indirect-collection notification. There is no general controller registration/filing obligation, consistent with the Act's light-touch, principles-based design.

Periodic update · new data 2026-09-21

Regulator & Framework

IPP3A, a new information privacy principle introduced by the Privacy Amendment Act 2025, came into force on 1 May 2026. It requires agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from third-party sources, subject to a set of listed exceptions. This closes a notice gap in New Zealand's Privacy Act framework that most comparable regimes, including the EU's Article 14 GDPR notice obligation and Australia's APP 5, had already addressed, and it is confirmed with high confidence based on the Office of the Privacy Commissioner's own statement on the amendment's passage.

The new obligation does not apply retroactively: it does not reach personal information collected before 1 May 2026. This transition-scope limitation is itself confirmed, drawn from the legislation's own published text, and it means the practical operational effect of IPP3A on agencies' existing data holdings will build progressively rather than applying to the full stock of previously collected personal information immediately upon commencement.

The introduction of IPP3A is New Zealand's most significant framework-level privacy development in this cycle, extending the country's indirect-collection notice standard in a way that had been a recognised gap relative to peer jurisdictions.

Outlook

The practical operation of IPP3A, including how agencies interpret the listed exceptions to the notice obligation, has not yet been tested through any enforcement action or Office of the Privacy Commissioner guidance identified this cycle. Whether the Office issues interpretive guidance or takes any enforcement action specifically citing IPP3A in the coming cycle is the key framework-level watch item.

Sources and claims (5)
  1. ConfirmedDataGuidance — The Privacy Act established the Office of the Privacy Commissioner of New Zealand (OPC), which acts as the data protection authority and is referred to as 'the Commissioner' within the Privacy Act and the Privacy Act 2020.observed
  2. ConfirmedDataGuidance — On 1 December 2020, the OPC announced the entry into effect of the Privacy Act 2020, which repeals and replaces the 27-year-old Privacy Act 1993.observed
  3. ProbableIAPP — New Zealand's Privacy Amendment Act 2025 was signed into law and officially enacted after receiving Royal Assent on 23 September 2025, introducing new Information Privacy Principle 3A requiring notification when personal information is collected indirectly.observed
  4. ConfirmedDataGuidance — Unlike the GDPR, neither the Privacy Act 1993 nor the Privacy Act 2020 provide for special categories of data or clearly define what types of data processing fall under their scope.observed
  5. ConfirmedDataGuidance — The Privacy Act 2020 has expanded extraterritorial scope, encompassing overseas businesses or organisations that 'carry on business' in New Zealand even if they do not have a physical presence in the country.observed

#

Core structural gaps versus GDPR analogues (no enumerated lawful bases, no statutory special categories, no anonymisation safe-harbour) justify amber despite functioning principle-based alternative.

Primary frameworkPrivacy Act 2020 (NZ) - Information Privacy Principles
Traffic-light rationale — AmberCore structural gaps versus GDPR analogues (no enumerated lawful bases, no statutory special categories, no anonymisation safe-harbour) justify amber despite functioning principle-based alternative.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art 6-style lawful bases; IPP1 requires collection for a lawful purpose connected to the agency's functions and that collection be necessary for that purpose.

Claims (1):

  • Personal information must not be collected unless the collection is for a lawful purpose connected with the functions or activities of the agency and is necessary for that purpose (IPP 1).

Special CategoriesAmber

Neither Act defines special/sensitive categories of data; the OPC has issued non-binding guidance addressing sensitive personal information, and sector codes (health, biometric) provide de facto heightened protection for particular data types.

Claims (1):

  • Neither the Privacy Act 2020 nor the Privacy Act 1993 define special categories of data, unlike the GDPR's treatment of sensitive data such as racial/ethnic origin, health, or biometric data for unique identification.

Pseudonymisation And AnonymisationRed

No statutory definition or safe-harbour for pseudonymisation/anonymisation was located.

Absence provenance: unavailable. Searched: New Zealand Privacy Act pseudonymisation anonymisation definition.

Category narrative74 words

New Zealand's regime does not use a GDPR-style enumerated 'lawful basis' menu or treat consent as a central organising principle. Collection is instead governed by necessity/purpose principles (IPP1-IPP4). The Act does not define statutory special/sensitive categories of data, though the OPC has issued non-binding guidance on 'sensitive personal information' and sector-specific codes (Health Information Privacy Code, Biometric Processing Privacy Code) impose heightened rules for particular data classes. Pseudonymisation/anonymisation are not defined in the Act.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedDataGuidance — Personal information must not be collected unless the collection is for a lawful purpose connected with the functions or activities of the agency and is necessary for that purpose (IPP 1).observed
  2. ConfirmedDataGuidance — Neither the Privacy Act nor the Privacy Act 2020 establish consent as a main principle like the GDPR, nor do they address matters such as rights to erasure, object, data portability, sensitive data, or DPIAs in the same manner.observed
  3. ConfirmedDataGuidance — Neither the Privacy Act 2020 nor the Privacy Act 1993 define special categories of data, unlike the GDPR's treatment of sensitive data such as racial/ethnic origin, health, or biometric data for unique identification.observed

#

Access/correction/response-window mechanics are robust and enforceable, but erasure, restriction/objection, and portability rights are largely absent, warranting amber overall.

Primary frameworkPrivacy Act 2020 (NZ) - IPP 6, IPP 7
Traffic-light rationale — AmberAccess/correction/response-window mechanics are robust and enforceable, but erasure, restriction/objection, and portability rights are largely absent, warranting amber overall.

Sub-modules (5)

Access RightGreen

IPP6 grants individuals a right to confirm and access personal information held about them; OPC can issue binding access determinations where an agency refuses release.

Claims (1):

  • Under the Act, if an agency refuses to make personal information available upon request, the OPC has the power to demand the release of this information through a binding access determination.

Rectification And ErasureAmber

IPP7 provides a correction right; there is no general statutory right to erasure/deletion, and OPC's children's privacy consultation records calls for a 'right to be forgotten' for children not yet enacted.

Claims (1):

  • The Privacy Act does not currently provide any specific right to delete personal information, and many submitters to the OPC's children's privacy consultation argued in favor of a 'right to be forgotten' for children.

Restriction And ObjectionRed

No GDPR Art 18/21-style formal restriction or objection right was located; use/disclosure limits (IPP10/IPP11) provide indirect, narrower protection.

Absence provenance: unavailable. Searched: New Zealand Privacy Act right to object right to restrict processing.

Data PortabilityRed

No data portability right equivalent to GDPR Art 20 was identified.

Absence provenance: unavailable. Searched: New Zealand Privacy Act data portability right.

Deadlines And Response WindowsGreen

Access requests must generally be responded to within 20 working days under s41, with extensions permissible where reasonable; the Human Rights Review Tribunal has reviewed the reasonableness of such extensions.

Claims (1):

  • The Human Rights Review Tribunal considered whether an agency's extension of the 20-working-day timeframe for responding to an information request under s41 of the Act had been made reasonably.
Category narrative63 words

Individuals have an access right (IPP6) and correction right (IPP7), with a statutory 20-working-day response window (extendable on reasonable grounds) enforceable via OPC binding access determinations/enforceable access directions. The Act does not provide a standalone right to erasure ('right to be forgotten'), restriction, objection, or portability comparable to GDPR Arts 16-21, a gap the OPC's own children's-privacy consultation has flagged for possible reform.

Sources and claims (3)
  1. ConfirmedDataGuidance — Under the Act, if an agency refuses to make personal information available upon request, the OPC has the power to demand the release of this information through a binding access determination.observed
  2. ProbableIAPP — The Privacy Act does not currently provide any specific right to delete personal information, and many submitters to the OPC's children's privacy consultation argued in favor of a 'right to be forgotten' for children.observed
  3. ConfirmedDataGuidance — The Human Rights Review Tribunal considered whether an agency's extension of the 20-working-day timeframe for responding to an information request under s41 of the Act had been made reasonably.observed

#

Breach notification and security-of-processing duties are in force and actively enforced, but DPIA, ROPA, and processor-liability gaps (flagged by the regulator itself following the 2025/2026 MMH breach) justify amber rather than green.

Primary frameworkPrivacy Act 2020 (NZ), Part 6; Privacy Regulations 2020
Traffic-light rationale — AmberBreach notification and security-of-processing duties are in force and actively enforced, but DPIA, ROPA, and processor-liability gaps (flagged by the regulator itself following the 2025/2026 MMH breach) justify amber rather than green.

Sub-modules (7)

Accountability And DpiaAmber

Neither the Privacy Act 1993 nor the Privacy Act 2020 mandate data protection/privacy impact assessments; the OPC has only recommended such assessments in non-binding guidance.

Claims (1):

  • Neither the Privacy Act nor the Privacy Act 2020 provide for data protection or privacy impact assessments; the OPC has recommended such assessments only in non-binding guidance.

Dpo RequirementsGreen

Agencies must appoint one or more privacy officers, who may be located within or outside the agency (including contracted-out arrangements), unlike the 1993 Act's internal-only requirement.

Claims (1):

  • The Privacy Act 2020 allows agencies to appoint privacy officers from outside the agency, unlike the 1993 law which required appointment 'from within that agency'.

Ropa RequirementsRed

No explicit records-of-processing-activities obligation equivalent to GDPR Art 30 was identified.

Absence provenance: unavailable. Searched: New Zealand Privacy Act records of processing obligation.

Joint Controller ArrangementsAmber

Agencies remain responsible for protecting personal information handled by third-party service providers on their behalf (s11), but the OPC's MMH inquiry found the Act imposes no direct security obligation on the processor itself and recommended reform.

Claims (1):

  • The OPC's Phase 1 inquiry into the Manage My Health breach recommended amending the Privacy Act 2020 to make third-party service providers directly liable for failing to implement reasonable security safeguards, noting the Act currently imposes no equivalent direct processor obligations found in overseas jurisdictions.

Security MeasuresAmber

IPP5 requires agencies to take reasonable steps to protect personal information against loss or unauthorised access, use, modification or disclosure; the OPC's MMH inquiry found both MMH and Health NZ breached Rule 5 of the Health Information Privacy Code for failing to maintain reasonable security safeguards.

Claims (1):

  • The OPC found that both Manage My Health and Health New Zealand breached Rule 5 of the Health Information Privacy Code by failing to maintain reasonable security safeguards.

Breach NotificationGreen

Part 6 of the Act requires notification to the OPC and affected individuals of 'notifiable privacy breaches' causing or likely to cause serious harm, with detailed procedures in s12 of the Privacy Regulations 2020; failure to notify is an offence.

Claims (2):

  • Part 6 of the Privacy Act 2020 establishes a legal obligation to notify the OPC of 'notifiable privacy breaches,' as well as affected individuals or the public under certain circumstances, with further procedures set out in Section 12 of the Privacy Regulations 2020.
  • Agencies must notify the OPC and any affected individuals if there is a breach that has caused, or poses a risk of causing, serious harm, as soon as practicable after becoming aware of a notifiable breach, subject to limited exceptions (e.g. endangering safety or revealing a trade secret).

Retention And DisposalGreen

IPP9 prohibits agencies from keeping personal information longer than required for the purposes for which it may lawfully be used.

Claims (1):

  • Principle 9 provides that an agency holding personal information shall not keep it for longer than is required for the purposes for which the information may lawfully be used.
Category narrative111 words

Agencies must appoint one or more privacy officers (internal or external) and maintain reasonable security safeguards (IPP5) and retention limits (IPP9). Part 6 of the Act creates a mandatory notifiable-privacy-breach regime (OPC + affected individuals, for breaches causing or likely to cause serious harm), detailed further in the Privacy Regulations 2020. There is no mandatory DPIA requirement (only non-binding OPC guidance recommending PIAs), no explicit ROPA obligation, and no direct statutory security obligation on processors/third-party service providers equivalent to GDPR Art 28 — a gap highlighted by the OPC's own Manage My Health (MMH) breach inquiry, which recommended amending the Act to make third-party service providers directly liable for security failures.

Periodic update · new data 2026-09-28

Controller/Processor Duties

A notable breach-notification event surfaced this cycle. The Office of the Privacy Commissioner reported that Manage My Health notified it of a privacy breach, and the OPC advised that primary-care providers did not need to separately notify in connection with that breach. This event is an operation of the Privacy Act 2020's mandatory breach-notification regime, which introduced mandatory breach notification in New Zealand for the first time; prior to the 2020 Act, New Zealand agencies had no statutory duty to notify a regulator of a data breach.

The OPC's guidance that primary-care providers did not need to separately notify indicates a degree of consolidation in how notification duties are being administered where a shared health-sector platform is the entity experiencing the breach, rather than each downstream provider being treated as independently obligated to notify for the same underlying incident. This is a controller/processor-duties-relevant clarification for organisations operating shared platforms serving multiple downstream entities, since it suggests notification responsibility can attach at the platform level rather than being duplicated across every organisation using that platform.

No other controller or processor duty development, such as new data-retention rules or processor-contract requirements, was identified this cycle beyond this breach-notification event.

Outlook

The Manage My Health notification is a live illustration of the Privacy Act 2020's mandatory breach-notification regime in the health sector specifically, and how the Office of the Privacy Commissioner continues to administer notification responsibility across shared platforms and their downstream users will be the relevant thing to watch for controllers and processors operating similar multi-provider arrangements.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedDataGuidance — Neither the Privacy Act nor the Privacy Act 2020 provide for data protection or privacy impact assessments; the OPC has recommended such assessments only in non-binding guidance.observed
  2. ConfirmedIAPP — The Privacy Act 2020 allows agencies to appoint privacy officers from outside the agency, unlike the 1993 law which required appointment 'from within that agency'.observed
  3. ProbableIAPP — The OPC's Phase 1 inquiry into the Manage My Health breach recommended amending the Privacy Act 2020 to make third-party service providers directly liable for failing to implement reasonable security safeguards, noting the Act currently imposes no equivalent direct processor obligations found in overseas jurisdictions.observed
  4. ConfirmedDataGuidance — The OPC found that both Manage My Health and Health New Zealand breached Rule 5 of the Health Information Privacy Code by failing to maintain reasonable security safeguards.observed
  5. ConfirmedDataGuidance — Part 6 of the Privacy Act 2020 establishes a legal obligation to notify the OPC of 'notifiable privacy breaches,' as well as affected individuals or the public under certain circumstances, with further procedures set out in Section 12 of the Privacy Regulations 2020.observed
  6. ConfirmedDataGuidance — Agencies must notify the OPC and any affected individuals if there is a breach that has caused, or poses a risk of causing, serious harm, as soon as practicable after becoming aware of a notifiable breach, subject to limited exceptions (e.g. endangering safety or revealing a trade secret).observed
  7. ConfirmedIAPP — Principle 9 provides that an agency holding personal information shall not keep it for longer than is required for the purposes for which the information may lawfully be used.observed

#

Confirmed, currently-maintained EU adequacy plus an operative IPP12 transfer mechanism support green, tempered by gaps in TIA/localisation coverage.

Primary frameworkPrivacy Act 2020 (NZ) - IPP 12; EU Adequacy Decision 2013/65/EU
Traffic-light rationale — GreenConfirmed, currently-maintained EU adequacy plus an operative IPP12 transfer mechanism support green, tempered by gaps in TIA/localisation coverage.

Sub-modules (6)

Transfer MechanismsGreen

IPP12 permits overseas disclosure where the agency believes on reasonable grounds the recipient is subject to privacy laws that, overall, provide comparable safeguards, among other prescribed mechanisms.

Claims (1):

  • The New Privacy Act outlines that an agency will be permitted to disclose personal information overseas if it believes on reasonable grounds that the recipient or entity is subject to privacy laws that, overall, provide comparable safeguards.

Adequacy ReceivedGreen

New Zealand is not itself an adequacy 'recipient' jurisdiction in the EU sense (it is the adequacy grantee/recipient of an EU finding); this sub-module is not applicable in the way it would be for an EU member state and is scoped instead to NZ's status as an EU adequacy partner (see adequacy_granted).

Absence provenance: unavailable. Searched: New Zealand adequacy decisions received from other regimes.

Adequacy GrantedGreen

The European Commission determined New Zealand ensures an adequate level of data protection under Directive 95/46/EC (Commission Decision, December 2012), and its January 2024 review confirmed data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards.

Claims (2):

  • The European Commission determined that New Zealand ensures an adequate level of protection for personal data transferred from the EU, per the adequacy decision adopted in 2012.
  • The European Commission's January 2024 review confirmed that personal data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards, following legislative reforms including the Privacy Act 2020.

Sccs And BcrsGreen

The OPC has published model contract clauses to assist agencies in meeting IPP12 obligations for overseas disclosure, functioning as an SCC-equivalent mechanism.

Claims (1):

  • The Office of the Privacy Commissioner New Zealand has published model clauses that assist entities in meeting their overseas-disclosure obligations under IPP12.

Transfer Impact AssessmentAmber

No formal Schrems II-style transfer impact assessment requirement was identified as part of IPP12 compliance.

Absence provenance: unavailable. Searched: New Zealand Privacy Act transfer impact assessment IPP12.

Data LocalisationGreen

No general data-localisation mandate was identified for New Zealand under the Privacy Act.

Absence provenance: unavailable. Searched: New Zealand data localisation requirement Privacy Act government cloud.

Category narrative73 words

IPP12 (introduced by the 2020 Act) governs overseas disclosure of personal information, permitting transfer where the receiving agency is subject to comparable safeguards, via individual authorisation, prescribed binding schemes, or OPC-published model contract clauses. New Zealand itself holds EU adequacy status, originally granted under Directive 95/46/EC in December 2012 and reaffirmed as continuing in the European Commission's January 2024 review of 11 adequacy decisions. No data-localisation mandate or formal transfer-impact-assessment requirement was identified.

Periodic update · new data 2026-09-21

Cross-Border & Adequacy

IPP3A was introduced primarily to help New Zealand retain its EU adequacy status, aligning New Zealand's indirect-collection notice obligations with the EU's Article 14 GDPR standard and Australia's APP 5. This adequacy-preservation motivation is confirmed with high confidence, and it is a significant framing point: it demonstrates that New Zealand's ongoing privacy reform agenda continues to be shaped substantially by the practical need to maintain the cross-border data-flow arrangements that its EU adequacy status supports.

Notably, this adequacy-motivated reform proceeded despite the Office of the Privacy Commissioner continuing to operate without GDPR-equivalent direct administrative fining powers, a materially more limited enforcement toolkit than EU-model data protection authorities possess. This juxtaposition, a substantive notice obligation newly aligned with EU standards, paired with an enforcement toolkit that remains structurally narrower than the EU model, is itself worth noting as a persistent feature of New Zealand's approach to maintaining adequacy: substantive alignment without full enforcement-power parity.

Outlook

Whether the European Commission or other EU institutions formally comment on or reference IPP3A in any adequacy-review context is the key cross-border watch item for the coming cycle. No such formal EU-side response was identified this cycle, and New Zealand's adequacy status itself was not reported as under active review.

Sources and claims (4)
  1. ConfirmedDataGuidance — The New Privacy Act outlines that an agency will be permitted to disclose personal information overseas if it believes on reasonable grounds that the recipient or entity is subject to privacy laws that, overall, provide comparable safeguards.observed
  2. ConfirmedEUR-Lex — The European Commission determined that New Zealand ensures an adequate level of protection for personal data transferred from the EU, per the adequacy decision adopted in 2012.observed
  3. ConfirmedEUR-Lex — The European Commission's January 2024 review confirmed that personal data transferred from the EU to New Zealand continues to benefit from adequate data protection safeguards, following legislative reforms including the Privacy Act 2020.observed
  4. ProbableDataGuidance — The Office of the Privacy Commissioner New Zealand has published model clauses that assist entities in meeting their overseas-disclosure obligations under IPP12.observed

#

Strong evidence for the health-sector code; other sectoral overlays (credit, telecoms, education, insurance, financial) are asserted by general NZ privacy-law knowledge but not independently confirmed this run, requiring escalation.

Primary frameworkPrivacy Act 2020 (NZ) - Codes of Practice regime
Traffic-light rationale — AmberStrong evidence for the health-sector code; other sectoral overlays (credit, telecoms, education, insurance, financial) are asserted by general NZ privacy-law knowledge but not independently confirmed this run, requiring escalation.

Sub-modules (7)

Financial Sector OverlayAmber

No financial-sector-specific privacy code was confirmed in this research pass; general Privacy Act obligations apply to financial agencies alongside AML/CFT obligations administered by other regulators.

Absence provenance: unavailable. Searched: New Zealand financial sector privacy code overlay.

Health Sector OverlayAmber

The Health Information Privacy Code governs health agencies' handling of health information; its Rule 5 security requirement was found breached in the OPC's Manage My Health inquiry.

Claims (1):

  • The OPC's inquiry into the Manage My Health breach was conducted under Section 17(1)(i) of the Privacy Act and focused on whether MMH and Health New Zealand had adequate security safeguards as required by Rule 5 of the Health Information Privacy Code.

Telecoms And EprivacyAmber

A Telecommunications Information Privacy Code is understood to exist under the OPC's code-making power but was not independently verified this pass.

Absence provenance: unavailable. Searched: New Zealand Telecommunications Information Privacy Code.

Employment DataAmber

Employment-related personal information (e.g., security camera footage, references) is governed by the general IPPs rather than a dedicated employment code; agencies are advised to reflect collection purposes in employment agreements.

Claims (1):

  • If agencies are collecting personal information about their employees, employment agreements and policies should make clear what personal information may be collected and used, and employee agreement to that collection should be obtained.

Credit And ScoringAmber

A Credit Reporting Privacy Code is understood to exist but was not independently verified in this research pass.

Absence provenance: unavailable. Searched: New Zealand Credit Reporting Privacy Code details.

EducationRed

No education-sector-specific privacy overlay was identified in this research pass.

Absence provenance: unavailable. Searched: New Zealand education sector privacy code.

InsuranceRed

No insurance-sector-specific privacy overlay was identified in this research pass.

Absence provenance: unavailable. Searched: New Zealand insurance sector privacy rules.

Category narrative92 words

Sector-specific overlays operate via OPC-issued binding codes of practice that adapt the IPPs to particular data classes or industries. The Health Information Privacy Code (HIPC) governs health-sector personal information (its Rule 5 security requirement was central to the 2025/2026 Manage My Health breach findings). A Credit Reporting Privacy Code and Telecommunications Information Privacy Code are understood to exist but were not independently verified in this research pass. Employment data is subject to the general IPPs without a dedicated employment code identified. Education and insurance sector-specific overlays were not identified in this pass.

Periodic update · new data 2026-09-21

Sectoral Watch

The notable sectoral development this cycle is health-sector specific: the Office of the Privacy Commissioner's finding that Manage My Health and Health NZ breached the Privacy Act through inadequate security safeguards following a cyber incident. This finding, reported at Probable confidence given reliance on a single lower-tier source, places the health sector at the centre of this cycle's controller/processor-duty enforcement attention, distinct from the framework-level IPP3A and biometric-code developments affecting agencies generally across sectors.

The recommended response, compliance notices and centralised verification measures for health-sector vendors, if adopted, would represent a sector-specific structural intervention rather than a general Privacy Act amendment, targeting the health-vendor ecosystem specifically in response to the identified security-safeguards gap.

Outlook

Whether the centralised verification measures proposed for health-sector vendors are formally adopted, and how broadly they would apply across New Zealand's health-technology vendor ecosystem, is the key sectoral watch item for the coming cycle.

Sources and claims (2)
  1. ConfirmedDataGuidance — The OPC's inquiry into the Manage My Health breach was conducted under Section 17(1)(i) of the Privacy Act and focused on whether MMH and Health New Zealand had adequate security safeguards as required by Rule 5 of the Health Information Privacy Code.observed
  2. ProbableDataGuidance — If agencies are collecting personal information about their employees, employment agreements and policies should make clear what personal information may be collected and used, and employee agreement to that collection should be obtained.observed

#

No adtech-specific commercial-privacy regime was substantiated in this pass; this is an explicit, evidenced gap rather than silent omission.

Traffic-light rationale — Not assessedNo adtech-specific commercial-privacy regime was substantiated in this pass; this is an explicit, evidenced gap rather than silent omission.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie-consent statute was identified; general IPPs would apply to any personal information collected via trackers.

Absence provenance: unavailable. Searched: New Zealand cookie consent law ePrivacy equivalent.

Dark PatternsRed

No NZ-specific dark-pattern prohibition was identified.

Absence provenance: unavailable. Searched: New Zealand dark patterns privacy law prohibition.

Opt Out SignalsRed

No recognised technical opt-out signal (e.g., Global Privacy Control) regime was identified for New Zealand.

Absence provenance: unavailable. Searched: New Zealand Global Privacy Control opt-out signal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room specific rules were identified.

Absence provenance: unavailable. Searched: New Zealand clean room data collaboration privacy rules.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' concept or cross-context advertising rule was identified.

Absence provenance: unavailable. Searched: New Zealand cross-context advertising sale share rules.

Direct MarketingAmber

No dedicated direct-marketing consent/suppression regime was independently verified in this research pass beyond general IPP use/disclosure limits.

Absence provenance: unavailable. Searched: New Zealand direct marketing consent suppression rules Privacy Act.

Category narrative56 words

No NZ-specific cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal (e.g. GPC), clean-room framework, or CPRA-style 'sale/share' concept was identified; the general Privacy Act IPPs apply to any online collection of personal information but do not create adtech-specific rules. A dedicated direct-marketing/anti-spam statute may exist in New Zealand but was not verified in this research pass.

#

A dedicated, binding Biometric Processing Privacy Code is a significant, verified development, but ADM transparency, profiling restrictions, and genetic-data regimes remain unaddressed gaps acknowledged by the regulator itself.

Primary frameworkBiometric Processing Privacy Code 2025; Privacy Act 2020 IPPs (applied to AI via OPC guidance)
Traffic-light rationale — AmberA dedicated, binding Biometric Processing Privacy Code is a significant, verified development, but ADM transparency, profiling restrictions, and genetic-data regimes remain unaddressed gaps acknowledged by the regulator itself.

Sub-modules (6)

Profiling RestrictionsRed

No Art 22 GDPR-analogue profiling restriction was identified; general IPPs apply to any profiling activity involving personal information.

Absence provenance: unavailable. Searched: New Zealand Privacy Act profiling restriction Article 22 analogue.

Automated Decision Making TransparencyAmber

Commissioner Webster has stated he believes clearer rules around automated decision-making would enable a better regulatory response to AI risks, indicating this remains an identified gap rather than a codified right.

Claims (1):

  • Privacy Commissioner Michael Webster believes a financial penalty regime, more accountability obligations, and clearer rules around automated decision-making would enable a better regulatory response to the risks created by AI.

Ai Risk AssessmentsAmber

The OPC's AI guidance expects organisations to conduct privacy impact assessments, obtain senior leadership approval based on full consideration of risks and mitigation, and ensure human review before acting on AI outputs, though this is guidance rather than a binding statutory AI risk-assessment obligation.

Claims (1):

  • The OPC's AI guidance expects organisations to conduct a preliminary assessment of necessity and proportionality, obtain senior leadership approval of AI tool use based on full consideration of risks and mitigation, conduct PIAs, be transparent about AI use, and ensure human review before acting on AI outputs.

Biometric RegimeGreen

The Biometric Processing Privacy Code, issued 6 August 2025, adapts the 13 IPPs specifically to biometric processing, covering the full information lifecycle and introducing necessity and proportionality assessments; it excludes biometric processing of health information (covered by the Health Information Privacy Code) and consumer devices such as fitness trackers.

Claims (2):

  • The OPC issued the Biometric Processing Privacy Code on 6 August 2025, regulating how organizations in New Zealand use biometric technologies to collect and process biometric information.
  • The Biometric Processing Privacy Code excludes biometric processing of health information by health agencies, which are already subject to the Health Information Privacy Code, and does not apply to consumer devices such as fitness trackers or smartwatches.

Genetic DataRed

No dedicated genetic-data regime was identified for New Zealand.

Absence provenance: unavailable. Searched: New Zealand genetic data privacy regime.

State Surveillance CarveoutsAmber

New Zealand Police commissioned an independent expert review of facial recognition technology (FRT) use, providing advice on opportunities and risks; broader statutory state-surveillance carve-out detail was not fully verified this pass.

Claims (1):

  • The New Zealand Police released findings from an independent expert review of Facial Recognition Technology, providing detailed advice on the opportunities and risks associated with its use.
Category narrative117 words

New Zealand has no standalone AI statute; the OPC has instead issued guidance (June and October 2023) applying the 13 IPPs to AI systems, recommending PIAs, senior-leadership approval, transparency, human review, and consideration of Te Ao Māori perspectives. Commissioner Michael Webster has publicly called for clearer automated-decision-making rules and a financial penalty regime to better govern AI risk. Biometric processing is now regulated via the OPC's binding Biometric Processing Privacy Code (issued 6 August 2025), which imposes necessity/proportionality assessments and notice obligations across the biometric information lifecycle, while excluding consumer devices and health-agency biometric processing (covered by the Health Information Privacy Code). No Art 22 GDPR-style profiling restriction, genetic-data regime, or codified state-surveillance carve-out framework was substantiated.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

New Zealand's biometric-governance framework moved from a transitional to a settled compliance posture this cycle. The Biometrics Processing Privacy Code, which came into force in November 2025, governs purpose, sourcing, collection, storage, accessibility, retention, disclosure and use limitations for biometric information, providing New Zealand with a dedicated regulatory instrument for biometric processing specifically, distinct from the general provisions of the Privacy Act 2020.

The Code included a grace period allowing agencies with historical biometric-processing arrangements, meaning arrangements already in place before the Code's November 2025 commencement, time to bring those arrangements into line with the Code's requirements. That grace period expired on 3 August 2026. From that date forward, historical biometric processing is subject to the same compliance expectations as biometric processing that began after the Code took effect, closing what had been a transitional tolerance window.

No algorithmic-governance or automated-decision-making-specific development, as distinct from the biometric-processing Code, was identified this cycle; the material signal in this module this cycle is concentrated entirely in the biometric-processing grace-period expiry.

Outlook

With the grace period now expired, the Office of the Privacy Commissioner's practical enforcement posture toward agencies with legacy biometric-processing arrangements that have not yet achieved Code compliance is the key development to watch. Whether the Commissioner pursues active compliance-checking of historical arrangements, or relies on complaint-driven enforcement, will determine how quickly the Code's requirements are realised in practice across affected sectors.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedIAPP — Privacy Commissioner Michael Webster believes a financial penalty regime, more accountability obligations, and clearer rules around automated decision-making would enable a better regulatory response to the risks created by AI.observed
  2. ConfirmedIAPP — The OPC's AI guidance expects organisations to conduct a preliminary assessment of necessity and proportionality, obtain senior leadership approval of AI tool use based on full consideration of risks and mitigation, conduct PIAs, be transparent about AI use, and ensure human review before acting on AI outputs.observed
  3. ConfirmedIAPP — The OPC issued the Biometric Processing Privacy Code on 6 August 2025, regulating how organizations in New Zealand use biometric technologies to collect and process biometric information.observed
  4. ConfirmedIAPP — The Biometric Processing Privacy Code excludes biometric processing of health information by health agencies, which are already subject to the Health Information Privacy Code, and does not apply to consumer devices such as fitness trackers or smartwatches.observed
  5. ProbableDataGuidance — The New Zealand Police released findings from an independent expert review of Facial Recognition Technology, providing detailed advice on the opportunities and risks associated with its use.observed

#

Absence of parental consent mechanisms, profiling bans, and dependent-adult protections, combined with the regulator's own acknowledgement that reform is still under consideration, supports a red rating for this module.

Primary frameworkPrivacy Act 2020 (NZ) - s49(1)(c)
Traffic-light rationale — RedAbsence of parental consent mechanisms, profiling bans, and dependent-adult protections, combined with the regulator's own acknowledgement that reform is still under consideration, supports a red rating for this module.

Sub-modules (5)

Age VerificationRed

No formal age-verification regime was identified; age 16 functions only as a threshold for a narrow information-withholding ground, not a general consent-age mechanism.

Claims (1):

  • Section 49(1)(c) of the Privacy Act permits an organization to withhold personal information if the requester is under age 16 and providing the information would be contrary to their interests; the Privacy Amendment Act 2025 extends this to allow refusal if releasing the information would be contrary to the interests of another person under age 16.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: unavailable. Searched: New Zealand minor profiling ban privacy.

Education SettingsRed

No education-settings-specific children's data rule was identified in this research pass.

Absence provenance: unavailable. Searched: New Zealand education settings children's data privacy rule.

Dependent AdultsRed

No dependent-adults-specific privacy protection regime was identified in this research pass.

Absence provenance: unavailable. Searched: New Zealand dependent adults privacy protection elderly incapacitated.

Category narrative103 words

New Zealand's Privacy Act does not contain a GDPR Art 8/COPPA-style parental-consent regime or a general age-of-consent threshold for data processing. Age 16 is used only as a narrower ground allowing an agency to withhold information from (or about) a requester under that age where release would be contrary to their interests, a ground extended by the Privacy Amendment Act 2025. The OPC's children's privacy consultation has surfaced options — a 'best interests of the child' obligation and a child-specific right to be forgotten — that are under discussion but not yet enacted. No minor-profiling ban, education-settings-specific rule, or dependent-adults regime was substantiated.

Sources and claims (1)
  1. ConfirmedIAPP — Section 49(1)(c) of the Privacy Act permits an organization to withhold personal information if the requester is under age 16 and providing the information would be contrary to their interests; the Privacy Amendment Act 2025 extends this to allow refusal if releasing the information would be contrary to the interests of another person under age 16.observed

#

Active, escalating enforcement and a functioning (if narrow) redress pathway exist, but the acknowledged absence of a civil-penalties regime for principal IPP breaches is a material, regulator-acknowledged weakness.

Primary frameworkPrivacy Act 2020 (NZ) - Parts 5-8
Traffic-light rationale — AmberActive, escalating enforcement and a functioning (if narrow) redress pathway exist, but the acknowledged absence of a civil-penalties regime for principal IPP breaches is a material, regulator-acknowledged weakness.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

OPC powers include compliance notices and enforceable access directions; criminal offence fines are capped at NZD10,000 and there is no general civil penalty for IPP breaches; HRRT damages awards (e.g., NZD50,000 in the ACC case) provide the main financial remedy.

Claims (3):

  • Under the current framework, financial penalties of up to NZD10,000 are available only in relation to a small number of offences, including a failure to notify the privacy commissioner of a serious privacy breach, with no financial penalties at all for breaching the information privacy principles themselves.
  • The Human Rights Review Tribunal can award damages of up to NZD350,000 to an aggrieved individual, though this requires referral from the privacy commissioner or a decision by the commissioner not to investigate further, and damages are not punitive, requiring proof of harm.
  • The Human Rights Review Tribunal awarded NZD50,000 in damages against the Accident Compensation Corporation for breaching information privacy principles 5 and 6 of the Privacy Act 1993 by destroying a file before the purpose for which it was collected had been fulfilled.

Enforcement Activity IndexAmber

The OPC's 2024-25 Annual Report noted a 43% increase in serious privacy breaches notified to the regulator, and the OPC issued a compliance notice to the Reserve Bank of New Zealand in 2021 following a cyber-attack.

Claims (2):

  • The OPC's 2024-25 Annual Report noted a 43% increase in the number of serious privacy breaches notified to the regulator.
  • The OPC issued a compliance notice to the Reserve Bank of New Zealand, triggered by a cyber-attack in December 2020.

Regulator Funding And CapacityAmber

No specific data on OPC funding levels or headcount was identified in this research pass.

Absence provenance: unavailable. Searched: Office of the Privacy Commissioner New Zealand funding budget headcount.

Collective Redress And Class ActionsAmber

2020 amendments to the Privacy Bill clarified the potential for class actions, and HRRT damages could accumulate substantially in a class-action context, though the process remains lengthy and requires OPC referral.

Claims (1):

  • Amendments to the Privacy Bill on 3 June 2020 clarified matters such as liabilities and the potential for class action alongside enforcement powers and cross-border transfer mechanisms.

Private Right Of ActionAmber

Individuals can file a claim in the HRRT within six months of an OPC Section 98 notice, or following a Commissioner decision not to investigate further, rather than through unrestricted direct court access.

Claims (1):

  • Individuals have six months to file a claim in the Human Rights Review Tribunal starting from when an OPC investigator issues a Section 98 notice.

Recent Developments 180DAmber

Within the last 180 days, the OPC's Phase 1 Manage My Health inquiry recommended legislative amendment for third-party service-provider liability; New Zealand published its Cyber Security Strategy 2026-2030 (27 February 2026) and associated Action Plan 2026-2027; and public/political pressure (including a parliamentary petition) for a civil-penalties regime has intensified.

Claims (2):

  • The OPC's May 2025/2026 Phase 1 inquiry report into the Manage My Health breach recommended compliance notices, a centralized supplier-verification program, and Privacy Act amendments to establish third-party service-provider liability.
  • Following the Manage My Health breach, New Zealand's Prime Minister publicly underscored the need to strengthen cybersecurity laws, and this was followed on 27 February by publication of NZ's Cyber Security Strategy 2026-2030 and associated Cyber Security Action Plan 2026-2027.
Category narrative182 words

The OPC can issue compliance notices and binding/enforceable access directions, and can investigate complaints, but criminal offences under the Act (e.g., failure to notify a serious breach, misleading an agency, destroying requested information) carry a maximum fine of only NZD10,000, and there is no general civil-penalties regime for breaches of the information privacy principles themselves. The Human Rights Review Tribunal (HRRT) can award damages (e.g., NZD50,000 against ACC in 2020; reported ceiling around NZD350,000), but access requires OPC referral or a decision not to investigate, and claims must be filed within six months of a Section 98 notice. Enforcement activity has intensified: the OPC's 2024-25 Annual Report recorded a 43% rise in notified serious breaches, and its 2025/2026 Phase 1 inquiry into the Manage My Health breach recommended compliance notices, a centralised health-sector supplier verification programme, and legislative amendments for third-party liability. The Commissioner and commentators are actively campaigning for a financial penalties regime, referencing Australia's AUD50 million maximum penalty as a comparator; NZ's Cyber Security Strategy 2026-2030 (published 27 February 2026) is cited as a first concrete sign of possible reform.

Periodic update · new data 2026-09-28

Enforcement & Redress

A structural limitation in New Zealand's enforcement toolkit remains material this cycle: the Office of the Privacy Commissioner does not have GDPR-equivalent direct administrative fining powers, despite New Zealand holding an EU adequacy decision. This gap between New Zealand's adequacy status, which is typically associated with GDPR-comparable protections, and its enforcement toolkit, which lacks the direct fining mechanism that underpins GDPR enforcement in the EU, is a standing feature of the regime rather than a new development, but it carries particular salience this cycle given the adequacy-retention rationale attached to the IPP 3A amendment discussed elsewhere in this brief.

Where the OPC's own toolkit does have teeth, it operates through investigative and enforcement powers including the issuing of compliance notices, rather than through direct monetary penalties. Separately, individuals are not left solely dependent on OPC action: they may bring privacy claims before the Human Rights Review Tribunal, which can award damages. This private right of action functions as an independent redress channel that operates regardless of whether the OPC itself pursues an enforcement notice against the same conduct.

The Manage My Health breach notification, discussed under Controller/Processor Duties, is the notable enforcement-adjacent event this cycle, illustrating the mandatory breach-notification regime in active operation, though it did not itself generate a public enforcement action or Tribunal claim within the evidence reviewed this cycle.

Outlook

Whether New Zealand's enforcement architecture evolves toward direct administrative fining powers, closer to the GDPR model, or continues to rely on compliance notices and Tribunal-based private redress, remains an open structural question, and one made more salient by the jurisdiction's adequacy status. The Human Rights Review Tribunal's caseload and damages awards are the practical indicator to watch for how meaningful the private right of action proves in redressing individual harm.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Enforcement & Redress

The Office of the Privacy Commissioner continues to operate without GDPR-equivalent direct administrative fining powers, a materially more limited enforcement toolkit than EU-model data protection authorities. Reports suggest this structural limitation persists despite New Zealand's EU adequacy status and despite this cycle's IPP3A reform substantively aligning notice obligations with EU standards; this is a standing caution flag rather than a new development, carried forward at Probable-consistent, hedged confidence given reliance on a lower-tier source.

Against this backdrop, the Office's finding against Manage My Health and Health NZ, recommending compliance notices and centralised verification measures following a cyber incident, represents active use of the Commissioner's available (non-fining) enforcement tools. Separately, the New Zealand Government's announcement of a new Cyber Security Strategy 2026-2030 and accompanying Action Plan 2026-2027 signals a renewed cross-government push to strengthen resilience to digital threats; this is reported at Probable confidence and represents a forward-looking policy signal rather than a confirmed enforcement-posture change within this monitor's specific remit this cycle.

Outlook

Whether the Office of the Privacy Commissioner has taken any enforcement action specifically citing IPP3A since its 1 May 2026 commencement remains unestablished; no case notes were retrieved this cycle. How the new Cyber Security Strategy interacts with the Commissioner's own enforcement priorities, particularly regarding health-sector security failures of the kind identified against Manage My Health and Health NZ, is the key watch item for the coming cycle.

Sources and claims (9)
  1. ConfirmedIAPP — Under the current framework, financial penalties of up to NZD10,000 are available only in relation to a small number of offences, including a failure to notify the privacy commissioner of a serious privacy breach, with no financial penalties at all for breaching the information privacy principles themselves.observed
  2. ProbableIAPP — The Human Rights Review Tribunal can award damages of up to NZD350,000 to an aggrieved individual, though this requires referral from the privacy commissioner or a decision by the commissioner not to investigate further, and damages are not punitive, requiring proof of harm.observed
  3. ConfirmedDataGuidance — The Human Rights Review Tribunal awarded NZD50,000 in damages against the Accident Compensation Corporation for breaching information privacy principles 5 and 6 of the Privacy Act 1993 by destroying a file before the purpose for which it was collected had been fulfilled.observed
  4. ConfirmedIAPP — The OPC's 2024-25 Annual Report noted a 43% increase in the number of serious privacy breaches notified to the regulator.observed
  5. ConfirmedDataGuidance — The OPC issued a compliance notice to the Reserve Bank of New Zealand, triggered by a cyber-attack in December 2020.observed
  6. ConfirmedDataGuidance — Amendments to the Privacy Bill on 3 June 2020 clarified matters such as liabilities and the potential for class action alongside enforcement powers and cross-border transfer mechanisms.observed
  7. ConfirmedDataGuidance — Individuals have six months to file a claim in the Human Rights Review Tribunal starting from when an OPC investigator issues a Section 98 notice.observed
  8. ProbableDataGuidance — The OPC's May 2025/2026 Phase 1 inquiry report into the Manage My Health breach recommended compliance notices, a centralized supplier-verification program, and Privacy Act amendments to establish third-party service-provider liability.observed
  9. ProbableIAPP — Following the Manage My Health breach, New Zealand's Prime Minister publicly underscored the need to strengthen cybersecurity laws, and this was followed on 27 February by publication of NZ's Cyber Security Strategy 2026-2030 and associated Cyber Security Action Plan 2026-2027.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct13.04
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for New Zealand
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 39 claim(s) (39 category placement(s)), 35 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacydata localisation
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. Strong T1/T3-corroborated coverage (multiple independent sources) for regulator_and_framework, controller_processor_duties (breach notification, security), cross_border_and_adequacy (EU adequacy status confirmed via T1 EU Commission/EDPB documents), and algorithmic_biometric_and_surveillance_governance (biometric code, AI guidance). Moderate coverage (T3 only, single-to-few sources) for lawful_processing_and_special_data, data_subject_rights, enforcement_and_redress, and sectoral_watch (health sub-module only strongly evidenced). Weak/absent coverage requiring explicit gap-narratives for adtech_and_commercial_privacy (no NZ-specific adtech regime substantiated) and children_and_vulnerable_groups (no parental-consent/profiling-ban mechanisms substantiated) — both carry red traffic lights with absent_field_provenance rather than fabricated obligations. No direct access to official legislation.govt.nz text or privacy.org.nz primary code documents was performed this run; all claims rest on secondary analyst/regulatory-commentary sources (IAPP, DataGuidance) plus official EU Commission/EDPB T1 documents for the adequacy finding.

Unresolved questions (6):

  • Exact commencement/in-force date of IPP3A under the Privacy Amendment Act 2025.
  • Independent verification of the Credit Reporting Privacy Code and Telecommunications Information Privacy Code content directly from OPC primary sources.
  • Confirmation of any financial-sector-specific privacy overlay beyond general AML/CFT Act administration by other regulators.
  • Precise, primary-source-verified maximum HRRT damages ceiling (NZD350,000 figure sourced from a single secondary commentary).
  • Whether New Zealand has designated any 'prescribed countries' under IPP12's binding-scheme mechanism.
  • Confirmation of any dedicated anti-spam/direct-marketing statute (e.g., an Unsolicited Electronic Messages-type Act) and its current status.

Escalate to primary-source review: yes