{"id":832,"date":"2021-11-18T10:51:00","date_gmt":"2021-11-18T10:51:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=832"},"modified":"2026-03-12T09:15:33","modified_gmt":"2026-03-12T08:15:33","slug":"new-zealand","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/new-zealand\/","title":{"rendered":"New Zealand\u2019s Privacy Act 2020"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-quick-summary\">Quick summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-new-zealand-s-privacy-act-2020-in-brief\">New Zealand\u2019s Privacy Act 2020, in brief<\/h3>\n\n\n\n<p>New Zealand\u2019s Privacy Act was originally drafted and passed in 1993 and has been in place ever since, making it one of the earliest data privacy laws in the world.<\/p>\n\n\n\n<p>New Zealand is also one of only 12 nations worldwide to have an <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/international-dimension-data-protection\/adequacy-decisions_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">adequacy agreement with the EU<\/a>, ensuring unrestricted, free flow of personal data to and from the two.<\/p>\n\n\n\n<p>In December 2020, <a href=\"https:\/\/www.justice.govt.nz\/justice-sector-policy\/key-initiatives\/privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">a new and amended NZ Privacy Act 2020 took effect<\/a>, strengthening cross-border regulations, data breach requirements and more.<\/p>\n\n\n\n<p>In short, New Zealand\u2019s <strong>Privacy Act 2020<\/strong>&nbsp;governs all handling of personal information through the <strong>13 NZ Privacy Principles<\/strong>; requiring you to <strong>notify and inform<\/strong>&nbsp;users about collection, use and sharing of their personal information and empowering them with the <strong>right to access<\/strong>&nbsp;and <strong>correct<\/strong>&nbsp;their data. It is enforced by the <strong>Privacy Commissioner<\/strong>&nbsp;and <strong>applies to all websites<\/strong>, <strong>companies<\/strong>&nbsp;or <strong>organizations<\/strong>&nbsp;that handle personal information from inside New Zealand \u2013 <strong>regardless of where in the world<\/strong>&nbsp;they themselves are located.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see where in the world you send data to<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4029\/aaron-birch-w_j6znpgru4-unsplash.jpg?width=341&amp;\" alt=\"NZ Privacy Act and its NZ Privacy Principles require your website to inform users.\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">New Zealand\u2019s Privacy Act 2020 requires you to inform users about your website\u2019s use of cookies and its processing of personal information.<\/figcaption><\/figure>\n\n\n\n<p><strong>NZ Privacy Act 2020 quick breakdown \u2013<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;took effect on December 5, 2020. It repeals and replaces the older Privacy Act 1993.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;governs all collection, processing, use and sharing of personal information from individuals located inside the territory of New Zealand.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;defines personal information broadly as information about an identifiable individual.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;applies to any website, company or organization (\u201cagency\u201d in the law) that collects, uses, shares or stores personal information from individuals inside New Zealand. This means that if your website is located outside New Zealand, but you have visitors from inside the country, you\u2019re required to comply with the NZ Privacy Principles.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;works through 13 Privacy Principles that map out the legal framework for handling personal information from inside New Zealand, among others the requirement to inform users about your website\u2019s data collection, its purposes and who you share it with.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;empowers users inside New Zealand with the right to access personal data which has been collected from them, and the right to correct it if inaccurate.<\/li>\n\n\n\n<li>Transfer of personal information outside of New Zealand is governed by adequacy principles in the <strong>NZ Privacy Act 2020<\/strong>. Cross-border data flow is only permitted if data can be protected by comparable privacy standards by the recipient.<\/li>\n\n\n\n<li>Fines for non-compliance with the <strong>NZ Privacy Act<\/strong>&nbsp;and NZ Privacy Principles can reach $10,000.<\/li>\n\n\n\n<li><strong>NZ Privacy Act 2020<\/strong>&nbsp;is enforced by the Office of the Privacy Commissioner.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4030\/adrien-olichon-rui6l-akra-unsplash.jpg?width=348&amp;\" alt=\"Mirror in street reflecting a building - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">The NZ Privacy Principles demand that users be notified before their personal information is being collected.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot consent management platform (CMP) for free<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to see what cookies and trackers are in operation<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookies-trackers-and-the-nz-privacy-act-2020\">Cookies, trackers and the NZ Privacy Act 2020<\/h2>\n\n\n\n<p>Cookies and trackers are the <strong>most common way<\/strong>&nbsp;for websites to process personal information.<\/p>\n\n\n\n<p>Most websites in the world process data that is defined as&nbsp;<em>personal<\/em>, meaning <strong>data that is able to identify a living person<\/strong>, either directly or indirectly through inference.<\/p>\n\n\n\n<p><strong>Personal information<\/strong>&nbsp;under New Zealand\u2019s Privacy Act 2020 is defined very broadly as&nbsp;<em>\u201cinformation about an identifiable individual\u201d<\/em>, and this includes data that is commonly collected and processed by third-party trackers and cookies used by social media platforms (e.g., via a like button on your domain) or marketing services (e.g., advertisement on your website).<\/p>\n\n\n\n<p>Cookies and trackers can be notoriously difficult to detect and control without any assisting technology, especially considering that \u2013<\/p>\n\n\n\n<p><strong>72% of cookies<\/strong>&nbsp;are hidden inside other cookies \u2013 also known as trojan horses.<\/p>\n\n\n\n<p><strong>18% of cookies<\/strong>&nbsp;hide even deeper inside other hidden cookies, sometimes loaded by eight other cookies.<\/p>\n\n\n\n<p><strong>50% of trojan horses<\/strong>&nbsp;will have changed upon repeated visits by users.<\/p>\n\n\n\n<p>Source: <a href=\"https:\/\/arxiv.org\/abs\/2001.10248\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Beyond the Front Page<\/em><\/a>, a 2020 study of more than ten thousand websites and their cookies.<\/p>\n\n\n\n<p>At the end of the day, the legal responsibility under New Zealand\u2019s Privacy Act 2020 and its NZ Privacy Principles rests <strong>with the website owner and operator<\/strong>&nbsp;to be in compliance with the notification and information requirements, including (but not limited to) to <strong>always have an updated privacy policy<\/strong>&nbsp;with all required information.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4033\/tobias-keller-73f4pkoukm0-unsplash.jpg?width=341&amp;\" alt=\"View of a mountain range with a lake - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Non-compliance with New Zealand\u2019s Privacy Act can cost up to $10,000 in fines.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-13-nz-privacy-principles\">The 13 NZ Privacy Principles<\/h3>\n\n\n\n<p>New Zealand\u2019s Privacy Act 2020 revolves around<strong>&nbsp;13 Privacy Principles<\/strong>.<\/p>\n\n\n\n<p>Together, they<strong>&nbsp;form a map of the legal way<\/strong>&nbsp;to collect, process, share, store (and in any other way handle) the personal information of users located inside New Zealand.<\/p>\n\n\n\n<p>The <strong>13 Privacy Principles<\/strong>&nbsp;are (in detail later in this blogpost) \u2013<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Purpose for collection<\/li>\n\n\n\n<li>Source of information<\/li>\n\n\n\n<li>What to tell an individual<\/li>\n\n\n\n<li>Manner of collection<\/li>\n\n\n\n<li>Storage and security<\/li>\n\n\n\n<li>Access<\/li>\n\n\n\n<li>Correction<\/li>\n\n\n\n<li>Accuracy<\/li>\n\n\n\n<li>Retention<\/li>\n\n\n\n<li>Use<\/li>\n\n\n\n<li>Disclosure<\/li>\n\n\n\n<li>Disclosure outside New Zealand<\/li>\n\n\n\n<li>Unique identifiers<\/li>\n<\/ol>\n\n\n\n<p>Website owners and operators should be particularly aware of <strong>NZ Privacy Principle 3<\/strong>.<\/p>\n\n\n\n<p>Why?<\/p>\n\n\n\n<p>Well, websites most often collect and process personal information from their visitors through cookies and trackers embedded on their domain via analytics software, marketing services or social media integrations.<\/p>\n\n\n\n<p><strong>NZ Privacy Principle 3<\/strong>&nbsp;is the part of the law that <strong>requires you to make sure that your website\u2019s users from New Zealand are made aware<\/strong>&nbsp;\u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>that you collect personal information from them<\/li>\n\n\n\n<li>of the purposes for which their personal information is being collected by your website<\/li>\n\n\n\n<li>of whom you share their personal information with, including the name and address of the agency collecting the information and the agency who will store the information.<\/li>\n<\/ul>\n\n\n\n<p><strong><em>Practical example of NZ Privacy Principle 3<\/em><\/strong><\/p>\n\n\n\n<p>If your website uses a third-party service to get statistics about user visits on your domain (like <a href=\"\/en\/google-analytics-gdpr\/\">Google Analytics<\/a>) or use a third-party marketing service (like <a href=\"\/en\/hubspot-and-gdpr\/\">HubSpot<\/a>), <strong>third-party cookies<\/strong>&nbsp;and <strong>trackers<\/strong>&nbsp;will be embedded and in operation on your website.<\/p>\n\n\n\n<p>These cookies and trackers collect and process personal information from users \u2013 such as <strong>IP addresses<\/strong>, <strong>unique IDs<\/strong>, <strong>search<\/strong>&nbsp;and <strong>browser history<\/strong>, among many other kinds of data.<\/p>\n\n\n\n<p>Under the NZ Privacy Act 2020 and the NZ Privacy Principle 3, <strong>you are required to notify users<\/strong>&nbsp;of all cookies and trackers and<strong>&nbsp;inform users<\/strong>&nbsp;about <strong>what kind<\/strong>&nbsp;of personal information they collect, <strong>how you use<\/strong>&nbsp;the data and <strong>who you share<\/strong>&nbsp;the data with, <strong>where<\/strong>&nbsp;it is stored and <strong>for how long<\/strong>.<\/p>\n\n\n\n<p>When using third-party services, like Google Analytics or HubSpot, <strong>you need to inform your users about the third-party cookies and trackers<\/strong>&nbsp;that these services set on your domain; including what kind of data they collect, for what purposes, for how long the data is retained, and where in the world it is sent to and stored.<\/p>\n\n\n\n<p>You are also required to notify and inform users about these things <strong>before<\/strong>&nbsp;any personal information has been collected (with exceptions).<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Learn more about cookies and website tracking<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.privacy.org.nz\/privacy-act-2020\/privacy-principles\/3\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about NZ Privacy Principle 3 from the Privacy Commissioner<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4034\/steven-coffey-_q4v8_iy0ra-unsplash.jpg?width=341&amp;\" alt=\"Man walking through a green space with rocks around him - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Under New Zealand\u2019s Privacy Act 2020, personal information is any kind of data that is able to identify an individual.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-nz-privacy-act-compliance-with-cookiebot-cmp\">NZ Privacy Act Compliance with Cookiebot CMP<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cookiebot-cmp-offers-plug-and-play-control-of-all-cookies-and-trackers\">Cookiebot CMP offers plug-and-play control of all cookies and trackers<\/h3>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is the world\u2019s leading consent management platform, built <strong>around a powerful website scanner<\/strong>&nbsp;that detects all known cookies, trackers and trojan horses embedded and in operation on your domain.<\/p>\n\n\n\n<p>The biggest compliance issue for your website under the New Zealand\u2019s Privacy Act 2020 is to ensure that you have notified and informed your users <strong>in an exhaustive and correct manner<\/strong>, before you collect and process their personal information.<\/p>\n\n\n\n<p>What does this mean in practice?<\/p>\n\n\n\n<p>First of all, it means to make sure that <strong>all cookies<\/strong>, <strong>trackers<\/strong>&nbsp;and <strong>third-party technologies<\/strong>&nbsp;that collect and process personal information on your domain have been detected.<\/p>\n\n\n\n<p>Second of all, it means to notify and inform your users about what kinds of data these cookies and similar tracking technologies collect from them.<\/p>\n\n\n\n<p>Using\u00a0Cookiebot CMP\u00a0takes the hard work out of this.<\/p>\n\n\n\n<p>Scan your entire website with<a href=\"\/\">&nbsp;Cookiebot CMP<\/a>&nbsp;and map out exactly what cookies are in use, see what kind of personal information they collect, for what purpose and which third parties they share this data with \u2013 all requirements under the New Zealand Privacy Act 2020.<\/p>\n\n\n\n<p>Cookiebot CMP\u00a0is fully automated and offers you plug-and-play compliance with not only the NZ Privacy Act 2020, but all major data privacy laws, including\u00a0<a href=\"\/en\/gdpr\/\">EU\u2019s GDPR\/ePR<\/a>,\u00a0<a href=\"\/en\/ccpa\/\">California\u2019s CCPA\/CPRA<\/a>,\u00a0<a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>,\u00a0<a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>\u00a0and more.<\/p>\n\n\n\n<p>Whether your users are from Europe, the US, South America, Africa or New Zealand,\u00a0Cookiebot CMP\u00a0automatically geotargets their location and ensures that they are presented with the correct and fully compliant data privacy requirements \u2013 without you having to do anything.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days\u00a0<\/a>\u2013 or forever if you have a small website.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see what cookies and trackers are in use<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-nz-privacy-act-2020-in-detail\">NZ Privacy Act 2020, in detail<\/h2>\n\n\n\n<p>Let\u2019s look at the New Zealand Privacy Act 2020 and its NZ Privacy Principles in closer detail, including what kind of data \u201cpersonal information\u201d covers, what the 13 NZ Privacy Principles are, and what new amendments have been made to the law in December 2020.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-nz-privacy-act-2020-and-personal-information\">NZ Privacy Act 2020 and personal information<\/h3>\n\n\n\n<p>Personal information in New Zealand is any kind of data that can identify an individual.<\/p>\n\n\n\n<p>This includes the more obvious information, such as \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>name, address<\/li>\n\n\n\n<li>e-mail<\/li>\n\n\n\n<li>telephone number<\/li>\n\n\n\n<li>social security numbers<\/li>\n\n\n\n<li>date of birth<\/li>\n\n\n\n<li>signature<\/li>\n\n\n\n<li>passport numbers<\/li>\n\n\n\n<li>racial or ethnic information<\/li>\n\n\n\n<li>political opinions and religious beliefs<\/li>\n\n\n\n<li>sexual orientation<\/li>\n\n\n\n<li>health, genetic and biometric information<\/li>\n<\/ul>\n\n\n\n<p>But also, the not-so obvious yet very common information, such as \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP-addresses<\/li>\n\n\n\n<li>Unique IDs set by Google-cookies and other third-party services<\/li>\n\n\n\n<li>Search and browser history<\/li>\n\n\n\n<li>Data about device, operating systems, updates etc.<\/li>\n\n\n\n<li>Location data<\/li>\n\n\n\n<li>Purchase and online shopping history<\/li>\n\n\n\n<li>Settings and website preferences<\/li>\n\n\n\n<li>Behavioral data, such as speed of scrolling and hovering of mouse and cursor.<\/li>\n<\/ul>\n\n\n\n<p>Your website might not be collecting or processing much data from the more obvious set, such as passport numbers and sexual orientation of your users, but <strong>it almost certainly collects data from the not-so obvious set<\/strong>, namely <strong>information about your users\u2019 online presence<\/strong>, their devices, history of preference and behavior on the Internet.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4035\/dan-freeman-hikvsvkh7no-unsplash.jpg?width=341&amp;\" alt=\"Auckland waterfront - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">Your website\u2019s cookies likely collect personal information from its visitors \u2013 use Cookiebot CMP to detect and control them.<\/figcaption><\/figure>\n\n\n\n<p><strong>This is personal information<\/strong>&nbsp;\u2013 and most third-party cookies and trackers in the world have it as their mission to collect exactly such kind of data for their operations, be it analytics, advertisement or social media interactions.<\/p>\n\n\n\n<p>If your website is in contact with such data <a href=\"\/en\/website-tracking\/\">through its cookies and trackers<\/a>, <strong>you are required by New Zealand\u2019s Privacy Act 2020 and its NZ Privacy Principles<\/strong>&nbsp;to notify users before collection and inform them of what, why and who you share it with.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see all cookies and trackers<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/website-tracking\/\">Learn more about website cookies and trackers<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a>\u00a0\u2013 or forever if you have a small website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-nz-privacy-principles\">NZ Privacy Principles<\/h3>\n\n\n\n<p>Of the <strong>13 NZ Privacy Principles<\/strong>, let\u2019s look at the most relevant for your website and its use of cookies and personal information collection.<\/p>\n\n\n\n<p>All 13 NZ Privacy Principles are vital for full compliance with the New Zealand Privacy Act 2020, but we\u2019ll focus particularly on the ones that are paramount to websites, who processes personal information via cookies and trackers.<\/p>\n\n\n\n<p>For a full overview of the 13 New Zealand Privacy Principles, <a href=\"https:\/\/www.privacy.org.nz\/privacy-act-2020\/privacy-principles\/\" target=\"_blank\" rel=\"noreferrer noopener\">visit the Office of the Privacy Commissioner<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4036\/stephen-dawson-faqfyuod-ra-unsplash.jpg?width=341&amp;\" alt=\"Man looking out over a lake with mountain in the background - Cookiebot\" width=\"770px\" height=\"578px\"\/><figcaption class=\"wp-element-caption\">New Zealand\u2019s 13 Privacy Principles empower users with the right to know, to access and to correct their data.<\/figcaption><\/figure>\n\n\n\n<p><strong>NZ Privacy Principle 1<\/strong>&nbsp;concerns the <strong>purpose of collection<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is required to <strong>only collect personal information if it is for a lawful purpose<\/strong>, meaning in connection with and necessary for the functions and activities of your website.<\/li>\n\n\n\n<li>In other words, you\u2019re not allowed to collect information from users that is not relevant to your website and its function and content.<\/li>\n\n\n\n<li>This <strong>purpose of collection<\/strong>&nbsp;is also part of the information that you are required to notify users about before collecting data from them.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 2<\/strong>&nbsp;concerns the<strong>&nbsp;sources of personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Personal information should always be collected directly from the individual.<\/li>\n\n\n\n<li>This is often the case anyway online, since your website will collect data from the user themselves, when they land on and move around on your domain.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 3<\/strong>&nbsp;concerns the <strong>information requirement to users<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website <strong>must be open about<\/strong>&nbsp;why you are collecting personal information and <strong>what you will do<\/strong>&nbsp;with it.<\/li>\n\n\n\n<li>Your website is required to notify its users about: <strong>why<\/strong>&nbsp;the data is being collected, <strong>who<\/strong>&nbsp;it will be shared with, <strong>whether<\/strong>&nbsp;collection is compulsory or voluntary, <strong>what<\/strong>&nbsp;can happen if the data is not collected.<\/li>\n\n\n\n<li>Offering a clear overview of such information to your users <strong>via your privacy policy<\/strong>&nbsp;is a good way to ensure that your website meets the notification and information requirements.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 4<\/strong>&nbsp;concerns the <strong>way you collect personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website must only collect personal information in a way that is fair and legal.<\/li>\n\n\n\n<li>Unfair and illegal ways of collecting personal information is to threaten, coerce or mislead users to give out their personal information.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 5<\/strong>&nbsp;concerns the <strong>storage and security<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website must ensure safeguards around personal information collected from individuals, e.g. to ensure secure storage and prevent loss, misuse or disclosure of their data.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 6&nbsp;<\/strong>concerns a user\u2019s right to access their personal information<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users have the right to request <strong>access<\/strong>&nbsp;to the personal information that you have collected about them, e.g. through your website\u2019s cookies and trackers.<\/li>\n\n\n\n<li>You must provide means of requesting access, e.g. a <strong>link<\/strong>&nbsp;or an <strong>e-mail address<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 7&nbsp;<\/strong>concerns a user\u2019s right to correct their personal information<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users have the right to request <strong>corrections<\/strong>&nbsp;to the personal information that you have collected about them, e.g. through your website\u2019s cookies and trackers.<\/li>\n\n\n\n<li>You must provide means of requesting access, e.g. a link or an e-mail address.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 8&nbsp;<\/strong>concerns the <strong>accuracy of personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users have the right to request <strong>corrections<\/strong>&nbsp;to the personal information that you have collected about them, e.g. through your website\u2019s cookies and trackers.<\/li>\n\n\n\n<li>You must provide means of requesting access, e.g. a link or an e-mail address.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 9&nbsp;<\/strong>concerns the <strong>retention<\/strong>&nbsp;(i.e. for how long you store data)<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is not allowed to store and use personal information for longer than necessary to fulfill the purpose intended by the collection of the data in the first place.<\/li>\n\n\n\n<li>As an example, your website is not allowed to keep personal information about a user that was collected only to be used in the session in which they visited your website.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 10&nbsp;<\/strong>concerns the <strong>use of personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is only allowed to use collected personal information for the purpose already given to the individual before collection.<\/li>\n\n\n\n<li>Using personal information for longer or for different purposes requires you to notify and inform the user again.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 11&nbsp;<\/strong>concerns the <strong>disclosure of personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is only allowed to use collected personal information for the purpose already given to the individual before collection.<\/li>\n\n\n\n<li>Using personal information for longer or for different purposes requires you to notify and inform the user again.<\/li>\n<\/ul>\n\n\n\n<p><strong>NZ Privacy Principle 12&nbsp;<\/strong>concerns the<strong>&nbsp;cross-border disclosure of personal information<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is only allowed to send personal information from users inside New Zealand to other countries, if the data privacy laws in the recipient\u2019s country provide comparable security and can protect the data adequately.<\/li>\n\n\n\n<li>As an example, your website can use New Zealand\u2019s <a href=\"https:\/\/privacy.org.nz\/responsibilities\/your-obligations\/disclosing-personal-information-outside-new-zealand\/\" target=\"_blank\" rel=\"noreferrer noopener\">model contract clauses<\/a>&nbsp;to do so.<\/li>\n\n\n\n<li>To help you determine whether the NZ Privacy Principle 12 applies to you, <a href=\"https:\/\/privacy.org.nz\/responsibilities\/disclosing-personal-information-outside-new-zealand\/decision-tree-page\/\" target=\"_blank\" rel=\"noreferrer noopener\">check out the Principle 12 Decision Tree by the Privacy Commissioner<\/a>.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/privacy.org.nz\/responsibilities\/disclosing-personal-information-outside-new-zealand\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about sending personal information overseas in New Zealand<\/a><\/p>\n\n\n\n<p><strong>NZ Privacy Principle 13&nbsp;<\/strong>concerns <strong>unique identifiers<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website is only allowed to assign unique identifiers (individual identification sequences, such as a driver\u2019s license or a unique ID from a third-party cookie) when it is necessary.<\/li>\n\n\n\n<li>In other words, collecting personal information through technologies that assign unique identifiers must be done with care. Make sure to inform your users about exactly what kind of data you intend to collect, how, why and who you share it with.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/4037\/steven-biak-ling-rteyd-gdag4-unsplash.jpg?width=341&amp;\" alt=\"Three people sitting on a hill watching the sunset over a city - Cookiebot\" width=\"770px\" height=\"513px\"\/><figcaption class=\"wp-element-caption\">New Zealand\u2019s Privacy Act has been in effect since 1993 but updated in 2020 to match new tech developments.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-s-new-in-nz-privacy-act-2020\">What\u2019s new in NZ Privacy Act 2020<\/h2>\n\n\n\n<p>On December 5, a new and amended version of the NZ Privacy Act went into effect, repealing and replacing the 1993 version.<\/p>\n\n\n\n<p>The new amendments to the NZ Privacy Act include \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Stronger data breach security and control<\/strong>&nbsp;\u2013 if your website experiences a data breach (e.g. an unintended disclosure of personal information from its users), you are required to notify the individuals affected to the Privacy Commissioner.<\/li>\n\n\n\n<li><strong>Stronger enforcement tools for the Privacy Commissioner<\/strong>.<\/li>\n\n\n\n<li><strong>Decisions on access requests<\/strong>&nbsp;will now be made by the Privacy Commissioner and not the Human Rights Review Tribunal.<\/li>\n\n\n\n<li><strong>Stronger cross-border transfer regulations<\/strong>&nbsp;\u2013 your website must take steps to ensure that personal information transferred out of New Zealand can be protected adequately and comparable to the New Zealand\u2019s data privacy standards.<\/li>\n\n\n\n<li><strong>Stronger fines for non-compliance<\/strong>&nbsp;\u2013 of up to $10,000.<\/li>\n\n\n\n<li><strong>Class action lawsuits for non-compliance<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/www.justice.govt.nz\/justice-sector-policy\/key-initiatives\/privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Visit the Privacy Commissioner for an overview of the new amendments in the NZ Privacy Act 2020<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-summary-of-new-zealand-s-privacy-act-2020\">Summary of New Zealand\u2019s Privacy Act 2020<\/h2>\n\n\n\n<p>New Zealand\u2019s Privacy Act 2020 and its NZ Privacy Principles governs all handling of personal information from individuals inside the country and map out the legal way for your website to collect, use and share such data.<\/p>\n\n\n\n<p>The NZ Privacy Act 2020 requires your website to notify and inform users in New Zealand of your website\u2019s intended collection of personal information, including the purposes for which you collect and who you will be sharing it with (e.g. Google or Facebook).<\/p>\n\n\n\n<p>Using Cookiebot CMP takes all the hard work out of data privacy law compliance by offering plug-and-play compliance with New Zealand\u2019s Privacy Act 2020 \u2013 and a host of other major data laws like <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, <a href=\"\/en\/ccpa\/\">California\u2019 CCPA<\/a>, <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>, <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>&nbsp;and more.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Try Cookiebot CMP free for 14 days<\/a>\u00a0\u2013 or forever if you have a small website.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Get started with Cookiebot CMP and Google Consent Mode<\/a><\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Quick summary New Zealand\u2019s Privacy Act 2020, in brief New Zealand\u2019s Privacy Act was originally drafted and passed in 1993 and has been in place ever since, making it one of the earliest data privacy laws in the world. New Zealand is also one of only 12 nations worldwide to have an adequacy agreement with [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":12451,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":"The image is too white. Please, check the original image for faulty SVGs. If the original image is in SVG format, try to upload the PNG or JPEG version instead.","thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2021\/11\/New-Zealands-flag_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=832"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/832\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/12451"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}