A privacy statement is more than a page added to your website because customers expect to see one. It should explain, in clear terms, what personal information your business collects, why you collect it and what happens to it afterwards.
Many businesses begin with a template, change the name and contact details, and publish it without looking closely at how information moves through the business. The wording may appear professional, but it can still be inaccurate or incomplete.
A more reliable starting point is to understand the information your business actually handles. Once you know what you collect, where it is stored, who receives it and how long it is kept, the privacy statement becomes much easier to write.
The Privacy Act applies to most New Zealand businesses
The Privacy Act 2020 applies broadly to New Zealand businesses and organisations, including small businesses, sole traders, charities, clubs and government agencies. There is no general revenue threshold that excludes most smaller businesses. Some limited exceptions apply, including certain personal or domestic activities, judicial functions and news activities.
The Act regulates personal information, which means information about an identifiable person. This can include obvious details such as names, phone numbers and email addresses, as well as photographs, recordings, notes, correspondence, identification numbers and information that identifies someone when combined with other details.
Some sectors and types of information are also covered by privacy codes that modify how the Act applies. These include health information, credit reporting, telecommunications information and biometric information. Businesses working in these areas may need to consider both the Privacy Act and the relevant code.
Understand the role of a privacy statement
The Privacy Act focuses on the information people should receive when their personal information is collected.
A privacy statement is commonly used to provide this information. It explains what an organisation collects and what it will use the information for, and it may be published on a website, included with a service or displayed where information is requested. Privacy statements help businesses comply with Information Privacy Principle 3 and, in some situations, the newer Information Privacy Principle 3A.
A general website statement can provide a useful overview, but it may not cover every collection situation. Recruitment, customer onboarding, newsletter registration, event bookings and referral arrangements may each require more specific wording at the point where information is collected.
The goal is to give people relevant information at a time and in a form that helps them understand what is happening.
Explain what personal information you collect
A privacy statement should identify the kinds of personal information your business usually collects. Depending on your activities, this might include:
- Customer names and contact details.
- Account, billing and payment information.
- Information submitted through enquiries and support requests.
- Employee, contractor and job applicant information.
- Website, device and usage information.
- Identity documents or verification information.
- Health, financial or other sensitive information.
The list should reflect the information your business genuinely handles. Including every possible category can make the statement harder to understand and may create confusion about your actual practices.
This review also helps the business apply Information Privacy Principle 1, which provides that personal information should only be collected where it is necessary for a lawful purpose connected with the organisation’s activities.
Explain why the information is collected
When personal information is collected directly from someone, the business must take reasonable steps to make sure they understand why the information is being collected and what will happen to it.
This generally includes explaining:
- The purpose for collecting the information.
- The people or organisations that may receive it.
- Whether providing the information is voluntary or required.
- What may happen if the information is not provided.
- The person’s right to request access to or correction of their information.
Common purposes may include providing products or services, processing payments, maintaining customer accounts, responding to enquiries, meeting legal obligations, supporting employees or carrying out permitted marketing.
The explanation should be specific enough to be meaningful. Broad phrases such as “for business purposes” give people very little understanding of how their information will be used.
Cover information collected from other sources
Businesses often receive personal information from someone other than the individual concerned. This may happen through referrals, business partners, employers, public databases, service providers, credit checks or information supplied by another family member or customer.
Since 1 May 2026, Information Privacy Principle 3A generally requires an organisation that collects personal information indirectly to take reasonable steps to notify the individual, unless an exception applies. The organisation collecting the information is responsible for providing the notification.
For indirect collection, the person may need to be told:
- That their information has been collected.
- The purpose for which it was collected.
- The intended recipients.
- The name and address of the organisation collecting the information.
- The name and address of the organisation holding it.
- The particular law authorising or requiring collection, where relevant.
- Their rights to access and correct the information.
There are exceptions, including situations where the person has already received the required information, the information is publicly available, notification would not prejudice their interests, or another specific statutory exception applies. Businesses should understand which exception they rely on rather than assuming indirect collection is automatically exempt.
This change makes it especially helpful to map referral processes, purchased lists, third-party data sources and information exchanged between related organisations.
Identify who collects and holds the information
A privacy statement should clearly identify the organisation responsible for collecting and holding the information. It should provide contact details that people can use when they have a privacy question or want to exercise their rights.
Where multiple businesses, related companies or service providers are involved, the wording should make each organisation’s role understandable. Someone should be able to tell which business holds their information and where a request should be sent.
Durable contact details, such as a role-based privacy email address, are often easier to maintain than the name of an individual employee.
Explain how information is stored and protected
The privacy statement can provide a general explanation of how and where personal information is held. This might include business systems, email, customer management platforms, accounting software, cloud storage, physical records and third-party providers.
Information Privacy Principle 5 requires organisations to use safeguards that are reasonable in the circumstances to protect personal information against loss, misuse and unauthorised access, use, modification or disclosure.
A public statement does not need to describe sensitive technical details. It can explain the general approach, such as the use of access controls, staff procedures, secure systems and reputable service providers.
The underlying protections matter more than polished wording. A business may say it takes reasonable security measures while still having shared accounts, weak access controls, unrestricted folders or former employees with active access. These practical gaps should be addressed so the statement remains accurate.
Explain how information is used and shared
Personal information should generally be used for the purpose for which it was collected, or for a directly related purpose. Similar limits apply when information is disclosed to another person or organisation. The Act provides exceptions, but businesses should have a clear and supportable basis for relying on them.
The privacy statement should describe the usual uses and recipients in language that customers can understand. Depending on the business, recipients might include payment providers, technology suppliers, professional advisers, delivery companies, contractors or government authorities where disclosure is required.
This section becomes more useful when it explains real categories of recipients rather than relying on language such as “we may share your information with third parties.”
Review overseas providers and disclosures
Many New Zealand businesses use cloud, communication, marketing and support providers located overseas. Information Privacy Principle 12 requires businesses to consider whether personal information disclosed to an overseas recipient will receive safeguards comparable to those provided under New Zealand law.
This does not mean that every use of an overseas cloud service is automatically treated as an overseas disclosure under IPP 12. Where a provider stores or processes information solely on behalf of the New Zealand business, the business will generally remain the holder of and responsible for that information. The precise position depends on how the provider uses and handles the data.
A practical review should identify:
- Where personal information is stored or accessed.
- Whether the overseas provider uses it for its own purposes.
- What contractual privacy and security protections apply.
- Whether the provider is subject to New Zealand law or comparable safeguards.
- Whether customers have been given an accurate explanation of the arrangement.
The Office of the Privacy Commissioner provides an IPP 12 decision tool and model contract clauses that may assist businesses assessing overseas arrangements.
Explain how people can access or correct their information
People generally have the right to request access to personal information held about them and to ask for corrections where the information is inaccurate.
The privacy statement should explain how to submit these requests and provide an appropriate contact point. Although there are limited reasons why access may sometimes be withheld, the starting point is that people are entitled to request their own information.
The business also needs a working process behind the statement. Someone should know how to locate the information, confirm the requester’s identity, review any withholding grounds and respond within the applicable timeframe.
Appoint a privacy officer
Every New Zealand organisation must have at least one person fulfilling the role of privacy officer. This can be an employee or an external person who understands the organisation and its privacy obligations.
The privacy officer’s responsibilities include helping the organisation comply with the Act, overseeing access and correction requests, dealing with privacy complaints and acting as a point of contact with the Office of the Privacy Commissioner.
In a smaller business, this may be the owner, an operations manager or another senior employee. The role does not require a lawyer or a full-time privacy specialist, but the person should have enough authority and understanding to make sure privacy matters are followed through.
Including a privacy contact in the public statement makes it easier for people to raise questions or concerns.
Have a process for privacy complaints and breaches
A privacy statement should explain how someone can make a privacy complaint and where it should be sent. Internally, the business should have a consistent way to investigate, respond and record the outcome.
The business also needs a process for privacy breaches. If a breach has caused, or may cause, serious harm, the organisation has a legal obligation to notify the Office of the Privacy Commissioner and usually the affected people. Notification should happen as soon as practicable, with the Commissioner recommending notification within 72 hours of becoming aware of a notifiable breach.
The privacy statement does not need to reproduce the complete response plan. However, the business should know who will assess a breach, contain it, gather information, make the notification decision and communicate with affected people.
A privacy statement and an internal policy serve different purposes
Businesses often use the terms privacy statement and privacy policy interchangeably, although they can serve different audiences.
A privacy statement is generally written for customers, employees, applicants and other people whose information is collected. It explains what the organisation is doing with their information.
An internal privacy policy provides guidance to employees and contractors. It may cover matters such as approved collection methods, access permissions, data sharing, storage, retention, disposal, requests, complaints and breach response.
A business may benefit from both. The public statement creates transparency, while the internal policy and supporting procedures help the team carry out the promises made in that statement.
Follow a manageable process
The work becomes clearer when it is divided into practical stages. The aim is to understand the business first and then prepare wording that accurately describes it.
- Identify the personal information you hold. Include information about customers, staff, contractors, applicants and other identifiable people.
- Record how it is collected. Separate information collected directly from information received through referrals, partners and other sources.
- Clarify why it is needed. Connect each category of information to a lawful and necessary business purpose.
- Map where it goes. Identify systems, devices, service providers, recipients and overseas arrangements.
- Review security and access. Check who can access the information and whether the safeguards are reasonable.
- Document retention and disposal. Decide how long information is needed and how it will be securely removed.
- Establish request and complaint processes. Make sure someone owns and understands each process.
- Prepare appropriate privacy statements. Use clear wording suited to each collection context.
- Assign a privacy officer. Give the person enough information and authority to fulfil the role.
- Review the arrangements regularly. Update them when systems, providers, purposes or collection methods change.
This sequence allows the documentation to grow from a clear picture of the business rather than from assumptions in a template.
Avoid common privacy statement mistakes
Most problems arise when the wording does not match the way the business operates. A useful review should look for the following issues:
- The statement was copied from another country and refers to laws that do not apply in New Zealand.
- The business lists protections or procedures that have not been implemented.
- The purposes for collecting information are vague or overly broad.
- The statement does not explain the consequences of withholding requested information.
- Indirect collection has not been considered under IPP 3A.
- Service providers and overseas arrangements have not been mapped.
- The statement is expected to replace specific notices at every point of collection.
- Access, correction and complaint contact details are missing or out of date.
- The business has no assigned privacy officer.
- The statement has not been updated after introducing new systems or uses of information.
The Privacy Commissioner has specifically warned businesses about using overseas templates that reference the wrong laws or provide inaccurate information. A New Zealand privacy statement should reflect the Privacy Act 2020 and the organisation’s own practices.
How BrightShield can support your business
BrightShield helps small and growing businesses turn privacy obligations into practical processes that work within the business.
With BrightShield Guided, your team works through the process with clear guidance, practical templates and expert support. This can include:
- Identifying the personal information the business collects and holds.
- Mapping direct and indirect collection under IPP 3 and IPP 3A.
- Recording systems, suppliers, recipients and overseas arrangements.
- Reviewing privacy statements and collection notices.
- Establishing access, correction and complaint procedures.
- Developing retention and disposal practices.
- Strengthening access controls and other security safeguards.
- Preparing accurate draft documentation for legal review where appropriate.
With BrightShield Complete, we can take a more hands-on role by interviewing team members, conducting the information inventory, mapping systems and providers, documenting current practices and coordinating the work needed to close important gaps.
This can also include establishing request and breach-response workflows, reviewing third-party arrangements, improving security controls and preparing policy content based on the way the business actually operates.
BrightShield does not provide legal opinions or guarantee compliance. Where legal interpretation is required, we can help prepare the operational information, evidence and draft documentation needed for review by an appropriately qualified New Zealand privacy lawyer.
Clear privacy information begins with clear business practices
A useful privacy statement grows from a proper understanding of the personal information your business handles. When the collection methods, purposes, systems, providers and responsibilities are clear, the public wording becomes easier to prepare and easier to maintain.
BrightShield can help you map your information, understand where the important gaps are and put the supporting privacy and security processes in place. This gives your business a practical foundation for meeting its responsibilities and keeping the statement accurate as the organisation changes.


