Your NZ business is covered by the Privacy Act the moment you paste a customer’s details into AI, and two rules changed in 2026
If you run a business in New Zealand, here is a line that catches a lot of owners by surprise: the Privacy Act 2020 applies to you the moment you handle someone’s personal information, no matter how small your business is. There is no threshold to cross, no headcount you have to reach first. A sole trader with one laptop is an “agency” under the Act, exactly like a bank.
That matters more than ever now, because the fastest new way for personal information to leave your control is an AI tool. When you paste a customer’s details, a client file, or a staff record into a chatbot, a notetaker, or an “AI assistant” built into your software, you are handling personal information under the Act. If that tool stores it, trains on it, or has a breach, the responsibility still sits with you, not the vendor. That is the heart of what we call AI leakage: sensitive information leaving your control through an AI tool.
Two changes landed in 2026 that most small-business owners have not heard about. Here is the plain-English version, and what to do about it.
There is no small-business exemption
Unlike some overseas regimes, New Zealand’s Privacy Act has never had a carve-out for small businesses. The 13 Information Privacy Principles apply to every agency that collects, uses, stores or discloses personal information. Putting a person’s information into an AI tool can involve several of those principles at once: collection, use, disclosure to a third party (the AI vendor), and your duty to keep it secure.
The practical test is simple: if you would not email a customer’s file to a stranger, do not paste it into a free AI tool whose data terms you have not checked. The tool is the stranger.
Change one: new notification rules for information you collect indirectly (from 1 May 2026)
The Privacy Amendment Act 2025 added a new principle, IPP 3A, which came into force on 1 May 2026. Until now, you only had to tell people you were collecting their information when you collected it directly from them: a form, a phone call, a sign-up. IPP 3A closes the gap: from 1 May 2026, if you collect someone’s personal information indirectly (from a third party rather than from the person themselves), you generally have to take reasonable steps to make sure they are told about it, unless an exception applies.
Why does this touch AI? Because a growing number of AI tools collect information indirectly on your behalf: enrichment tools that pull in contact data, research assistants that gather details about a person from other sources, lead tools that build profiles. If you feed that indirectly-collected information into your systems, IPP 3A may now require you to notify the person. It is worth reviewing any AI tool that brings in data about people you did not get from those people directly.
Change two: new rules for biometrics, with a deadline of 3 August 2026
The Biometric Processing Privacy Code 2025 came into force on 3 November 2025. It sets specific rules for any business using biometric technology: facial recognition, fingerprint scanning, and voice identification among them. Businesses already using biometrics before 3 November 2025 were given a nine-month grace period to comply, and that period ends on 3 August 2026.
This is easy to overlook because you might not think of yourself as “using biometrics.” But AI voice tools that identify speakers, face-matching in security or check-in systems, and some AI notetakers touch biometric information, which the Code treats as some of the most sensitive personal information there is. The Code expects a documented privacy impact assessment before you deploy, a genuine necessity-and-proportionality test, clear notice to the people affected, and an assessment of bias risk for Māori, Pacific peoples and other groups. If any AI tool in your business processes faces or voices, this deadline applies to you.
What a leak actually costs you
If personal information escapes through an AI tool and it is likely to cause serious harm, that is a notifiable privacy breach. Under the Act you must tell both the Office of the Privacy Commissioner and the affected people as soon as practicable. The Commissioner’s guidance points to around 72 hours of realising a breach is notifiable. Failing to notify the Commissioner is an offence carrying a fine of up to NZ$10,000, and affected people can take a claim to the Human Rights Review Tribunal, which can award damages that have run well into the tens of thousands.
The reputational cost is usually worse than the fine. For a small business, the clients you lose after “they leaked my details into some AI app” are the ones you never win back.
What to actually do this month
You do not need to be technical to get on top of this. A short, honest pass is enough to remove most of the risk:
- List the AI tools your team actually uses, including the free ones and the AI features baked into software you already pay for.
- For each one, check whether it trains on or retains what you put in, and on which plan. The tier matters as much as the tool: a free account and a business account of the same product can carry very different risk.
- Never paste customer, financial, health, legal, HR or other sensitive information into a free or unchecked tool.
- Look for any tool that collects information about people indirectly (IPP 3A) or processes faces or voices (the biometric deadline).
- Write it all down in a simple policy so your team knows the rules. You can start from our AI Tool Risk Directory, which rates common tools in plain English.
The Privacy Act has always made you responsible for the personal information in your care. AI has just made it far easier for that information to slip out the side door. Ten minutes of checking now is a great deal cheaper than a breach notification later.
If you found this useful and you want to protect your business, consider signing up for our free monthly newsletter. We send plain-English alerts when an AI tool you use changes its data policy or has an incident, and the rule changes, like the two above, that quietly shift what your business is responsible for. You can subscribe here.
How this was written: this article was drafted with AI and reviewed by a person before publishing, the same disciplined use of AI we advocate. The legal changes described are sourced from the Office of the Privacy Commissioner and the New Zealand Ministry of Justice. It is general information for New Zealand businesses, not legal advice; check your own situation and seek advice where needed.
