Doing Business In..._2026

NEW ZEALAND Law and Practice Contributed by: Fiona Ashby, Luke Bowers, Daniel Erickson, Jessica Phillips, Natalie Foster, Shelley Slade-Gully, Tina Liu and Theresa Le Bas, Tompkins Wake

The Act is principles-based and regulates the full information life cycle through 13 Information Privacy Principles (IPPs), covering: • the purpose and source of collection; • transparency at collection; • the collection of information from third parties; • storage and security; • access and correction rights; • accuracy, retention, use and disclosure; The Act also contains a mandatory notifiable privacy breach regime. Agencies must notify the Privacy Com - missioner and affected individuals where a privacy breach has caused serious harm, or is likely to do so. The Privacy Commissioner may issue codes of prac - tice, which form part of New Zealand’s data protection framework, and may modify the IPPs for particular sectors, activities or types of personal information. The codes of practice that are currently in force are: • overseas transfer; and • use of unique identifiers. • Health Information Privacy Code 2020; • Credit Reporting Privacy Code 2020; • Telecommunications Information Privacy Code 2020; • Biometric Processing Privacy Code 2025; • Civil Defence National Emergencies (Information Sharing) Code 2020; • Justice Sector Unique Identifier Code 2020; and • Superannuation Schemes Unique Identifier Code 2020. 8.2 Geographical Scope The Privacy Act has express extraterritorial applica - tion. It applies not only to New Zealand companies, but also to overseas companies that are “carrying on business” in New Zealand, regardless of where the personal information is or was collected or held by the overseas company. A foreign company targeting New Zealand customers may therefore be required to comply with the Act if it is “carrying on business” in New Zealand in respect of personal information collected or held by the foreign

company. “Carrying on business in New Zealand” is not defined in the Act, but a foreign company may be treated as “carrying on business in New Zealand” without necessarily: • being a commercial operation; • having a place of business in New Zealand; • receiving any monetary payment for the supply of services; or • intending to make a profit from its business in New Zealand. When assessing whether the test is satisfied, the Pri - vacy Commissioner would consider a range of factors, including whether the foreign company: • offers goods or services to New Zealanders; • has ongoing New Zealand-facing activities involv - ing personal information on a repeated or system - atic basis; • operates through a NZ-facing website or app; • has activities that are carried out in or have effect in New Zealand; or • uses New Zealand domain names or trade marks (including where it holds relevant registrations). Where the Act applies, the foreign company must comply with the IPPs or any code of practice that is applicable to either the relevant sector that the foreign company operates in or the type of personal informa - tion being collected. It must also appoint a privacy officer. The Act also regulates international transfers of per - sonal information. Under Information Privacy Prin - ciple 12, the New Zealand or foreign company (that is subject to the Privacy Act) may generally disclose personal information to an overseas recipient only if the recipient is subject to the Privacy Act, comparable privacy laws, a prescribed binding scheme or other comparable safeguards, such as contractual protec - tions. Alternatively, the individual must authorise the overseas transfer after being expressly informed that the overseas recipient may not provide comparable protection to the Privacy Act.

771 CHAMBERS.COM

Powered by