Skip to content
← Back to articles
Security
Compliance

IPP3 vs IPP3A: Website Forms, Referrals and Privacy Notices in NZ

IPP3 covers direct collection. IPP3A concerns information collected from another source. Understand the distinction before changing website forms, referral workflows or CRM imports.

By Rupert GoughPublished Updated
IPP3 vs IPP3A: Website Forms, Referrals and Privacy Notices in NZ

What is the difference between IPP3 and IPP3A?

IPP3 covers notification when personal information is collected directly from the person concerned. IPP3A concerns collection from another source. The source of the information, not simply the presence of a website form, determines which notification question to examine.

Discuss your website and information-handling requirements, users and existing tools so we can define a useful website or web app scope. Discuss your website or app.

Key takeaways
  • IPP3 covers notification when you collect information directly from the person. IPP3A concerns information collected from another source.
  • A website form can collect directly about its user and indirectly about someone else. Map the actual information flow, not just the form name.
  • A clear notice is useful, but it does not replace checking whether the collection itself is justified or whether an exception applies.
On this page 6 sections

Correction, 5 September 2026: an earlier version confused IPP3 with IPP3A. This version distinguishes direct and indirect collection. It is practical information, not legal advice for a particular business.

Start with the source, not the form #

A contact form, referral form and CRM import may look like three ways to create the same record. The important question is whose information is being collected, and from whom. That distinction should guide the privacy review before anyone rewrites the interface.

For example, a person entering their own contact details is different from a partner sending you someone else’s details. A form asking for both the submitter and another person needs a more careful review than its title suggests.

IPP3: information collected directly #

IPP3 requires reasonable steps to inform the person about direct collection. Its requirements include the purpose, intended recipients, the collecting and holding agencies, relevant legal requirements, consequences of not providing information, and access and correction rights. Notification is required before collection or, where that is not practicable, as soon as practicable afterwards. Exceptions exist.

Read the Privacy Commissioner’s explanation of IPP3. A useful design response is to put clear, relevant information where people decide whether to provide their details, with a link to fuller information.

IPP3A: information collected from another source #

IPP3A concerns indirect collection: information obtained from someone other than the individual concerned. It took effect on 1 May 2026. The collecting agency must take reasonable steps to notify the person as soon as reasonably practicable after collection, unless it has done so sooner or an exception applies.

The notification covers the collection, its purpose and intended recipients, the collecting and holding agencies, any law authorising or requiring it, and access and correction rights. IPP3A does not itself authorise indirect collection; the basis for collecting from another source still needs assessment under IPP2.

The Privacy Commissioner’s IPP3A guidance explains the requirements and exceptions. Do not assume that “we received a referral” answers the notification question, or that every movement between software providers is a separate agency collection. Establish the actual roles and circumstances.

A practical review of the workflow #

I would map each collection point in a small working register, rather than start with a generic block of legal text. My suggested fields are:

  • The information collected, the person it concerns and its source.
  • The business purpose and the reason each field is needed.
  • The organisations and systems receiving or holding it.
  • The notice or other information already given to the person.
  • The owner of any notification, exception assessment or unresolved question.

For a referral workflow, that could become a task for the responsible staff member to review what the person was told before the record enters an automated sequence. For a direct enquiry, it could mean clearer form copy and fewer fields. These are design examples, not findings that a particular workflow complies.

Make the system support the decision #

A useful system can preserve the source of a record, the version of a notice and the responsible person’s decision. It should not quietly turn an uncertain privacy judgment into an automatic tick.

Before changing a live workflow, have the relevant privacy owner or adviser confirm the obligations and any claimed exception. Then implement that decision consistently across forms, imports, referrals and follow-up tasks. A polished footer is not a substitute for understanding where information comes from.

Sources and further reading #

Primary references: Office of the Privacy Commissioner — IPP3, IPP3A, and Ministry of Justice — changes to the Privacy Act. These sources were checked for this correction on 5 September 2026.

For the wider system design questions, see the NZ Privacy Act and business software.

A useful companion: Workflow Mapping Worksheet.

Quick Questions

Is IPP3A the rule for ordinary contact forms?

Not generally when someone supplies their own details. Direct-collection notification is covered by IPP3. A form collecting details about another person can raise indirect-collection questions under IPP3A.

Will a privacy-policy checkbox make a workflow compliant?

A checkbox alone does not establish compliance. Identify the source, purpose, recipients and applicable obligations, then make the necessary information clear to the affected person. Get advice where the facts or an exception are uncertain.

Where should a software review start?

Start with an inventory of collection points and data sources, including referrals and imports. Record what is collected, why it is needed, who receives it, what the person is told, and who owns any required follow-up.