NZ Privacy Act: Practical Questions for Business Software
Map the personal information your software collects, why it is needed, who can access it and how requests or incidents are handled. Software supports privacy practice; it does not establish compliance by itself.

The practical answer
Map the personal information your software collects, why it is needed, who can access it and how requests or incidents are handled. Software supports privacy practice; it does not establish compliance by itself.
Put your website and information-handling questions into a broader roadmap that reflects your business goals and the resources available. Explore Tech Clarity.
Start with the information flow #
List the forms, imports, referrals, integrations and manual uploads that bring personal information into your business. Identify the purpose, system owner, users, providers and any onward sharing for each flow.
Use that map to decide what should be collected, what is unnecessary and where people need a clear explanation. Avoid copying a generic privacy policy while leaving the actual collection journey unclear.
Distinguish direct and indirect collection #
A form completed by the person and information received from another organisation are different collection situations. Review the applicable notice requirements and any exception with your privacy adviser.
The Privacy Commissioner explains IPP3A and indirect collection. See our guide to website forms and collection notices for implementation questions.
Turn responsibilities into requirements #
Define access by role and task. Specify how staff identify a record, correct information, export the relevant material and apply the agreed retention rules. Include the database, file storage, logs, backups and integrated systems in the discussion.
For a new build, test both permitted and denied access. For an existing system, review how accounts are created, changed and removed. Keep an owner for these checks after launch.
Prepare for an incident #
A notifiable privacy breach must be reported as soon as practicable. The Privacy Commissioner encourages notification ideally within 72 hours after becoming aware of a notifiable breach; this is not a blanket statutory 72-hour deadline for every incident.
Use the Commissioner’s NotifyUs guidance and obtain advice on your circumstances, including notification of affected people. Your technical process should preserve evidence, identify the scope and support the responsible person’s decisions.
Review the agreement and the actual system #
Ask about provider responsibilities, subcontractors, information locations, access, deletion and incident communication. A provider’s assurance report does not certify your application configuration or your business practices.
This is an implementation checklist, not legal advice. The appropriate requirements depend on your information and activities. Use the current law and regulator guidance, with specialist advice where needed.
Primary reference: Privacy Act 2020.
A useful companion: Workflow Mapping Worksheet.
Other articles worth reading

IPP3 vs IPP3A: Website Forms, Referrals and Privacy Notices in NZ

Building for Resilience: Security, Backups and Recovery

