Compliance software · New Zealand

Privacy Act and compliance software for New Zealand businesses

New Zealand's Privacy Act 2020 applies to almost every business, large or small, and it keeps growing — a new principle on indirect collection takes effect in 2026. AI Pazz Govnex turns the principles into owned controls, published policies and a breach process you can show the Privacy Commissioner.

In short

Almost every New Zealand organisation must follow the Privacy Act 2020 and its 13 Information Privacy Principles, appoint a privacy officer, and notify the Privacy Commissioner and affected people of a privacy breach that has caused or is likely to cause serious harm. There is no small business exemption. Govnex keeps the principles as your own control set, with owners, evidence and a breach register.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in New Zealand

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

Privacy Act 2020

Privacy Act 2020 and the Information Privacy Principles

Track it with your own controls
Regulator
Office of the Privacy Commissioner
Who it applies to
Almost every agency — business, not-for-profit or government — that handles personal information, whatever its size.
If you fall short
Fines of up to NZD 10,000 for offences such as failing to notify a breach, and damages through the Human Rights Review Tribunal.
What it asks of you
  • Follow the 13 Information Privacy Principles on collection, storage, use, disclosure, access and correction
  • Appoint one or more privacy officers
  • Notify the Privacy Commissioner and affected people as soon as practicable of a notifiable privacy breach
  • Take care before sending personal information overseas (IPP 12)
  • From 1 May 2026, tell people when you collect their information from someone else (IPP 3A, added by the Privacy Amendment Act 2025)

Source: privacy.org.nz

HSWA 2015

Health and Safety at Work Act 2015

Track it with your own controls
Regulator
WorkSafe New Zealand
Who it applies to
Every person conducting a business or undertaking (PCBU).
If you fall short
Fines of up to NZD 3 million for a body corporate for the most serious offences.
What it asks of you
  • Ensure, so far as reasonably practicable, the health and safety of workers
  • Notify WorkSafe of notifiable events and keep records of them
  • Engage with workers on health and safety

Source: worksafe.govt.nz

PSR and NZISM

Protective Security Requirements and the NZ Information Security Manual

Track it with your own controls
Regulator
NZ Security Intelligence Service and the Government Communications Security Bureau (GCSB)
Who it applies to
Government agencies, and suppliers that handle government information.
If you fall short
A condition of government work rather than a penalty regime.
What it asks of you
  • Protective security governance, information, personnel and physical security
  • Technical information security controls for government systems

Source: protectivesecurity.govt.nz

Standards New Zealand buyers ask for

How AI Pazz Govnex helps in New Zealand

What you needHow Govnex does itModule
The 13 privacy principlesAdd the IPPs as your own controls, assign owners and collect evidence cycle by cycle.
Notifiable privacy breachesLog each breach as an issue with its serious-harm assessment, owner, notification and actions.
Knowing what you hold and where it goesKeep a register of personal information, its owners and overseas recipients.
Privacy policy and staff awarenessPublish policies and see who has acknowledged them.
Health and safety incidentsRecord incidents, investigations and corrective actions, and the notifiable events WorkSafe must hear about.

Your first 90 days

  1. 1Name your privacy officer and record who is responsible for each principle.
  2. 2Add the 13 IPPs — including IPP 3A — as your own control set and assign owners.
  3. 3Map the personal information you hold, including what you collect from third parties.
  4. 4Put a breach process in place: assess serious harm, notify, and fix the cause.
  5. 5Run your first assessment cycle and report where you stand.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in New Zealand: questions and answers

Does the Privacy Act 2020 apply to small businesses?
Yes. Unlike Australia, New Zealand has no small business exemption — almost every organisation that handles personal information must follow it.
What is a notifiable privacy breach?
A privacy breach that has caused, or is likely to cause, serious harm to someone. It must be reported to the Privacy Commissioner and the affected people as soon as practicable.
What changes in 2026?
The Privacy Amendment Act 2025 adds Information Privacy Principle 3A from 1 May 2026: when you collect personal information about someone from another source, you must generally tell them.
Do we need a privacy officer?
Yes. Every agency must have at least one privacy officer, who can be an existing staff member.
Is the New Zealand Privacy Act in the Govnex Library?
Not yet as a ready-made set — you add the principles as your own controls in minutes, and track them exactly like a Library standard. ISO 27001, the Essential Eight and NIST CSF are ready-made.
What else does Govnex do?
Policies, risk registers, issues, internal audits, regulatory change, a data register and ESG & EHS — one workspace for a small team.

Modules New Zealand teams start with

Every plan

Compliance management software

Compliance and Control Tracker

Track recurring compliance obligations, assign owners and record the evidence, cycle by cycle.

  • Adopt controls from the Compliance Library — ISO 27001, SOC 2, GDPR, Sri Lanka PDPA and more — as your own editable copies
  • Cycles and assessments whose scope is fixed the moment they open
  • Coverage and maturity scoring, withheld below a coverage floor you set
More about Compliance and Control Tracker
Small business and up

Issue and remediation tracking software

Issue & Remediation

Log what is wrong — gaps, findings, incidents — assign it to whoever has to put it right, and see it closed with evidence and a second pair of eyes.

  • Anyone can open a register and run it: its own severities with target days, categories, custom attributes and visibility
  • A due date from the severity, moved only with a reason that is logged
  • A ladder per register: overdue by so many days, escalate to the administrator, the Module Admins or a named person — worked out live, never stale
More about Issue & Remediation
Small business and up

Data protection compliance software

Data Compliance Tracker

What you hold data about and what you do with it: entities and their records with a business owner and a data owner for each, and Records of Processing Activities with a compliance checklist answered item by item.

  • Entities — Customer, Employee, Supplier — each with a business owner and a data owner
  • A RoPA for each activity: its purpose, its owners, and the records it processes — what they hold read beside it
More about Data Compliance Tracker