.jpg%3Fwidth%3D900&w=3840&q=75)
Last updated 21 July 2026
The New Zealand Privacy Act applies to AI whenever AI systems collect, use or disclose personal information. It doesn't ban AI, but it does require organisations to handle personal data lawfully — collecting only what's needed, being transparent about use, keeping it secure, and taking care when data is processed offshore by public AI services. In practice, that shapes which AI tools you can safely use and how.
Does the Privacy Act cover AI specifically?
The Act isn't AI-specific, but its information privacy principles apply to any system that handles personal information — including AI. So when staff paste customer details into a chatbot, or an AI tool analyses personal records, the same obligations apply as to any other processing. The novelty of AI doesn't create an exemption.
What are the main risks when using AI with personal data?
- Offshore processing — sending personal information to AI services hosted overseas without appropriate safeguards.
- Over-collection — feeding more personal data into AI than the task actually requires.
- Transparency gaps — using personal data in AI in ways individuals wouldn’t reasonably expect.
- Security — personal data being retained or exposed by unmanaged or personal-account AI use.
- Loss of control — no oversight of what staff are entering into which tools.
How do organisations stay compliant while using AI?
The practical answer is governance plus the right tools. Publish a clear policy on what personal data can go into which AI tools, provide sanctioned options rather than driving staff to personal accounts, and for sensitive data consider keeping processing onshore or inside your own infrastructure. For genuinely sensitive workloads, a private AI instance avoids the offshore-processing question entirely.
Which Privacy Act principles matter most for AI?
A few of the thirteen information privacy principles do most of the work when AI is involved. Principle 1 limits collection to what you actually need — relevant when it is tempting to feed an AI more personal data than the task requires. Principle 5 requires you to keep personal information secure, which is hard to show if staff use unmanaged accounts. Principle 10 limits using information for a purpose other than the one it was collected for, which matters when personal data gathered for one reason is repurposed to train or prompt an AI. And Principle 11 governs disclosure — including sending personal information to an overseas AI provider. Mapping your AI use against these four is a practical first compliance step.
When do you have to notify a breach involving AI?
The Privacy Act 2020 requires you to notify the Office of the Privacy Commissioner, and affected individuals, when a privacy breach has caused or is likely to cause serious harm. That duty applies just as much to an AI-related incident — a staff member pasting a client list into a personal chatbot, or an AI tool exposing records it should not have — as to any other breach. Because notifications have been rising sharply, regulators are paying closer attention, so the safer posture is to prevent the exposure in the first place by governing which tools staff use and keeping sensitive data inside your control.
How does the NZ Privacy Act compare with privacy law overseas?
If you serve customers overseas — or you’re benchmarking your AI governance against international practice — it helps to see where New Zealand sits. The striking thing is how much the principles converge: every major jurisdiction expects you to know where personal data is processed, collect only what you need, be transparent, and stay accountable when a third party (including an AI vendor) processes data on your behalf. The instruments differ; the questions they make you answer are nearly identical.
| Jurisdiction | Core privacy law | AI-specific regulation | What it means for AI use |
|---|---|---|---|
| New Zealand | Privacy Act 2020 (13 privacy principles) | None yet — principles-based OPC guidance | Existing principles apply fully to AI; take care with offshore disclosure (IPP 12) |
| Australia | Privacy Act 1988 (APPs) | No AI-specific act; OAIC guidance | Similar posture to NZ; APP 8 governs sending data overseas |
| United Kingdom | UK GDPR + Data Protection Act 2018 | Regulator-led, principles-based approach | Lawful basis and impact assessments for higher-risk AI processing |
| European Union | GDPR | EU AI Act (obligations phasing in from 2025) | Risk-tiered AI obligations layered on top of GDPR |
| United States | Sectoral + state laws (e.g. HIPAA, CCPA/CPRA) | No single federal AI law | Obligations vary by sector and state; contracts carry much of the weight |
The practical takeaway: an architecture that keeps sensitive data inside infrastructure you control gives you the same defensible answer in every one of these jurisdictions. That’s why private AI deployments travel well — the compliance question changes wording at each border, but "our data is processed inside our own boundary" answers all of them.
Frequently asked questions
Often yes, for non-sensitive tasks and under an enterprise plan with proper controls — but you must consider where data is processed and what you enter. For sensitive personal information, keeping processing onshore or private is the safer path.
It is not prohibited, but you remain responsible for that personal information and must ensure appropriate protections. Many NZ organisations limit sensitive data to onshore or private deployments to reduce this risk.
They can. Laws like the EU/UK GDPR apply extraterritorially when you offer goods or services to, or monitor, people in those jurisdictions — regardless of where your organisation sits. If your AI processes data about overseas customers, map which regimes apply before choosing where that processing happens.
No. This is general guidance, not legal advice. For your specific obligations, consult the Office of the Privacy Commissioner’s guidance and your own legal advisors.
SOVATA