New Zealand - AI Privacy Guidance

Office of the Privacy Commissioner — Guidance/Expectations on the use of AI (privacy guidance)

New Zealand

RAI-NZ-NA-OPCGUXX-2023
Effective: September 21, 2023
In Force(In Force)
GuidelineGovernance and OversightData Protection and PrivacyRisk Management
Export PDF

New Zealand's Office of the Privacy Commissioner issued guidance in 2023 directing public and private agencies on complying with the Privacy Act 2020 when using personal data in AI. It sets expectations for privacy impact assessments, human oversight, and Māori data engagement, and has been in force since 2023-09-21.

Summary

As of 6 September 2026, the Office of the Privacy Commissioner's guidance titled 'Artificial Intelligence and the Information Privacy Principles' remains in force. The most recent dated event for this instrument was its publication on 21 September 2023, building upon an initial statement of expectations issued by the Privacy Commissioner on 15 June 2023. As a non-binding regulatory guidance document, no body enforces the instrument itself, although the Privacy Commissioner oversees statutory compliance with the underlying Privacy Act 2020 and may conduct investigations, issue compliance notices, make public disclosures, or refer statutory breaches to the Human Rights Review Tribunal.

The guidance clarifies that New Zealand's technology-neutral Privacy Act 2020 and its 13 Information Privacy Principles apply to all public and private sector agencies collecting, processing, or sharing personal information through AI systems. It expands the practical understanding of personal information to encompass traditional identifiers, technical metadata, and inaccurate or generated data such as deepfakes. Compliance obligations attach across every stage of the AI lifecycle, including training data curation, model development, runtime prompt inputs, and downstream decision-making.

The document establishes explicit expectations for agencies deploying AI. Key operational requirements include obtaining documented senior leadership approval, assessing the necessity and proportionality of AI tools, conducting formal Privacy Impact Assessments prior to deployment, maintaining public transparency regarding AI usage, engaging with Māori on data sovereignty and cultural taonga, enforcing human oversight for decisions that impact individuals, and establishing strict vendor contracts to block unauthorized data retention or secondary model training.

The guidance maps specific risk controls to individual privacy principles, focusing on data minimisation, purpose limitation, security of prompts and datasets, accuracy testing, and rights of access. While adherence to the guidance itself is non-binding, failure to fulfill the statutory requirements of the Privacy Act 2020 exposes agencies to regulatory enforcement actions, public breach reporting, and civil proceedings.

Full article

Read full text ↗

Overview

The Office of the Privacy Commissioner (OPC) published detailed guidance titled "Artificial intelligence and the Information Privacy Principles" on 21 September 2023. The guidance explains that the Privacy Act 2020 and the 13 Information Privacy Principles (IPPs) apply to the full lifecycle of AI systems used in New Zealand, including generative AI. The OPC sets clear expectations for organisations considering or using AI: secure senior leadership approval; assess necessity and proportionality; carry out Privacy Impact Assessments (PIAs) and Algorithmic/AI Impact Assessments (AIAs); be transparent with people about AI use; engage with Māori and affected communities; ensure human review for decisions affecting people; and prevent AI providers from retaining or disclosing personal information without lawful basis. The OPC guidance is available on its website and as a full PDF guide (see OPC AI topic page and the full guidance AI and the Information Privacy Principles (PDF)).

Definitions

The guidance uses a broad working definition of "AI tools" to include systems that perform tasks that appear to exhibit intelligent behaviour: machine learning models trained on data, classifiers, interpreters (speech-to-text, image captioning), generative systems (text, image, code) and automated decision systems. "Personal information" is defined in line with the Privacy Act 2020: information about an identifiable individual, including traditional identifiers (name, address), technical metadata (IP addresses, device IDs), and even inaccurate or fabricated data (deepfakes, fake profiles) where a person is identifiable. The guidance distinguishes training data (used to build models), model artefacts (weights, pre-trained models), runtime inputs (prompts, user data) and outputs (responses or decisions), and treats each stage as potentially engaging the IPPs.

Governance and Institutional Framework

The OPC expects organisations to embed AI privacy governance at senior leadership level and to assign clear accountability (privacy officers, data governance leads). Organisations should: (1) obtain explicit senior leadership approval informed by documented risk assessment and mitigations; (2) integrate PIAs/AIAs into project governance and procurement; and (3) include privacy and security conditions in supplier contracts. The guidance encourages cross-functional teams (privacy, legal, cybersecurity, data science, Māori engagement) and recommends that boards and executive teams be briefed about AI risks and compliance obligations. For public sector agencies the guidance aligns with New Zealand public service material such as the Algorithm Impact Assessment user guide and joint system leads' tactical guidance on generative AI — and encourages agencies to follow established procurement, security, and data governance frameworks. The OPC also notes its statutory role: it provides guidance, investigates complaints, may issue compliance notices and works with other agencies on sectoral codes; organisations should engage proactively with the OPC where novel or high-risk uses are contemplated. For further context see the OPC AI guidance and the OPC topic overview at OPC AI topic page.

Key Focus Areas

The guidance organises privacy risk across the AI lifecycle and highlights several focus areas: data sourcing and training (lawful collection, quality and bias risks, consent and purpose-limitation), model development (data minimisation, anonymisation limits, and provenance), operational use (inputs, prompts and inadvertent disclosure of PII), accuracy and fairness (testing, validation, representative datasets), transparency and explainability (clear public information, ability for individuals to understand and challenge decisions), human oversight (effective ‘human-in-the-loop’ design), security (protecting training data, prompts and models from leakage), and contractual safeguards (requirements for third-party AI providers not to retain or repurpose uploaded personal data). The OPC emphasises obligations under particular IPPs: collection and purpose (IPPs 1–4), storage and security (IPP 5), accuracy (IPP 8), limits on use/retention (IPPs 10–13), and disclosure (IPP 11–12). Cultural and equity considerations are central: the guidance recommends proactive engagement with Māori to address taonga data, tikanga, and data sovereignty concerns. The OPC also provides practical questions for each focus area to guide PIAs/AIAs and governance decisions.

Implementation Framework

The guidance recommends a practical implementation framework organisations can follow: (1) scope and purpose — document the intended use, expected benefits, and affected populations; (2) initial risk screen — assess whether the AI use involves personal information or high-impact decisions; (3) PIA/AIA — conduct a formal impact assessment with community engagement, including Māori where relevant; (4) procurement and contracts — include clauses on data handling, retention, deletion, and non-training/secondary-use promises; (5) testing and validation — implement accuracy, bias and robustness testing with representative datasets; (6) deployment controls — impose human oversight, error-reporting and fallback/manual processes; (7) monitoring and incident response — ensure breach detection, notification and remediation capabilities; and (8) documentation and transparency — publish plain-language statements on AI use, data practices and redress routes. The OPC also advises smaller organisations to err on the side of caution: avoid putting personal or sensitive information into third-party AI tools unless contractual and technical safeguards are demonstrably in place.

Monitoring and Evaluation

Monitoring should be continuous and multi-modal: technical monitoring (model performance, drift, error rates), privacy monitoring (access logs, prompt capture, retention checks) and governance monitoring (PIA reviews, contract audits, supplier assurance). The guidance recommends scheduled re-testing, post-deployment audits, incident logging and community feedback mechanisms, and the maintenance of records to demonstrate compliance. Organisations should document evidence of board/executive approvals, PIAs/AIAs, user notices, Māori engagement, testing outcomes, and supplier assurances. Where privacy risks materialise, organisations must follow breach-notification obligations under the Privacy Act and undertake remediation with transparency toward affected people.

Penalties, Liability, and Appeals

The OPC guidance is non-binding but sits within the enforcement architecture of the Privacy Act 2020. Organisations that fail to meet statutory obligations may face OPC investigations, compliance notices, published findings, and potential referral to the Human Rights Review Tribunal where individuals seek remedies. The Privacy Act contains criminal sanctions for some offences (for example failing to notify the Commissioner of a notifiable privacy breach can attract a monetary penalty), and remedies through tribunals or courts may include compensation and orders to change practices. The OPC emphasises reputational and contractual risks in addition to regulatory consequences and encourages proactive remediation, transparency, and engagement with the regulator to reduce enforcement risk.

Relationship to Other Instruments

The guidance cross-references New Zealand instruments and sectoral rules: the Privacy Act 2020 and associated Codes of Practice such as the Health Information Privacy Code 2020; public-sector AIA guidance and the Algorithm Impact Assessment user guide; procurement and cybersecurity guidance (including CERT NZ and GCSB materials on secure AI); and international instruments and standards (OECD AI principles, EDPB/ICO materials). The OPC positions its guidance as complementary to other statutory and non-statutory frameworks and recommends coordination across legal, human-rights, cyber security, procurement and indigenous-data-governance regimes to manage AI-associated privacy risks coherently.

International Alignment

The OPC situates New Zealand guidance within global developments: it references the alignment of privacy-by-design and transparency principles with international privacy regulators and standards bodies. The guidance acknowledges rapid international work on AI governance (EU AI Act deliberations, EDPB/ICO guidance, and cross-jurisdictional enforcement cooperation) and encourages organisations to track international standards, supplier commitments and model provenance, especially where models or services are provided from overseas. The OPC also highlights transborder data transfer considerations in light of disclosure and cross-border IPP rules and encourages contractual and technical safeguards for overseas processing.

Implementation Timeline

MilestoneDate
Commissioner expectations issued (initial statement)2023-06-15
Full guidance published (AI and the IPPs)2023-09-21
Recommended: organisations begin PIAs/AIAs for planned AI projectsOngoing from 2023-09
OPC monitoring and iterative updates to guidanceOngoing

Sources and References

SourceType
Artificial Intelligence and the Information Privacy Principles (OPC AI topic page)Primary Source
AI and the Information Privacy Principles (full OPC guidance PDF)Primary Source

Requirements for a company

What an organisation has to do under New Zealand - AI Privacy Guidance, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

9
  • Obtain explicit senior leadership approval informed by risk assessments before deploying AI tools.Organisations in New Zealand deploying AI tools using personal information
  • Conduct Privacy Impact Assessments and Algorithmic Impact Assessments during project governance and procurement.Organisations developing, procuring, or deploying AI systems
  • Engage proactively with Māori and affected communities to address data sovereignty and privacy concerns.Organisations using AI systems that impact Māori or local communities
  • Include privacy and security clauses in supplier contracts to restrict data retention and secondary use.Organisations procuring third-party AI services or tools
  • Ensure effective human review for AI-driven decisions that significantly affect individuals.Organisations using AI for automated decisions affecting individuals
  • Publish plain-language transparency statements explaining AI use, data handling practices, and available redress.Organisations deploying AI tools that interact with personal information
  • +3 more in the table below

Should not do

1
  • Do not input personal or sensitive information into third-party AI tools without robust contractual safeguards.Organisations utilizing third-party AI applications

Who must do what

The obligations under New Zealand - AI Privacy Guidance, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organisations in New Zealand deploying AI tools using personal informationObtain explicit senior leadership approval informed by risk assessments before deploying AI tools.
obtain explicit senior leadership approval informed by documented risk assessment and mitigations
Before deploymentRecommended
2Organisations developing, procuring, or deploying AI systemsConduct Privacy Impact Assessments and Algorithmic Impact Assessments during project governance and procurement.
integrate PIAs/AIAs into project governance and procurement
Before procurement or deploymentRecommended
3Organisations using AI systems that impact Māori or local communitiesEngage proactively with Māori and affected communities to address data sovereignty and privacy concerns.
engage with Māori and affected communities
Recommended
4Organisations procuring third-party AI services or toolsInclude privacy and security clauses in supplier contracts to restrict data retention and secondary use.
include privacy and security conditions in supplier contracts
Before contractingRecommended
5Organisations using AI for automated decisions affecting individualsEnsure effective human review for AI-driven decisions that significantly affect individuals.
ensure human review for decisions affecting people
Recommended
6Organisations deploying AI tools that interact with personal informationPublish plain-language transparency statements explaining AI use, data handling practices, and available redress.
publish plain-language statements on AI use, data practices and redress routes
Recommended
7Organisations developing or deploying AI modelsTest and validate AI tools with representative datasets for accuracy, bias, and robustness prior to deployment.
implement accuracy, bias and robustness testing with representative datasets
Before deploymentRecommended
8Organisations utilizing third-party AI applicationsDo not input personal or sensitive information into third-party AI tools without robust contractual safeguards.
avoid putting personal or sensitive information into third-party AI tools unless contractual and technical safeguards are demonstrably in place
Recommended
9Organisations contracting with third-party AI vendorsProhibit third-party AI providers from retaining or disclosing uploaded personal information without a lawful basis.
prevent AI providers from retaining or disclosing personal information without lawful basis
Recommended
10Organisations operating active AI tools processing personal dataMaintain continuous technical, privacy, and governance monitoring of deployed AI systems.
Monitoring should be continuous and multi-modal
Recommended

© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash