Insights

The Privacy Act 2020 and AI: what NZ organisations can actually do with customer data

Australia gets automated decision-making disclosure obligation on 10 December 2026, which we covered here. New Zealand isn’t thinking the same way yet. The Law Commission is starting a review of automated decision-making in the public sector later in 2026, but there’s no bill in sight. If you run an AI-driven decision system and you were waiting for NZ-specific AI legislation, the honest answer is that there probably won’t be anything soon.

What NZ organisations do have is the Privacy Act 2020, thirteen Information Privacy Principles written before ChatGPT. The Office of the Privacy Commissioner (OPC) has said in September 2023 that all thirteen apply to AI across its full lifecycle, which means automated decisions is included. No new law was needed, because the old one already reaches this far.

Why the gap is a choice, not an oversight

This is not New Zealand running behind. The government’s AI Strategy, released in July 2025, commits explicitly to “light touch, proportionate” regulation through existing, technology-neutral law (privacy, consumer protection, human rights) rather than a standalone AI statute. The stated reasoning is that regulatory uncertainty slows AI adoption more than gaps in coverage do.

That is a real policy bet, and it is the opposite bet to the one Australia and the EU have made. They are choosing purpose-built rules for certainty. New Zealand is choosing flexibility for business, and asking a 2020 privacy act, built on principles that trace back to 1993, to stretch over a technology nobody was regulating for when they were written. Whether that bet pays off is a fair question. What it means today is not in dispute: the stretch is the compliance environment New Zealand organisations are actually operating in.

The principle that gets missed: you can’t hide behind the algorithm

The OPC’s clearest line is also the one worth repeating internally: agencies remain responsible for decisions made using AI tools, and reliance on an automated system does not displace existing Privacy Act obligations. “The model decided” is not a defence under IPP anything. If a decision affecting a customer was wrong, biased or unexplainable, the organisation that deployed the system owns that outcome, not the vendor, not the model.

Automated decision-making has been an OPC priority area since 2023, specifically because of bias risk. The practical expectation that follows is meaningful human oversight on significant decisions, not automation for its own sake, and not a rubber stamp either.

Four principles that do the real work

None of these four were written about AI. They matter to it anyway.

Four Information Privacy Principles most relevant to AI-driven decisions under New Zealand's Privacy Act 2020: IPP 8 accuracy before use, IPP 10 limits on use, IPP 6 access, and IPP 7 correction.

IPP 8, accuracy before use, requires reasonable steps to check personal information is accurate, current and relevant before it is used, and a decision is a use. A model trained on stale addresses, outdated income figures or a data entry error is not a technical footnote if that data drives a credit, claims or eligibility decision. It is a live compliance question every time the decision runs.

IPP 10, limits on use, restricts personal information to the purpose it was collected for. Transaction data collected to process a payment, later repurposed to train a churn or risk model without a fresh look at consent or notice, is exactly the kind of quiet scope creep this principle exists to catch. AI makes repurposing data easy. IPP 10 does not care that it got easier.

IPP 6 and IPP 7, access and correction, give customers the right to ask what you hold about them and to have it fixed if it is wrong, and if you refuse a correction, to have their statement of disagreement attached to the record. For an automated decision system, this is not paperwork. It is the mechanism by which a customer contests the exact data that produced a decision about them, and it only works if the correction actually reaches the system making the decision, not just a customer service database three systems away from it.

What this means in practice

Technically, no new legislation is required, but it depends on how the law is interpreted and applied. At a minimum, firms should conduct an honest inventory of where AI touches customer decisions.

  1. Is the data behind each automated decision demonstrably current and accurate, not just collected once and trusted forever.
  2. Was that data collected for this purpose, or a different one the customer never saw coming.
  3. Can a customer actually get access to what fed a decision about them, in a form that means something.
  4. And when customers ask for a correction, does it reach the model or the ruleset, or does it just create a record nobody connects to the next decision?

The Privacy Act already governs the decisions AI consulting engagements build today, and it governs them now, in sectors like healthcare where the accuracy and purpose questions carry real weight. Honestly, NZ-specific AI law would probably make sense, and we think it will be required eventually.

The Law Commission’s review, whenever and however it lands, will very likely tighten what already applies rather than invent something new. Getting the four IPPs right today is not a stopgap. It is very probably the actual compliance bar, but it was written years before anyone needed it for this and it probably needs to be formally framed with an AI context for legal interpretation and application.

Let's talk about what you're trying to change.

A 30 minute call. No deck, no discovery workshop. Just the problem and whether we can help.

Book a call