Skip to main content

Guide · Privacy

Using AI in your business under the NZ Privacy Act

You can use AI tools in a New Zealand business and still look after people's personal information. It comes down to a few habits: the right accounts, care with what goes in, a person checking what comes out, and being open with your customers.

1. Yes, the Privacy Act applies to AI

The Privacy Act 2020 covers personal information: anything about an identifiable person, such as a customer's name, email, health details or job history. Its 13 Information Privacy Principles apply however that information is handled, including when it is typed into an AI tool.

The Privacy Commissioner is clear that this includes staff using AI informally, and AI providers based overseas. If a team member pastes a client email into a chatbot, the Act applies to that too.

2. What the Privacy Commissioner expects

The Office of the Privacy Commissioner has published expectations for organisations using generative AI. In short:

  • Leadership signs off. Senior people should approve the use of AI tools after thinking through the risks.
  • Check it is needed. Consider whether AI is necessary and proportionate for the job.
  • Assess the privacy risks first. Do a privacy impact assessment before you start using a tool. For a small business this can be short.
  • Be open with people. Tell customers how, when and why you use AI if it affects them.
  • A person checks the output. Review what AI produces before you act on it.
  • Be careful what goes in. Do not enter personal or confidential information unless you have confirmed it is not kept or used by the provider.

3. The privacy principles that matter most

The Information Privacy Principles (IPPs) most relevant to AI
PrincipleWhat it meansWhat it means for AI
IPP1: PurposeOnly collect information you need for a lawful purposeUse AI for clear business purposes, not to gather extra data about people
IPP3: OpennessTell people what you collect and whySay in your privacy notice that you use AI tools
IPP5: SecurityProtect information from loss and misuseProtect prompts and files you give AI, and use accounts with proper admin controls
IPP8: AccuracyCheck information is correct before using itAI can be wrong, so a person checks before acting on it
IPP10 and 11: Use and disclosureOnly use and share information for the reason you collected itDo not let a provider reuse your customers' information, for example to train its AI
IPP12: Sending overseasRules for sending information outside New ZealandSee below. Most AI tools are run overseas

4. Is it a problem that the AI company is overseas?

Not by itself. The main AI providers store and process data outside New Zealand, often in the United States. The Privacy Commissioner's guidance says that using an overseas provider to store or process your data is not treated as sending it overseas under IPP12, as long as the provider is not using that information for its own purposes. You stay responsible for it either way.

That is why the type of account matters. Business plans are designed so the provider does not use your data for its own purposes. For example, Anthropic states that by default it does not use inputs or outputs from its commercial products, such as Claude Team, to train its models. OpenAI makes similar statements for its business plans. Free and personal accounts can work differently, so check the current terms for any tool before your team uses it for work.

5. What changed in 2025 and 2026

  • New principle IPP3A, in force from 1 May 2026. If you collect personal information about someone from another source rather than from them directly, you now generally need to take reasonable steps to tell them. There are exceptions, for example when the person already knows or the information is publicly available. Think about this if an AI or automation tool pulls information about people from other places.
  • Biometric Processing Privacy Code, in force from 3 November 2025. This covers tools that recognise people by their face, fingerprint, voice and similar features. It matters if you use voice or face recognition, not for everyday chat assistants.
  • Government guidance for businesses. MBIE published voluntary Responsible AI Guidance for Businesses in July 2025. It recommends knowing what personal information you hold, building privacy in from the start and being open about your use of AI.

6. If something goes wrong

Mistakes happen, such as a staff member pasting a customer list into a personal AI account. If a privacy breach has caused, or is likely to cause, serious harm, you must tell the Privacy Commissioner and the people affected. The Commissioner's guidance is to notify within 72 hours of becoming aware of it. Whether a particular AI mistake counts as a notifiable breach depends on the facts, such as how sensitive the information was and what the provider's terms allow.

The best protection is a simple rule that staff report mistakes straight away, so you can assess them quickly.

7. A practical checklist

  1. Approve each AI tool as a business decision, not something staff pick up on their own.
  2. Do a short privacy check before you start: what information will go in, and where does it go?
  3. Use business plans in your company's name, with no training on your data. Retire personal and free accounts for work.
  4. Keep sensitive information out unless you have confirmed how the provider stores and uses it.
  5. Have a person check AI output before it is sent or acted on.
  6. Update your privacy notice to say you use AI tools and why.
  7. Check IPP3A if any tool collects information about people from other sources.
  8. Name a privacy officer and have a breach plan, so mistakes are reported and assessed quickly.

8. How Nexron sets up AI with privacy in mind

When we set up AI for a business, we use business accounts in your company's name, explain in writing where your information goes and who can see it, keep sensitive records out of the AI unless you decide otherwise, and connect nothing without your OK. Every automation has a person approving important actions. We are not lawyers, so for legal advice on your situation we will point you to a privacy specialist.

See how this works in AI Set-Up & Training and AI Automation, or read about Nexron Connect. For costs, see How much does AI automation cost in NZ?

Sources

Questions about AI and privacy

Can my staff use free ChatGPT or Claude for work?

It is safer not to. Free and personal accounts can have different data terms from business plans. Give staff business accounts in your company's name, and keep customer information out of personal accounts.

Do I have to tell customers that we use AI?

The Privacy Commissioner expects businesses to tell people how, when and why AI is used if it affects them. Adding a short section to your privacy notice is a good start.

Do I need a privacy officer?

Yes. Every New Zealand organisation that holds personal information needs a privacy officer. In a small business this is usually the owner or manager.

Is AI safe for health or other sensitive records?

Take extra care. Keep sensitive records out of AI tools unless you have checked how the provider stores and uses them, and consider getting specialist advice first.

Want AI set up the careful way?

We set up business AI with privacy in mind from day one, and train your team in person.

027 869 0304 Book a Free Consultation Palmerston North based, working across New Zealand
Free consultation Tap to call