No. New Zealand's Privacy Act 2020 has no specific rule that says you need a cookie banner. But if your site tracks visitors, you still have to tell them, and a banner may matter if you sell to people in Europe or the UK.
What NZ law actually asks for
Information privacy principle 3 (IPP3) is about being open. When you collect personal information, people should know why and who will receive it. Tell them before you collect it, or as soon as practicable after.
On a website, the usual way to do that is a privacy statement. The Privacy Commissioner's guide to privacy statements lists collecting IP addresses, cookies and other analytics through your website as something to cover.
So for a typical NZ trade or service business, the job is to say plainly in your privacy statement what tracking runs on your site, what it's for and who gets the data. If you don't have one yet, start with what a privacy policy for an NZ website needs.
What's probably on your site
Common ones:
- Google Analytics. It sets a cookie called
_gato tell visitors apart, which by default lasts two years (Google). - The Meta (Facebook) pixel. It saves a unique identifier in a cookie called
_fbpso Meta can match visits to ads (Meta). - Google Ads tags, chat widgets, embedded YouTube videos and booking tools, which may set their own.
Cookies the site needs to work, like keeping someone logged in or holding a shopping basket, are what European guidance calls strictly necessary.
When you might need a banner
The EU and UK have a separate rule just for cookies. Under it, you need consent before setting cookies that aren't strictly necessary. The EU's business guidance names cookies for behavioural advertising, analytics and market research as needing it.
The GDPR can reach an NZ business. Article 3 covers businesses outside the EU that offer goods or services to people in the EU, or monitor their behaviour there. A plumber in Tauranga isn't offering services to Europeans. A tourism operator taking bookings from Germany may well be.
The UK has loosened its rules a little. Since the Data (Use and Access) Act, simple analytics used only to improve your site can run without opt-in consent, as long as you explain it and offer an easy way to object. Advertising cookies still need consent (ICO).
| Kind of cookie | Example | EU | UK |
|---|---|---|---|
| Strictly necessary | Keeping someone logged in, a shopping basket | No consent needed | No consent needed |
| Analytics | Google Analytics (_ga) |
Consent first | Simple analytics can skip opt-in, if you explain it and let people object |
| Advertising | Meta pixel (_fbp) |
Consent first | Consent first |
Google adds its own layer. Its EU user consent policy asks sites using its products to get valid consent from visitors in the EEA, UK and Switzerland where the law requires it. Google's consent mode passes each visitor's choice to your Google tags so they adjust.
A sensible approach for most NZ businesses
- List what's running. Check your plugins and ask whoever set up your ads.
- Remove what you don't use. Old pixels from a campaign that ended years ago are common. Every tracking script also slows the page down, which is one reason a site is slow on phones.
- Name the rest in your privacy statement. Say what each tool is for and who receives the data.
- Add a banner if you target the EU or UK. If you do, make it real.
- Consider cookie-free analytics. Tools like Cloudflare Web Analytics and Plausible count visits without setting cookies.
When to get help
It's worth a second pair of eyes if:
- You sell online to customers overseas, especially in Europe or the UK.
- You run Meta or Google ads and aren't sure what the tags collect.
- Your site was set up by someone else and nobody knows what's on it.
If you're not sure what your site is loading, our free website check is a good place to start.