If your website collects personal information, and a contact form, quote request or newsletter sign-up all do, then in practice yes, you need a privacy statement. The Privacy Act 2020 says that when you collect information from people, you have to tell them what you're collecting and why.
What the Privacy Act asks of a website
The Act is built on information privacy principles. The ones that touch a small business website:
| Principle | What it means for your website |
|---|---|
| 1 | Only collect what you need. If a name and phone number will do, don't ask for a date of birth. |
| 3 | Tell people when you collect their information. This is what your privacy statement does. |
| 5 | Keep it secure, including the inbox where enquiries land. |
| 6 and 7 | People can see and correct what you hold about them. |
| 11 | Don't pass it on unless that's why you collected it, or another exception applies. |
| 12 | Extra rules apply when you disclose information to someone overseas. |
The new rule from May 2026
The Privacy Amendment Act 2025 added principle 3A, which came into force on 1 May 2026. It covers information you get about someone from somebody else, rather than from them.
For a small business, that's usually referrals and leads. If a partner passes on someone's details, you generally need to take reasonable steps to tell that person:
- that you have their information
- why
- who it goes to
- how to see or correct it.
There are exceptions, such as when they already know or the information is publicly available.
What to put in your privacy statement
The Privacy Commissioner's guidance on privacy statements lists what people should know. For a website, use this as a checklist:
- What you collect. The fields on each form, plus anything collected in the background: analytics, cookies, a Meta pixel, chat widgets.
- Why. To reply to an enquiry, send a quote, send a newsletter they asked for.
- Who it goes to. Your email provider, form or booking service, CRM and analytics provider. Many are overseas. If they only store it for you, the Commissioner's overseas guidance says that usually isn't a disclosure under principle 12, but say where it's held anyway.
- How long you keep it. Principle 9 says not longer than you need it.
- Whether they have to give it, and what happens if they don't.
- How to ask for access or correction, and who to contact.
That contact is your privacy officer. The Act requires every organisation to have at least one. In a small business that's usually the owner.
The Commissioner has a free tool, the Priv-o-matic, that builds a basic privacy statement from your answers. Check the result against what your site actually does.
Common mistakes
- Copying an overseas template. A policy written for the GDPR or US law talks about rights and rules that don't apply here, and can miss what NZ law asks for. The Privacy Commissioner has warned about this: your policy needs to reflect the Privacy Act 2020.
- A policy that doesn't match the site. The statement says you collect a name and email, but the site also runs Google Analytics, a Meta pixel and a chat widget nobody mentioned. Check what's actually installed. If you use tracking cookies, our guide to cookie banners in NZ covers that side.
- Writing it once and forgetting it. Add a booking system or a new form and the policy is out of date. Update it when the site changes.
If something goes wrong
Enquiries lost to a broken contact form are a business problem, not usually a privacy one. A hacked site is different.
If personal information is accessed or leaked and it's reasonable to believe someone has suffered or is likely to suffer serious harm, that's a notifiable privacy breach. Then:
- You must tell the Privacy Commissioner as soon as practicable, ideally within 72 hours, using its NotifyUs tool.
- You must also tell the people affected.
- Get the site cleaned up. Start with our hacked website guide.
When to get help
You can write this yourself. Get help when:
- You're not sure what scripts, cookies or tracking your site runs.
- You collect sensitive information, such as health details, or share data with partners.
- You think you've had a breach. Talk to a lawyer, and the Privacy Commissioner's office.
For a second opinion on your site, start with our free website check.