Skip to content

Privacy policy for an NZ business website: what the Privacy Act 2020 expects

Does your NZ business website need a privacy policy? What the Privacy Act 2020 expects, what to put in it, and the mistakes to avoid.

By Miro, Wave Digital. Updated .

If your website collects personal information, and a contact form, quote request or newsletter sign-up all do, then in practice yes, you need a privacy statement. The Privacy Act 2020 says that when you collect information from people, you have to tell them what you're collecting and why.

What the Privacy Act asks of a website

The Act is built on information privacy principles. The ones that touch a small business website:

Principle What it means for your website
1 Only collect what you need. If a name and phone number will do, don't ask for a date of birth.
3 Tell people when you collect their information. This is what your privacy statement does.
5 Keep it secure, including the inbox where enquiries land.
6 and 7 People can see and correct what you hold about them.
11 Don't pass it on unless that's why you collected it, or another exception applies.
12 Extra rules apply when you disclose information to someone overseas.

The new rule from May 2026

The Privacy Amendment Act 2025 added principle 3A, which came into force on 1 May 2026. It covers information you get about someone from somebody else, rather than from them.

For a small business, that's usually referrals and leads. If a partner passes on someone's details, you generally need to take reasonable steps to tell that person:

There are exceptions, such as when they already know or the information is publicly available.

What to put in your privacy statement

The Privacy Commissioner's guidance on privacy statements lists what people should know. For a website, use this as a checklist:

That contact is your privacy officer. The Act requires every organisation to have at least one. In a small business that's usually the owner.

The Commissioner has a free tool, the Priv-o-matic, that builds a basic privacy statement from your answers. Check the result against what your site actually does.

Common mistakes

If something goes wrong

Enquiries lost to a broken contact form are a business problem, not usually a privacy one. A hacked site is different.

If personal information is accessed or leaked and it's reasonable to believe someone has suffered or is likely to suffer serious harm, that's a notifiable privacy breach. Then:

  1. You must tell the Privacy Commissioner as soon as practicable, ideally within 72 hours, using its NotifyUs tool.
  2. You must also tell the people affected.
  3. Get the site cleaned up. Start with our hacked website guide.

When to get help

You can write this yourself. Get help when:

For a second opinion on your site, start with our free website check.

Is your site slow on phones, out of date or marked "Not secure"?

Put in your web address and find out free in about 30 seconds.

Rather not deal with this yourself?

Safe includes a privacy policy written for your site and kept up to date with NZ privacy law, along with hosting, backups and security updates. Safe is $95 a month + GST, with no setup fee and no fixed term.