WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

New Zealand privacy law has moved further in the last eighteen months than in the four years before it. If your privacy documentation was written when the Privacy Act 2020 came into force and has not been touched since, it is now out of date in at least two specific ways.

What changed, and when

October 2025: ISO 27701 became a standalone standard

Until the 2025 revision, ISO 27701 was an extension to ISO 27001. You could not certify to it on its own. The 2025 edition removed that dependency, so an organisation can now be certified to ISO/IEC 27701 as a standalone Privacy Information Management System, with or without ISO 27001. Most privacy content still says otherwise.

November 2025: The Biometric Processing Privacy Code came into force

New Zealand's first dedicated rulebook for biometric processing, issued by the Privacy Commissioner under the Privacy Act. It applies to facial recognition, fingerprint and voiceprint processing, and it requires organisations to demonstrate that collection is necessary, effective and proportionate before deployment. It took effect for new biometric processing from 3 November 2025.

May 2026: IPP3A took effect

The Privacy Amendment Act 2025 introduced Information Privacy Principle 3A, requiring agencies to take reasonable steps to notify individuals when their personal information has been collected indirectly, meaning from someone other than the person themselves. Data brokers, third party enrichment, scraped sources. It applies to information collected from 1 May 2026 and there are exceptions, but the default is now notification.

August 2026: The biometric grace period ended

The transitional relief for biometric processing already underway before the Code came into force expired on 3 August 2026. Organisations running door readers, payroll time clocks or retail cameras that were installed before November 2025 no longer have a grace period to rely on.

The advantage New Zealand has and Australia does not

EU adequacy
New Zealand holds an adequacy decision from the European Commission, meaning personal data can flow from the European Union to New Zealand without additional safeguards. Australia does not have one. For a New Zealand business processing European personal data, or competing against Australian providers for European work, that is a real commercial advantage. Maintaining alignment with international privacy standards is part of what protects it, which is one reason the IPP3A amendment was framed as supporting adequacy.

ISO 27701 is the management system standard most commonly used to demonstrate that alignment. It maps to GDPR concepts directly, which makes it the practical bridge between New Zealand obligations and European customer expectations.

Two vocabularies you have to hold at once

New Zealand privacy law does not use the controller and processor distinction. The Privacy Act refers to agencies, and an agency that holds information on behalf of another is generally treated as the other agency holding it. ISO 27701 uses PII controller and PII processor, following international convention.

This is not a problem, but it is a translation exercise, and it is where trans-Tasman and international templates go wrong. We document the role determination in ISO terms because that is what the certification body audits, and we map it back to agency obligations under the Privacy Act because that is what the Privacy Commissioner enforces.

Standalone or alongside ISO 27001?

Standalone PIMS

Suits organisations whose primary exposure and primary customer question is privacy rather than broad information security. Health and wellbeing services, education providers, membership organisations, HR and recruitment platforms, marketing and customer data businesses. If nobody has asked you for ISO 27001, standalone is faster, narrower and cheaper to maintain.

Combined with ISO 27001

Suits organisations already certified, or being asked for security certification by customers. The two share governance, risk methodology, internal audit and management review, so running them together avoids duplicating all of it. If you already hold ISO 27001, adding 27701 is a materially smaller project than either alone.

How Nathan ISO Consulting assists

First: Establishing ground truth

  • Personal information inventory: what you collect, why, where it lives, who processes it, and how long you keep it.
  • Indirect collection audit against IPP3A. Where does personal information reach you from somewhere other than the individual, and what notification now applies?
  • Biometric processing assessment where facial recognition, fingerprint or voiceprint systems are in use, including the proportionality assessment the Code requires.
  • Role determination in ISO terms, mapped back to Privacy Act agency obligations.
  • Gap assessment against ISO/IEC 27701:2025, the Privacy Act 2020 and the Information Privacy Principles together.

Second: Building the system

  • Privacy policy and external notices, updated for indirect collection notification.
  • Statement of Applicability, standalone or combined with an ISO 27001 SoA.
  • Access and correction request procedure under IPP 6 and IPP 7, with realistic internal timeframes.
  • Breach assessment and notification runbook built to the serious harm test, not to a European clock.
  • Privacy impact assessment methodology and templates.
  • Cross-border disclosure controls under IPP 12, and supplier and processor agreements.
  • Retention and disposal schedules that someone actually owns.

Third: Proving it works

  • Role-specific training for anyone handling requests or breach triage.
  • Internal audit against the standard and against your IPP obligations.
  • Documented management review, certification body selection, and attendance at Stage 1 and Stage 2.
  • Ongoing support as the regime continues to develop.

Why organisations choose Nathan

What you will hear elsewhereWhat is actually true
"You need ISO 27001 before ISO 27701"Not since October 2025. Standalone PIMS certification is available and is often the better fit
"You have 72 hours to notify a breach"That is the GDPR. New Zealand applies a serious harm test with notification as soon as practicable and no fixed clock
"Australian privacy guidance covers New Zealand"It does not. New Zealand uses Information Privacy Principles, not Australian Privacy Principles, and holds EU adequacy that Australia lacks
"Biometrics are just personal information"Since November 2025 they have their own Code with a proportionality requirement, and the grace period has ended
"Privacy is a policy exercise"Privacy is an inventory exercise first. Until you know what you hold and where it came from, the policy is guesswork
"We will look at IPP3A later"It applies to information collected from 1 May 2026. Later has already arrived

Where we work

Privacy work runs largely remotely, with workshops and data mapping sessions on site where being in the room helps. Auckland accounts for most of our New Zealand privacy work across health technology, financial services, retail, education technology and SaaS. Wellington work is weighted toward government agencies and contracted providers. Christchurch, Hamilton, Tauranga, Dunedin, Palmerston North, Napier and Nelson clients span health, education, membership organisations and professional services.

Frequently asked questions

Yes, since the 2025 edition. ISO/IEC 27701:2025 is a standalone management system standard, so certification is available on its own. Guidance stating otherwise reflects the superseded 2019 edition, which existed only as an extension to ISO 27001.

Information Privacy Principle 3A requires agencies to take reasonable steps to notify individuals when their personal information has been collected indirectly rather than from the person themselves. It applies to information collected from 1 May 2026, subject to a set of practical exceptions.

No standard confers legal compliance. ISO 27701 gives you the structure, controls and evidence to demonstrate that personal information is managed deliberately. We map the standard against the Information Privacy Principles so you can show where each obligation is met.

There is no fixed deadline. Where a breach is likely to cause serious harm you must notify the Privacy Commissioner and affected individuals as soon as practicable after becoming aware of it. The 72-hour figure comes from the GDPR and does not apply here.

Organisations processing biometric information must demonstrate that collection is necessary, effective and proportionate, disclose the purpose, inform people of alternatives, identify recipients, specify retention, and provide a complaints process. It applied to new processing from November 2025.

No. The transitional relief for biometric processing already underway before the Code took effect expired on 3 August 2026. Legacy door readers, time clocks and camera systems now carry the same obligations as newly deployed ones.

It means personal data can flow from the European Union to New Zealand without additional safeguards, which simplifies European contracts considerably. Australia does not hold an adequacy decision, so New Zealand providers have a genuine advantage when competing for European work.

New Zealand law uses the term agency rather than controller and processor, but ISO 27701 uses the international terms and that is what a certification body audits. Most organisations are both, depending on the activity, and we document it activity by activity.

Considerably. The standard was written with GDPR concepts in mind and the 2025 edition strengthens that alignment. For New Zealand organisations with European customers, a PIMS is the most practical way to run one privacy system across both regimes.

You will transition to the 2025 edition on your certification body's timeline. Most existing content carries across. The main work is restructuring the Statement of Applicability and adjusting for the standard operating independently rather than as an ISO 27001 extension.

Around 14 to 24 weeks for a standalone PIMS, and considerably less where ISO 27001 is already certified. The personal information inventory determines the timeline and is the phase organisations most often underestimate.

Possibly. New Zealand has codes covering health information, credit reporting, telecommunications and biometric processing, among others. Where a code applies it modifies the Information Privacy Principles for your sector, and the obligations register has to reflect the code rather than the base principles.

Start with the inventory

If you already have a personal information inventory, send it through. If you do not, that is where we begin, and it is the single most useful thing your organisation can own whether or not you go on to certify.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance