Reviewed by Jonathan West · Updated Aug 19, 2026

New Zealand Privacy Act 2020 and the Health Information Privacy Code: AI Compliance

What a New Zealand NGO must get right before it puts client or health data near an AI tool.

Reviewed by Jonathan West · Updated Aug 19, 2026

New Zealand has no single "health data AI" law. AI use is governed by the Privacy Act 2020 and, for health agencies, the Health Information Privacy Code 2020 (HIPC). Together they set the rules for collecting, using, storing, and disclosing personal and health information.

For an NGO, three things matter most. You must be open about AI use, keep client data secure, and treat sending health information to an overseas provider as a regulated act under Information Privacy Principle 12 (IPP 12).

This guide explains the regime in plain terms and gives a practical rollout checklist. It is general guidance, not legal advice. Verify each point on the official pages we cite and get professional review before you go live.


The Privacy Act 2020 and Its 13 Information Privacy Principles

The Privacy Act 2020 is New Zealand's main data-protection law and came into force on 1 December 2020.

It works through 13 Information Privacy Principles (IPPs) that apply to almost every organisation, or "agency", that handles personal information.

The principles cover the full lifecycle of personal data. IPP 1 to 4 govern collection, IPP 5 governs storage and security, IPP 6 and 7 give people access and correction rights, IPP 9 covers retention, IPP 10 and 11 cover use and disclosure, and IPP 13 governs unique identifiers.

IPP 12 was new in the 2020 Act. It controls disclosure of personal information to a person or organisation outside New Zealand, which is the principle that matters most when you use overseas cloud and AI providers.

The Office of the Privacy Commissioner (OPC) enforces the Act and publishes the official guidance you should rely on.

Rolling out AI in your NGO under the Privacy Act 2020 without breaching the Health Information Privacy Code? Layer3 Labs maps your data, runs the PIA, and builds an IPP 12-safe stack.

Book a Consultation

The IPPs That Matter Most for AI

For AI projects, a handful of principles carry most of the risk. Start with collection, security, access, and retention.

Collection principles (IPP 1 to 4) mean you only collect personal information you need, for a lawful purpose, in a fair way, and usually from the person directly. Feeding client records into an AI tool is a new use you must be able to justify.

Security (IPP 5) requires reasonable safeguards against loss, misuse, and unauthorised access. This covers your AI prompts and any data the tool stores or logs.

Access and correction (IPP 6 and 7) let people see and fix their information. If an AI system holds or generates records about a client, those records are in scope.

Retention (IPP 9) says you must not keep personal information longer than needed. Check whether an AI vendor retains prompts or uses them to train models.

Use and disclosure (IPP 10 and 11) limit you to using information for the purpose it was collected and restrict sharing it. Unique identifiers (IPP 13) limit how you assign and use identifiers like the National Health Index number.

  • IPP 1 to 4: collect only what you need, fairly, for a clear purpose.
  • IPP 5: keep prompts, outputs, and stored data secure.
  • IPP 6 and 7: honour access and correction requests over AI-held data.
  • IPP 9: do not let a vendor retain data longer than you need.
  • IPP 10, 11, 13: limit use, disclosure, and use of identifiers.

IPP 12: Sending Health Data to Overseas AI and Cloud Providers

IPP 12 is the offshore rule, and it is the principle most NGOs miss. It applies the moment client data leaves New Zealand for a provider based overseas.

Most mainstream AI and cloud services host or process data outside New Zealand. Using Microsoft Azure, Microsoft 365, or an overseas AI API can count as a disclosure to a foreign recipient.

Under IPP 12 you may only make that disclosure if you meet one of its conditions. The recipient must be subject to the Privacy Act, be bound by a prescribed scheme or approved country, be subject to comparable privacy laws, or be required by contract to provide comparable safeguards. As an alternative, the individual can authorise the transfer after being told the overseas recipient may not have to protect the data to New Zealand's standard.

In practice this means "comparable safeguards or informed authorisation". For a health NGO, the cleanest routes are keeping health data hosted in New Zealand, or signing a contract with the provider that requires comparable protection.

Check where the service actually processes and stores data. Some Azure and Microsoft services offer New Zealand or Australia data residency, but consumer AI chatbots generally do not.

IPP 12 is not a formality. Sending client health data to an overseas AI tool without one of its legal bases can itself be a breach.

The Health Information Privacy Code 2020

The Health Information Privacy Code 2020 (HIPC) is a code of practice issued by the Privacy Commissioner for the health sector.

It restates the Privacy Act's principles as 13 Health Information Privacy Rules that apply specifically to health information held by "health agencies".

A health agency is any organisation that provides health or disability services, or that otherwise handles health information in the sector. Examples include general practices, rest homes, pharmacists, hospitals, ACC, health insurers, and the Ministry of Health.

If your NGO delivers health or disability services, or holds clients' medical information, the HIPC rules apply to that data instead of the general IPPs.

The rules mirror the IPP numbering. Rule 5 covers storage and security, Rule 11 covers disclosure, and Rule 12 covers sending health information outside New Zealand, so the offshore analysis above applies to your health records too.

Health information is treated as sensitive, so regulators expect a higher standard of care around it than for ordinary personal data.


The Notifiable Privacy Breach Regime (Part 6)

Under Part 6 of the Privacy Act 2020, you must report a privacy breach that is likely to cause serious harm.

You notify both the Privacy Commissioner and the affected people as soon as practicable after you become aware the breach is notifiable.

To judge "serious harm", the Act asks you to weigh factors such as how sensitive the information is, what harm could result, whether it was protected by security like encryption, and who may have obtained it.

The OPC runs an online tool called NotifyUs to help you decide whether a breach must be reported and to file the notification.

Failing to notify a notifiable breach is an offence and can attract a fine. An AI incident, such as client data leaking through a mis-configured tool or a shared prompt log, can be a notifiable breach.

Build breach assessment into your AI rollout from day one, not after something goes wrong.


The Privacy Commissioner's AI Guidance and Expectations

The OPC has published guidance on using AI tools and how the IPPs apply to them, most recently expanded in September 2023.

Its core message is caution: if in doubt, do not use AI tools to handle personal information.

The guidance sets clear expectations before you adopt an AI tool. Senior leadership should review and explicitly approve the tool, and you should complete a Privacy Impact Assessment (PIA) first and keep it updated.

It also expects transparency with the people affected, engagement with communities including Māori, and human review of AI output rather than blind reliance.

Other expectations include data minimisation, checking that training data is relevant and reliable, keeping prompts and data secure, and using contracts to lock in safeguards.

In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is staff pasting client data into consumer AI tools that have no contract and no data-residency guarantee.

  • Get senior leadership sign-off before adopting an AI tool.
  • Run a Privacy Impact Assessment and keep it current.
  • Be transparent, engage communities including Māori, and keep a human in the loop.
  • Minimise data, secure prompts, and use contracts for safeguards.

How an NGO Adopts AI Under NZ Law: A Practical Checklist

A compliant AI rollout follows a clear order: classify, assess, contract, control, and train. Work through it before any client data touches a tool.

First, classify your data. Separate ordinary personal information from health information, because the HIPC rules and higher expectations apply to the latter.

Then assess the risk with a Privacy Impact Assessment, and get leadership to approve the specific tool and use case in writing.

Next, deal with the offshore question under IPP 12. Keep health data hosted in New Zealand where you can, or sign a contract that requires comparable safeguards before any data goes overseas.

Finally, put day-to-day controls in place. Keep a human reviewing AI output, tell clients how you use AI, log and secure prompts, and train staff on what they must never paste into a tool.

  • Classify data: separate health information from ordinary personal data.
  • Run a PIA and get written leadership approval for the tool.
  • Vet the vendor contract for security, retention, and non-training terms.
  • Handle IPP 12: keep health data onshore or secure comparable safeguards.
  • Keep a human in the loop and be transparent with clients.
  • Train staff and ban consumer AI tools for client or health data.

New Zealand Has No HIPAA: The Equivalent Explained

New Zealand has no exact equivalent of the United States' HIPAA. The Privacy Act 2020 and the Health Information Privacy Code together do the job HIPAA does in the US.

The models differ in structure. HIPAA is a dedicated federal health-privacy law with its own Business Associate Agreement (BAA) mechanism for vendors.

New Zealand instead layers a health code over a general privacy law, and relies on contracts plus IPP 12 rather than a single named agreement.

So a vendor's HIPAA compliance is helpful evidence of good practice, but it does not by itself satisfy New Zealand law. You still need to meet the Privacy Act and the HIPC on their own terms.

If a provider offers a HIPAA BAA, treat it as a starting point, then confirm data residency and comparable safeguards for IPP 12.

Frequently Asked Questions

  • Yes. New Zealand has no separate AI law, so AI use is governed by the Privacy Act 2020 and its 13 Information Privacy Principles. For health information, the Health Information Privacy Code 2020 applies. The Privacy Commissioner has also published specific guidance on AI and the principles.
  • IPP 12 controls disclosing personal information to a person or organisation outside New Zealand. It matters because most AI and cloud providers process data overseas. You may only disclose if the recipient is subject to comparable safeguards, or the individual authorises the transfer after being informed the recipient may not meet New Zealand's standard.
  • You are likely a health agency if you provide health or disability services or otherwise handle health information. Examples include practices, rest homes, insurers, and providers of disability support. If the HIPC applies, its 13 Health Information Privacy Rules govern that data instead of the general IPPs.
  • Possibly, but only with the right controls. You must satisfy IPP 12 for any overseas processing, which usually means data-residency settings that keep data in New Zealand or Australia, plus a contract requiring comparable safeguards. Consumer chatbots without a contract or data-residency guarantee are generally not suitable for client health data.
  • You must notify the Privacy Commissioner and affected people when a breach is likely to cause serious harm, as soon as practicable after you become aware of it. The OPC's NotifyUs tool helps you decide. Failing to notify a notifiable breach is an offence, so assess every AI incident against the serious-harm test.
  • No. HIPAA is a United States law, and New Zealand has no exact equivalent. A HIPAA Business Associate Agreement is useful evidence of good practice but does not by itself satisfy the Privacy Act 2020 or the HIPC. You still need to meet New Zealand's principles, including IPP 12 on overseas disclosure.
  • Run a Privacy Impact Assessment, classify your data, and get written leadership approval for the specific tool and use case. Confirm where the vendor stores and processes data, check retention and training terms in the contract, keep a human reviewing output, and train staff. The OPC expects all of this before you go live.
  • No. This is general guidance to help you understand the regime. Privacy law is fact-specific, so verify each point on the official Office of the Privacy Commissioner and legislation.govt.nz pages, and get professional legal review before you deploy AI with client or health data.

Roll Out AI Without Breaching NZ Privacy Law

Layer3 Labs helps New Zealand NGOs and health-adjacent organisations adopt AI under the Privacy Act 2020 and the Health Information Privacy Code. We map your data, run the Privacy Impact Assessment, and design an IPP 12-safe stack. Book a free AI compliance review to see where you stand.

Book a Compliance Review