Privacy education, consultancy & implementation in 50+ jurisdictions.enquiry@vedhacon.com
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Australia · New Zealand · Privacy law

Two neighbouring regimes, different compliance tests.

Australia’s Privacy Act 1988 and New Zealand’s Privacy Act 2020 share accountability, security, access and correction principles. Their coverage, overseas-disclosure rules and enforcement pathways differ enough that a single regional policy needs local controls.

Researched against OAIC, Australian Government, New Zealand legislation and Privacy Commissioner sources on . Written by Shambhu Kumar, Vedhacon.

Regional orientation

Similar principles do not mean interchangeable controls

Both regimes regulate the lifecycle of personal information and expect organisations to be transparent, minimise collection, maintain quality and security, and support access and correction. The practical split starts with scope: Australia generally covers Australian Government agencies, organisations above the statutory turnover threshold and specified categories; New Zealand uses a broad agency concept and expressly reaches some overseas agencies carrying on business in New Zealand.

Governance first

Assign ownership, maintain a personal-information inventory, and connect privacy controls to procurement, security and incident response.

Design for both

Use the stricter local rule where one process serves both markets, but document which law and entity each control supports.

Evidence decisions

Keep collection notices, access decisions, vendor diligence, retention rules and breach assessments auditable.

Australia

Privacy Act 1988 and the Australian Privacy Principles

Who is covered

Australian Government agencies and many private-sector organisations, generally including businesses with annual turnover above A$3 million plus specified smaller entities such as health service providers and organisations trading in personal information.

The 13 APPs

The APPs cover open and transparent management, anonymity and pseudonymity, collection, notice, use and disclosure, direct marketing, cross-border disclosure, identifiers, data quality, security, access and correction.

Security and retention

APP 11 requires reasonable steps to protect personal information and to destroy or de-identify it when no longer needed, subject to lawful retention requirements.

Individual rights

APP 12 and APP 13 provide access and correction rights. Unlike GDPR, the federal Act does not present a single equivalent catalogue of erasure, portability and objection rights.

Reform watch: the Privacy and Other Legislation Amendment Act 2024 introduced the first reform tranche. A further 2026 reform package remained a consultation proposal at the research date; do not treat draft measures as operative requirements.

New Zealand

Privacy Act 2020, strengthened by IPP3A

Broad agency scope

The Act generally applies across public and private sectors. Its territorial provisions can cover an overseas agency carrying on business in New Zealand, whether or not it has a physical presence there.

Information privacy principles

The IPPs govern purpose, source, notice, manner of collection, storage and security, access, correction, accuracy, retention, use, disclosure, overseas disclosure and unique identifiers.

IPP3A from 1 May 2026

An agency that collects personal information indirectly must take reasonable steps to notify the individual as soon as reasonably practicable, unless a statutory exception applies. Notices cover the collection, purpose, recipients, agency details, legal authority, and access and correction rights.

Enforcement pathway

The Privacy Commissioner investigates and can issue compliance notices. Complaints may proceed through the Human Rights Review Tribunal, which can grant remedies including damages.

Side by side

Where the operating model changes

IssueAustraliaNew ZealandControl implication
Primary frameworkPrivacy Act 1988; 13 APPsPrivacy Act 2020; IPPs including IPP3AMap each processing activity to the correct entity and principle.
Typical private-sector scopeTurnover threshold plus specified categories and exceptionsBroad agency definitionDo not apply Australia’s small-business threshold to New Zealand.
Access and correctionAPPs 12 and 13IPPs 6 and 7Use local response grounds, timing and escalation routes.
Indirect collection noticeAPP 5 notice obligations apply to collection circumstancesSpecific IPP3A duty from 1 May 2026Update broker, enrichment, referral and data-sharing workflows.
Overseas disclosureAPP 8 accountability model, subject to exceptionsIPP 12 prescribed safeguard or authorisation routesRecord destination, recipient, safeguards and relied-on route.
Notifiable breachLikely serious harm; notify OAIC and affected individualsCaused or likely to cause serious harm; notify Commissioner and affected peopleUse one triage process with jurisdiction-specific decision records.
Incident response

A four-stage ANZ breach workflow

Contain

Stop further access, loss or disclosure while preserving evidence and system logs.

Assess

Identify information, people, likely consequences, mitigation and the applicable serious-harm test.

Notify

Where the threshold is met, notify the relevant regulator and affected people using the local statutory content and timing rules.

Remediate

Document root cause, control changes, communications, vendor actions and residual risk.

Australia: the NDB scheme applies when an eligible data breach is likely to result in serious harm. New Zealand: a notifiable privacy breach is one that has caused or is likely to cause serious harm, and notification must be made as soon as practicable.

Cross-border data

The transfer routes are not the same

Australia · APP 8

Before disclosing personal information overseas, an APP entity generally takes reasonable steps to ensure the recipient does not breach the APPs. The Australian entity can remain accountable for the recipient’s conduct, subject to statutory exceptions.

New Zealand · IPP 12

Overseas disclosure must fit an IPP 12 route, such as the recipient being subject to the Act, comparable privacy safeguards, an approved binding scheme, contractual comparable safeguards, or informed authorisation where protection may not be comparable.

Operational rule: distinguish a disclosure to an independent overseas recipient from storage or processing by a provider acting solely on your behalf; then document the legal route, contractual safeguards, access locations and onward-transfer controls.

Implementation

What to do now

1. Confirm coverage

Record the Australian entity, turnover and exception analysis; separately document New Zealand territorial scope.

2. Refresh notices

Map direct and indirect collection. Add IPP3A notices to enrichment, referral, fraud, recruitment and shared-service flows.

3. Map vendors

Identify overseas recipients, hosting locations, subprocessors and the APP 8 or IPP 12 transfer route.

4. Test rights handling

Run access and correction exercises with local identity checks, exceptions, response letters and escalation paths.

5. Rehearse breaches

Use scenarios to test serious-harm assessment, regulator notification, individual communications and evidence capture.

6. Track reform

Separate enacted obligations from consultations and update the control register only when commencement is confirmed.

Frequently asked

Practical questions

Do both countries use 13 principles?

Australia has 13 APPs. New Zealand’s framework is organised as information privacy principles and now includes the additional IPP3A indirect-collection notification rule.

Is consent always required?

No. Both regimes regulate purpose and fairness through detailed collection, use and disclosure rules rather than treating consent as the only possible basis.

Must every breach be reported?

No. Both schemes use a serious-harm threshold, but every suspected incident should be contained, assessed and recorded.

Can one privacy notice cover ANZ?

Yes, if it clearly addresses both regimes and the actual data flows. Local supplements are often cleaner where entities, rights contacts or transfer routes differ.

Primary sources

Verify against the current law

This page is general information, not legal advice. Confirm current commencement, sector rules and regulator guidance for the processing activity concerned.