Governance first
Assign ownership, maintain a personal-information inventory, and connect privacy controls to procurement, security and incident response.
Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.
Open the guideWe scope against the laws that actually apply to you, then sequence the work by risk.
Start the assessmentWhat must be operational before the substantive obligations commence in 2027.
Read the briefingAnswer 18 questions and get a prioritised control roadmap instantly.
Start the assessmentTrack 01 assumes no prior knowledge of governance, risk and compliance.
Start Track 01Australia’s Privacy Act 1988 and New Zealand’s Privacy Act 2020 share accountability, security, access and correction principles. Their coverage, overseas-disclosure rules and enforcement pathways differ enough that a single regional policy needs local controls.
Researched against OAIC, Australian Government, New Zealand legislation and Privacy Commissioner sources on . Written by Shambhu Kumar, Vedhacon.
Both regimes regulate the lifecycle of personal information and expect organisations to be transparent, minimise collection, maintain quality and security, and support access and correction. The practical split starts with scope: Australia generally covers Australian Government agencies, organisations above the statutory turnover threshold and specified categories; New Zealand uses a broad agency concept and expressly reaches some overseas agencies carrying on business in New Zealand.
Assign ownership, maintain a personal-information inventory, and connect privacy controls to procurement, security and incident response.
Use the stricter local rule where one process serves both markets, but document which law and entity each control supports.
Keep collection notices, access decisions, vendor diligence, retention rules and breach assessments auditable.
Australian Government agencies and many private-sector organisations, generally including businesses with annual turnover above A$3 million plus specified smaller entities such as health service providers and organisations trading in personal information.
The APPs cover open and transparent management, anonymity and pseudonymity, collection, notice, use and disclosure, direct marketing, cross-border disclosure, identifiers, data quality, security, access and correction.
APP 11 requires reasonable steps to protect personal information and to destroy or de-identify it when no longer needed, subject to lawful retention requirements.
APP 12 and APP 13 provide access and correction rights. Unlike GDPR, the federal Act does not present a single equivalent catalogue of erasure, portability and objection rights.
Reform watch: the Privacy and Other Legislation Amendment Act 2024 introduced the first reform tranche. A further 2026 reform package remained a consultation proposal at the research date; do not treat draft measures as operative requirements.
The Act generally applies across public and private sectors. Its territorial provisions can cover an overseas agency carrying on business in New Zealand, whether or not it has a physical presence there.
The IPPs govern purpose, source, notice, manner of collection, storage and security, access, correction, accuracy, retention, use, disclosure, overseas disclosure and unique identifiers.
An agency that collects personal information indirectly must take reasonable steps to notify the individual as soon as reasonably practicable, unless a statutory exception applies. Notices cover the collection, purpose, recipients, agency details, legal authority, and access and correction rights.
The Privacy Commissioner investigates and can issue compliance notices. Complaints may proceed through the Human Rights Review Tribunal, which can grant remedies including damages.
| Issue | Australia | New Zealand | Control implication |
|---|---|---|---|
| Primary framework | Privacy Act 1988; 13 APPs | Privacy Act 2020; IPPs including IPP3A | Map each processing activity to the correct entity and principle. |
| Typical private-sector scope | Turnover threshold plus specified categories and exceptions | Broad agency definition | Do not apply Australia’s small-business threshold to New Zealand. |
| Access and correction | APPs 12 and 13 | IPPs 6 and 7 | Use local response grounds, timing and escalation routes. |
| Indirect collection notice | APP 5 notice obligations apply to collection circumstances | Specific IPP3A duty from 1 May 2026 | Update broker, enrichment, referral and data-sharing workflows. |
| Overseas disclosure | APP 8 accountability model, subject to exceptions | IPP 12 prescribed safeguard or authorisation routes | Record destination, recipient, safeguards and relied-on route. |
| Notifiable breach | Likely serious harm; notify OAIC and affected individuals | Caused or likely to cause serious harm; notify Commissioner and affected people | Use one triage process with jurisdiction-specific decision records. |
Stop further access, loss or disclosure while preserving evidence and system logs.
Identify information, people, likely consequences, mitigation and the applicable serious-harm test.
Where the threshold is met, notify the relevant regulator and affected people using the local statutory content and timing rules.
Document root cause, control changes, communications, vendor actions and residual risk.
Australia: the NDB scheme applies when an eligible data breach is likely to result in serious harm. New Zealand: a notifiable privacy breach is one that has caused or is likely to cause serious harm, and notification must be made as soon as practicable.
Before disclosing personal information overseas, an APP entity generally takes reasonable steps to ensure the recipient does not breach the APPs. The Australian entity can remain accountable for the recipient’s conduct, subject to statutory exceptions.
Overseas disclosure must fit an IPP 12 route, such as the recipient being subject to the Act, comparable privacy safeguards, an approved binding scheme, contractual comparable safeguards, or informed authorisation where protection may not be comparable.
Operational rule: distinguish a disclosure to an independent overseas recipient from storage or processing by a provider acting solely on your behalf; then document the legal route, contractual safeguards, access locations and onward-transfer controls.
Record the Australian entity, turnover and exception analysis; separately document New Zealand territorial scope.
Map direct and indirect collection. Add IPP3A notices to enrichment, referral, fraud, recruitment and shared-service flows.
Identify overseas recipients, hosting locations, subprocessors and the APP 8 or IPP 12 transfer route.
Run access and correction exercises with local identity checks, exceptions, response letters and escalation paths.
Use scenarios to test serious-harm assessment, regulator notification, individual communications and evidence capture.
Separate enacted obligations from consultations and update the control register only when commencement is confirmed.
Australia has 13 APPs. New Zealand’s framework is organised as information privacy principles and now includes the additional IPP3A indirect-collection notification rule.
No. Both regimes regulate purpose and fairness through detailed collection, use and disclosure rules rather than treating consent as the only possible basis.
No. Both schemes use a serious-harm threshold, but every suspected incident should be contained, assessed and recorded.
Yes, if it clearly addresses both regimes and the actual data flows. Local supplements are often cleaner where entities, rights contacts or transfer routes differ.
This page is general information, not legal advice. Confirm current commencement, sector rules and regulator guidance for the processing activity concerned.