First Published: 06 October, 2026
As of the 1st of May 2026, amendments to our NZ privacy legislation came into effect. Specifically, the Privacy Amendment Act 2025 which introduced a new Information Privacy Principle (IPP3A) which now requires additional notification for individuals when organisations are receiving data that they did not collect themselves i.e. receiving data indirectly or using 3rd Party Data.
This high-level flowchart shows when you need to notify individuals under IPP3A
FAQs
Do individuals need to be notified if we have received information before the 1st May 2026?
No, the new amendments are not retrospective and only apply to data collected after 1st May 2026 (refer Section 25A of the Privacy Act 2020). Organisations still need to ensure they comply with all the other requirements of the Privacy Act and Privacy Principles.
Do the changes apply to Charities?
Yes, charities and non-profit organisations must comply with Privacy Regulations in the same way that commercial organisations do.
What are 3rd Party data sources?
Any data you did not collect yourself. Examples may be data sources externally from
Things you need to check if using 3rd Party data
It’s important to do your due diligence before receiving data from a 3rd Party. Things to check include:
After you’ve collected contact details from a 3rd party what do you need to do?
IPP3A requires you to take reasonable steps to make sure that the person concerned is informed:
When should you notify the individual?
IPP3A (2) states notification must take place “As soon as reasonably practicable after the information has been collected”.
The Office of the Privacy Commissioner (OPC) states that agencies must be able to justify any delay in notification. You should also document your rationale and decision-making if notification is delayed.
While there may be some limited cases where a small delay could be justified (e.g. until a planned campaign launches) a longer delay in notification could be a breach of IPP3A.
Further guidance can be found on the OPC website: https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/#timing
Do individuals also need to be notified about other parties that may be acting on behalf of the receiving organisation for example Mail houses or Call Centres?
If a service provider is receiving data to provide outsourced services on behalf of another organisation the individual does not have to be notified about that 3rd party provider, only the brand that they are acting for. For example, in the context of a marketing campaign the notification is required for the brand or organisation the campaign is about.
If you are using an outsource provider or supplier, you may be responsible for what that third party does with the information. You should do your due diligence with suppliers on their terms of service, data security and data retention policies. For more guidance on working with 3rd Parties - https://www.privacy.org.nz/resources-and-learning/a-z-topics/working-with-third-party-providers/
If the outsource provider or data services provider is using the data for themselves then they also become responsible for notification.
Do the changes apply to Market Research?
Yes, if personal information was collected indirectly from third parties i.e. a marketing list was acquired from a third party or through social media scraping individuals must be notified that the information is being held.
Exceptions may apply if the information is immediately de-identified or anonymized and used solely for statistical/research purposes.
What are the notification requirements?
When collecting information about people it is important that they are informed:
Transparency is key and ideally your Privacy Policies should make the above clear for people you are collecting information from. More guidance on notification requirements can be found here - https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/#notification-requirements
Are there any exceptions where notification is not required?
Yes, there are a range of exceptions which are detailed on the Office of the Privacy Commissioner website here: https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/#exceptions
Exceptions include:
If you are sourcing or using 3rd party data it is important to do your due diligence to ensure that the data you are receiving is already compliant with IPP3A or, whether further notification will be required when receiving and using the data.
Too time consuming or expensive to notify is not a valid excuse, you must notify!
If you are not sure this flowchart shows when you should notify individuals under IPP3A - https://www.privacy.org.nz/assets/DOCUMENTS/251104-IPP3A-decision-flowchart.pdf
If we are doing a Direct Marketing campaign using an external list what is the best way to notify individuals?
Here are some examples of notifications that could be used for Direct Mail our outbound Telemarketing –
Direct Mail (privacy explanation to add to letter footer)
Your details were sourced from [name or a 3rd party]. Please see our privacy policy [insert link https://www.your website/your privacy policy] for how we use and protect your details. If you have any questions about how your information was collected or to be removed from the database, please contact [insert 3rd party contact details]"
Telemarketing (privacy explanation to use on a call)
Hello, I’m [name] from [organisation]. We got your number from [name of 3rd party]. You can read about how we use and protect your details on our website [https://www.your website/your privacy policy]. If you have any questions about how your information was collected or to be removed from the database please contact [insert 3rd party contact details]"
What do we need to do with our existing data?
Here are some recommendations for keeping track of the privacy status of your data. It is recommended to ensure your systems are setup to Date Stamp data at collection. If this is not setup then add a Date stamp to your existing data, so you know its status under Section 25A of the Privacy Act 2020 which states that Information Privacy Principle 3A (IPP 3A) does not apply to personal information collected before 1 May 2026.
You could add an “IPP-3A_Status” field to your database to flag all your existing data and new data with an IPP-3A Status, for example:
It is also good practice to include a “Source” field, so you have an audit trial on how the data was collected or if it came from a 3rd party, who that was, when it was received and the Privacy Status of that information.
Other things you can do to ensure compliance:
Review and update privacy statements including IPP3A and if applicable Biometrics & AI.
Review contracts with agencies, lead providers, and service partners. Ensure partners also understand the requirements.
Conduct Privacy Impact Assessments (PIA) when reviewing new data sources or providers including IPP3A status and compliance.
Create an audit trail showing how individuals were informed. Work with your data team.
Update call centre training manuals and scripts to ensure notification requirements are properly met.
Authors: Darron Jermy, Brent Martin, Sharon Abbott, Keith Norris, 6th September 2026
Category
Contact us if you have any suggestions on resources you would like to see more of, or if you have something you think would benefit our members.
Get in TouchSign up to receive updates on events, training and more from the MA.