Understanding the Privacy Act 2020 for New Zealand Fintech

·13 min read·
--
--

Fintech companies collect a large amount of personal information. A payment app holds names and account details, a lending platform holds income and identity documents, and an investment tool holds transaction history. In New Zealand, the Privacy Act 2020 sets the rules for how this information can be collected, stored, used and shared. Anyone planning to build, join or start a fintech business here needs a working knowledge of it. This article explains the Act in simple terms, with examples from the sector. It is based on the version of the Act current at 1 May 2026.

Why it matters in fintech

Financial data says a lot about a person. It shows where they spend money, what they earn, what they owe and often where they live and travel. A fintech company that loses this data or uses it carelessly damages customer trust, and trust is what a financial product depends on. The Act gives businesses clear rules to follow and gives customers legal rights over their own information.

Who the Act applies to

The Act uses the word agency for any person or organisation that handles personal information. A startup, a bank, a payment processor and a lender are all agencies, and so is a sole trader building an app.

The Act also applies to overseas businesses. Under section 4, an overseas agency must follow it when it carries on business in New Zealand. If a company based in Singapore offers its app to New Zealand customers, it is covered for that activity. It does not matter where the data is stored or where the customer is at the time.

Personal information means information about an identifiable individual. An account number linked to a name is personal information. So is an email address, or a device ID that can be tied to one person.

The information privacy principles

Section 22 of the Act sets out 13 information privacy principles. An additional principle, Principle 3A, was added on 1 May 2026. Most of the Act's obligations sit within these principles, so they are worth knowing well.

Principle 1 Purpose of collection

An agency can only collect personal information for a lawful purpose connected to its work, and only when the collection is necessary for that purpose. If a task does not need a person's identity, the agency cannot require it.

For example, a budgeting app that sorts spending into categories has no need for a customer's passport number. A lender that must verify identity does.

Principle 2 Source of information

Information should be collected from the person it is about. There are exceptions, such as when the person authorises collection from someone else, when the information is publicly available, or when collecting it directly is not reasonably practicable.

For example, if a lending app wants to confirm an applicant's income with a third party, it should first get the applicant's permission.

Principle 3 Telling people about collection

When collecting information from a person, the agency must take reasonable steps to make sure the person knows what is being collected, why, who will receive it, and who is collecting and holding it. They must also know whether providing it is voluntary or required by law, what happens if they do not provide it, and that they can ask to see and correct it. This is usually done through a privacy statement.

For example, the sign up screen of an investment platform should link to a clear privacy statement before the customer submits their details.

Principle 3A Information collected from other sources

This principle is new. When an agency collects personal information about a person from a source other than that person, it must take reasonable steps to tell them, as soon as reasonably practicable. It does not have to do this if the person already knows, or if the information is publicly available, along with some other exceptions.

For example, if a fintech receives customer data from a partner company, the customers should be told about it, unless the partner has already made sure they were informed.

Principle 4 Manner of collection

Information must be collected lawfully and fairly, and without intruding unreasonably on a person's private affairs. Particular care is needed when the information comes from children or young people.

For example, gathering a person's social media activity to build a credit profile without telling them would be difficult to defend as fair.

Principle 5 Storage and security

An agency must protect personal information with security safeguards that are reasonable in the circumstances. These should guard against loss, unauthorised access, misuse and unauthorised disclosure. If a service provider handles the information for the agency, the agency must do everything reasonably within its power to prevent that provider from misusing or disclosing it.

For example, this includes encryption, access controls, staff training and regular testing. If a product runs on a cloud platform, the fintech is still responsible for how it is configured. A publicly accessible storage bucket containing customer records is the fintech's responsibility.

Principle 6 Access to information

A person can ask an agency whether it holds information about them and can ask for access to it. Under section 44, the agency must respond as soon as reasonably practicable and no later than 20 working days after receiving the request.

For example, a customer emails support asking for all the data held about them. The business needs a process to find that data across its systems and reply on time. Missing the deadline can be treated as a refusal without proper basis, which is an interference with privacy under section 69.

Principle 7 Correction of information

A person can ask an agency to correct their information. If the agency decides not to make the change, the person can provide a statement of correction, and the agency must attach it so that it is always read with the record. If information is corrected, the agency must tell others it has shared the information with, where reasonably practicable.

For example, a customer's credit file may show a missed payment that was caused by a bank error. The customer can ask for the record to be corrected or annotated.

Principle 8 Accuracy before use

Before using or disclosing information, an agency must take reasonable steps to check that it is accurate, up to date, complete, relevant and not misleading.

For example, before an automated system declines a loan using stored data, the business should have ways of keeping that data accurate. Outdated or wrong data can lead to unfair decisions.

Principle 9 Retention

An agency must not keep personal information for longer than it is needed for the purposes it can lawfully be used for.

For example, if someone starts an account application and never finishes it, keeping their identity documents indefinitely is hard to justify. A fintech should set retention periods and delete data accordingly. Other laws, such as anti money laundering rules, may require certain records to be kept for a set period, so both need to be considered together.

Principle 10 Limits on use

Information collected for one purpose cannot be used for another purpose unless an exception applies. The exceptions include a directly related purpose, the person's authorisation, and use in a form that does not identify the person.

For example, transaction data collected to process payments should not be given to a marketing team to target advertising unless customers agreed to it or the use is directly related to the original purpose.

Principle 11 Limits on disclosure

An agency can only disclose personal information when an exception applies. The most common ones are that the disclosure is one of the purposes for which the information was collected or is directly related to them, the person authorised it, or the disclosure is to the person themselves. Others cover serious threats to health or safety and the enforcement of the law. The principle also allows disclosure when it is necessary for the sale of a business as a going concern.

For example, an app cannot pass a customer's spending history to a partner retailer only because it would be commercially useful.

Principle 12 Disclosure outside New Zealand

Fintech businesses often use overseas cloud servers, offshore developers and international partners, so this principle is especially relevant. Before disclosing personal information to a foreign person or company, the agency must be satisfied that one of several conditions is met. These include that the person authorised the disclosure after being told the overseas party may not offer comparable protection, that the overseas party is subject to the Act, that it is subject to privacy laws with comparable safeguards, or that an agreement between the two requires comparable protection.

For example, before sending customer data to a support team in another country, a fintech should check the privacy law that applies there or put a contract in place that requires equivalent protection. Where an overseas provider only stores or processes data on the agency's behalf, the Act may treat this differently from a disclosure to another business, so it is worth taking advice on how it applies to a particular arrangement.

Principle 13 Unique identifiers

An agency can assign a unique identifier, such as a customer number, only when it is necessary for its work. It generally cannot use an identifier that another agency has already assigned to the same person. It must also take reasonable steps to reduce the risk of misuse, for example by showing shortened account numbers on receipts and letters.

For example, a fintech should not use a customer's IRD number or driver licence number as its own customer ID.

Privacy breaches

A privacy breach is unauthorised or accidental access to, or disclosure, alteration, loss or destruction of, personal information. It also includes any action that stops the agency from accessing the information. A phishing attack, a lost laptop, an email sent to the wrong customer and a ransomware attack are all examples.

Not every breach has to be reported. A notifiable privacy breach is one that has caused, or is likely to cause, serious harm to an affected person. To judge this, the Act requires the agency to consider what it has done to reduce the risk, how sensitive the information is, the kind of harm that could result, who has or may obtain the information, whether the information was protected by a security measure such as encryption, and any other relevant matters.

If a breach is notifiable, the agency must tell the Privacy Commissioner as soon as practicable after becoming aware of it. It must also tell the affected people as soon as practicable, or give public notice if contacting each person is not reasonably practicable. Failing to notify the Commissioner without a reasonable excuse is an offence with a fine of up to $10,000, and it is not a defence that the agency has taken steps to fix the breach.

For example, if a hacker downloads a file containing customer names, bank account numbers and addresses, the possible harm includes fraud, so the breach would very likely be notifiable. A fintech should prepare an incident response plan in advance, so that the team knows who assesses the breach, who contacts the Commissioner and how customers will be told.

Privacy officers

Under section 201, every agency must appoint at least one privacy officer. The role includes encouraging compliance with the principles, dealing with requests made under the Act, working with the Commissioner during investigations, and making sure the agency follows the Act. In a small startup this can be a founder or senior team member. Larger firms often have a dedicated person or team. The privacy officer can also be someone outside the organisation.

Enforcement and penalties

The Privacy Commissioner can investigate complaints and can issue a compliance notice to an agency that may have breached the Act. A compliance notice sets out what the agency must do to put the problem right.

A person who is affected by a breach of a principle can make a complaint. If it is not resolved, the matter can go to the Human Rights Review Tribunal, which can award damages under section 103. Harm is not limited to financial loss. Under section 69, an action can be an interference with privacy if it causes loss or damage, affects a person's rights or interests, or causes significant humiliation, loss of dignity or injury to feelings.

The Act also sets fines of up to $10,000 for certain offences. These include failing to notify a notifiable breach, failing to comply with a Tribunal access order, obstructing the Commissioner, and giving the Commissioner false information.

These fines are lower than penalties under some overseas privacy laws. For a fintech, the more significant costs are usually lost customers, investigation time, legal fees, damages and the effect on relationships with banks, partners and regulators.

The Commissioner can issue codes of practice that change how the principles apply to certain industries or types of information. A code can set stricter or looser standards, or explain how a principle should be followed. The Credit Reporting Privacy Code is relevant to lending and credit businesses. There is also a code covering biometric information, which matters for fintechs that use face scans or fingerprints for identity checks. Codes are updated from time to time, so the current versions should always be checked on the Privacy Commissioner's website.

The Privacy Act is one of several laws that apply to fintech. Businesses also deal with anti money laundering and countering financing of terrorism rules, financial services licensing and conduct rules overseen by the Financial Markets Authority, and consumer credit rules. New Zealand is also developing customer data legislation that will allow customer data to be shared between banks and other providers with the customer's consent. These laws interact with the Privacy Act, and sometimes they require a business to collect or keep information that a privacy principle would otherwise limit. Anyone entering the sector should learn how they fit together.

Practical steps for someone starting out

The first step is to record what personal information the business collects, where it comes from, where it is stored, who can access it and who it is shared with.

Privacy should be considered from the start of product design. This means collecting only the data that is needed, explaining why it is needed and giving customers a simple way to see and correct their information.

Retention periods should be set, and data should be deleted once it is no longer needed.

Vendors and overseas partners should be reviewed, including their security practices, and the right contract terms should be in place, especially where data leaves New Zealand.

A breach response plan should be written and tested, with clear roles for assessing harm, notifying the Commissioner and informing customers.

A privacy officer should be appointed and given enough time and authority to do the role properly.

Everyone who handles customer data should be trained. Many breaches begin with a simple mistake such as a wrong email address or a weak password.

Conclusion

The Privacy Act 2020 gives fintech businesses a clear framework for handling customer information responsibly. Understanding the principles, the breach notification rules and the requirements for sending data overseas is a strong foundation for a career or business in this sector. The Act itself and the Privacy Commissioner's guidance are the best sources to read next, and legal advice should be sought for any specific product. This article is general information and not legal advice.

Reference

Privacy Act 2020, New Zealand Legislation

Share