Privacy Act 2020: What Boards Need to Know

Posted on Sep 25, 2026 in IT policy

Group of business professionals collaborating over technology in a modern office

Image: fauxels via Pexels

New Zealand’s Privacy Act 2020 has been in force for several years now, yet conversations with board members and senior leaders suggest that governance-level understanding of the Act’s obligations remains patchy. If you sit on a board — or advise one — here is what you genuinely need to have across.

Directors Have a Governance Duty Around Privacy

Privacy is not just an operational matter for your IT team or your privacy officer to manage quietly in the background. Under the Privacy Act 2020, organisations are accountable for how they collect, store, use, and share personal information. That accountability flows upward. Boards set culture, approve resourcing, and oversee risk — which means directors need to satisfy themselves that adequate privacy controls are in place, not simply assume someone else has it handled.

A useful starting point is the Office of the Privacy Commissioner’s guidance on the Privacy Act 2020, which outlines the information privacy principles your organisation is required to follow.

Mandatory Breach Notification — and What It Actually Requires

One of the most significant changes the 2020 Act introduced was mandatory breach notification. If your organisation experiences a privacy breach that has caused, or is likely to cause, serious harm, you are required to notify both the Privacy Commissioner and the affected individuals as soon as reasonably practicable.

“Serious harm” is a deliberately broad threshold. It can include financial loss, reputational damage, physical safety risks, or significant distress. In practice, this means your organisation needs a clear, tested incident response process — one that includes a pathway for escalating potential breaches to the board quickly, so that notification timelines can be met.

Boards should be asking: Do we have a documented breach response plan? When was it last tested? Who makes the call on notification?

Penalties Have Real Teeth

The 2020 Act introduced fines of up to $10,000 for certain offences — including failing to notify a serious breach, misleading an organisation to access someone else’s information, and obstructing the Privacy Commissioner. While these figures may seem modest, enforcement action and public findings from the Commissioner carry significant reputational consequences, particularly for professional services firms, health providers, and organisations that handle sensitive data.

What Good Governance Looks Like

Boards that are getting this right tend to have a few things in common:

  • A named privacy officer whose role and responsibilities are clearly defined
  • Regular privacy risk reporting to the board, not just to management
  • A tested incident response plan that includes breach notification procedures
  • Staff training that is refreshed regularly, not just completed at onboarding
  • Vendor contracts that include clear data processing and security obligations

A Practical First Step

If your board has not formally reviewed your organisation’s privacy posture in the past twelve months, that is a reasonable place to start. A gap analysis against the information privacy principles — ideally with input from your IT provider and legal counsel — can surface risks before they become incidents.

Privacy compliance and good IT security go hand in hand, and our team is always happy to help organisations work through where the gaps might be.

Jessica Falconer
Director, Resolve Technology

When she’s not wrangling IT strategies, Jessica can be found wrangling labradoodles, teenagers, and parishioners — not necessarily in that order.

Leave a Reply