If your website collects personal information, even just a name and email in an enquiry form, the Privacy Act 2020 expects you to tell people what you collect, why, who sees it and how they can access or correct it. A clear privacy policy linked from your form is the simplest way to do that.
This guide is general information, not legal advice. For anything specific to your business, talk to a lawyer or check the Privacy Commissioner’s guidance.
What the Privacy Act 2020 asks of small businesses
The Privacy Act applies to almost every business in New Zealand, whatever its size. Its 13 information privacy principles (IPPs) cover how you collect, store, use and share personal information.
For a website, the key one is principle 3: when you collect personal information from someone, you need to take reasonable steps to make sure they know:
- that you’re collecting it, and why;
- who will receive it;
- your business name and address;
- whether giving it is optional, and what happens if they don’t;
- that they can ask to see and correct it.
What changed in May 2026: IPP3A
From 1 May 2026, a new principle, IPP3A, applies when you collect personal information about someone from someone else rather than from them directly. For example, a customer who books on behalf of a friend, or details you get from another business. In that case, you need to take reasonable steps to let the person know, unless an exception applies.
It only applies to information collected from 1 May 2026. Information you receive from a service provider acting for you (like your email or booking system) counts as collected directly.
What to put in your website’s privacy policy
| Section | What to say |
|---|---|
| Who you are | Your business name, address and how to contact you about privacy |
| What you collect | For example: name, email, phone and the message in your form |
| Why | To reply to enquiries, prepare quotes, deliver orders |
| Who sees it | Your team, and providers like your email, hosting or payment provider |
| Where it’s stored | Including if your providers store it overseas |
| How long you keep it | Only as long as you need it |
| Cookies and analytics | What your website uses, if anything |
| Access and correction | How people can ask to see or fix their information |
Keep your form small
The easiest way to reduce privacy risk is to collect less. Ask only for what you need to reply: a name, a way to contact them and a message. Health, financial or ID details belong in a secure system, not a website form.
What about cookies?
New Zealand doesn’t have a specific cookie consent law like Europe’s. But if your website uses analytics or advertising cookies, the Privacy Act still expects you to be open about it, so mention them in your privacy policy.
Marketing emails
If you want to send newsletters or promotions, the Unsolicited Electronic Messages Act 2007 requires consent and an easy way to unsubscribe. Replying to an enquiry is fine; adding that person to your mailing list without asking isn’t.
Every website we build at Upfront Sites includes a privacy policy written for the information your form actually collects, and a contact form that only asks for what you need. See our websites for health and wellness practitioners for an example of a careful form.
Compare our three websites side by side, prices and all.
Frequently asked questions
Do I need a privacy officer?
Yes. The Privacy Act requires every agency to have at least one. In a small business, it’s usually the owner.
What happens if there’s a privacy breach?
If a breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and the people affected as soon as practicable.
Can I copy another website’s privacy policy?
It’s better not to. A privacy policy has to describe what your business actually does with information.