Quick answer
IPP3A is a new information privacy principle added to the Privacy Act 2020 by the Privacy Amendment Act 2025, in force from 1 May 2026. It covers personal information an organisation collects from a source other than you, and generally requires it to take reasonable steps to tell you, subject to exceptions. In a business loan, it applies to information such as credit reports, verification results and data from public registers.
Key points
- IPP3A has applied since 1 May 2026
- It covers personal information collected indirectly, not from you
- Loan-related examples: credit reports, ID verification results, register searches
- It sits alongside your existing rights to access and correct information
- Exceptions exist, so not every indirect collection triggers a notice
For most of its life, the Privacy Act 2020 has focused on information you hand over yourself. You fill in a form; the organisation tells you why it wants the information and what it will do with it. But a modern loan application involves plenty of information that does not come from you: a credit report, an identity check result, a company register search, a property title. Since 1 May 2026, a new principle — IPP3A — has addressed that gap.
What is IPP3A?
The Privacy Act 2020 is built on information privacy principles. Principle 3 deals with what an organisation must tell you when it collects personal information from you. The Privacy Amendment Act 2025 added principle 3A, which the Privacy Commissioner describes as “collection of information from another source — what to tell the individual”. It became effective on 1 May 2026.
In short: when an organisation collects your personal information indirectly, it generally needs to take reasonable steps to make sure you know about it, including key details such as the fact of collection and who has it — subject to a set of exceptions.
Why was it introduced?
Indirect collection has grown enormously. Data flows between businesses, registers, data brokers and verification services, often without the individual realising. Principle 3 already ensured transparency for direct collection; IPP3A extends a similar expectation to indirect collection. The aim is that people are not left in the dark about who holds information about them.
Where does indirect collection happen in a business loan?
More often than you might think:
| Stage | Indirect source | Personal information involved |
|---|---|---|
| Assessment | Credit reporter | Director’s or sole trader’s credit report |
| Identity | Verification service | Document and selfie match result |
| Company checks | Companies Register | Directors’ names and addresses |
| Property-secured loans | Land title records | Owners’ names on the title |
| Bank data | Open banking provider | Account holder details and transactions |
| References | Accountant or existing lender | Comments about the borrower |
Some of these involve information you also supply yourself; some do not. IPP3A is concerned with the indirect pieces.
Does IPP3A change what lenders can collect?
Not directly. IPP3A is a notification principle, not a consent principle. Other principles — purpose (IPP1), source (IPP2), manner of collection (IPP4), use (IPP10) and disclosure (IPP11) — and codes such as the Credit Reporting Privacy Code 2020 continue to govern whether information can be collected and how it can be used. What IPP3A adds is the expectation that you are told.
In practice, many lenders and brokers already explain in their privacy statements and application consents that they will obtain information from credit reporters, verification services and public registers. Clear upfront notice of that kind is one of the ways organisations meet the new principle. You may notice privacy statements in loan applications becoming more specific since May 2026.
What exceptions apply?
IPP3A includes exceptions, so not every indirect collection triggers a separate notice. Rather than paraphrase the legal wording loosely, we suggest reading the Privacy Commissioner’s guidance on IPP3A, which explains the exceptions with examples. The practical takeaway for borrowers: you should generally expect to be told about indirect collection, but there are recognised situations where that is not required.
If you want to see how we explain our own collection, our privacy policy sets it out. And if you are ready to begin, our enquiry involves no credit check, so no credit reporter is contacted at that stage.
How does IPP3A interact with credit checks?
Credit information has its own detailed code, the Credit Reporting Privacy Code 2020. It already gives you strong rights: free access to your credit information from each credit reporter within 10 working days, correction rights, and an access log showing who has requested your information. When a lender obtains your credit report, that is a classic example of indirect collection. Between the code and IPP3A, the expectation is clear: you should know it is happening.
Our page on credit checks for business loans explains when lenders check and what they see.
What should you look for in a loan application now?
Since 1 May 2026, a well-run online application should make it easy to understand:
- Which third parties will be asked for information about you — credit reporters, verification services, registers.
- Why — for example, to verify identity and assess creditworthiness.
- Who will hold the information — the lender, the broker, both.
- How to access and correct it — your IPP6 and IPP7 rights.
If an application is vague — “we may obtain information from various sources” with no further detail — it is reasonable to ask for specifics.
Does IPP3A apply to company information?
The Privacy Act protects personal information about identifiable individuals, not companies as such. But in a small-business loan, company information and personal information are tightly linked. A company search reveals directors’ names and addresses; a guarantee involves a director’s personal finances; a sole trader’s business is personal by definition. So IPP3A is very much relevant to business borrowers.
What are your rights if something goes wrong?
Your existing rights remain:
- Access — ask what personal information is held about you (IPP6).
- Correction — ask for it to be corrected (IPP7).
- Complaint — raise concerns with the organisation, and then with the Office of the Privacy Commissioner if needed.
If a breach occurs that has caused or is likely to cause serious harm, the organisation must notify the Privacy Commissioner and affected people as soon as practicable. Financial fraud and identity theft are explicitly among the harms the Commissioner lists, which is why loan data deserves care.
A practical scenario
Worked example (illustrative): a Dunedin furniture-maker applies for a property-secured loan. The lender’s application explains that it will obtain her credit report, run an electronic identity check, search the Companies Register and obtain the property’s title. After settlement, she asks the lender what it holds. The response lists each source, what was obtained and how long it will be kept. She notices her old address on the credit report, asks the credit reporter to update it, and the correction is made — all within the rights the Act and code provide.
What does this mean for how we work?
We collect only what is needed to match you with a suitable lender. The enquiry is direct — you tell us. Indirect collection, such as a credit check or identity verification, happens only once you decide to proceed, and we tell you before it does. If you want to know what we hold, ask. For a plain-English summary of all 13 principles, read Privacy Act basics, and for what you agree to when connecting data, see data-sharing consent.
Is IPP3A a reason to worry about applying online?
No. It is a reason to feel more confident. The law now expects transparency about indirect collection, on top of strong existing rights. Online applications that are clear about their data sources tend to be the well-run ones.
Will you get a separate notice for every check?
Not necessarily. Organisations can meet their obligations in different ways, and many will explain all their indirect sources in a single, clear statement at the start of an application rather than sending a separate message for each one. What matters is that the information is given to you in a way you can actually read and understand before or soon after the collection happens, unless an exception applies. If a statement is buried in fine print, ask for a plain summary.
Start an enquiry that respects your information
The enquiry asks for the basics only and takes about a minute. There is no credit check at that stage, your information is kept with one team rather than circulated to a list of lenders, and a real person reads it. When further checks are needed, we will explain them first. Please answer accurately, so those later checks confirm what you told us. See if your business qualifies.
Frequently asked questions
What does IPP3A stand for?
Information privacy principle 3A. It was added to the Privacy Act 2020 by the Privacy Amendment Act 2025.
When did IPP3A take effect?
On 1 May 2026.
Does IPP3A mean I have to consent to every data source?
No. IPP3A is a notification principle — it is about being told, not about consent. Other principles and codes govern when information can be collected and used.
Does IPP3A apply to business information?
It applies to personal information about identifiable individuals. In a business loan, that includes directors, guarantors and sole traders.
Are there exceptions?
Yes. The principle includes exceptions, so an organisation does not always have to notify. The Privacy Commissioner publishes guidance on how they work.
What should I do if I think an organisation has not complied?
Raise it with the organisation first. If you are not satisfied, you can complain to the Office of the Privacy Commissioner.