Quick answer
The Privacy Act 2020 sets rules for how organisations in New Zealand collect, store, use and share personal information. Its 13 information privacy principles cover why information is collected, keeping it secure, your right to access and correct it, and limits on use and disclosure. A new principle, IPP3A, applies from 1 May 2026 to information collected from other sources. Serious privacy breaches must be notified.
Key points
- 13 information privacy principles govern collection, storage, use and disclosure
- You can ask to access and correct personal information held about you
- IPP3A, from 1 May 2026, covers information collected from third parties
- Breaches likely to cause serious harm must be notified to the Commissioner and affected people
An online business loan involves handing a lot of personal information to people you have not met: your ID, your directors’ details, sometimes your home address and personal credit history. The Privacy Act 2020 is the law that decides what they can do with it. You do not need to be a lawyer to understand the parts that matter.
What are the 13 information privacy principles?
The Act is built on 13 information privacy principles, often called IPPs. In plain English:
| IPP | What it means for you |
|---|---|
| 1. Purpose of collection | Information should be collected only for a lawful purpose connected with what the organisation does |
| 2. Source | It should usually be collected from you directly |
| 3. What you are told | You should be told why it is collected, who will receive it and your rights |
| 4. Manner | Collection must be lawful, fair and not unreasonably intrusive |
| 5. Storage and security | It must be protected against loss and misuse |
| 6. Access | You can ask for the information held about you |
| 7. Correction | You can ask for it to be corrected |
| 8. Accuracy | It must be checked for accuracy before use |
| 9. Retention | It should not be kept longer than needed |
| 10. Use | It should be used only for the purpose it was collected, with exceptions |
| 11. Disclosure | It should not be disclosed except in permitted circumstances |
| 12. Overseas disclosure | Sending it overseas needs comparable protection |
| 13. Unique identifiers | Rules on assigning and using identifiers |
The Privacy Commissioner’s website has the full wording and guidance.
What changed in May 2026?
The Privacy Amendment Act 2025 added a new principle, IPP3A, which applies from 1 May 2026. It deals with personal information an organisation collects from somewhere other than you — for example, from a credit reporter, a public register or another business. In general, the organisation must take reasonable steps to tell you it has collected the information and give you key details, subject to exceptions. For loan applicants, it means more transparency about where information came from. Our IPP3A guide goes into detail.
How does the Act apply to an online loan?
At each stage of the online journey, principles apply:
- Enquiry — collect only what is needed (IPP1, IPP4), and tell you why (IPP3).
- Documents and ID — store securely (IPP5), use only for the application and legal obligations (IPP10).
- Sharing with a lender — disclose only as needed and as you were told (IPP11).
- After the decision — do not keep it forever (IPP9).
- Any time — you can ask for access (IPP6) or correction (IPP7).
Our own privacy policy explains how we apply these.
Comfortable with how your data is handled? Start your enquiry — it asks only what is needed to match you.
What must happen if there is a data breach?
Under the Act, a privacy breach that has caused or is likely to cause serious harm must be notified to the Privacy Commissioner and to the affected individuals as soon as practicable. Serious harm can include financial fraud or identity theft, which is exactly the risk with loan documents. If a lender or broker notifies you of a breach, follow their advice, watch your accounts and consider changing passwords.
How do you request your information?
Ask the organisation in writing. Say who you are, what you are asking for (for example, “all personal information you hold about me relating to my loan enquiry”) and how you would like to receive it. The organisation must respond within the timeframe the Act sets, and the Privacy Commissioner’s website explains what to expect. If it refuses or delays without good reason, you can complain to the Office of the Privacy Commissioner.
What about credit information?
Credit reporters have their own code, the Credit Reporting Privacy Code 2020, with specific rules on access and correction. You can request your credit information from each credit reporter free of charge, and they must respond within 10 working days. See credit checks for business loans.
Worked example (illustrative): after a loan is declined, a Palmerston North company director asks the broker what personal information it holds and who it shared it with. Within the required time she receives a summary: her enquiry, her ID check result and confirmation it was shared with one lender only. That clarity is what the Act is designed to give.
What can you do to protect your own information?
- Share documents only through secure portals, never plain email. See uploading documents securely.
- Read the privacy statement before submitting a form.
- Ask who your information will be shared with. “A panel of lenders” is a different answer from “one lender”.
- Request deletion of information that is no longer needed, where appropriate.
Does the Act apply to businesses outside New Zealand?
Overseas organisations that carry on business in New Zealand can be covered too, and IPP12 restricts sending personal information overseas unless it will be protected in a comparable way. If a lender, verification service or cloud provider stores your data outside New Zealand, you can ask where and how it is protected.
Start with a team that asks only what it needs
Our enquiry takes about a minute and does not involve a credit check. It goes to one team rather than being distributed to a crowd of lenders, and a real person reads it. Answer accurately; we use the information only to find you a suitable option. Check what you could qualify for.
Frequently asked questions
Does the Privacy Act cover business information?
It covers personal information about identifiable individuals. In a business loan, that includes directors', guarantors' and sole traders' details, ID documents and often personal credit information.
Can I ask a lender what information it holds about me?
Yes. Principle 6 gives you the right to request access to personal information an organisation holds about you.
What is IPP3A?
A new principle added by the Privacy Amendment Act 2025, in force from 1 May 2026. It requires organisations to tell people when they collect personal information about them from another source, subject to exceptions.
What happens if a lender has a data breach?
If a breach has caused or is likely to cause serious harm, the organisation must notify the Privacy Commissioner and affected individuals as soon as practicable.
Who do I complain to?
First raise it with the organisation. If you are not satisfied, you can complain to the Office of the Privacy Commissioner.