New Zealand’s Privacy Act is set to change on 1 May 2026, and the update has practical implications for how organisations handle background screening. This article sets out what the change involves and how your organisation can get ready.
What Is Changing?
New Zealand’s Privacy Act 2020 has long required organisations to notify individuals when collecting personal information directly from them. Until now, however, there was no equivalent requirement when that information was collected indirectly, that is, from a third party rather than from the person themselves.
The Privacy Amendment Act 2025 closes that gap. It introduces a new Information Privacy Principle, IPP 3A, which comes into force on 1 May 2026. Under IPP 3A, if your organisation collects personal information about an individual from a source other than the individual themselves, you are now required to take reasonable steps to make that individual aware of the collection.[1]
Privacy Commissioner Michael Webster commented when the Act passed: “Telling people when you’re collecting information about them supports open and transparent collection practices and helps people better understand where and how their information is being used.”[2]
The change was also designed to keep New Zealand in step with international privacy standards. According to the Ministry of Justice, the gap in New Zealand’s existing law was specifically highlighted by the European Union during its assessment of New Zealand’s EU adequacy status, the recognition that allows New Zealand businesses to receive personal data from the EU without individual contractual arrangements. The Amendment Act is designed to support New Zealand retaining that status going forward.[1]
Why This Matters for Employers Who Use Background Screening
This is where IPP 3A becomes directly relevant to organisations that conduct background screening. When you instruct a background check provider like Kinatico CVCheck to run a police check, a child worker safety check, or any other form of screening on an individual at any point in the employment lifecycle, that information is being collected from a third-party source, not from the individual themselves. Under the new law, that is an indirect collection, and IPP 3A applies.[3]
In practical terms, this means that from 1 May 2026, your organisation needs to ensure that individuals are clearly informed:
- that their personal information is being collected
- the purpose of that collection
- who the intended recipients of that information are
- the name and contact details of the agency collecting the information and the agency holding it
- if the collection is authorised or required by law, which law
- their right to access and correct the information[2]
This notification obligation sits with your organisation as the indirect collector, the party instructing the background check.[3]
What “Reasonable Steps” Looks Like in Practice
The Office of the Privacy Commissioner (OPC) has published detailed guidance on what constitutes reasonable steps to meet the IPP 3A notification requirements.[3] The good news is that for most employers, this obligation can be met through existing touchpoints across the employment lifecycle, provided those touchpoints are updated to include the right information.
The OPC’s guidance confirms that notification can be provided through a variety of formats, including written forms, online notices, or phone scripts, as long as the information is communicated clearly. A layered approach is acceptable, for example, a brief privacy notice on a form supplemented by a fuller privacy statement available online.[3]
Critically, the OPC guidance also makes clear that relying on generic wording in an existing privacy statement is unlikely to be sufficient. The notification needs to be specific enough that the individual understands exactly what information is being collected, why, and by whom. The guidance suggests a useful test: consider whether the person could reasonably be surprised at how their information is being used. The more likely they would be surprised, the more detailed the explanation needs to be.[3]
For large employers running high volumes of checks across multiple roles, business units, and stages of the employment lifecycle, banks, insurers, health providers, this points to a practical compliance task: reviewing all touchpoints where individuals may be subject to third-party screening or verification, and ensuring those touchpoints include the specific disclosures IPP 3A requires.
Are There Exceptions?
Yes. IPP 3A includes a range of practical exceptions, and the OPC has published a decision flowchart to help organisations work through whether notification is required in their specific circumstances.[3]
The most relevant exception for employers is where the individual has already been made aware of the collection. If your existing communications with employees or prospective employees already clearly disclose that background checks will be conducted, name the types of checks and the provider used, and explain the purpose and recipients of that information, then you may be able to rely on this exception going forward, because the individual has already been notified.
Other exceptions include where telling the individual would prejudice the purpose of the collection (for example, in a fraud investigation), where the information is publicly available, or where notification is not reasonably practicable because you don’t hold contact details for the individual.[3]
However, the OPC is clear that inconvenience, administrative burden, or cost alone does not make notification “not reasonably practicable.” Organisations are expected to build notification into their processes and systems, not treat it as optional.[3]
The Key Question to Ask About Your Current Process
For most employers, the practical question is straightforward: do your current processes already tell individuals, in sufficient detail, that you will be collecting their personal information from third-party sources like background check providers, at any point across the employment lifecycle?
If the answer is yes, if your forms, employee and candidate communications, or privacy notices already name the types of checks being conducted, identify CVCheck as your provider, state the purpose of those checks, and explain how individuals can access or correct their information, then you may already be well-placed to meet the new requirements, provided that information is specific enough to satisfy the OPC’s guidance.
If the answer is no, or if you’re not sure, now is the time to review your processes and communications across the full employment lifecycle and update them before 1 May 2026.
How Kinatico CVCheck Can Help
Kinatico CVCheck conducts background checks on behalf of employers across New Zealand, including police checks and child worker safety checks, as well as a range of verification services covering identity, qualifications, and work entitlements.
As your screening partner, Kinatico CVCheck can assist with the practical side of meeting your IPP 3A obligations, including providing clear, accurate descriptions of the checks we conduct on your behalf, which you can incorporate into your privacy notices and communications with individuals.
The compliance obligation under IPP 3A sits with your organisation as the indirect collector, but getting the language right about what is being collected and why is something we can support you with. Talk to our team about how we can help you build a screening process that is both thorough and compliant with the new requirements.
The deadline is 1 May 2026. IPP 3A applies to all personal information collected indirectly on or after that date.[1] The time to review your processes and update your privacy notices is now.
References
- New Zealand Ministry of Justice. Enhancing the Privacy Act. https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/
- Office of the Privacy Commissioner. Privacy Amendment Act passes. https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-amendment-act-passes/
- Office of the Privacy Commissioner. IPP3A: notification requirements for indirect collection of personal information. https://www.privacy.org.nz/resources-and-learning/a-z-topics/ipp3a/




