AI and the Privacy Act: what IPP3A means for your AI tools

Since 1 May 2026, if you collect information about someone from somewhere other than them, you usually have to tell them. Plenty of AI tools do exactly that kind of collecting. Here is what the rule asks, where AI comes in, and a short checklist for any tool.

By Miro · A 10-minute read · for NZ businesses using AI tools with customer or client data · Last checked: 8 October 2026

IPP3A is a new information privacy principle, added to the Privacy Act 2020 by the Privacy Amendment Act 2025. It came into force on 1 May 2026. It covers indirect collection: personal information you get about someone from a third party rather than from them.

This guide is our plain-English reading of the rule and the Privacy Commissioner's guidance. It isn't legal advice. If you rely heavily on data about people from other sources, get advice for your situation.

What changed on 1 May 2026

Before IPP3A, the Privacy Act's notice rule (IPP3) only applied when you collected information directly from the person. Now, when you collect personal information about someone from someone else, you must take reasonable steps to make sure they know about it, unless an exception applies.

Where AI tools come in

Many AI tools collect information about people indirectly, sometimes without anyone noticing. Some examples:

  • Enrichment tools. A sales tool that looks up a lead's company, job title, LinkedIn profile or phone number is collecting information about that person from other sources.
  • AI notetakers. A client mentions their business partner's health or money troubles in a recorded meeting. For the partner, that's indirect collection.
  • Prospect lists. Using AI to build a list of named sole traders from directories and websites is indirect collection. People often rely on the "publicly available" exception here, but check it fits your purpose. This applies to consultancies doing outreach too, us included.
  • Referrals and handovers. A GP referral to a physio, an owner passing tenant details to a property manager, or a bank feed going to an accountant. Adding AI to how you process these doesn't change that they're indirect collection.

What you have to tell people

The Privacy Commissioner's guidance lists what people must be made aware of when you collect their information indirectly:

  • that the information has been collected
  • why it was collected
  • who will receive it
  • the name and address of the agency that collected it and the agency that holds it
  • if a law authorises or requires the collection, which law
  • their rights to access and correct their information

On timing, the guidance says this should happen "as soon as reasonably practicable after the information has been collected". If you delay, be ready to explain why.

The exceptions, and their limits

You don't have to notify in some situations. The Privacy Commissioner's list includes when:

  • the person is already aware of the collection
  • the information is publicly available
  • not notifying won't prejudice the person's interests
  • notifying would undermine the purpose of the collection
  • notifying is not reasonably practicable
  • a serious threat to public health or safety, or to someone's life or health, is involved
  • the information won't be used in a form that identifies the person, or is for research or statistics

There are also exceptions for law enforcement, security and some other specific situations. Two points matter for most businesses. First, the guidance says an agency isn't exempt "just because it may be inconvenient, time-consuming or incur some cost". Second, if you rely on an exception, write down your reasoning at the time.

Offshore AI tools and IPP12

Most AI tools run on servers outside New Zealand. IPP12 sets rules for disclosing personal information to someone overseas. Whether it applies depends on how the provider treats your data.

The Privacy Commissioner's guidance on overseas disclosure explains that when a provider holds information only as your agent (section 11 of the Act), the information is treated as still held by you. You stay responsible for it. But if the provider uses or discloses the information for its own purposes, it is treated as held by the provider too, and IPP12 can come into play. IPP12 then needs a basis for the disclosure, such as believing the recipient protects the information in a comparable way, or a contract using the Privacy Commissioner's model clauses.

Our reading: a tool that trains its own models on your customers' data is using that data for its own purposes. So the "training off, no retention" setting on a business-tier plan is often what keeps an AI tool on the agent side of the line. That's our reading of the guidance, not a ruling, and terms vary between vendors. Read the vendor's data terms, and get advice for your situation if the data is sensitive.

Health information

Clinics and other health agencies follow the Health Information Privacy Code 2020 rather than the IPPs. The code has its own versions of both rules:

  • Rule 3A mirrors IPP3A for health information collected indirectly, also from 1 May 2026. The Privacy Commissioner's guidance says it does not apply to health information collected before that date. Its examples include a GP receiving a hospital discharge summary.
  • Rule 12 covers disclosing health information outside New Zealand. It matters for AI scribes and chat tools hosted overseas.

Professional bodies are adding their own expectations. The Dental Council's guidance, for example, says to explain what AI will be used for and get consent before using it in patient care. And if you use face or voice recognition, the separate Biometric Processing Privacy Code 2025 applies. It came into force on 3 November 2025, and its transition period for existing users ended on 3 August 2026.

Six questions for any AI tool

Ask these before a tool goes near customer, client or patient information. Write the answers down; they become your record.

  1. What personal information goes in? Be specific. Names and emails are different from health details or bank statements.
  2. Where is it stored? Which country, and which company.
  3. Does the vendor keep it or train on it? Check the plan you're on, not the marketing page.
  4. Does the tool bring in information about people from elsewhere? If yes, IPP3A (or rule 3A) applies, and you need to decide how people will be told.
  5. Who checks the output? Name the role, not "someone".
  6. What do we tell people? Update your privacy notice, and decide when you tell people in person.

Update your privacy notice

Your website privacy notice is usually the cheapest way to cover part of the job, though for indirect collection you may still need to tell people directly. Here's a sample paragraph for a made-up business. Adapt it; don't copy it word for word.

Sample

Harbourside Physio (a made-up clinic): "We use an AI tool to help our physiotherapists write up treatment notes. The tool is provided by [vendor], stores data in [country], and does not use your information to train its models. Your physio checks every note before it is saved. When we receive information about you from someone else, such as a referral from your GP or ACC, we will let you know what we received and why. You can ask to see or correct your information at any time by contacting us at [address]."

When to call a lawyer

Get advice if you collect sensitive information about people from third parties at scale, if you're relying on an exception you aren't sure of, if a vendor's data terms are unclear, or if you're deciding anything significant about people with AI. A privacy lawyer can usually look at one tool and one data flow quickly.

Sources

Checked on 8 October 2026. Laws and guidance change, so check the source before relying on it.

Written by Miro at Even Odds · Not legal advice · Last checked: 8 October 2026

IPP3A questions

Does IPP3A apply to information I collected before May 2026?

IPP3A came into force on 1 May 2026. The Privacy Commissioner's guidance on the health version, rule 3A, says it does not apply to health information collected before that date. Our reading is that IPP3A works the same way, but check the guidance if it matters for your situation.

Is using ChatGPT "sending data overseas" under the Privacy Act?

It depends on how the provider treats your data. If it holds the data only as your agent, the Privacy Commissioner treats the data as still held by you. If it uses the data for its own purposes, such as training, IPP12 can apply. Business plans with training off are generally the safer choice. That's our reading, not legal advice.

Does IPP3A apply to every business, including sole traders?

Yes. The Privacy Act applies to businesses of every size, including sole traders.

What is the quickest thing to do this week?

List the AI tools your team uses, and for each one answer the six questions in this guide. Then update your privacy notice. That gets most businesses a long way.

What about face or voice recognition?

That is covered by a separate code, the Biometric Processing Privacy Code 2025. It came into force on 3 November 2025, and the transition period for existing users ended on 3 August 2026.

Want this sorted for your tools?

Start with the free check to see where AI fits in your business. If your team already uses AI with customer data, the AI Usage Policy ($295 + GST) sets the rules, with an approved-tools list covering where each tool keeps data.

The check is free. The AI Opportunity Report is $495 + GST and includes privacy notes for every tool it recommends.