Mi-IT / IT SUPPORT FOR BUSINESSMi-IT / IT SUPPORT FOR BUSINESSMi-IT / IT SUPPORT FOR BUSINESSMi-IT / IT SUPPORT FOR BUSINESS
  • About
    • Why Choose Mi-IT as your MSP
    • Our Leadership Team
    • Our Partners
    • Qualified Multitenant Hoster Program
  • Capabilities
    • IT Support
    • Microsoft 365 Managed Services
    • Cloud
    • Cyber Security
    • Data Backup and Recovery
    • VOIP
    • IT Procurement
  • Happy Clients
  • Blog
  • Contact Us

Privacy Act 2020: Critical Steps Auckland Businesses Must Take Before Year-End

    Home Business Continuity Privacy Act 2020: Critical Steps Auckland Businesses Must Take Before Year-End
    Privacy Act 2020

    Privacy Act 2020: Critical Steps Auckland Businesses Must Take Before Year-End

    By Tolla Baroutsos | Business Continuity, IT Support, IT Trends, Microsoft Office 365 | Comments are Closed | 28 August, 2026 | 1

    The Privacy Act 2020 isn’t new, but many Auckland businesses still aren’t fully compliant. As the year winds down, this is the moment to fix that, before an audit, a breach or a customer complaint forces the issue.

    This guide breaks down exactly what the Privacy Act 2020 requires, and what Auckland small businesses need to action before year-end. Work through each section below.

    If you need help, MIIT can assess your setup and close the gaps.

    1. What the Privacy Act 2020 Actually Requires

    The Privacy Act 2020 governs how New Zealand businesses collect, store, use and disclose personal information. It applies to every business that holds customer, staff or supplier data regardless of size.

    Thirteen Information Privacy Principles sit at the core of the law. They cover everything from why you collect data, to how securely you store it, to when you must delete it. Principles worth paying close attention to include:

    • Limiting collection to what’s genuinely necessary
    • Keeping information accurate and up to date, and
    • Only retaining data for as long as there’s a legitimate business reason to do so.

    Most small businesses fall short without realising it. Data gets collected for one purpose, then quietly used for another, or kept indefinitely simply because deleting it feels riskier than keeping it. Neither approach sits comfortably with the Act.

    Privacy Act 2020 for small business

    2. When and How to Notify

    Not every IT incident is a notifiable breach. But many business owners don’t know where that line sits, which creates real risk, either through under-reporting genuine incidents or panicking over minor ones.

    A breach becomes notifiable when it’s likely to cause serious harm. This includes lost laptops with unencrypted customer data, misdirected emails containing personal details or a hacked system exposing client records. Serious breaches must be reported to the Office of the Privacy Commissioner and affected individuals as soon as practicable.

    By contrast, a minor internal mix-up with no real risk of harm, like an email briefly sent to the wrong internal team member and immediately recalled, usually won’t meet the threshold. When in doubt, it’s safer to assess formally rather than assume it doesn’t count.

    3. Review Information You Hold

    Most Auckland businesses collect more data than they think, spread across email, spreadsheets, CRMs and old files nobody has opened in years. Data sprawl like this makes compliance and breach response, much harder.

    Run a simple data audit before year-end. List what personal information you hold, where it’s stored, and why you still need it. Include shared drives, old marketing lists, and archived HR records not just your main systems.

    Anything you no longer have a legitimate reason to keep should be securely deleted, not left sitting as a liability. Fewer records held means less exposure if something ever does go wrong.

    4. Update Policies and Staff Practices

    A privacy policy that hasn’t been reviewed since it was first written is a red flag. Your policy should reflect what your business actually does today, not what it did years ago, including any new software, marketing tools or data collection methods added since.

    Make sure staff understand basic privacy obligations, especially around emailing personal information and handling customer requests for access to their own data. Under the Privacy Act 2020, individuals have a right to request the information you hold about them, and staff should know how to handle that request correctly.

    A short refresher session before year-end costs little and prevents easily avoidable mistakes. Even a 30-minute team briefing can meaningfully reduce your risk of a staff-caused breach.

    5. Strengthen Your Data Security

    The Privacy Act 2020 expects businesses to take reasonable security steps to protect personal information. Weak passwords and unpatched systems no longer meet that bar and regulators increasingly treat basic security as the baseline, not best practice.

    Enable multi-factor authentication across email and cloud accounts. Encrypt sensitive files, particularly on laptops and mobile devices that leave the office. Keep operating systems and software patched, since outdated systems are one of the most common routes attackers use to access personal data.

    These changes are quick to implement and directly reduce your breach risk. Most can be rolled out across a small business within a single working week.

    Are you looking for a reliable Managed IT Support and Services Provider in Auckland?

    Mi-IT is a leading, New Zealand owned Managed IT Support and Services provider. We support our clients in their business goals through reliable and scalable solutions.

    Send us an Email

    6. Check Your Third-Party Agreements

    If a third-party supplier mishandles data you’re responsible for, your business can still be held accountable under the Privacy Act 2020. Outsourcing a task doesn’t outsource the compliance obligation that comes with it.

    Review contracts with payroll providers, cloud platforms and marketing tools. Confirm they meet appropriate security and privacy standards and clarify who does what if a breach occurs. Look specifically for how each provider stores data, whether it’s encrypted and where their servers are physically located.

    This is easy to overlook, and it’s exactly where gaps hide. A quick supplier review before year-end often uncovers risks business owners didn’t know existed.

    7. Prepare a Breach Response Plan

    Businesses without a breach response plan waste critical hours figuring out what to do while a breach is actively unfolding. That delay increases harm, regulatory risk and reputational damage.

    Document clear steps: who gets notified internally, how affected individuals are contacted, and when the Privacy Commissioner must be informed. Assign specific responsibility to named people, not just a general team, so nothing stalls waiting for someone to take ownership.

    A simple one-page plan is far better than no plan at all. Test it once a year, ideally alongside your IT provider, so everyone knows their role before a real incident happens.

    8. Understand Cross-Border Data Disclosure Rules

    Many Auckland businesses use overseas cloud tools without realising this counts as an overseas data disclosure under the Privacy Act 2020. Popular platforms for email marketing, project management, and customer support are often hosted offshore by default.

    Before sending personal information offshore, via a US-based CRM or an overseas payroll system, confirm the receiving party offers comparable privacy protections to those required in New Zealand. Many major providers publish this information in their privacy or trust documentation, but it’s worth checking rather than assuming.

    This is a commonly missed requirement, and one regulators are paying closer attention to as more small businesses adopt overseas software by default.

    9. Why This Matters for Your Auckland Business

    Non-compliance isn’t just a legal risk. It damages customer trust and rebuilding that trust after a breach is far harder than preventing one.

    Year-end is a natural checkpoint. Use it to close out Privacy Act 2020 gaps before they carry into 2026. Pairing this with your broader IT checklist for 2026 gives your business a complete, audit-ready foundation

    Frequently asked questions

    1. Does the Privacy Act 2020 apply to small businesses?

    Yes. The Privacy Act 2020 applies to every New Zealand business that holds personal information, regardless of size or industry. There’s no small business exemption, even for sole traders and one-person operations.

    2. What counts as personal information under the Act?

    Personal information includes anything that identifies a person, such as names, email addresses, phone numbers, and financial or health details. It applies to customer, staff, and supplier data alike, including information stored in emails and spreadsheets.

    3. What happens if we don’t report a notifiable breach?

    Failing to report a notifiable breach can result in reputational damage. The Privacy Commissioner can also investigate and issue compliance orders against non-compliant businesses, which can be costly and time consuming to resolve.

    4. How long do we have to report a breach?

    Businesses must notify the Privacy Commissioner and affected individuals as soon as practicable once they become aware of a notifiable breach. Delaying notification increases legal and reputational risk.

    5. Do we need a written privacy policy?

    While not always strictly mandatory, a clear written privacy policy is strongly recommended and expected by most customers. It also demonstrates good faith compliance if a complaint or breach occurs.

    6. Are overseas cloud tools like US-based software a problem?

    They can be, if the overseas provider doesn’t offer comparable privacy protections to New Zealand law. Always check a provider’s privacy terms before sending customer data offshore.

    7. How often should we review our Privacy Act 2020 compliance?

    At least once a year, ideally before year-end, alongside a broader IT and security review. Regular reviews catch small gaps before they become serious problems.

    8. Can MI-IT help with Privacy Act 2020 compliance?

    Yes. Mi-IT helps Auckland businesses secure customer data, implement breach response plans, and meet the practical security expectations of the Privacy Act 2020. Get in touch for a compliance-focused IT review.

    IT Support Provider

    • Cloud
    • VOIP
    • Data Backup and Recovery
    • Microsoft 365 Managed Services
    • Cyber Security
    • IT Procurement
    About
    Our Partners
    Blog
    Terms and Conditions

     

          

    Please Contact us:

    +64 9 476 4540

    info@miit.co.nz

    2B William Pickering Drive, Albany, Auckland, 0632

    Designed by Graphic Detail Ltd. Copyright © 2018.
    • About
      • Why Choose Mi-IT as your MSP
      • Our Leadership Team
      • Our Partners
      • Qualified Multitenant Hoster Program
    • Capabilities
      • IT Support
      • Microsoft 365 Managed Services
      • Cloud
      • Cyber Security
      • Data Backup and Recovery
      • VOIP
      • IT Procurement
    • Happy Clients
    • Blog
    • Contact Us
    Mi-IT / IT SUPPORT FOR BUSINESS