NZ Privacy Act 2020 for Care Providers — What You Need to Know

Disability and aged care providers handle some of the most sensitive personal information in existence — diagnoses, medication histories, behavioural profiles, financial arrangements, daily routines, and family circumstances. Under the Privacy Act 2020, that information comes with significant obligations around how it's collected, stored, used, disclosed, and what happens when something goes wrong.

The 2020 Act replaced the Privacy Act 1993 and introduced two major changes that directly affect care providers: mandatory breach notification and strengthened access rights for individuals. Combined with the Health Information Privacy Code (HIPC), these rules create a compliance framework that every care organisation needs to understand and build into daily operations.

This article is a general guide only. It is not legal advice. Consult a privacy professional or legal adviser for guidance specific to your organisation. Last reviewed: Aug 2026.

Why This Matters More in Care Than Most Sectors

The Privacy Commissioner treats health information as among the most sensitive categories of personal information. A support worker reading a progress note on their phone on the bus, a care plan emailed to the wrong address, a shared login giving a former worker ongoing access to client records — these aren't abstract risks. They happen in care organisations regularly, and the consequences are serious: harm to vulnerable people, regulatory action, loss of funder trust, and potential prosecution.

Care providers are also in a position of significant power relative to the people they support. Many service users cannot easily advocate for themselves if their information is misused. The Act places the burden of getting this right firmly on the provider, not the individual.

The 13 Information Privacy Principles

The Act is built around 13 Information Privacy Principles (IPPs). For care providers, the most operationally relevant are:

Collection (IPP 1–4)

  • IPP 1 — Purpose: Only collect information that is necessary for a specific, lawful purpose directly connected to your service. Don't collect information speculatively because it might be useful one day.
  • IPP 2 — Source: Collect information directly from the person wherever possible. If you collect from a third party (family member, GP, previous provider, NASC assessor), the person should generally know this is happening.
  • IPP 3 — Collection notice: When collecting information directly, tell the person what you're collecting, why, who will have access, and what happens if they don't provide it. This is typically handled through your intake consent process — but generic consent forms that people sign without reading don't discharge this obligation properly.
  • IPP 4 — Manner of collection: Don't collect information in ways that are unlawful, deceptive, or would be considered unfair given the circumstances. Recording conversations without consent or using data from one purpose for another are examples of problematic collection.

Storage and Use (IPP 5, 9, 10)

  • IPP 5 — Security: Take reasonable steps to keep information secure against unauthorised access, use, disclosure, alteration, or loss. "Reasonable" scales with the sensitivity of the information — health information requires more robust security than, say, a mailing list.
  • IPP 9 — Retention: Don't keep information longer than necessary. Establish retention periods for different record categories and actually delete or destroy records when they expire. Keeping indefinite archives of sensitive client data is itself a privacy risk.
  • IPP 10 — Limits on use: Use information only for the purpose it was collected, or a directly related purpose. Using a client's home address collected for care delivery to send them marketing material is a misuse.

Disclosure and Access (IPP 6, 7, 11, 12)

  • IPP 6 — Access: Individuals have the right to request access to personal information you hold about them. This must be responded to within 20 working days with very limited exceptions.
  • IPP 7 — Correction: If information you hold is inaccurate, the individual can request correction. If you disagree that it's inaccurate, you must note their request for correction alongside the record.
  • IPP 11 — Limits on disclosure: Don't disclose information to third parties unless authorised. Sharing client information with their family members requires consideration — family isn't always the right person to receive this information, particularly where there are safety or relationship dynamics.
  • IPP 12 — Overseas disclosure: Before sending information overseas (including to cloud software hosted outside NZ), take reasonable steps to ensure the recipient provides comparable privacy protections. This applies to your care management software, your email provider, and any cloud storage you use.

Health Information — Heightened Obligations

Most information care providers hold about service users qualifies as health information under the Act and is subject to the Health Information Privacy Code (HIPC). The HIPC applies specific rules to health information on top of the general IPPs.

Health information in a care context includes diagnoses and medical history, medication records, behavioural support plans, progress notes, incident reports involving health events, assessment results, and NHI numbers. If you're uncertain whether a particular record is health information, assume it is — the downside of over-protecting is minimal; the downside of under-protecting is substantial.

The HIPC specifically addresses:

  • Health practitioners' obligations when collecting and disclosing health information
  • The rights of people to access their health records (generally broader than standard IPP 6)
  • Special rules for sensitive categories within health information (mental health, reproductive health, HIV status)
  • Disclosure to family members — the HIPC has specific provisions about when health information can be shared with whānau without the person's explicit consent

Handling Access Requests

Any person has the right to request access to personal information you hold about them. In practice, this means service users, former service users, their authorised representatives, and sometimes family members (with appropriate authority). Here's the process:

  1. Acknowledge within 20 working days: The clock starts when you receive the request — not when you finish locating the documents. If the request is complex and you need more time, you may extend by up to 20 additional working days, but you must notify the requester before the initial 20 days expire.
  2. Verify identity: Confirm you're providing information to the right person. For requests from authorised representatives (lawyers, guardians, advocates), confirm the basis and scope of their authority in writing.
  3. Locate all relevant information: This includes paper files, digital records, care management system records, emails, text messages, and any other format. "We couldn't find it" is not an acceptable response when records exist — it's a failure of records management.
  4. Review for exceptions: There are narrow grounds to withhold or redact information, including where disclosure would endanger someone's safety, reveal information about identifiable third parties who haven't consented, or is subject to legal professional privilege. These exceptions are genuinely narrow — when in doubt, seek legal or privacy advice before withholding.
  5. Provide in accessible format: The information should be provided in a format the person can actually use. If a service user has a communication disability, a 40-page PDF emailed to a support coordinator who reads it to them is not equivalent to a direct, accessible response.
  6. Document the request and response: Keep a record of who requested what, what was provided, any redactions made and the reason, and the dates. This is your evidence of compliance if the request is later disputed.

Mandatory Breach Notification — The Most Important Change

The Privacy Act 2020 introduced mandatory notification of privacy breaches. This replaced the previous voluntary regime and is the change most likely to catch providers off guard.

What Is a Notifiable Breach?

A privacy breach is notifiable if it has caused, or is likely to cause, serious harm to any affected individual. Factors the Privacy Commissioner considers in assessing serious harm:

  • The sensitivity of the information (health information almost always rates as high sensitivity)
  • Whether the breach could enable harm — discrimination, exploitation, identity-based violence, financial harm
  • The scale — one person's records sent to the wrong address vs. a system breach exposing hundreds of records
  • Whether the affected person is vulnerable
  • Whether the information could be used by someone with malicious intent

In a care context, almost any breach involving health information about a service user should be assessed as potentially notifiable. When in doubt, notify — the Commissioner's guidance is that it's better to report a breach that turns out not to require notification than to fail to report one that does.

Examples of Likely Notifiable Breaches

  • A support plan or behavioural assessment emailed to the wrong address
  • A shared device lost or stolen with unencrypted client records on it
  • A former worker who still has access to your care management system after they left
  • Physical files containing health information left in a public location or recycling
  • A database breach exposing client records to unauthorised parties
  • Progress notes for one client accidentally visible to another client's family through a software misconfiguration

What to Do When a Breach Occurs

  1. Contain the breach immediately: Revoke access, recall emails (where possible), secure the device, prevent further disclosure
  2. Assess the seriousness: Apply the serious harm test — is this notifiable?
  3. Notify the Privacy Commissioner: As soon as practicable after becoming aware of a notifiable breach. Use the Commissioner's online notification form. There is no fixed deadline in days, but prompt notification is both legally expected and practically important — delay is itself a compliance risk.
  4. Notify affected individuals: Where you can identify who is affected, notify them directly in plain language
  5. Investigate root cause: Understand what went wrong and why — human error, process failure, or system vulnerability
  6. Remediate and document: Fix the underlying issue and document the full timeline: when the breach occurred, when it was discovered, what was done, and what was changed to prevent recurrence

Failure to notify a notifiable breach is itself a breach of the Act. The Commissioner can issue a compliance notice, which can escalate to prosecution. More practically: if a serious breach causes harm to a service user and it later emerges that you knew and didn't notify, the reputational and legal consequences are far worse than the original breach.

Practical Compliance Steps

Know What You Hold and Where

Many care providers hold information in multiple places simultaneously — a care management system, paper files, email inboxes, shared drives, text message threads, and individual staff phones. You cannot protect what you can't find. Map your information assets: what is collected, where it lives, who has access, and how long you keep it.

Privacy Policy and Consent

Your intake process must include meaningful consent to collect and use health information. "Meaningful" means the person actually understands what they're consenting to — not just signing a form placed in front of them. Your privacy policy should be available in accessible formats and easy to find, not buried in an onboarding pack.

Staff Training

Most privacy breaches in care settings are caused by staff who don't recognise what constitutes a breach, don't follow information-handling procedures, or don't know who to tell when something goes wrong. Annual privacy training should be mandatory and should cover: what is personal and health information, secure handling practices, what not to share and with whom, and the breach reporting process. Keep training records — auditors and the Commissioner may ask for them.

Technical Security Controls

Basic security hygiene prevents a large proportion of data breaches: strong passwords or passphrase requirements, multi-factor authentication on any system holding client data, regular access reviews (remove access within 24 hours of a worker leaving), device encryption on any portable device with client data, and role-based access control so workers only see information relevant to the people they support.

Offshore Cloud Services

Most modern care management systems store data in cloud infrastructure outside NZ — commonly in Australia (AWS Sydney) or the US. Under IPP 12, you must take reasonable steps to ensure the overseas provider offers comparable privacy protections. Check the vendor's data processing agreement, privacy policy, and physical data location. "Our servers are in Australia and we comply with Australian Privacy Act" is a reasonable starting point but is not equivalent to NZ Privacy Act compliance — the two frameworks have differences.

Privacy compliance in care isn't just a legal obligation — it's a direct expression of respect for the people you support. Their information belongs to them. Your job is to be a trustworthy custodian of it. See how KareShift handles data security for NZ providers.

Secure, compliant data handling for NZ care providers

KareShift stores client and worker data with encryption at rest and in transit, role-based access controls, and full audit trails. 90 days free — no credit card required.

Start Free Trial