Source: Privacy Commissioner
| IPP 1 – Purpose for collection |
Make sure you are only collecting personal information for a reason to do with your business or organisation. |
For example, your purpose for collecting personal information could be to deliver a product, provide a service, or to find the right person to employ. |
| IPP 2 – Source of personal information |
Collect personal information directly from the person it is about. |
For example, if you are collecting personal information from your customers to contact them with or process orders, you should collect this information directly from them. |
| IPP 3 – Notification |
Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it. The best way to do this is usually with a clear privacy statement. |
Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it.
The best way to do this is usually with a clear privacy statement.
|
| IPP 3A – Notification of indirect collection |
Tell people if you collect their personal information from someone other than the person themselves. |
For example, if you have collected personal information that wasn’t sourced from the individual directly, such as if you receive customer personal information from another business or organisation. Read our guidance on what you need to tell people when you’ve collected their information from someone else. |
| IPP 4 – Manner of collection |
Make sure the way you collect peoples’ information is done in a fair and reasonable way.
What is fair depends a lot on the circumstances like the individual concerned (age and capacity), the sensitivity of the information, the purpose for collection, or the degree to which the collection intrudes on privacy.
|
For example, you shouldn’t record CCTV footage in restricted places, such as changing rooms. |
| IPP 5 – Storage and security |
You need to have safeguards to protect peoples’ information. |
Protection of personal information could look like storing personal information such as any physical copies of personal information (such as CVs) in a physically locked drawer or cupboard, or for online storage, using individual logins, multi-factor authentication to access systems, only having access to personal information if your role requires it. |
| IPP 6 – Access to personal information |
People can ask you to see their personal information. Read our guidance on handling access and correction requests. |
For example, you need to be able to provide personal information you hold about a customer when a customer asks for it. This could be their contact details, bank account details, address information you might hold about them as a customer, or other information you have collected or generated about them as a customer, such as their spending habits. |
| IPP 7 – Correction of personal information |
People can ask you to correct information about them if they think it is wrong. |
For example, an individual may request that their address or contact number be corrected. Read our guidance on handling access and correction requests. |
| IPP 8 – Accuracy |
Before using or disclosing personal information, check that it is accurate and up-to-date. |
For example, if you are concerned a person has shoplifted from your store, you need to take steps to check the information is accurate before using it. Sharing CCTV footage publicly, such as online or in-store, to claim that a person has committed a crime carries high privacy risk. Read our guidance on sharing CCTV images in shops or on social media. |
| IPP 9 – Retention |
Delete personal information once you no longer need it. |
For example, your organisation may delete customer information after a transaction has been completed. You will need to have a retention policy and know whether you have any specific legal requirements that apply to how long you can or must hold onto information to understand how long to hold onto personal information for. |
| IPP 10 – Use |
Use personal information only for the reason it was collected. |
For example, if you’ve collected personal information to provide a digital receipt to a customer, you won’t be able to use that information to market your products unless an exception under IPP10 applies, such as getting permission from the customer at the time of collection to contact them for marketing. |
| IPP 11 – Disclosure |
You can only share personal information with other organisations if it’s for the reason you originally collected the information or for a directly related purpose. There are other reasons you might be able to share information, such as if the person tells you that you can or if it’s necessary to prevent or lessen a threat to public health or safety. |
For example, you share customers’ personal information with other stores or service providers to facilitate another service that your business does not provide. |
| IPP 12 – Disclosure outside New Zealand |
If you are sharing personal information to an organisation or location that is based overseas, you need to make sure you comply with IPP12.
If you are sending personal information to a third-party solely for storage, then you may not need to comply with IPP12. Read our guidance on using third-party providers for information about your privacy obligations.
|
For example, your store has locations in multiple countries. The head office is located overseas and has requested employee data. There is a risk sharing personal information that has not been de-identified overseas so you need to ensure employee awareness and authorisation.
Under IPP12, you make sure that the personal information you send will be protected by comparable privacy laws in the country the agency is based in.
|
| IPP 13 – Unique identifiers |
Unique identifiers are subject to some restrictions.Unique identifiers are individual numbers, references, or other forms of identification allocated to people by organisations as a way to uniquely identify the person to the organisation assigning the identifier. Examples include driver’s licence numbers, passport numbers, IRD numbers, or National Health Index (NHI) numbers. You shouldn’t assign unique identifiers issued by other agencies as the primary identifier for a person in your own system. |
For example, you shouldn’t use a unique identifier from another organisation, such as a driver’s licence number, to identify someone in your system. |
Original source: https://nz.mil-osi.com/2026/09/29/guidance-for-the-retail-sector/