Source: Privacy Commissioner
28 Sept 2026, 14:00
Retailers have obligations to protect personal information under the Privacy Act 2020. This means you need to know what personal information you are collecting and why, be open with your customers and employees, have a plan to keep the information safe, and delete it when it’s no longer required.
This guidance also includes examples about how retailers interact with the Health Information Privacy Code, for example pharmacists.
We are currently developing further comprehensive retail sector guidance about the use of Facial Recognition Technology (FRT) and other biometric technologies. We don’t yet have a date for release but keep an eye on our website.
Collecting personal information
When collecting personal information as a retailer you need to:
Data minimisation
A key safeguard for protecting personal information is the idea of data minimisation. This is about only collecting and holding the information you really need.
Before you ask people for their personal information, think carefully about the reason you are collecting it. The more information you hold and the longer you hold it for increases the risk and the harm that could occur in the case of a privacy breach.
You should never keep information just in case you may need it in the future. It is important your business has a retention policy on how long information is kept for and a secure process for disposing of information once is not longer needed.
For example, as a supermarket, you might view drivers’ licences when verifying the age of a customer buying alcohol, but you shouldn’t need to collect or retain driver licence information in order to fulfil this purpose. However, you might collect and retain the name and address of a customer to issue a membership card or contact them with deals.
Collection – retail sector examples
Jewellery store collects CVs
CVs contain personal information like your name, address, contact details, and employment or education history.
A local jewellery store is reviewing the way they collect personal information and whether this is in line with the Privacy Act’s collection rules. They assess that they comply with the collection rules based on the following practises:
- IPP1: their reason for collecting the CVs is to be able to hire staff to work in their store.
- IPP2: they collect CVs directly from the individuals themselves via email or physical drop-off.
- IPP3: when CVs are dropped off in person, the duty manager is called to receive it. The store manager tells the person about their vacancies and how long the CV will be held on file for, and that only the owner will view CVs in order to make a hiring decision. Once the recruitment process has been finalised, CVs are then securely disposed of. This information is also passed on via auto-reply email for CVs emailed.
- IPP3A: the owner collects personal information about the job applicant from a referee (and not the individual directly). The individual was made aware of this collection when the owner asked them to provide referee details.
- IPP4: they collect information in a way that is lawful, fair, and not unreasonably intrusive, for example they only contact referees that the applicant has nominated.
Boutique clothing store
New owners have recently bought a local boutique clothing store. The new owners want to set up an online store to widen their sales reach. To manage online sales, they will need to collect personal information from their customers, such as name, contact details, and delivery address to process deliveries.
When thinking about the rules around collecting information they assess the following:
- IPP1: the reason for collecting personal information is to advertise their product, or communicate about special promotions, as well as to manage the purchase and delivery of products.
- IPP2: The store collects this information directly from the person it’s about.
- IPP3: The website field where people enter their personal information links to their privacy statement discussing how the information will be used and whether personal information will be shared with any third parties.
- IPP3A: The new owners also acquired the existing customer database in the sale. Because of this they also need to think about their obligations under IPP3A for indirect collection of personal information. Before selling the business, the previous owners informed their customers that the names, contact details, and addresses they held on file would be transferred to the new owners and that customers retained the right to access and correct this personal information. The previous owners provided the new owners with evidence of the communication sent to their customers, and the new owners were comfortable that the individuals had already been made aware of the indirect collection. Both the previous and new owners communicated with the customers in the database to give them the opportunity to unsubscribe if they don’t want to remain in the database.
- IPP4: They collect personal information fairly and are transparent about what they are collecting, why they’re collecting it, and how they’ll use it. They only collect contact details, rather than more sensitive personal information about family, income, and spending habits. They don’t obtain information by coercing people or through deception (e.g. offering a prize that doesn’t exist). When asking if a customer is part of their loyalty system, they ask for the customer’s name and one more confirming detail e.g. phone number or email to verify the individual.
Local pharmacy
Pharmacies collect lots of health information to provide medicine to people. Health information is sensitive personal information which means more care needs to be given to ensure that it is protected effectively. The Health Information Privacy Code 2020 (HIPC) creates rules around how health information is handled by health agencies.
A local pharmacy is reviewing their privacy practices. When looking into the collection rules under the HIPC, they assess the following:
- Rule 1: Their reason for collecting health information is to provide medicine to people and information about how to use them.
- Rule 2: Rule 2 says that information must be collected from the person directly unless an exception applies. Pharmacies often collect peoples’ health information indirectly through scripts sent by General Practitioners (GPs). Exceptions to Rule 2 include when an individual authorises their information to be collected from somewhere else as long as the individual has been made aware of the required information under Rule 3A, or when collecting from the individual’s representative, or when it is not reasonably practicable in the circumstances.
- Rule 3: The pharmacy has a privacy statement it has on display on their website and physically in-store. This outlines that health information is being collected, the reason it’s being collected, who will see the information, the pharmacy’s contact information, that the collection of certain information is mandatory in order to supply medicine and that if the information is not collected, they are unable to fulfil their service, as well as the right to access and correct health information under rules 6 and 7.
- Rule 3A: Before the GP sends the script to the pharmacy, they ask the patient which pharmacy they’d like them to send it to. This informs the patient that their information will be sent to a certain location. When the patient picks up their medication from the pharmacy, the pharmacy also provides the patient with the information that was sent by the GP.
- Rule 4: When the individual comes to collect a script from the pharmacy, the pharmacy verifies the individual by asking for their address and date of birth. The pharmacy staff are careful to be discreet when asking for this information, or when discussing certain medications with the individual to ensure this doesn’t unnecessarily disclose medical conditions to other staff and customers in the pharmacy.
Read our guidance on the collection of health information.
Storage and security (IPP5)
Organisations must ensure there are safeguards in place that are reasonable in the circumstances to prevent loss, misuse or disclosure of personal information.
System errors, scams, and employee browsing can all lead to a security failure. A secure IT network will help protect the personal information your organisation works with from hacks, viruses, and malware. The National Cyber Security Centre (NCSC) provides cybersecurity guidance that will help you keep personal information safe in your network.
The controls available to you in these scenarios can be categorised as:
- Physical – for example, building access, physical documents, and mobile device protection.
- Technical – for example, IT systems and cyber security.
- Organisational – for example, policies and procedures, staff behaviour, training, and awareness.
Often, you will need to use a combination of controls from all three categories to ensure you have a robust security system in place to reduce the likelihood of breaches.
What steps are appropriate will depend entirely on the context of your organisation, including:
- How sensitive is the personal information involved?
- What are you using the personal information for?
- What security measures are available, and how will using these measures impact on your organisation’s functions?
- What might the consequences be for the individual if the information is not kept secure?
Read our guidance on Security and Internal Access Controls for more information on preventative controls, secure storage and software, and employee browsing.
Storage and security – retail sector examples
Jewellery store assesses storage of CVs
A jewellery store receives CVs from people both physically by drop-offs and digitally via email.
The owner of the store usually stores the digital CVs in a folder on their personal laptop and the physical CVs in the drawer under a till. After an increase in digital CVs being received, the owner has decided to review how they manage them.
They assess that their physical storage of the CVs does not offer enough security and decide to digitise CVs that are being assessed or retained for upcoming positions, securely disposing of the physical copies immediately (such as shredding or using a secure destruction service) and deleting the digital copies once they’re no longer needed to fill roles. Only the owner who is in charge of hiring new staff needs to see CVs. They will store all CVs in a password protected file requiring multi-factor authentication on their laptop which is only accessed by the manager.
Boutique clothing store uses customer information
Before their online shop goes live, they go through the IPPs to make sure that they comply with their obligations for protecting personal information. For their compliance with IPP5, they assess that all personal information will be stored electronically through a third-party provider. The organisation understands that they are responsible for anything that happens to the personal information held by the third party, so they perform due diligence to ensure that the third party has security measures in place to protect against malicious actors or other unauthorised access and so the third party knows when to notify the store of any information breaches. We have guidance on what to do before using a third-party provider. They also put other measures in place so only staff that need to access information (i.e. to process online orders) will be able to do so via individual log-ins. The third-party provider offers the ability to audit access to personal information, and the shop undertakes spot audits to ensure that staff aren’t accessing it for other reasons. Staff are regularly reminded about this policy.
Local pharmacy
To comply with rule 5, health agencies need to consider what risks there are for the health information they hold, make a plan to address those risks and do what is necessary to carry it out. Read our guidance on storage and security for health information.
The local pharmacy uses a Pharmacy Management System where they receive scripts and other information from health agencies such as GPs and hospitals. This system enables limited access to information, and they provide regular privacy training to their staff on how to protect personal information.
Retention and disposal (IPP9)
You must not hold personal information for longer than is required for using the information for a lawful purpose. This means your retention policy will depend on your business’ particular context, for example, the purpose for collection and use.
How to manage retention as an organisation
We recommend setting up retention and disposal systems which could operate alongside other processes such as stocktaking.
These may look like:
- Have a clear process outlined in a policy: Your organisation should have a clear process to support the lawful retention and secure disposal of information.
- Different retention periods for different information: You also need to ensure that retention periods can be tailored to different circumstances.
- Regular review: Retention and disposal policies should be regularly reviewed to ensure that they are fit for purpose and appropriately followed in practice.
- Automated deletion: If possible, set up your systems to action your retention and disposal decisions in an automated way. Not doing so is a common cause of over-retention issues in organisations.
- Manual deletion: If there is no ability to automatically dispose of personal information, you will need to consider other ways, such as regular audits or manual review of the information you hold.
- Effective disposal: You need to consider how to effectively dispose of personal information so that it is unable to be retrieved.
Retention and disposal – retail sector examples
Jewellery store assesses how long to hold onto CVs
While thinking about the security of CVs they collect, the owner also looks into how long they should hold onto CVs for. Since retention of personal information is tied to the purpose they collected it for, they think about the original purpose of collecting CVs – to fill vacant roles. The rate of staff turnover means that the jewellery store is hiring regularly. It receives a high volume of CVs, so they tend to only look at CVs that have been dropped off recently when looking to fill roles. Because of these factors, they decide to delete CVs after three months.
Petrol station retains images of suspected shop lifters
A petrol station has experienced an increase in theft over the last month. When this occurs, they review the security camera footage and create a still image of the suspect where the footage is clear they have stolen something. These are reported to Police. The petrol station makes sure that only authorised staff can access and view the images for safety purposes, such as behind the counter where customers cannot see. Until now, the petrol station has collected a large number of these still images without getting rid of them, so they decide to set-up a rule to ensure that they delete them once they’re no longer needed. The images are given dates and manually deleted after two years, which is also when the security footage is deleted.
It is an offence to delete personal information if this information has been requested by the individual. Because of this, the petrol station checks that there aren’t live access requests before footage is deleted. Agencies must not deliberately delete or allow personal information (for example still photos or CCTV footage) to be deleted knowing a request for that information has been made. To do so is a criminal offence under the Privacy Act.
Local pharmacy
In line with Health Act regulations, the pharmacy’s Pharmacy Management System allows for automated deletion of scripts after a certain amount of time. The pharmacy has a policy that any physically printed scripts are to be securely destroyed once no longer needed to provide medicine to someone. This is communicated to staff in the regular privacy training sessions.
Where to go for more
Original source: https://nz.mil-osi.com/2026/09/29/how-retailers-can-protect-personal-information/
