New Zealand Privacy Act 2020
New Zealand's primary privacy legislation establishing 13 Information Privacy Principles and mandatory breach notification. Applies to any agency that collects, holds, uses, or discloses personal information in New Zealand, with no revenue threshold.
See where NodeZero appliesWhat is the NZ Privacy Act?
The Privacy Act 2020 is New Zealand's primary privacy legislation, replacing the Privacy Act 1993 and introducing mandatory breach notification for the first time. It establishes 13 Information Privacy Principles (IPPs) governing how agencies collect, store, use, and disclose personal information. For security teams, IPP 5 is the critical obligation -- it requires agencies to ensure personal information is protected by "such security safeguards as it is reasonable in the circumstances to take" against loss, unauthorised access, use, modification, or disclosure.
The Act introduced mandatory privacy breach notification from 1 December 2020. Agencies must notify the Office of the Privacy Commissioner (OPC) and affected individuals when a breach has caused, or is likely to cause, serious harm. The OPC has enforcement powers including compliance notices, and individuals can complain to the Human Rights Review Tribunal for interference with privacy. The Act also has extraterritorial reach -- it applies to overseas agencies that carry on business in New Zealand, regardless of where the personal information is collected or held.
Where NodeZero applies
NodeZero addresses IPP 5 — the security safeguard obligation — by generating evidence that technical controls protecting personal information hold under real attack. Autonomous pentesting identifies exploitable paths to systems storing personal information, audits credentials that typically enable those attacks, classifies which categories of personal information an attacker could exfiltrate (processed locally, no data leaves your network), and validates segmentation around sensitive systems. For the mandatory breach-notification obligation, NodeZero produces preventive evidence and post-incident remediation verification. Governance IPPs covering collection, purpose limitation, and individual rights sit outside autonomous testing.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following require separate evidence: Information privacy principles 1–4 — Collection of personal information, Information privacy principles 6–11 — Access, correction, use and disclosure of personal information and Information privacy principles 12–13 — Disclosure outside New Zealand and unique identifiers.
Showing coverage grouped by compliance category.
Information privacy principle 5 — Storage and security of personal information
Strong alignment. NodeZero tests whether security safeguards protecting personal information hold under real attack.
Internal pentestingCore
Proof-of-exploit evidence of whether safeguards against unauthorised access, use, modification, or disclosure actually hold under real attack — the "reasonable in the circumstances" test.
External pentestingCore
IPP 5(a) is agnostic to where the exposure sits, and internet-facing assets are a primary attacker path to personal information — External pentesting maps the perimeter and chains paths to impact, with timestamped proof an attacker reached the asset.
Web application pentestingPriced separately
Tests the agency's own web applications and portals for the exploitable access-control and authentication weaknesses that let one person reach another's information — evidence of the safeguard failing, distinct from the perimeter mapping External pentesting provides.
Cloud pentestingCore
Most agencies hold personal information in AWS, Azure or M365 -- credentialed cloud pentesting proves IAM misconfiguration, privilege-escalation and lateral-movement paths to that data, including full Entra ID tenant compromise with no CVE. AWS, Azure/Entra ID and Kubernetes only -- no standalone GCP coverage.
AD Password AuditCore
Weak and reused credentials are the dominant path to unauthorised access — finds them before attackers do.
Phishing Impact TestingCore
Phished credentials are a dominant route to unauthorised access — Phishing Impact consumes credentials captured by your own phishing tool and proves what each one can reach: admin, cloud pivot, domain compromise, or data.
Advanced Data PilferingElite only
Shows which categories of personal information an attacker could reach inside your own environment, so you can see the exposure before handing data to a service provider — processing happens locally on your Docker host, no data leaves your network. Note: NodeZero does not test the service provider's own controls.
Segmentation testingCore
Validates whether the boundaries around PII-storing systems actually contain an attacker's lateral movement.
NodeZero TripwiresPro & Elite
Validates whether your detection stack would notice an attacker reaching PII-adjacent assets — Tripwires plant decoys during the test and any interaction with them is malicious by definition, so a missed alert exposes a monitoring gap.
NodeZero InsightsCore
One-click evidence-pack exports map findings from the tests below directly to the Privacy Act — evidence you can put in front of the OPC before an inquiry, or your board when reviewing IPP 5 safeguards. It packages the underlying Tier A/B evidence; it is not itself proof a safeguard works.
Part 6 — Notifiable privacy breaches
Preventive coverage. NodeZero identifies exploitable paths to personal information before they become notifiable breaches.
Internal pentestingCore
Every finding comes with proof of exploitation, giving you concrete evidence of what a weakness could actually reach — a firmer basis for the serious-harm assessment under s 112 and 113.
Advanced Data PilferingElite only
Shows the actual PII an attacker could reach on each path — concrete input to the s 113(b) sensitivity limb and the s 113(c) potential-harm limb of the serious-harm test.
Rapid ResponsePro & Elite
Rapid Response tests your exposure to newly-disclosed CVEs — often within hours of disclosure — so you can remediate an exploitable path before it becomes a notifiable breach; preventive evidence if the OPC asks how a breach could have been prevented.
Quick VerifyCore
Audit-ready evidence that remedial action closed the path that caused the breach — concrete input to the s 113(a) "action taken to reduce risk of harm" factor.
See every control mapped to NodeZero
The full control-by-control coverage map — every NZ Privacy Actrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
The NZ Privacy Act applies to every "agency" in New Zealand -- a term that covers government departments, local authorities, private sector organisations of any size, non-profits, trusts, and sole traders. Unlike the Australian Privacy Act, there is no revenue threshold -- the Act applies to all organisations that collect, hold, use, or disclose personal information in New Zealand.
The Act has extraterritorial application. If your organisation is based outside New Zealand but carries on business in New Zealand and collects personal information about New Zealand residents, the Act applies to you. This is particularly relevant for Australian organisations with New Zealand operations or customers.
If your organisation handles personal information of New Zealand residents -- whether you are a government agency, a private company, or an overseas entity doing business in New Zealand -- the Privacy Act 2020 applies to you. There are limited exemptions for news media, courts, and Members of Parliament acting in their official capacity.
Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.