Privacy & IPP Mapping (NZ)

We align our workflows with the Privacy Act 2020 Information Privacy Principles (IPPs). Below is a plain-English mapping of what that means in practice.

🛡️

Trusted, NZ-compliant AI solutions

  • Aligned to NZ Privacy Act 2020 and MBIE AI guidance.
  • Human-in-the-loop for auditability & clear accountability.
  • Versioned and transparent—no black boxes.
#PrincipleWhat it meansHow NZGPTS applies itEvidence
1Purpose of CollectionWe collect only what's needed to deliver the agreed services.Scoped intake forms; optional data minimisation by default.Scoped SOW + Audit Questionnaire
2Source of Personal InformationWe prefer collecting data directly from you unless impracticable.Client-owned exports; access via secure channels only.DPA + Secure Transfer SOP
3Collection from SubjectPeople are aware of collection where reasonable.Client informs staff/customers where needed.Privacy Notice Template
4Manner of CollectionCollection is lawful and fair.No scraping of private systems without written consent.SOW + Consent Clause
5Storage & SecurityReasonable safeguards against loss/unauthorised access.Encrypted at rest; least-privilege access; log review.Security Controls Checklist
6Access & CorrectionIndividuals can access and correct information.We assist clients to respond to requests quickly.Access Request SOP
8AccuracyWe take reasonable steps to ensure accuracy.Human-in-the-loop verification on deliverables.QA Sign-off
9RetentionKeep only as long as necessary.Default: 90-day retention; client override available.Data Retention Policy
10Use of InformationUse only for the purpose collected.No secondary use without consent.DPA Purpose Limitation
11DisclosureDisclose only with authority or lawful reason.Sub-processors listed; changes notified.Sub-processor Register
12Cross-borderTake steps to ensure comparable safeguards.Model clauses; reputable AI vendors; client approval.Cross-border Addendum
13Unique IdentifiersAvoid creating new identifiers unless necessary.We don't create new IDs; we use client references.Data Model Design
🔒 Your information never leaves New Zealand without explicit consent.

Privacy Documentation

Questions? Contact us. This page is versioned and updated as regulations evolve.