This is general guidance for small business owners, to help judge whether this needs attention and roughly what it involves. For your actual obligations, follow the Privacy Commissioner’s current guidance, and take professional advice where sensitive information or complex situations are involved — this article does not substitute for legal advice.
When it applies
New Zealand privacy law applies to agencies collecting personal information, and there is no size threshold — “we are too small for this” is not a category.
The question is whether your website collects personal information.
Many people assume that without a membership system nothing is collected. In fact all of the following count:
Contact forms. Name, email, phone — collection in its most direct form.
Email subscriptions. An address is enough.
Online bookings. Usually including preferences and sometimes more sensitive detail.
Analytics. Frequently overlooked — tools like Google Analytics record visitor behaviour and identifiers. You see aggregates; collection still occurred.
Third-party tracking code. Advertising pixels, chat widgets, embedded maps can all collect data from your pages.
So in practice the great majority of commercial websites collect personal information, and some of their owners do not know it.
What a privacy policy generally covers
The purpose is telling visitors what you take, what for, who else sees it, and what they can do. Usually:
What is collected. Listed specifically, not “we may collect certain information”.
Why. Purposes stated concretely. “To improve our services” is broad enough to mean nothing.
Where it is held and for how long. If data sits on overseas servers — common in New Zealand, where many providers host in Australia or the United States — that belongs in the policy.
Who else receives it. The third-party services you use are processing this data: email providers, form services, analytics, a CRM. Name them.
The visitor’s rights. People have the right to see the information you hold about them and to request correction. Your policy should explain how — usually by providing a contact.
Contact details. A person or address for privacy matters.
What most sites get wrong
Among websites that do have a policy, a large share share one problem: the policy does not describe what the site actually does.
Typically it was copied from elsewhere and mentions cookie banners, member accounts and features you do not have — or the reverse, where three analytics tools are installed and none appear in the policy.
This is worse than having none. An inaccurate statement is itself a problem.
So the practical first step is not finding a template. It is establishing what your site actually loads: open the network panel in developer tools and look at which third-party domains are requested. You will likely find things you had forgotten — a pixel from a finished campaign, a chat widget trialled and never removed, analytics installed by a previous supplier.
That step alone often removes several unnecessary things and makes the site faster.
Do you need a cookie banner
Frequently confused.
New Zealand currently has no equivalent to the EU requirement for cookie consent banners. So their absence from many New Zealand websites is not an oversight.
Two situations warrant thought: if your site addresses EU visitors, those rules may apply; and some advertising platforms require consent under their own terms.
For a small business serving New Zealand customers, a banner is usually unnecessary. If in doubt, an accurate privacy policy is worth more than a copied pop-up asking people to agree to something nobody has defined.
Not only a compliance matter
Worth viewing from another angle.
A specific, honest privacy policy is a trust signal, particularly for visitors about to leave a phone number or request material. Someone hesitating may genuinely open that link.
A visibly copied policy describing features you do not have communicates that you did not take it seriously.
It belongs to the same family as everything else verifiable on a site — registration number, real address, defined scope — each of which lowers the cost of deciding to trust you.
How to go about it
1. Find out what your site collects. Network panel, list every third-party request. Free, and frequently surprising.
2. Remove what you do not need. Dormant pixels, unused tools. One less thing collected is one less thing to explain.
3. Write the policy against what remains. A template can start you off, but check every clause against reality and delete descriptions of features you do not have.
4. Link it in the footer on every page. Not prominent, but findable.
5. Update it when you add tools. The most commonly missed step — a new analytics tool or a changed form service leaves the policy out of date.
If your business involves sensitive personal information — health, financial, anything concerning children — or you handle data from overseas visitors, this is worth having reviewed professionally, at a cost well below dealing with a problem afterwards.
When we deliver a project we give the client a list of what the site actually collects, as the basis for writing a policy — because the usual problem is not an absent policy but one that disagrees with the site. We suggest the policy itself is finalised by the client or their adviser; we do not provide legal advice.