Office of the Privacy Commissioner | Guidance for the retail sector
The retail sector has obligations under the Privacy Act. If you’re a retailer, you need to make sure you have a plan for how to handle personal information, and how to communicate this to your customers. You don’t need to overcomplicate it, and we’ve got plenty of guidance to help you get started.
Read the answers to questions retailers ask often:
- What is personal information?
- Are there any rules about where CCTV can be used?
- Can I use facial recognition technology?
- Can a business use a photo of me in their advertising without my consent?
- Can I get an organisation to take down a photo they have of me?
- As a retailer, can I publish a video or photos of people I suspect are shoplifting?
- Can I record someone without telling them?
- What should I do if I have become aware of, or have caused, a privacy breach?
Quick links for retailers
Doing privacy well is the law, but it also helps you improve data quality, innovation, customer and stakeholder trust, and decision-making processes. A strong privacy culture is a competitive advantage.
You need to know the reason you are collecting personal information, how you will tell your customers what you are doing, and how you will keep the information you hold safe.
- CCTV – when and how to use CCTV.
- Sharing CCTV images in shops – also known as ‘walls of shame'. Read about why this practice is likely to breach privacy.
- Poupou Matatapu – a free online toolkit to help you do privacy well.
- Information for privacy officers. The Privacy Act requires organisations to have at least one person who fulfils the role of privacy officer.
- Privacy Statement Generator – make a quick, free privacy statement for your business.
- Biometrics guidance for when you're using biometric technologies like facial recognition technology in your store.
- Working with third-party providers. What you need to think about from choosing a third-party provider, to your ongoing responsibilities when using them.
- Artificial Intelligence. Protecting privacy when using AI.
- IPP3A – requirements when collecting personal information from a source other than the person it’s about.
- Children and Young People Project. To guide you on when you should or shouldn’t collect personal information from children and young people, for example when developing apps targeted at children.
- Protecting personal information in the retail sector. Information and examples for retail organisations on storing and deleting personal information.
Case notes
- Organisation uses teenager’s image without consent, uses it in advertising campaign
- Charity shop failed to notify CCTV cameras recorded audio
- Photo of woman kept in public view at organisation
- Collection of credit information about job applicant by potential employer
- Employee objects to employer’s hidden tape recording in theft investigation
OPC compliance team’s decision notes:
- Two PAK’nSAVE stores found in breach of Privacy Act
- Utility providers’ poor ID verification processes lead to customer harm
Tribunal decisions
Upskill your privacy knowledge with our free e-learning modules
Whether you’ve got 30 minutes or four hours, we’ve got free online privacy training to suit. Our modules outline the basics, give examples, then test you on what you’ve learnt. You can redo the tests over and over until you get it right and we’ll show you the answers so you can see how you went and help you learn from your mistakes.
Useful for: you, your team, your manager - anyone who handles or has access to personal information should use these training modules.
- Privacy 101 – an introduction to the Privacy Act 2020
- Privacy Breach Reporting
- Employment and Privacy
- Find an e-learning course that best suits your needs
Privacy breaches and when to notify us
A privacy breach occurs when an organisation or individual either intentionally or accidentally:
- Provides unauthorised or accidental access to someone's personal information.
- Discloses, alters, loses or destroys someone's personal information.
A privacy breach also occurs when someone is unable to access their personal information due to, for example, their account being hacked.
If your organisation has a privacy breach that either has caused or is likely to cause anyone serious harm, you must notify the Privacy Commissioner and any affected people as soon as you are practically able, and no later than 72 hours after becoming aware of a notifiable privacy breach.
- Read more information on notifiable privacy breaches.
- Notify Us of a serious harm privacy breach.
- Read our comprehensive guidance on breach management.
Examples of how privacy works in retail
| IPP 1 – Purpose for collection | Make sure you are only collecting personal information for a reason to do with your business or organisation. | For example, your purpose for collecting personal information could be to deliver a product, provide a service, or to find the right person to employ. |
| IPP 2 – Source of personal information | Collect personal information directly from the person it is about. | For example, if you are collecting personal information from your customers to contact them with or process orders, you should collect this information directly from them. |
| IPP 3 – Notification | Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it. The best way to do this is usually with a clear privacy statement. | Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it. The best way to do this is usually with a clear privacy statement. |
| IPP 3A – Notification of indirect collection | Tell people if you collect their personal information from someone other than the person themselves. | For example, if you have collected personal information that wasn’t sourced from the individual directly, such as if you receive customer personal information from another business or organisation. Read our guidance on what you need to tell people when you’ve collected their information from someone else. |
| IPP 4 – Manner of collection | Make sure the way you collect peoples’ information is done in a fair and reasonable way. What is fair depends a lot on the circumstances like the individual concerned (age and capacity), the sensitivity of the information, the purpose for collection, or the degree to which the collection intrudes on privacy. |
For example, you shouldn’t record CCTV footage in restricted places, such as changing rooms. |
| IPP 5 – Storage and security | You need to have safeguards to protect peoples’ information. | Protection of personal information could look like storing personal information such as any physical copies of personal information (such as CVs) in a physically locked drawer or cupboard, or for online storage, using individual logins, multi-factor authentication to access systems, only having access to personal information if your role requires it. |
| IPP 6 – Access to personal information | People can ask you to see their personal information. Read our guidance on handling access and correction requests. | For example, you need to be able to provide personal information you hold about a customer when a customer asks for it. This could be their contact details, bank account details, address information you might hold about them as a customer, or other information you have collected or generated about them as a customer, such as their spending habits. |
| IPP 7 – Correction of personal information | People can ask you to correct information about them if they think it is wrong. | For example, an individual may request that their address or contact number be corrected. Read our guidance on handling access and correction requests. |
| IPP 8 – Accuracy | Before using or disclosing personal information, check that it is accurate and up-to-date. | For example, if you are concerned a person has shoplifted from your store, you need to take steps to check the information is accurate before using it. Sharing CCTV footage publicly, such as online or in-store, to claim that a person has committed a crime carries high privacy risk. Read our guidance on sharing CCTV images in shops or on social media. |
| IPP 9 – Retention | Delete personal information once you no longer need it. | For example, your organisation may delete customer information after a transaction has been completed. You will need to have a retention policy and know whether you have any specific legal requirements that apply to how long you can or must hold onto information to understand how long to hold onto personal information for. |
| IPP 10 - Use | Use personal information only for the reason it was collected. | For example, if you’ve collected personal information to provide a digital receipt to a customer, you won’t be able to use that information to market your products unless an exception under IPP10 applies, such as getting permission from the customer at the time of collection to contact them for marketing. |
| IPP 11 - Disclosure | You can only share personal information with other organisations if it’s for the reason you originally collected the information or for a directly related purpose. There are other reasons you might be able to share information, such as if the person tells you that you can or if it’s necessary to prevent or lessen a threat to public health or safety. | For example, you share customers’ personal information with other stores or service providers to facilitate another service that your business does not provide. |
| IPP 12 – Disclosure outside New Zealand | If you are sharing personal information to an organisation or location that is based overseas, you need to make sure you comply with IPP12. If you are sending personal information to a third-party solely for storage, then you may not need to comply with IPP12. Read our guidance on using third-party providers for information about your privacy obligations. |
For example, your store has locations in multiple countries. The head office is located overseas and has requested employee data. There is a risk sharing personal information that has not been de-identified overseas so you need to ensure employee awareness and authorisation. Under IPP12, you make sure that the personal information you send will be protected by comparable privacy laws in the country the agency is based in. |
| IPP 13 – Unique identifiers | Unique identifiers are subject to some restrictions.Unique identifiers are individual numbers, references, or other forms of identification allocated to people by organisations as a way to uniquely identify the person to the organisation assigning the identifier. Examples include driver’s licence numbers, passport numbers, IRD numbers, or National Health Index (NHI) numbers. You shouldn’t assign unique identifiers issued by other agencies as the primary identifier for a person in your own system. | For example, you shouldn’t use a unique identifier from another organisation, such as a driver’s licence number, to identify someone in your system. |