Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

The retail sector has obligations under the Privacy Act. If you’re a retailer, you need to make sure you have a plan for how to handle personal information, and how to communicate this to your customers. You don’t need to overcomplicate it, and we’ve got plenty of guidance to help you get started.  

A man in a suit sits on a bed using a laptop. He is surrounded by shopping bags.

IPP3A

A long shot of a black woman shopping in a supermarket. She pushes a trolley.

Biometrics

A woman's hands sit on a laptop

Sorting privacy breaches

Read the answers to questions retailers ask often:

A middle aged woman in a teal top with shoulder length blonde hair uses an eftpos machine in a shop Quick links for retailers

Doing privacy well is the law, but it also helps you improve data quality, innovation, customer and stakeholder trust, and decision-making processes. A strong privacy culture is a competitive advantage. 

You need to know the reason you are collecting personal information, how you will tell your customers what you are doing, and how you will keep the information you hold safe.

Case notes

OPC compliance team’s decision notes:

Tribunal decisions

Upskill your privacy knowledge with our free e-learning modules

Whether you’ve got 30 minutes or four hours, we’ve got free online privacy training to suit. Our modules outline the basics, give examples, then test you on what you’ve learnt. You can redo the tests over and over until you get it right and we’ll show you the answers so you can see how you went and help you learn from your mistakes. 

Useful for: you, your team, your manager - anyone who handles or has access to personal information should use these training modules. 

Privacy breaches and when to notify us 

A privacy breach occurs when an organisation or individual either intentionally or accidentally:

  • Provides unauthorised or accidental access to someone's personal information.
  • Discloses, alters, loses or destroys someone's personal information.

A privacy breach also occurs when someone is unable to access their personal information due to, for example, their account being hacked.

If your organisation has a privacy breach that either has caused or is likely to cause anyone serious harm, you must notify the Privacy Commissioner and any affected people as soon as you are practically able, and no later than 72 hours after becoming aware of a notifiable privacy breach.

Examples of how privacy works in retail

IPP 1 – Purpose for collection Make sure you are only collecting personal information for a reason to do with your business or organisation.  For example, your purpose for collecting personal information could be to deliver a product, provide a service, or to find the right person to employ. 
IPP 2 – Source of personal information Collect personal information directly from the person it is about. For example, if you are collecting personal information from your customers to contact them with or process orders, you should collect this information directly from them. 
IPP 3 – Notification  Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it. The best way to do this is usually with a clear privacy statement.  Tell people when you are collecting their information from them, including what information you’re collecting, why, and what you’ll do with it. 

The best way to do this is usually with a clear privacy statement. 
IPP 3A – Notification of indirect collection Tell people if you collect their personal information from someone other than the person themselves.  For example, if you have collected personal information that wasn’t sourced from the individual directly, such as if you receive customer personal information from another business or organisation. Read our guidance on what you need to tell people when you’ve collected their information from someone else.
IPP 4 – Manner of collection Make sure the way you collect peoples’ information is done in a fair and reasonable way.

What is fair depends a lot on the circumstances like the individual concerned (age and capacity), the sensitivity of the information, the purpose for collection, or the degree to which the collection intrudes on privacy.
For example, you shouldn’t record CCTV footage in restricted places, such as changing rooms.
IPP 5 – Storage and security You need to have safeguards to protect peoples’ information.   Protection of personal information could look like storing personal information such as any physical copies of personal information (such as CVs) in a physically locked drawer or cupboard, or for online storage, using individual logins, multi-factor authentication to access systems, only having access to personal information if your role requires it. 
IPP 6 – Access to personal information People can ask you to see their personal information. Read our guidance on handling access and correction requests. For example, you need to be able to provide personal information you hold about a customer when a customer asks for it. This could be their contact details, bank account details, address information you might hold about them as a customer, or other information you have collected or generated about them as a customer, such as their spending habits. 
IPP 7 – Correction of personal information People can ask you to correct information about them if they think it is wrong. For example, an individual may request that their address or contact number be corrected. Read our guidance on handling access and correction requests.
IPP 8 – Accuracy  Before using or disclosing personal information, check that it is accurate and up-to-date. For example, if you are concerned a person has shoplifted from your store, you need to take steps to check the information is accurate before using it. Sharing CCTV footage publicly, such as online or in-store, to claim that a person has committed a crime carries high privacy risk. Read our guidance on sharing CCTV images in shops or on social media. 
IPP 9 – Retention  Delete personal information once you no longer need it. For example, your organisation may delete customer information after a transaction has been completed. You will need to have a retention policy and know whether you have any specific legal requirements that apply to how long you can or must hold onto information to understand how long to hold onto personal information for.  
IPP 10 - Use Use personal information only for the reason it was collected. For example, if you’ve collected personal information to provide a digital receipt to a customer, you won’t be able to use that information to market your products unless an exception under IPP10 applies, such as getting permission from the customer at the time of collection to contact them for marketing. 
IPP 11 - Disclosure You can only share personal information with other organisations if it’s for the reason you originally collected the information or for a directly related purpose. There are other reasons you might be able to share information, such as if the person tells you that you can or if it’s necessary to prevent or lessen a threat to public health or safety.  For example, you share customers’ personal information with other stores or service providers to facilitate another service that your business does not provide.  
IPP 12 – Disclosure outside New Zealand If you are sharing personal information to an organisation or location that is based overseas, you need to make sure you comply with IPP12. 

If you are sending personal information to a third-party solely for storage, then you may not need to comply with IPP12. Read our guidance on using third-party providers for information about your privacy obligations. 
For example, your store has locations in multiple countries. The head office is located overseas and has requested employee data. There is a risk sharing personal information that has not been de-identified overseas so you need to ensure employee awareness and authorisation. 

Under IPP12, you make sure that the personal information you send will be protected by comparable privacy laws in the country the agency is based in.
IPP 13 – Unique identifiers Unique identifiers are subject to some restrictions.Unique identifiers are individual numbers, references, or other forms of identification allocated to people by organisations as a way to uniquely identify the person to the organisation assigning the identifier.  Examples include driver’s licence numbers, passport numbers, IRD numbers, or National Health Index (NHI) numbers. You shouldn’t assign unique identifiers issued by other agencies as the primary identifier for a person in your own system. For example, you shouldn’t use a unique identifier from another organisation, such as a driver’s licence number, to identify someone in your system.