New Privacy Rules Are Coming: What IPP3A Means for Digital Investigations

New Zealand organisations routinely collect personal information from sources other than the individual concerned. During a workplace investigation, this may include information obtained from colleagues, customers, security systems, email accounts, mobile devices, public websites or an external investigator. Insurers, legal teams and fraud investigators may also obtain information from third parties when establishing what happened.

From 1 May 2026, a new privacy requirement will change how many of these indirect collections must be handled.

Information Privacy Principle 3A, known as IPP3A, will generally require an organisation to tell a person when it has collected personal information about them from another source, unless a specific exception applies.

At the end of March 2026, the Office of the Privacy Commissioner finalised corresponding changes to New Zealand’s health, telecommunications, credit reporting and biometric privacy codes. Organisations should now ensure their investigation and information-collection procedures are ready.

What Is Indirect Collection?

Indirect collection occurs when an organisation obtains personal information from someone or somewhere other than the individual concerned.

Examples may include:

  • interviewing an employee’s colleagues;
  • obtaining CCTV footage from a building manager;
  • collecting account information from a service provider;
  • reviewing publicly available social media content;
  • receiving information from another government agency;
  • obtaining records from an employer, insurer or financial institution; or
  • engaging an external investigator to gather relevant information.

The new rule applies to personal information collected indirectly from 1 May 2026. It does not retrospectively apply to information collected before that date.

What Must the Individual Be Told?

Where IPP3A applies, the collecting organisation must take reasonable steps to ensure the individual is told:

  • that their personal information has been collected;
  • the purpose for which it was collected;
  • the intended recipients of the information;
  • the name and address, or equivalent contact details, of the agency collecting and holding it;
  • where the collection is authorised or required by law, the particular law involved; and
  • that the individual has rights to access and request correction of their information.

In some situations, another organisation may provide this notice on behalf of the collecting agency. However, responsibility for compliance generally remains with the organisation collecting the information for its purposes. It should be able to demonstrate that the required notice was actually provided.

Does This Prevent Confidential Investigations?

IPP3A does not mean that every person must be notified immediately when an investigation begins. Notification must generally be provided as soon as reasonably practicable after the information is collected. A delay may be acceptable where it is operationally necessary and can be properly justified.

Separately, an exception may mean notification is not required at all. This includes situations where telling the person would prejudice the purpose of a legitimate investigation. For example, notifying someone that information is being collected during a suspected fraud investigation could give them an opportunity to delete evidence, influence witnesses or alter their account of events.

The Privacy Commissioner’s guidance specifically recognises that an internal fraud investigation may sometimes rely on this exception. However, the exception is not automatic. The organisation must still have a lawful basis for collecting the information indirectly under Information Privacy Principle 2. It should collect only information that is necessary and relevant to the matter being investigated. A preference for secrecy, administrative convenience, cost or concern that the person may be upset is not enough.

Organisations relying on a delay or exception should document:

  • the purpose of the investigation;
  • why indirect collection was necessary;
  • what information was collected;
  • why immediate notification would create a genuine risk;
  • whether an IPP3A exception applies;
  • when that risk is expected to end; and
  • whether notification should occur later.

Public Information Is Not Always Exempt

IPP3A contains an exception for certain publicly available information. This may cover information obtained from a public register, published news article, openly accessible website or genuinely public social media page.

The exception is unlikely to apply where access requires membership, approval, credentials or some other form of restricted access. This could include private social media accounts, closed groups or platforms that require permission before content can be viewed.

Investigators should therefore record not only the information collected, but also how it was accessed and whether it was genuinely available to the public.

A screenshot alone may not establish whether the underlying page was public, restricted or accessed through an authenticated account.

Sector-Specific Rules Have Also Changed

On 25 March 2026, the Privacy Commissioner issued amendments incorporating IPP3A into four privacy codes:

  • the Biometric Processing Privacy Code;
  • the Credit Reporting Privacy Code;
  • the Health Information Privacy Code; and
  • the Telecommunications Information Privacy Code.

The amended codes were published on 27 March 2026.

The amended rules generally take effect from 1 May 2026. However, the Biometric Processing Privacy Code has a separate transition period.

For biometric processing that began on or before 3 November 2025, the Code, including its new Rule 3A, will apply from 3 August 2026. Organisations that began relevant biometric processing after 3 November 2025 do not receive the same transition period.

The biometric rules may be particularly relevant to organisations using facial recognition, fingerprints, voice analysis or behavioural characteristics for identification, security or investigative purposes.

External Investigators and Forensic Providers

Where an external investigator or forensic provider handles information solely on behalf of an organisation, the Privacy Act may treat the information as being held by the instructing organisation rather than creating a separate collection for the provider’s own purposes.

Organisations should clarify:

  • whether the provider is acting solely on their behalf;
  • which organisation is the indirect collector;
  • who will provide any required IPP3A notice;
  • how notification will be documented;
  • what information the provider is authorised to collect; and
  • how the information will be secured, retained and deleted.

Using an external provider does not automatically transfer the organisation’s privacy responsibilities.

What Organisations Should Do Before 1 May

Legal, privacy, human resources and investigation teams should review their procedures now.

Identify indirect collection activities

Map where personal information is obtained from third parties, digital platforms, employees, contractors and public sources.

Update investigation plans

Include an IPP3A assessment at the beginning of workplace, fraud and misconduct investigations.

Review privacy notices

Confirm whether existing notices adequately explain routine indirect collection and identify the organisations involved.

Document delays and exceptions

Where notification could undermine an investigation, record the specific risk, the applicable legal basis and whether the position should be reviewed later.

Review provider agreements

Clarify each party’s role, who will provide notice and how the collecting organisation will verify that notification occurred.

Preserve collection records

Record the source, date, collection method, purpose and handling history of information gathered during an investigation.

The Takeaway

IPP3A introduces an important transparency requirement for New Zealand organisations.

It does not prohibit legitimate digital investigations or require investigators to alert a subject before evidence can be secured. It does require organisations to think carefully about why information is being collected indirectly, whether notification is required and whether any delay or exception can be properly justified.

The safest approach is to address privacy at the beginning of an investigation rather than trying to reconstruct the justification after a complaint has been made.

How Forensic Tech Can Help

Forensic Tech assists legal teams and organisations with the lawful identification, preservation and collection of digital evidence.

This includes workplace and fraud investigation support, forensic acquisition of computers and mobile devices, email and messaging collections, cloud evidence, metadata analysis, evidence scoping and the preparation of documented, defensible findings.

Sources

New Zealand Legislation, Privacy Amendment Act 2025

Office of the Privacy Commissioner, IPP3A: Notification Requirements for Indirect Collection of Personal Information

Office of the Privacy Commissioner, Privacy Amendment Act Passes

Office of the Privacy Commissioner, Incorporating IPP3A into Codes of Practice: Submitters’ Feedback and OPC Response

Office of the Privacy Commissioner, Biometric Processing Privacy Code 2025

Office of the Privacy Commissioner, Health Information Privacy Code 2020

Office of the Privacy Commissioner, Telecommunications Information Privacy Code 2020

Office of the Privacy Commissioner, Credit Reporting Privacy Code 2020