Sharing data in a deal: your Privacy Act 2020 obligations
A Bay of Plenty aged-care operator goes to market. Two villages, 140 residents, 210 staff. To save a day, the seller’s adviser opens a data room and uploads the raw operational drive whole: resident health charts, next-of-kin sheets, medication records, full payroll, ACC claim files. Three trade buyers get folder access on day one.
Nothing leaks. The deal still has a problem, because every one of those files is personal information about an identifiable person, disclosed to outside parties with no thought for the law that governs it. The signed NDAs protect the seller’s commercial secrets. They do nothing for the resident whose dementia diagnosis just landed in a stranger’s downloads folder.
Before any of the law, one decision frames everything: what you share files with. The tool sets the ceiling on how many duties you can even meet, so start there, not with the principles.
| Privacy Act duty | Email or USB | Consumer file-sharing | Deal-grade data room |
|---|---|---|---|
| Limit disclosure to authorised recipients (IPP 11) | ✗ | partial | ✓ |
| Keep a record of who accessed what (accountability) | ✗ | partial | ✓ |
| Revoke access after a party leaves the deal | ✗ | partial | ✓ |
| Disclose and control offshore storage (IPP 12) | ✗ | ✗ | ✓ |
| Detect and reconstruct a breach quickly | ✗ | ✗ | ✓ |
| Redact and minimise personal information | ✗ | ✗ | ✓ |
Read down the “Email or USB” column. It fails almost every row, and not because email is badly built. Email was never designed for controlled disclosure. A shared consumer drive scrapes a partial pass on a few rows and still cannot tell you, months later, exactly which bidder opened which file.
The rest of this guide is the law behind that table. It is not exotic. Privacy sits in almost every New Zealand deal, because almost every data room is thick with personal information: employee files, customer lists, director details, shareholder registers, contractor contracts.
Does the Privacy Act 2020 reach your deal documents?
Usually yes, and more broadly than deal teams expect. The Act protects “personal information”, meaning information about an identifiable individual. A due diligence pack is dense with it.
The scope catches, at a minimum:
- Employee files, salaries, performance notes and disciplinary records.
- Customer and client lists, especially where individuals are named.
- Director, shareholder and guarantor details, including home addresses.
- Contractor and referee contacts, email threads and photographs.
- In regulated sectors, health records, ACC files and client case notes.
Two things narrow the scope, and only two. Purely business information with no individual attached is out: aggregate revenue, plant valuations, a building lease. Information about a company, on its own, is out too, though the people behind it rarely are.
Everything else is a working assumption of “in scope”. The safe posture is simple. Assume a meaningful slice of your documents is personal information, then handle the whole room to the standard the sensitive parts demand.
What in the room actually counts as personal information?
The confusion is almost always the same one, and it is worth naming before you touch a permission setting.
Confidentiality is not privacy
Teams conflate the two constantly. They are related, and they are not the same thing.
- Confidentiality is a contract between the parties. An NDA protects the seller’s commercial secrets.
- Privacy is a duty you owe to individuals. It exists whether or not anyone signed anything.
- An NDA can be watertight and your privacy exposure still fully intact.
An NDA protects the seller’s secrets. It does nothing for the employee whose personal file you disclosed without a lawful basis. Privacy is a duty you owe to people, not a clause you owe to the counterparty.
Sensitivity is not flat
The Act does not grade information into formal tiers. Harm plainly scales anyway, and your controls should track it, as the grid above lays out.
- Highest: health data, ACC records, biometric or identity documents, bank details.
- High: salaries, home addresses, private contact details, disciplinary files.
- Moderate: work email threads, named performance notes, referee contacts.
- Low: names and roles already public on a register or a website.
For the aged-care operator, the room’s real risk lived in a handful of folders: resident health charts and staff medical records. Everything else was ordinary business information dressed up as a privacy problem. Naming the sensitive slice early is half the job.
What does IPP 11 ask when you disclose to a bidder?
IPP 11 is the disclosure principle. You engage it the instant you grant a bidder access to a folder. In short: you may only disclose personal information for a purpose connected to why you collected it, unless another lawful ground applies.
Running a genuine sale process generally fits. Disclosing what a buyer reasonably needs to assess the business generally fits. The principle still expects restraint, and restraint means minimisation:
- Prove your wage bill with a redacted schedule, not full employee files.
- Show customer concentration with aggregated figures, not the raw database.
- Release the most sensitive folders late, once a bidder is genuinely serious.
- Prefer view-only over download for anything in the highest sensitivity band.
The what documents go in a data room checklist is a good place to decide what genuinely belongs in the room versus what can wait or be masked. The tools IPP 11 rewards are exactly what a room provides: per-group permissions, staged access, and redaction so you can disclose the fact without the identity.
The Office of the Privacy Commissioner sets out all thirteen Information Privacy Principles in plain language on privacy.org.nz. It is worth a skim before you brief advisers. The same gap the matrix exposes is the one we cover in virtual data room vs Dropbox.
Compare data rooms on residency and controls
See how the providers we track handle offshore storage, permissions and audit trails, side by side.
What does IPP 12 ask when your data crosses the border?
This is the principle most New Zealand deal teams miss, because almost every data room stores your files offshore. Ansarada, iDeals, Datasite and Firmex run their infrastructure in Australia, the United States or the EU. The moment your personal information lands on a server outside New Zealand, IPP 12 is engaged.
IPP 12 does not ban offshore disclosure. It sets conditions. You may send personal information to a party outside New Zealand only through one of a defined set of gateways.
Where your deal data actually travels
The five gateways, in plain terms:
- The individual authorises the transfer after being told it may not be protected as it is here.
- The overseas party is subject to comparable safeguards to New Zealand’s.
- A binding contract requires the party to protect the information comparably.
- The party is bound by a prescribed binding scheme.
- The receiving country has privacy law comparable to New Zealand’s.
The full wording lives in the Privacy Act 2020 on legislation.govt.nz. For a reputable provider the workable route is usually two gateways at once: comparable safeguards, backed by a binding contract in the provider’s data-processing terms.
Your job on IPP 12 is small and concrete:
- Confirm the storage region in writing before you upload anything.
- Get the provider’s comparable-protection commitment in the contract, not the brochure.
- Prefer a provider that lets you choose or at least confirm where data sits.
- Treat Australia and the EU as comfortable; the US is common and workable with the right terms.
The failure mode is not choosing the wrong country. It is never asking the question. Our security guide’s data residency section walks through what to demand.
Which industries carry the heaviest privacy load?
Not every deal carries the same exposure. The volume of personal information, and its sensitivity, swings hard by sector, and that should shape how carefully you stage the room.
The pattern across New Zealand deals looks like this:
| Sector | The heaviest personal information | Control that earns its keep |
|---|---|---|
| Aged care and health | Resident charts, medication and ACC records | Locked folders released only at exclusivity |
| Professional services | Client files, matter notes, staff pay | Redaction and named-adviser access |
| SaaS and tech | Customer databases and support tickets | Aggregated metrics, not raw exports |
| Hospitality and retail | Rosters, payroll, loyalty-scheme data | Salary banding and view-only rosters |
| Construction and trades | Subcontractor and site-worker records | Per-group permissions by trade |
A few reads from the table. Health and aged-care sit at the top for a reason: harm from a leaked diagnosis is severe and immediate. Professional services firms carry a double load, their own staff data plus their clients’.
Tech companies underestimate the risk almost as a rule, because a customer database feels like an asset rather than a liability. The moment it is copied into a bidder’s environment “for analysis”, it becomes both.
The practical lesson holds across all of them. Match the tightness of your staging to the sensitivity of the sector, and default to holding the worst folders back until a bidder has earned them.
What can a privacy failure actually cost?
Put numbers on it, because the numbers frame every control decision that follows. New Zealand’s headline fines are modest by global standards. The civil damages and the deal fallout are not.
| Consequence | Figure (NZD) | Who imposes it |
|---|---|---|
| Damages for an interference with privacy | Up to $350,000 per person | Human Rights Review Tribunal |
| Fine for failing to notify a notifiable breach | Up to $10,000 | District Court (offence under the Act) |
| Fine for obstructing or misleading the Commissioner | Up to $10,000 | District Court |
| Compliance notice to fix a breach of the principles | No fine, but binding and public | Privacy Commissioner |
| Deal delay, re-trading or collapse after a leak | Often six figures in adviser time | The counterparty and the market |
Read the top row twice. The Human Rights Review Tribunal can award up to NZD $350,000 to a single individual for a serious interference with their privacy. Now recall the aged-care room: 210 staff files and 140 resident records. The per-person cap is the number that matters, because a room can put dozens of individuals in scope at once.
The $10,000 offence fines look almost trivial beside that, which is the point. The real exposure sits in two places the fine schedule cannot show:
- The civil track, where damages run per affected person and add up fast.
- The commercial track, where a leak during live diligence re-prices or kills the deal.
There is a subtler cost as well. Trust. A buyer who watches you fumble a staff file quietly re-prices the risk of everything else you are telling them. Privacy discipline reads, on a deal, as competence.
When does a room incident become a notifiable breach?
The Privacy Act 2020 made breach notification mandatory, and the duty falls on you as the agency holding the information, not on the software vendor alone. The test is a harm test, not a headcount test.
If a privacy breach is likely to cause “serious harm” to an affected individual, it is notifiable. You must tell the Privacy Commissioner and the affected people as soon as practicable. Serious harm is judged on:
- The sensitivity of the information involved.
- Whether it was protected, encrypted for example, or exposed in the clear.
- Who obtained it, and what they are realistically likely to do with it.
A leaked, unencrypted list of resident diagnoses and next-of-kin numbers is a world away from one non-sensitive document viewed by a party who should have lost access a day earlier. New Zealand sets no fixed countdown, but “as soon as practicable” is not “when it suits you”. The clock below is the shape of a competent response.
The Commissioner’s NotifyUs tool walks you through the assessment, and CERT NZ is where you report the security side of a cyber incident.
If you suspect a breach, work through this
Move quickly but deliberately. The audit log in a deal-grade room is what makes each of these steps possible.
- 1
Contain it
Revoke the access that caused the exposure, reset affected credentials, and stop any further disclosure. In a proper room you can cut a user off across every device in one click.
- 2
Reconstruct what happened
Pull the audit log to establish exactly which documents were accessed, by whom, and when. This is the evidence that lets you assess harm accurately rather than guessing.
- 3
Assess the harm
Weigh the sensitivity of the information, whether it was encrypted, who now holds it, and the likely consequences. Use the Privacy Commissioner's NotifyUs assessment to decide if the threshold is met.
- 4
Notify if it is notifiable
If serious harm is likely, notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. Failing to notify is itself an offence.
- 5
Record and remediate
Document the incident and your response, then fix the root cause: tighten permissions, close stale access, and review the process so the same gap cannot reopen.
The sequence has one hard dependency. You cannot assess harm you cannot see. A room without a page-level, tamper-evident audit log leaves you unable to tell the Commissioner what was actually accessed, which turns a manageable incident into an admission of ignorance. This is one reason the certifications that back a provider’s controls matter.
Who is accountable, you or the provider?
Both, but not equally. Under New Zealand’s framework the business running the deal is the agency accountable for the personal information. The provider is, in effect, processing that information on your behalf.
The split is clean once you name it:
- You choose the provider, configure it, and decide what goes in the room.
- The provider commits, by contract, to security, breach notification back to you, and comparable offshore protection.
- Those provider commitments are what help you satisfy IPP 5 and IPP 12.
- The decisions that cause most real breaches remain entirely yours.
Careless permissions, data you had no basis to disclose, a stale login left open after an adviser rolls off: none of that transfers to the vendor.
The provider gives you the controls. You are accountable for using them. A departed adviser’s still-live login is not a vendor failure; it is a housekeeping failure, and it is yours.
Choosing a serious provider raises your ceiling. It does not lower your floor. Our buyer’s guide to choosing a data room puts the privacy and security questions near the top of the checklist, where they belong.
What do you owe when your own advisers open the room?
The first parties you disclose to are almost never the buyer. They are your own side: the law firm running the sale, the accountant preparing the financials, the corporate finance adviser managing the process. Each opens the room and downloads personal information. Each is a disclosure under the Act.
The Act treats this more gently than a disclosure to a bidder, on one condition. Where an adviser holds personal information solely as your agent, in connection with the purpose you collected it for, it sits comfortably within IPP 11. “Solely as your agent” is a real limit, not a formality. An adviser steps outside it when they:
- Copy your customer list for their own marketing.
- Keep a diligence pack on file after the engagement ends.
- Store downloads on a personal drive outside the firm’s controls.
The practical move is to fold advisers into the same discipline as bidders:
- Give each adviser their own named permission group, never a shared login.
- Make the engagement letter require them to protect, then return or destroy, the data.
- Switch access off the moment their role ends.
Running the question-and-answer workflow through named accounts, not forwarded emails, keeps the accountability chain intact. It also means the audit log stays complete, which is the whole point of having one.
Does the buy-side carry privacy duties too?
Yes, and the sharp buyers act on it early. Once a bidder downloads personal information from the room, that bidder becomes an agency handling personal information in its own right, with its own duties under the Act.
A buyer who hoovers up the full customer database “for analysis” and stores it loosely has just created its own breach risk. A seller who allowed the download shares the exposure. So the discipline cuts both ways:
- Sellers should resist over-broad download requests and default the most sensitive material to view-only.
- Sellers should release copies only when the deal genuinely warrants it, usually at or after exclusivity.
- Buyers should pull only what they need and store it inside proper controls.
- Buyers should delete personal information if the deal collapses; a transaction that did not happen gives it no ongoing purpose.
On an M&A process, the parties who handle this crisply spend less time arguing about data handling and more time closing. It signals a well-run house on both sides of the table.
How does this sit with the Companies Act and NZX rules?
The Privacy Act does not operate alone. A deal touches other regimes, and they interact in ways that catch teams out. Two are worth naming.
First, some of the data in your room is already public, which softens part of the risk. The New Zealand Companies Register lists directors and shareholders under the Companies Act 1993, so a shareholder’s name is hardly a secret.
What the register does not publish is the sensitive detail:
- Salaries and pay records.
- Personal email addresses and mobile numbers.
- Bank account details.
- Home addresses beyond a director’s service address.
Those are exactly the fields a raw payroll export dumps into the room, and none of them stop being personal information because the company itself is on a public register.
Second, if the target is listed, NZX continuous-disclosure obligations sit alongside your privacy duties. A leak from the data room can become a market-sensitive event as well as a privacy breach, which means two clocks start at once. The general practice guidance at business.govt.nz is a sensible plain-English starting point before you loop in counsel on the listed-company overlay.
The takeaway is not to master three statutes. It is to recognise that a single sloppy disclosure can trip more than one, and to run the room tightly enough that none of them fire.
How do you run a Privacy-Act-safe sharing process?
You do not need a privacy lawyer on speed dial for an ordinary deal, though sensitive or large ones warrant advice. You need a short, deliberate routine, applied before documents go in, not after a bidder complains.
The routine, in order:
- Map the personal information in your document set, and flag the highest-sensitivity folders.
- Minimise before you upload: redact salaries to bands, mask identifiers, hold sensitive folders back.
- Choose a provider whose storage region is disclosed and whose contract commits to comparable safeguards. That covers IPP 12.
- Set least-privilege permissions per group, so each party sees only its scope. That covers IPP 11 by design.
- Keep the audit log close, and know your breach routine before you ever need it.
A tidy folder structure makes those permission groups fall out naturally, and a clear due diligence checklist stops you over-disclosing in the rush.
Back to the Bay of Plenty operator. The fix cost nothing but ten minutes of ordering. Two locked folders for health records, released only at exclusivity. Redacted payroll bands in place of raw exports. Named adviser logins. A disclosed storage region and a signed comparable-protection clause. Same deal, same buyers, same timeline, and the privacy exposure moved from unmanaged to boring. Boring is the goal.
See what a room with the right controls costs
A flat monthly plan with a 14-day free trial, disclosed residency, granular permissions and a full audit trail.
Privacy Act 2020 and data sharing: frequently asked questions
Does the Privacy Act 2020 apply to sharing documents in a data room?
Yes, whenever those documents contain personal information about identifiable individuals, which a due diligence pack almost always does. Employee files, customer lists, shareholder registers and director details are all personal information. A non-disclosure agreement protects commercial confidentiality but does not discharge your privacy duties to those individuals.
Can I store deal data offshore under the Privacy Act?
Yes, but only through an IPP 12 gateway. The workable route for a reputable provider is usually comparable safeguards backed by a binding contract that commits the provider to protect the data to a New Zealand-equivalent standard. Confirm the storage region in writing and prefer a provider that lets you choose or confirm it. See the Privacy Act 2020 for the exact wording.
When do I have to report a data room breach?
When the breach is likely to cause serious harm to an affected individual. That test weighs the sensitivity of the information, whether it was encrypted, who obtained it and what they might do. If the threshold is met you must notify the Office of the Privacy Commissioner and the affected people as soon as practicable, using the NotifyUs tool. Failing to notify a notifiable breach is an offence.
What is the maximum penalty for a privacy breach in New Zealand?
Offence fines under the Act are up to NZD $10,000, for example for failing to notify a notifiable breach or misleading the Commissioner. The larger exposure is civil: the Human Rights Review Tribunal can award damages of up to NZD $350,000 per person for a serious interference with privacy, and a deal room can involve many individuals at once.
Is the data room provider or my business responsible for compliance?
Your business is the accountable agency; the provider processes the data on your behalf. A good provider commits contractually to security, breach notification and comparable offshore protection, which helps you meet your duties, but configuring permissions, deciding what to disclose and managing access remain your responsibility.
How do I minimise personal information before sharing?
Redact identifiers you do not need to disclose, such as reducing salaries to bands or masking names in a customer sample, and stage the most sensitive folders so they open only for serious bidders. Prefer view-only access over download for the most sensitive material. A clean folder structure and permission groups make this straightforward.