
Information privacy compliance under the Protection of Personal Information Act applies to any business that collects, stores or processes personal information, customer details, employee records, marketing data, regardless of size, and understanding the core obligations matters given the real financial and reputational cost of a data breach.
These are the core obligations every business needs to understand.
Collect and use personal information lawfully and minimally
Personal information should only be collected for a specific, legitimate purpose, and only to the extent genuinely necessary for that purpose, rather than collecting broadly on the assumption it might be useful later.
Customers and employees need to understand what information is being collected and why, which means privacy notices and consent processes need to be clear and genuine, not buried in unreadable fine print.
Secure personal information properly
Reasonable technical and organisational measures to protect personal information against loss, unauthorised access or damage are a genuine legal requirement, not only good practice, and the specific measures needed scale with the sensitivity and volume of data held.
This applies regardless of business size; a small business handling customer data has the same underlying obligation as a large corporate, even if the specific security measures appropriate to its scale differ.
Respond correctly to a data breach
A data breach must be reported to the Information Regulator and to affected individuals as soon as reasonably possible, with no minimum threshold for what counts as reportable, unlike some other jurisdictions’ rules.
Having a clear, prepared response plan before a breach happens, rather than improvising during an actual incident, genuinely reduces both the damage and the compliance risk of the response itself.
Build compliance into ongoing operations
Compliance isn’t a once-off registration or policy document; it requires ongoing attention as the business collects new types of data, adopts new tools, or changes how information is used.
Our guide to why compliance genuinely matters for SMEs covers the broader business case for treating compliance as an ongoing discipline rather than a box ticked once.
Frequently asked questions
Does information privacy law only apply to large companies?
No. It applies to any business collecting, storing or processing personal information, regardless of size.
What does lawful, minimal collection mean in practice?
Only collecting personal information for a specific, legitimate purpose, and only to the extent genuinely necessary for that purpose.
Is securing personal information optional good practice?
No, it’s a genuine legal requirement, with the specific measures needed scaling with the sensitivity and volume of data held.
What must happen if a data breach occurs?
It must be reported to the Information Regulator and affected individuals as soon as reasonably possible, with no minimum reporting threshold.
Is compliance a once-off task?
No. It requires ongoing attention as a business collects new data types, adopts new tools, or changes how information is used.
