New Zealand's Privacy Act 2020 allows businesses to hire offshore teams, as long as personal information stays protected to New Zealand standards. Under Information Privacy Principle 12 (IPP 12) and section 11 of the Act, an offshore team member who processes data on your behalf is your agent, so your business, not the worker, remains responsible for that information. Pear Tree builds Privacy Act compliant workflows into every New Zealand placement, with Employer of Record and Contractor of Record services from AUD$400 per month.
Yes. The Privacy Act 2020 does not prohibit New Zealand businesses from engaging offshore staff who handle personal information. It regulates how that information is protected, not where the person handling it sits. Thousands of New Zealand organisations already work with offshore teams within the Act, and doing so compliantly is a matter of structure rather than special permission.
The Act, administered by the Office of the Privacy Commissioner (OPC), sets out 13 Information Privacy Principles that govern how agencies collect, use, store, and disclose personal information. Two of them, IPP 12 and the agent provision in section 11, do the heavy lifting when an offshore team is involved, and understanding both is what keeps a New Zealand business on the right side of the law.
IPP 12 governs the disclosure of personal information outside New Zealand. It says a New Zealand agency can send personal information overseas only where the recipient is subject to comparable privacy safeguards, whether through similar law, a binding contract, or the individual's authorisation. It exists so information about New Zealanders does not lose its protection the moment it crosses the border.
The important point for offshore hiring is what counts as a disclosure. Sending information to someone overseas to process solely on your behalf, as your agent, is not treated as a disclosure under IPP 12 (Office of the Privacy Commissioner, Privacy Act 2020). That distinction is the foundation of compliant offshore hiring, and section 11 explains why.
An offshore worker processing data on your behalf is your agent, not a third party you have disclosed information to. Section 11 of the Privacy Act 2020 states that where one party holds information as an agent for another, the information is treated as held by the principal agency, not the agent. In plain terms, a New Zealand business that engages an offshore team member to work its data still legally holds that data itself.
This carries a clear consequence: your business remains fully responsible for protecting the information and for ensuring your offshore agent meets New Zealand's privacy safeguards. The table below sets out the key obligations and what each means for an offshore team.
Because the worker is your agent rather than an external recipient, the compliance question is not "am I allowed to do this" but "have I put the safeguards in place". Those safeguards are practical and well within reach.
If a privacy breach involving offshore staff is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. The Privacy Act 2020 introduced this mandatory notifiable breach scheme, and the OPC expects notification within around 72 hours of an agency realising a breach is notifiable.
The obligation sits with your New Zealand business, not the offshore worker, because you remain the responsible agency under section 11. Serious harm is assessed on factors including how sensitive the information is, who accessed it, and what security was in place. This is why access control matters: a breach that never exposes sensitive data, or that was contained by strong security, is far less likely to reach the serious-harm threshold.
You keep offshore teams compliant by combining a written agreement, strong access controls, and the principle of least privilege. The Act requires reasonable security safeguards (IPP 5) and that information is used only for the purpose it was collected for (IPP 10 and 11), so an offshore team member should see only the data their role needs and use it only for your business.
The practical safeguards are straightforward, and the checklist below covers the core of them.
Pear Tree builds these controls into every New Zealand placement as standard: VPN, two-factor authentication (2FA), role-based cloud access, and a contract that binds the worker to New Zealand privacy safeguards. For businesses wanting a formal legal layer, an Employer of Record (EOR) formally employs the worker on your behalf, while a Contractor of Record (COR) does the same for contractor arrangements, both keeping the engagement compliant from AUD$400 per month.
Penalties under the Privacy Act 2020 are more modest than in some jurisdictions, but the reputational cost is not. Failing, without reasonable excuse, to notify the Commissioner of a notifiable breach is an offence carrying a fine of up to NZ$10,000. The OPC can also issue compliance notices, make binding decisions on access complaints, and name organisations publicly.
The real exposure is trust. New Zealand courts and regulators are increasingly scrutinising how businesses handle personal information (MBIE 2025), and a publicised breach involving customer or candidate data can do far more damage than the fine itself. Compliant offshore hiring protects the relationship with your customers as much as it satisfies the regulator.
Pear Tree helps New Zealand businesses by structuring every placement to meet the Privacy Act 2020 from day one. Compliant cloud workflows, VPN, 2FA, and role-based access are built into onboarding, which takes one to two weeks, and EOR or COR cover is available where a formal legal entity is preferred. Each placement also carries a six-month replacement guarantee.
With offices in Auckland and Hawke's Bay alongside Cebu, Manila, and Cape Town, Pear Tree operates in both the New Zealand market and the talent markets, so data governance is handled by people who understand New Zealand obligations and can enforce them on the ground. Across 750+ Australian and New Zealand companies, that is how offshore teams stay both productive and compliant.
The Privacy Act 2020 permits New Zealand businesses to hire offshore teams, and treats an offshore worker processing your data as your agent under section 11, which means your business stays responsible for protecting that information. Meet IPP 12 through comparable safeguards, secure access under IPP 5, and notify any serious breach, and offshore hiring is fully compliant. Pear Tree builds those safeguards into every New Zealand placement so the obligation is met by design.
AUTHOR BIO: Frank Kight is Co-Founder of Pear Tree, a direct offshore talent placement company helping Australian and New Zealand businesses hire world-class Filipino and South African professionals, without the agency markup. Frank leads operations and talent sourcing across the Philippines and South Africa, and works with New Zealand clients on building compliant, secure offshore teams. With offices in Sydney, Auckland, Cebu, Manila, Cape Town, and Hawke's Bay, Pear Tree has placed talent with 750+ companies and maintains a 90% retention rate.