← Back to Learning Centre

Privacy Act 2020 and Offshore Teams: NZ Data Protection Guide

Blog Author Image
Frank Kight
July 27, 2026

New Zealand's Privacy Act 2020 allows businesses to hire offshore teams, as long as personal information stays protected to New Zealand standards. Under Information Privacy Principle 12 (IPP 12) and section 11 of the Act, an offshore team member who processes data on your behalf is your agent, so your business, not the worker, remains responsible for that information. Pear Tree builds Privacy Act compliant workflows into every New Zealand placement, with Employer of Record and Contractor of Record services from AUD$400 per month.

In short

New Zealand's Privacy Act 2020 permits offshore teams; it regulates how personal information is protected, not where the person handling it sits. Under section 11, an offshore worker processing data on your behalf is your agent, so your business legally still holds the data and stays responsible for it. Sending data to an agent to process for you is not a "disclosure" under IPP 12, but you must ensure New Zealand-level safeguards apply. Secure access under IPP 5 with VPN, 2FA and role-based permissions, use the data only for its purpose (IPP 10 and 11), and notify the Privacy Commissioner and affected individuals of any breach likely to cause serious harm. Failing to notify carries a fine of up to NZ$10,000. Pear Tree builds these controls into every New Zealand placement.

Does the Privacy Act 2020 allow New Zealand businesses to hire offshore teams?

Yes. The Privacy Act 2020 does not prohibit New Zealand businesses from engaging offshore staff who handle personal information. It regulates how that information is protected, not where the person handling it sits. Thousands of New Zealand organisations already work with offshore teams within the Act, and doing so compliantly is a matter of structure rather than special permission.

The Act, administered by the Office of the Privacy Commissioner (OPC), sets out 13 Information Privacy Principles that govern how agencies collect, use, store, and disclose personal information. Two of them, IPP 12 and the agent provision in section 11, do the heavy lifting when an offshore team is involved, and understanding both is what keeps a New Zealand business on the right side of the law.

What is IPP 12 and how does it apply to offshore staff?

IPP 12 governs the disclosure of personal information outside New Zealand. It says a New Zealand agency can send personal information overseas only where the recipient is subject to comparable privacy safeguards, whether through similar law, a binding contract, or the individual's authorisation. It exists so information about New Zealanders does not lose its protection the moment it crosses the border.

The important point for offshore hiring is what counts as a disclosure. Sending information to someone overseas to process solely on your behalf, as your agent, is not treated as a disclosure under IPP 12 (Office of the Privacy Commissioner, Privacy Act 2020). That distinction is the foundation of compliant offshore hiring, and section 11 explains why.

Are offshore workers a disclosure or an agent under the Privacy Act?

An offshore worker processing data on your behalf is your agent, not a third party you have disclosed information to. Section 11 of the Privacy Act 2020 states that where one party holds information as an agent for another, the information is treated as held by the principal agency, not the agent. In plain terms, a New Zealand business that engages an offshore team member to work its data still legally holds that data itself.

This carries a clear consequence: your business remains fully responsible for protecting the information and for ensuring your offshore agent meets New Zealand's privacy safeguards. The table below sets out the key obligations and what each means for an offshore team.

Privacy Act 2020 obligations for offshore teams
Obligation Privacy Act 2020 basis What it means for your offshore team
Accountability for the dataSection 11 (agent provision)Your NZ business still legally holds the data; the offshore worker is your agent, and you stay responsible
Cross-border handlingIPP 12Processing on your behalf is not a "disclosure", but you must ensure comparable NZ-level safeguards apply
Data securityIPP 5Reasonable safeguards: VPN, 2FA, encryption and role-based access to limit what each person can see
Purpose limitationIPP 10 and 11Offshore staff use personal information only for the purpose you engaged them for
Breach notificationNotifiable breach scheme (Part 6)Notify the Privacy Commissioner and affected individuals if a breach is likely to cause serious harm

Sources: Privacy Act 2020, Office of the Privacy Commissioner (privacy.org.nz), New Zealand Legislation (legislation.govt.nz). General guidance, not legal advice.

Because the worker is your agent rather than an external recipient, the compliance question is not "am I allowed to do this" but "have I put the safeguards in place". Those safeguards are practical and well within reach.

What happens if there is a privacy breach involving offshore staff?

If a privacy breach involving offshore staff is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. The Privacy Act 2020 introduced this mandatory notifiable breach scheme, and the OPC expects notification within around 72 hours of an agency realising a breach is notifiable.

The obligation sits with your New Zealand business, not the offshore worker, because you remain the responsible agency under section 11. Serious harm is assessed on factors including how sensitive the information is, who accessed it, and what security was in place. This is why access control matters: a breach that never exposes sensitive data, or that was contained by strong security, is far less likely to reach the serious-harm threshold.

How do you keep offshore teams compliant with the Privacy Act 2020?

You keep offshore teams compliant by combining a written agreement, strong access controls, and the principle of least privilege. The Act requires reasonable security safeguards (IPP 5) and that information is used only for the purpose it was collected for (IPP 10 and 11), so an offshore team member should see only the data their role needs and use it only for your business.

The practical safeguards are straightforward, and the checklist below covers the core of them.

Privacy Act 2020 compliance checklist
  • Put a written agreement in place binding the worker to NZ privacy safeguards.
  • Give role-based access so staff see only the data their role needs.
  • Secure access with VPN, 2FA and encrypted cloud systems (IPP 5).
  • Limit use of personal information to its original purpose (IPP 10 and 11).
  • Have a breach response plan ready to notify the OPC within about 72 hours.

Pear Tree builds these controls into every New Zealand placement as standard: VPN, two-factor authentication (2FA), role-based cloud access, and a contract that binds the worker to New Zealand privacy safeguards. For businesses wanting a formal legal layer, an Employer of Record (EOR) formally employs the worker on your behalf, while a Contractor of Record (COR) does the same for contractor arrangements, both keeping the engagement compliant from AUD$400 per month.

What are the penalties for getting it wrong?

Penalties under the Privacy Act 2020 are more modest than in some jurisdictions, but the reputational cost is not. Failing, without reasonable excuse, to notify the Commissioner of a notifiable breach is an offence carrying a fine of up to NZ$10,000. The OPC can also issue compliance notices, make binding decisions on access complaints, and name organisations publicly.

The real exposure is trust. New Zealand courts and regulators are increasingly scrutinising how businesses handle personal information (MBIE 2025), and a publicised breach involving customer or candidate data can do far more damage than the fine itself. Compliant offshore hiring protects the relationship with your customers as much as it satisfies the regulator.

How does Pear Tree help New Zealand businesses stay compliant?

Pear Tree helps New Zealand businesses by structuring every placement to meet the Privacy Act 2020 from day one. Compliant cloud workflows, VPN, 2FA, and role-based access are built into onboarding, which takes one to two weeks, and EOR or COR cover is available where a formal legal entity is preferred. Each placement also carries a six-month replacement guarantee.

With offices in Auckland and Hawke's Bay alongside Cebu, Manila, and Cape Town, Pear Tree operates in both the New Zealand market and the talent markets, so data governance is handled by people who understand New Zealand obligations and can enforce them on the ground. Across 750+ Australian and New Zealand companies, that is how offshore teams stay both productive and compliant.

Key takeaway

The Privacy Act 2020 permits New Zealand businesses to hire offshore teams, and treats an offshore worker processing your data as your agent under section 11, which means your business stays responsible for protecting that information. Meet IPP 12 through comparable safeguards, secure access under IPP 5, and notify any serious breach, and offshore hiring is fully compliant. Pear Tree builds those safeguards into every New Zealand placement so the obligation is met by design.

AUTHOR BIO: Frank Kight is Co-Founder of Pear Tree, a direct offshore talent placement company helping Australian and New Zealand businesses hire world-class Filipino and South African professionals, without the agency markup. Frank leads operations and talent sourcing across the Philippines and South Africa, and works with New Zealand clients on building compliant, secure offshore teams. With offices in Sydney, Auckland, Cebu, Manila, Cape Town, and Hawke's Bay, Pear Tree has placed talent with 750+ companies and maintains a 90% retention rate.

Share this story:
Blog Social IconBlog Social IconBlog Social Icon

Just one more step to make your perfect choice. Click either button below to get started.