Why the Act applies to a chat window
The Privacy Act 2020 does not mention ChatGPT, and it does not need to. It regulates personal information, meaning information about an identifiable person, whatever system holds it. The Office of the Privacy Commissioner says plainly that the Act applies to the use of AI tools in New Zealand, and it has published guidance on how each information privacy principle applies to them2. A prompt that names a customer, a payslip uploaded for analysis and a summary of a staff complaint are all personal information under the Act.
Health businesses have a different rulebook. The Health Information Privacy Code 2020 takes the place of the information privacy principles for health information held by health agencies such as doctors, physiotherapists, pharmacists and health insurers13. If you run a clinic, read the rules in the Code alongside this guide. The ideas are similar, but the wording and some duties differ.
Every business that handles personal information must have a privacy officer8. MBIE's responsible AI guidance repeats that duty, and describes the privacy officer as the person who supports compliance, handles access and correction requests and works with the Commissioner on complaints8. In a small firm that is often the owner or the office manager. Before you roll out ChatGPT, make sure that person knows it is happening.
What the Privacy Commissioner expects
The Commissioner has set out specific expectations for any agency thinking about a generative AI tool1. They are not a separate law. They are the Commissioner's view of what compliance with the Act looks like for these tools, and a complaint investigation would likely start from them.
The six below are drawn from the Commissioner's eight expectations1. Read them as a project plan rather than a legal checklist.
- Have senior leadership approve the use, after full consideration of the risks and the ways to reduce them1.
- Review whether the tool is necessary and proportionate, given the privacy impacts1.
- Do a privacy impact assessment before you use the tool with personal information1,7.
- Be open with customers and clients about how, when and why the tool is used, in plain language1.
- Have a person review outputs before the business acts on them1.
- Do not enter personal or confidential information unless the provider has confirmed it does not retain or disclose it1.
The principles that bite in daily ChatGPT use
Collection and purpose come first. Information you collected to do a client's tax return was collected for that purpose. Using it to test a new marketing idea in ChatGPT is a different purpose, and the use and disclosure principles limit that. A simple rule for staff: only put personal information into ChatGPT when the task is the same job the client gave you the information for.
Indirect collection now has its own principle. Since 1 May 2026, information privacy principle 3A requires an agency that collects personal information from someone other than the individual to take reasonable steps to make sure the person knows about it, unless an exception applies3. That matters when staff use ChatGPT search or deep research to gather details about a named person, such as a job applicant or a debtor. The output is information you collected indirectly, so check whether IPP 3A requires you to tell the person.
Accuracy is the principle that catches most AI mistakes. The Commissioner warns that generative tools often produce confident errors of fact or logic and can repeat bias, and says you should not rely on their output without checking it2. Under IPP 8 a business must take reasonable steps to check information is accurate before it uses it2. In practice that means a named person reads every ChatGPT draft that says something about a real customer or employee before it goes anywhere.
Access and correction rights follow the information. If a ChatGPT summary of a phone call is saved into a client file, the client can ask to see it and ask for it to be corrected2. Decide where AI-assisted notes are stored, so a request under IPP 6 has one place to look.
Security, overseas storage and your contract with OpenAI
IPP 5 requires reasonable security safeguards. For ChatGPT the biggest safeguard is the plan. On personal plans, content can be used to train models unless the person turns off Improve the model for everyone under Settings, then Data controls9. On ChatGPT Business, Enterprise and Edu, OpenAI says it does not train on business data by default11. Staff using personal accounts for client work is a common gap in small firms, and it is the easiest one to close.
Overseas storage is the next question owners ask. When a provider stores or processes information only on your behalf, section 11 of the Privacy Act 2020 treats the transfer as yours, not as a disclosure to the provider4. Your business stays responsible for what happens to the information, so you need to be satisfied the provider protects it. If the provider uses the information for its own purposes, IPP 12 applies, and you need a ground such as comparable safeguards or the person's informed authorisation5. That is one reason the training setting matters: a business plan that excludes your content from training keeps OpenAI in the service-provider role.
Put the arrangement on paper. OpenAI offers a data processing addendum for ChatGPT Business, Enterprise and the API11. Sign it, save a copy with your privacy records, and note which plan and settings it covers. Under the addendum OpenAI processes customer data on your behalf and in line with your instructions12.
When a ChatGPT mistake becomes a privacy breach
A privacy breach includes personal information being disclosed without authorisation. A breach is notifiable when it has caused, or is likely to cause, serious harm6. Examples involving ChatGPT include a staff member sharing a project link that exposes client records to the wrong people, or pasting a spreadsheet of customer details into a personal account that is later compromised.
If a breach is notifiable, you must tell the Commissioner as soon as practicable. The Commissioner's NotifyUs guidance, not the Act itself, asks for notice ideally within 72 hours after you become aware that the breach is notifiable14. You also need to tell the affected people unless an exception applies. Failing to notify the Commissioner without a reasonable excuse is an offence that can lead to a fine6. The Commissioner treats information known by your employees or agents as known by the business, so awareness does not wait for the privacy officer15. Train staff to report AI mistakes the same day.
A worked example: a Hamilton accounting practice
Take a generic twelve-person accounting practice in Hamilton that wants to use ChatGPT to draft client letters, summarise IRD correspondence and analyse trial balances. The partners approve a trial, which meets the leadership expectation. The practice manager, who is also the privacy officer, runs a short privacy impact assessment using the Commissioner's toolkit7. It identifies three risks: staff on personal accounts, client tax numbers in prompts, and unchecked figures going into advice.
The fixes are practical. The practice moves everyone to a ChatGPT Business workspace, signs the data processing addendum and switches off connected apps it does not need. Staff remove IRD numbers and bank details before uploading files, and use client codes in place of names in analysis prompts. Every letter drafted with ChatGPT is reviewed by the accountant who owns the client, as the Commissioner expects1. The engagement letter gains one sentence saying the practice uses an AI assistant under its privacy controls, which covers the transparency expectation.
Your step-by-step checklist
Work through these steps in order, with one owner and one administrator.
- Name your privacy officer and brief them on the ChatGPT plan8.
- Get written leadership approval for the use, with the risks listed1.
- Complete a privacy impact assessment using the Commissioner's toolkit7.
- Move all work use to ChatGPT Business or Enterprise, and close personal accounts used for work9,11.
- Sign the data processing addendum and file it with your privacy records11.
- Write a one-page AI use policy: approved tool, banned data, review rule, who to ask.
- Update your privacy statement to say you use an AI service provider and why1.
- Check whether any research workflow collects information about people indirectly under IPP 3A3.
- Add AI mistakes to your breach reporting process, with a same-day reporting rule6.