Orange textured background

New Zealand law

New Zealand Privacy Act 2020 and browser fingerprinting

How New Zealand's Privacy Act 2020 regulates device fingerprinting through its 13 Information Privacy Principles, why routing fingerprint hashes to an overseas vendor triggers a cross-border compliance obligation, and what HRRT damages awards mean for practical exposure.

Reviewed

RegionNew Zealand
RegulatorOffice of the Privacy Commissioner (OPC)
Effective1 December 2020
Max penaltyNZ$10,000 per offence (statute); HRRT damages awards up to NZ$350,000 for humiliation, loss of dignity, and injury to feelings
Status in-force

Three features of the NZPA that make fingerprinting compliance distinct

Most privacy laws make headlines for their fine ceilings or their consent requirements. The New Zealand Privacy Act 2020 is different in three ways that matter specifically to fingerprinting deployments.

First, the practical penalty exposure is not the statutory maximum. The Privacy Act itself caps offence penalties at NZ$10,000, modest by international standards. The real financial risk runs through the Human Rights Review Tribunal, which can award damages of up to NZ$350,000 for humiliation, loss of dignity, and injury to feelings. Hartwoldt v Hardy, decided in 2024, set new precedent on the appropriate quantum for serious privacy harms, and the HRRT has shown willingness to award at the upper end of that range where conduct was deliberate or prolonged.

Second, IPP 12 imposes a cross-border disclosure obligation that is structurally unusual among major privacy laws. Unlike GDPR's Standard Contractual Clauses or Australia's accountability regime, IPP 12 requires the disclosing agency to take reasonable steps to ensure the overseas recipient is subject to comparable safeguards before disclosure. For a fingerprinting deployment, this means the agency must actively assess the privacy regime of every jurisdiction where a fingerprinting vendor processes the data; it cannot simply rely on a vendor's self-certified compliance.

Third, the OPC published specific guidance on automated decision-making in 2023 that applies directly to fingerprint-driven profiling. Agencies using fingerprint hashes to trigger automated decisions that significantly affect individuals (a fraud block, an account suspension, a credit decision) must be able to explain the basis for those decisions and provide a meaningful opportunity for human review.

What counts as personal information under the NZPA

The Privacy Act 2020 section 7 defines 'personal information' as information about an identifiable individual. The definition is deliberately broad: it does not require a name, a government identifier, or an email address. The question is whether, alone or in combination with other information reasonably available to the agency, the data can be used to identify a specific person.

A browser fingerprint (the hash derived from canvas rendering, installed fonts, GPU strings, audio context output, screen resolution, time zone, and similar device characteristics) satisfies this test the moment it is used to recognise the same visitor across sessions. The fingerprint does not need to identify the person by name; the ability to distinguish and track the same browser across multiple visits is sufficient to make it personal information about the individual who controls that browser.

The OPC's published privacy guidance notes that online identifiers, including device and browser characteristics used to recognise individuals, fall within the personal information definition. This aligns with the position taken by equivalent regulators in Australia, the EU, and the UK.

The 13 Information Privacy Principles and fingerprinting

The Privacy Act 2020 Schedule 1 sets out 13 Information Privacy Principles. Not all 13 are equally relevant to fingerprinting deployments, but six are operationally significant.

IPP 1 (Purpose of collection) requires that personal information is collected only for a lawful purpose connected with the agency's function and that collection is necessary for that purpose. A fingerprint collected for anti-fraud purposes that is then silently reused for behavioural advertising violates IPP 1 on the secondary use.

IPP 3 (Collection of information from subject) requires that where personal information is collected directly from the individual, the agency takes steps to ensure the individual is aware of the fact of collection, the purpose, and the intended recipients. A fingerprint script embedded invisibly on a page with no privacy notice disclosure violates IPP 3.

IPP 4 (Manner of collection) prohibits collecting personal information by means that are unlawful, unfair, or intrude to an unreasonable extent on the personal affairs of the individual. Covert fingerprinting that defeats browser privacy protections without disclosure raises IPP 4 concerns.

IPP 10 (Limits on use of personal information) prevents an agency from using personal information for any purpose other than the purpose for which it was collected, unless the individual consents, or a listed exception applies. A fingerprint collected for security that is later fed into a marketing profiling system violates IPP 10.

IPP 11 (Limits on disclosure of personal information) prevents disclosure to a third party unless the individual concerned authorises it, or a listed exception applies. Passing fingerprint hashes to a third-party analytics or advertising platform is a disclosure that requires either authorisation or a matching exception.

IPP 12 (Disclosure of personal information outside New Zealand) is covered separately below given its distinct operational consequences for fingerprinting vendors.

IPP 12: the cross-border rule and why it matters for fingerprinting vendors

IPP 12 is the most operationally significant provision for any fingerprinting deployment that routes data through an overseas vendor. Section 1 of Schedule 1 IPP 12 provides that an agency must not disclose personal information to a person or body in a foreign country unless the agency believes on reasonable grounds that the overseas recipient is subject to privacy safeguards that, overall, provide comparable protection to the Privacy Act.

Three alternatives exist if that comparability condition cannot be met. The agency may obtain the individual's consent to the disclosure. The agency may satisfy itself that one of the listed exceptions applies, for example that disclosure is necessary to prevent a serious threat to public health or safety, or that it is required by a New Zealand law. Or the agency may apply one of the narrower transfer mechanisms recognised by the OPC.

For a fingerprinting deployment, this means the following practical question must be answered before any hash leaves New Zealand: does the country in which the fingerprinting vendor processes data have a privacy regime that the agency can reasonably characterise as comparable to the Privacy Act 2020? The OPC does not publish a formal adequacy list equivalent to the EU's, so the assessment is agency-driven and fact-specific.

Countries that are generally considered to offer comparable safeguards include Australia (Privacy Act 1988, as amended), the EU member states, the UK, Canada, Japan, and South Korea. Countries that are not generally considered to offer comparable safeguards on a default basis include the United States (no federal omnibus law, sectoral patchwork only) and India (the Digital Personal Data Protection Act 2023 is not yet fully operationalised and its adequacy status is not established). Absent specific contractual or technical protections, these jurisdictions require additional compliance steps.

The consequence is that before routing fingerprint hashes to a US-based or India-based vendor, an NZ agency must either obtain individual consent to that specific overseas disclosure, put in place contractual arrangements that contractually require the overseas recipient to comply with IPP-equivalent standards, or satisfy itself that another listed exception applies. A vendor's generic privacy certification or ISO 27001 accreditation is not a substitute for this comparability assessment.

The 2023 OPC guidance on automated decision-making

In 2023, the Office of the Privacy Commissioner published guidance on automated decision-making under the Privacy Act. The guidance addressed the use of algorithms and automated systems to make decisions that significantly affect individuals. While not specifically targeted at fingerprinting, the guidance directly affects how fingerprint-driven profiling can be deployed.

The OPC's position is that IPP 1 (purpose limitation) and the fairness obligation implicit in IPP 4 together require agencies to be able to explain, in plain language, the basis on which automated decisions affecting individuals are made. For a fingerprinting deployment, this is most acute when a fingerprint match triggers an automated adverse outcome: an account block, a transaction decline, a fraud flag that restricts access. In those circumstances, the OPC expects the agency to have a human-review pathway and to disclose, at minimum, that an automated system was involved.

The guidance does not ban automated decision-making. It requires transparency about the fact of automation, the principal factors that influenced the decision, and a meaningful opportunity to contest the outcome. A fraud-detection fingerprinting deployment that provides no visibility to the individual about why they were blocked, and no path to human review, is at risk under this guidance.

Common fingerprinting purposes under the NZPA

PurposePersonal information?IPPs most relevantConsent required?IPP 12 issue if overseas vendor?
Anti-fraud at login or paymentYesIPP 1, IPP 3, IPP 10No, if disclosed in privacy notice and purpose-limitedYes: assess vendor jurisdiction comparability
Account takeover detectionYesIPP 1, IPP 3, IPP 5No, if disclosed and proportionateYes: same comparability assessment applies
Bot mitigation on a public formYesIPP 1, IPP 4No, generally proportionateYes, if hashes leave NZ
Cross-site behavioural advertisingYesIPP 1, IPP 10, IPP 11Effectively yes: IPP 10 bars secondary use without consentYes: advertising platforms typically US-based
Fingerprint-driven audience profilingYesIPP 1, IPP 10, IPP 11Yes: secondary use and 2023 OPC automated-decision guidance applyYes
Session continuity within a single visitYes (transient)IPP 1, IPP 4No, if genuinely session-scoped and not retainedUnlikely if processed domestically
Fraud-risk scoring feeding a credit decisionYesIPP 1, IPP 10, 2023 OPC ADM guidanceEffectively yes: ADM guidance requires explanation and human-review pathwayYes: scoring model vendor likely overseas
Product analytics using fingerprint as visitor IDYesIPP 1, IPP 3, IPP 10Disclosure required; consent if analytics platform overseasYes: most analytics platforms are US-based
Fingerprinting to enforce a ban or restrictionYesIPP 1, IPP 3, 2023 OPC ADM guidanceDisclosure required; human-review pathway expectedYes, if enforcement logic runs overseas

Mandatory breach notification under Part 6

Part 6 of the Privacy Act 2020 introduced a mandatory privacy breach notification scheme, which took effect alongside the rest of the Act on 1 December 2020. Under section 113, an agency must notify the Privacy Commissioner and affected individuals of a notifiable privacy breach, defined as a breach that has caused or is likely to cause serious harm to one or more affected individuals.

The serious harm test is not a bright-line threshold. The Privacy Commissioner's published guidance lists factors including the sensitivity of the information, the number of individuals affected, the likelihood of the information being misused, and the nature of the potential harm. A data exfiltration or unauthorised access event that exposes fingerprint hashes linked to behavioural profiles, browsing histories, or account credentials would almost certainly meet the serious harm threshold.

Notification to the Commissioner must occur as soon as practicable after the agency becomes aware of the breach and forms the view that notification is required. There is no statutory grace period. Notification to affected individuals must follow. Failure to notify when required is a privacy breach in itself and can attract a compliance notice from the Commissioner.

Enforcement and regulatory context

  • Office of the Privacy Commissioner compliance notices: the OPC can issue compliance notices under the Privacy Act 2020 Part 9 requiring an agency to do or refrain from doing something. Non-compliance with a compliance notice is a criminal offence carrying a fine of up to NZ$10,000.
  • Human Rights Review Tribunal damages: the HRRT is the primary route for substantive financial exposure. Under section 88, the Tribunal can award damages for humiliation, loss of dignity, and injury to feelings up to NZ$350,000. Hartwoldt v Hardy (2024) set new precedent on the quantum available for serious, deliberate privacy breaches.
  • Reserve Bank of New Zealand breach (2021): a third-party file-sharing application used by the RBNZ was accessed by an unauthorised party, exposing commercially sensitive information. The incident triggered OPC investigation and public reporting under the mandatory notification scheme, illustrating how Part 6 notification obligations operate in practice for major NZ institutions.
  • OPC investigation of commercial fingerprinting-adjacent practices: the Commissioner has opened inquiries into the use of device and browser identifiers in loyalty and marketing programs. No headline decision naming fingerprinting explicitly has been published as of the date of this page, but the OPC's public guidance makes clear that covert identifier-based tracking without IPP 3 disclosure is in scope.

How Benny the Doorman fits into an NZPA-aware deployment

Benny the Doorman's fingerprinting infrastructure is hosted in Chennai, India. India is not a country that the New Zealand Office of the Privacy Commissioner recognises as offering comparable privacy safeguards to the Privacy Act 2020. India's Digital Personal Data Protection Act 2023 is not yet fully operationalised, its enforcement regime is nascent, and NZ agencies cannot currently rely on a general comparability finding to satisfy IPP 12 when disclosing fingerprint hashes to Benny's infrastructure.

This does not mean using Benny is impermissible for NZ agencies. It means that IPP 12 compliance requires one of three additional steps: the agency can incorporate IPP 12-equivalent contractual obligations into its data processing agreement with Benny, requiring Benny to handle the data in a manner consistent with the Privacy Act 2020 standards; the agency can obtain the informed consent of individuals to the cross-border disclosure before a fingerprint is collected; or the agency can satisfy itself that another listed IPP 12 exception applies on the specific facts.

The contractual route is the most practical for a commercial deployment. Benny's Data Processing Agreement (available on request from the pricing page) includes provisions requiring Benny to process personal information only for the specified purpose, to maintain appropriate security measures, and to notify the agency of any breach. An NZ agency relying on the contractual route should document its IPP 12 assessment, noting the contractual mechanism and why it provides overall comparable protection, and retain that documentation in its privacy records.

Beyond IPP 12, a standard NZPA-aware Benny deployment requires: a privacy notice that discloses the use of device fingerprinting, the purpose for which the fingerprint is collected, and the fact that data is processed overseas; purpose limitation so that a fingerprint collected for anti-fraud is not reused for marketing profiling; a data retention policy that deletes fingerprints once their purpose has been served; and, where the fingerprint triggers automated adverse decisions, a human-review pathway consistent with the OPC's 2023 automated decision-making guidance.

Frequently asked questions

Is browser fingerprinting illegal under the New Zealand Privacy Act?

No. Browser fingerprinting is not prohibited. It is regulated as personal information once a fingerprint hash is used to identify or re-identify a specific visitor. Lawful use requires disclosing the collection in a privacy notice (IPP 3), limiting the fingerprint to its collected purpose (IPP 1 and IPP 10), keeping it secure (IPP 5), and satisfying the IPP 12 cross-border obligation if the data is sent to an overseas vendor.

Does the New Zealand Privacy Act require consent for fingerprinting?

The Privacy Act does not impose a blanket opt-in consent requirement for fingerprinting the way GDPR's ePrivacy layer does. However, consent is required in specific situations: when personal information is used for a materially different purpose than collection (IPP 10), when it is disclosed to a third party without another applicable exception (IPP 11), and when it is transferred overseas to a recipient in a country without comparable safeguards and no other IPP 12 exception applies. Transparency through a privacy notice is required regardless.

What does IPP 12 require when I send fingerprint hashes to an overseas vendor?

IPP 12 requires the disclosing agency to take reasonable steps to ensure the overseas recipient is subject to privacy safeguards that, overall, provide comparable protection to the Privacy Act 2020. If comparable safeguards cannot be established, the agency must either obtain the individual's informed consent to the overseas disclosure, rely on a listed exception, or put in place contractual arrangements that require the overseas recipient to comply with IPP-equivalent standards. The obligation sits with the agency, not the vendor.

Is India treated as having comparable privacy safeguards for IPP 12 purposes?

Not as a default. India's Digital Personal Data Protection Act 2023 is not yet fully operationalised and the OPC has not issued a comparability finding for India. NZ agencies sending fingerprint hashes to an India-hosted vendor (including Benny the Doorman, whose infrastructure is in Chennai) cannot rely on a general comparability finding. They must use a contractual mechanism, obtain individual consent, or identify another applicable IPP 12 exception.

What is the financial exposure for a Privacy Act violation in New Zealand?

The statutory offence penalty under the Privacy Act is NZ$10,000 per offence, modest compared to GDPR or CCPA. The more significant exposure runs through the Human Rights Review Tribunal, which can award damages of up to NZ$350,000 for humiliation, loss of dignity, and injury to feelings caused by a serious interference with privacy. Hartwoldt v Hardy (2024) set new precedent on the quantum available at the upper end of that range.

How does the OPC's 2023 automated decision-making guidance affect fingerprinting?

The OPC's 2023 guidance on automated decision-making requires agencies to be transparent about the fact of automation, to explain the principal factors that influenced a decision significantly affecting an individual, and to provide a meaningful human-review pathway. For fingerprinting, this is most acute when a fingerprint match triggers an account block, a transaction decline, or an access restriction. A deployment that provides no visibility and no review path is at risk under the guidance.

Does the mandatory breach notification scheme under Part 6 apply to fingerprint data?

Yes. Part 6 requires notification to the Privacy Commissioner and to affected individuals when a privacy breach has caused or is likely to cause serious harm. A breach exposing fingerprint hashes linked to behavioural profiles, session histories, or account credentials would almost certainly meet the serious harm threshold. Notification must occur as soon as practicable after the agency becomes aware of the breach and determines it is notifiable.

How is the New Zealand Privacy Act different from the Australian Privacy Act for fingerprinting?

Both laws treat device fingerprints as personal information, require transparency about collection, and impose cross-border transfer obligations. The key differences are: New Zealand's IPP 12 requires comparability of the overseas recipient's safeguards, while Australia's APP 8 imposes accountability on the Australian discloser; the HRRT damages mechanism in New Zealand (up to NZ$350,000) differs from Australia's focus on the OAIC and Federal Court; and New Zealand's OPC has issued specific automated decision-making guidance that Australia's OAIC has not yet matched with equivalent specificity.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06