Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Insights on data, AI & business. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

NZ Privacy Act, Cloud AI, and the CLOUD Act Explained
Blog AI

NZ Privacy Act, Cloud AI, and the CLOUD Act Explained

What Kiwi business owners need to know about the NZ Privacy Act, cloud AI tools, and overseas data access laws working together.

Sam McKay

Why this matters if your business uses cloud AI

If you run a business in New Zealand and you use any AI tool — ChatGPT, Copilot, Notion AI, a transcription service, a customer service bot, even the smart features now baked into Xero and MYOB , this topic touches you. The short version is this: the data you send up to a cloud AI tool sits on a server somewhere. Under certain conditions, overseas agencies can legally compel access to that data, even though you are a New Zealand business and even though the Privacy Act 2020 says your client files are supposed to be protected.

Three things collide here. The NZ Privacy Act 2020 and its 13 Privacy Principles. The US CLOUD Act, which forces US-controlled providers to hand over data held anywhere in the world when US authorities get a warrant. And the reality that most of the AI tools you are paying for are built by US-headquartered companies.

I want to walk you through what each piece actually means, where the gaps are, and the practical steps we see Kiwi business owners taking in 2026 to keep their exposure sensible without throwing the AI tools out the window.

The NZ Privacy Act 2020 in plain English

The Privacy Act 2020 governs how any agency , and yes, that includes your business , collects, stores, uses, and discloses personal information about identifiable people. It sits alongside the 13 Information Privacy Principles, often shortened to IPPs. The principles require you to collect only what you need, use it for the purpose you told the person about, keep it safe, let people see and correct it, and dispose of it when you no longer need it.

Two principles matter most for this topic.

IPP 5 (now often called Storage and Security of Personal Information , PP5 in the new numbering) says you must take reasonable steps to protect personal information from loss, unauthorised access, use, modification, or disclosure. “Reasonable” is judged against the sensitivity of the information and what a reasonable person in your position would do. So the bar shifts depending on what you are holding.

IPP 12 (PP12) is the cross-border disclosure rule. Before you send personal information offshore, you must either have the person’s authorisation or you must be satisfied on reasonable grounds that the destination country provides comparable safeguards to New Zealand’s own protections. This is the principle that knocks on the door every time you paste client data into a US-hosted AI tool.

The Privacy Commissioner can issue compliance notices, and penalties for serious breaches have lifted meaningfully in recent amendments. For larger organisations we work with, the cost of getting this wrong now runs into the hundreds of thousands of dollars in remediation, not counting the reputational damage with the people whose information was leaked.

Verify the exact wording of PP12 and any updated guidance with your lawyer or the Office of the Privacy Commissioner website, because amendments and codes of practice do shift over time.

What the US CLOUD Act actually does

The CLOUD Act is a US law that came into force in 2018. It amended the old Stored Communications Act to make it crystal clear: if a US provider holds your data, even on a server in Auckland, Frankfurt, or Sydney, a US warrant can compel that provider to hand the data over to US law enforcement. The geography of where the bits sit does not matter. The nationality of the company that controls them does.

This matters for New Zealand because the AI tools most Kiwi businesses reach for first , OpenAI’s ChatGPT, Google’s Gemini, Anthropic’s Claude, Microsoft’s Copilot , are US-controlled entities. So are the big cloud platforms underneath them: AWS, Azure, Google Cloud.

There is also a piece called Executive Order 12333, which governs US intelligence collection outside warrants. It is broader and less visible than the CLOUD Act but worth knowing the name of because you will see it in the small print of privacy policies.

Australia’s equivalent interplay , and many NZ businesses have AU clients or staff , involves the Assistance and Access Act and ASIC’s Regulatory Guide 265 on cyber resilience for financial services firms. APRA’s CPS 234 also forces banks, insurers, and super funds to manage information security risks across all the vendors they rely on, including offshore AI. None of these are identical to the CLOUD Act but they sit in the same family of regimes, which is why Australian-headquartered subsidiaries of US companies have to think carefully too.

Where the gap opens for NZ businesses

Here is the part that surprises most owners I talk to in Ponsonby, Parnell, Newmarket, and around Wellington’s waterfront.

You can do everything the Privacy Act asks. You can anonymise the data. You can sign the cleanest data processing agreement on earth. You can store the data locally with a NZ-based reseller. And still, if your AI vendor is a US-controlled entity and a US court issues a valid warrant, the vendor can be compelled to hand over the data sitting in that NZ-hosted environment, because the CLOUD Act travels with the provider, not with the server.

That is the structural gap. The Privacy Act assumes you control who gets access to personal information. The CLOUD Act puts a parallel door in that you cannot lock. Your job, then, is to reduce what can walk through that door and to know when something has.

A common mistake I see is the assumption that choosing an Australian provider solves the problem. It does not, if the Australian arm is a subsidiary of a US parent. CLOUD Act reach follows the chain of control, not the country on the datacentre door.

Three patterns we see across NZ and AU businesses

Rather than naming specific companies, here are the patterns that show up again and again with the businesses in our network. “Network” is doing some work , these are anonymised sightings from advisory work, not formal case studies.

The first pattern is the advisor who pastes client information into ChatGPT to draft emails, file notes, and even contract clauses. One Auckland accountant we spoke with had been doing this for two years before realising that every paste was training-context data being sent offshore. The fix was a simple change in habit and a paid tier with stronger data controls, not the end of AI use.

The second pattern is the small law firm in Sydney using a transcription service on a free or standard tier, where the provider’s terms clearly state audio and transcripts are used for model improvement. Once the principal understood that, the conversation moved quickly to enterprise agreements and redacted workflows. Rough pricing for an enterprise-tier AI tool that offers contractually stronger controls tends to land around NZD $30 to $80 per user per month, which is roughly USD $18 to $48, sometimes more for regulated industries. Treat that as a ballpark only.

The third pattern is the mid-sized NZ e-commerce business plugging a customer-service chatbot into its Trade Me and Shopify stores. Personal information flowing through that bot includes names, emails, order details, and complaint histories. The owners had not realised that the chatbot vendor’s main data centre was in Virginia, which made the CLOUD Act conversation immediate and practical rather than theoretical.

What “comparable safeguards” really means for PP12

PP12 is the principle that trips most people up because it asks you to make a judgement, not to follow a rule. Australia has a comparable regime, so most NZ businesses send data there freely. The European Union has GDPR, which many consider stronger in some areas and weaker in others, and is broadly treated as comparable. The United States has no single federal privacy law, but the CLOUD Act shows that US government access is real and warrants-based.

In practice we see NZ organisations doing one of three things when dealing with US AI providers.

They get the individual’s authorisation. This can be a checkbox at sign-up or a plain-English sentence in your privacy notice. It works, but only if the notice is genuine and the person can reasonably understand what they are agreeing to.

They use the contractual route. They negotiate or accept enterprise terms where the provider commits to notify them of any government access request where legally allowed, to challenge overbroad warrants, and to maintain audit logs. This does not stop CLOUD Act access. It gives you a fighting chance to be told about it and to comply with your own notification obligations later.

They avoid personal information altogether. They use synthetic data, they redact before pasting, they keep identifiers in NZ systems and only push pseudonymised fragments to the AI. This is the pattern we recommend most often because it shrinks the problem to almost nothing.

None of these is wrong. The wrong answer is doing none of them and hoping nobody notices.

Practical steps we recommend for NZ business owners

Here is the checklist I walk clients through. It is built around what an average Kiwi SMB can actually do, not what a multinational with a privacy office would do.

Step one is to write down every AI tool that touches personal information in your business. That includes the obvious ones like ChatGPT and Copilot, and the quiet ones like the AI features now sitting inside Xero, MYOB, your CRM, your helpdesk, and your recruitment platform if you hire through Seek. The list is usually longer than people expect.

Step two is to classify the data each tool sees. Public, internal, confidential, sensitive. Tax file numbers, medical history, criminal records, and any biometric or genetic data are treated with extra care, and AHPRA-registered health professionals carry their own professional obligations on top of the Privacy Act, so verify the codes relevant to your profession.

Step three is to check the provider. Where is the parent entity incorporated? Where do they store data? What does the data processing agreement actually say about government access, notifications, sub-processors, and retention? If the answer to any of those is “we never asked”, that is the gap to close first.

Step four is to set team rules. Where possible, set up a paid or enterprise tier where your inputs are excluded from model training by default. For example, ChatGPT’s Team, Enterprise, and API plans have data-use exclusions baked in, while the free tier does not. Then write a one-page internal guide covering what can and cannot be pasted into which tool. We see most breaches come from habit and convenience, not from malice.

Step five is to log incidents. If you suspect a privacy breach, the Privacy Act gives you a tight window to assess and notify. Have a simple runbook before you need it, not after.

How to read vendor privacy policies without the marketing gloss

Vendor policies are written by lawyers for other lawyers and tend to bury the load-bearing sentences. Three phrases matter most.

“Solely for the purpose of providing and improving our services” usually means your data is used for training. Run.

“We process your data in accordance with our privacy policy and applicable law” usually includes US warrants under the CLOUD Act. Expect.

“Customer data is not used to train our models” is the line you want on enterprise tiers of the major US providers. Read it carefully because the policy often distinguishes between the AI product and other services the same vendor sells.

Also look for data residency claims. They are useful but not the same as jurisdictional control. A datacentre in Sydney run by a US-controlled cloud provider still answers to US warrants for stored communications.

Where Australian counterparts fit in the picture

A quick note for the many NZ businesses with Australian customers, staff, or subsidiaries. Australia’s regulatory web is layered. The Privacy Act 1988 (Cth) and the Australian Privacy Principles cover personal information. ASIC’s RG 265 spells out cyber-resilience expectations for financial services. APRA’s CPS 234 forces banks, insurers, and super funds to test and govern the security of every material supplier, including AI tools. AHPRA codes carry force for registered health professionals. If any of these apply to you, the bar is higher than the SMB average and you will want formal documentation, not a one-page checklist.

A simple way to think about the layered risk

If you imagine the data you put into a cloud AI tool as a parcel, the Privacy Act is the lock on your office door and the CLOUD Act is a separate door at the freight depot. Your aim is not to pretend the second door does not exist. Your aim is to make sure the parcel contains as little identifying information as possible, is shipped under a contract that promises to tell you if anyone opens the second door, and is logged end to end so you can respond if it does.

That framing keeps the discussion honest. The threat is not hypothetical but it is also not daily. For most NZ SMBs the residual exposure after sensible controls sits at a level the business can manage. For healthcare, legal, financial services, education, and government-adjacent suppliers the residual exposure is higher and the controls need to be heavier.

Common objections and how we answer them

“But the AI tool says my data is encrypted.” Encryption protects data in transit and at rest from ordinary attackers. It does not stop a provider from handing over plaintext to a US authority under a valid warrant, because the provider holds the keys.

“But we are a small business, nobody cares.” The Privacy Act does not have a small-business exemption for collection and storage duties. Information Privacy Principle 12 and the comparable safeguards test both apply regardless of headcount.

“But our competitors are doing the same thing.” That is true and irrelevant. Two businesses breaking the same rule are still two businesses breaking the rule.

“But banning AI will tank our productivity.” Nobody in our network is recommending that. Reasonable use with sensible controls tends to deliver most of the productivity gain with a fraction of the risk.

A short roadmap for the next 30 days

If this article is the prompt that finally gets it on your agenda, here is what 30 days of focused effort looks like in the businesses we support.

Week one is the inventory. List every AI tool, who uses it, and what data flows through it. Week two is the classification. Decide which data categories are off-limits to which tools. Week three is the contract review. Pull the current data processing agreements for your top three AI vendors and read the government-access clauses. Week four is the team guide. Write the one-pager, train the team, and add the runbook for breach response to your standard operating procedures.

After 30 days, you should be able to answer any customer’s question about how their data is handled, including the awkward one about overseas government access.

The bigger picture

Cloud AI is a productivity tool your team is already using, with or without your blessing. The Privacy Act and the CLOUD Act together set the boundary conditions on what is safe to send into it. The good news is that the answer is not to switch off the tools. The answer is to choose the right tier, set the right rules, redact the right data, and have the right conversation with your vendor. NZ business owners who do this properly find they keep the upside of AI without inheriting someone else’s legal risk.

How Enterprise DNA can help

Enterprise DNA works with NZ and AU businesses on this challenge every week. The starting point is a 60-minute Omni Audit, where we map your AI tools to your data flows, classify the exposure, and give you a written action plan you can take to your lawyer or your IT provider. The audit covers Xero, MYOB, Trade Me, Seek, REA Group integrations and any custom AI work you have built. Pricing for the engagement varies by headcount and complexity, with a typical SMB audit in the NZD $1,500 to $3,000 range, roughly USD $900 to $1,800, and treated as a ballpark.

Book a 60-min Omni Audit: https://calendly.com/sam-mckay/discovery-call?utm_source=edna-landing&utm_medium=blog&utm_campaign=nzau

Verify the specifics of PP12, the latest Privacy Commissioner guidance, and any sector codes that apply to your business with your lawyer before acting on this article.