The Privacy Act and school boards
Everyone’s personal information is taonga (treasured) by them. It is their identity and history.
All New Zealanders, regardless of age or circumstance, have privacy rights.
Every board has the obligation to ensure that any information it collects about an individual is respected and cared for.
The Privacy Act 2020 sets out 13 privacy principles that direct how agencies (including school boards) collect, store, use, and share personal information.
Keep reading to learn more.
What is personal information?
The Privacy Commissioner defines personal information like this:
“Any information that tells us something about an identifiable individual. Personal information doesn’t need to include someone’s name. It only needs to include enough information to tell you or someone else who they are.”
In education, what constitutes personal information may be broader than you think. Examples include, but are not limited to:
- Names and contact information of anyone interacting with the school
- Unique identifiers, such as National Student Numbers, staff EdPay numbers, union numbers, etc.
- Photos, videos, and audio recordings
- Personal bank account details and other financial information, such as invoices and billing information
- Demographic information, such as sex and gender, ethnicity, age, iwi affiliation, and citizenship
- Health and wellbeing information, such as immunisation records, medical conditions, allergies, disabilities, etc.
- Information about their home life, such as pastoral care records, living arrangements, custody, protection or restraining orders
- Internet usage and device login information
- Career and pathway planning information, including employment records
- Individual student records and plans related to attendance, educational engagement, achievement, and behaviour
- Concerns or complaints about a student, staff, or board member
- Learning support, ORS (Ongoing Resourcing Scheme), or other funding supports
- Financial information and other information about benefactors, sponsors, or trusts administered by the school
- Commercially-sensitive information about individuals or businesses that hold external contracts for services
What does the Privacy Act say your board must do?
The Privacy Act states that your board (as an agency) is responsible for ensuring that everyone who interacts with the school knows:
- When their information is being collected (even indirectly from another agency)
- The reason the information is being collected
- How the school is ensuring it is kept safe and secure
- Who will see the information
- When and why it might be shared with another agency or individual
- That they can access and ask for their information to be corrected at any time.
It can be helpful for your school to include this information in their privacy statements.
Your board should ensure, through school policy, that only necessary information is collected and, if required, shared with other agencies.
Being clear about the reasons you need personal information will help you make good decisions about only collecting what you need.
That approach helps reduce your risk because the less personal information you hold, the easier it is to keep up to date, and the consequences of a mistake (a data breach) are easier to control.
The more sensitive the information collected, the greater the care the school needs to take to keep it safe and secure.
Board policies and procedures will need to be flexible enough to respond to the varying requirements of the information your school collects.
Your policies should also include procedures for the mandatory reporting of any privacy breach.
You can read more about the Privacy Act 2020 and the 13 privacy principlesopen_in_new on the Privacy Commissioner’s website.
What happens if your board collects personal information indirectly from a third party?
Everyone has a right to know who holds their personal information, why, that it is safe and used appropriately (including sharing between agencies), and that it is accurate.
It is easy to control what information is being collected and why, especially when working with the person directly.
However, schools do obtain information about individuals from other agencies.
From 1 May 2026, the new IPP3a (information privacy principle 3a) obligations are in effect.
These obligations give individuals the right to know exactly who has what information, why it was collected, and when it is passed on to another agency.
If an agency (such as your board) collects information about an individual from someone other than the individual, they now have a legal responsibility to tell the individual that their personal information has been collected indirectly.
You must also let them know the purpose for collecting it, how it will be stored, and how it will be disposed of.
You can read more about this new privacy principle and how your board can comply with itopen_in_new on the Privacy Commissioner’s website.
How does your board ensure the school is meeting its privacy obligations?
Ensuring privacy is done well requires a comprehensive and consistent approach across all areas of the school or kura.
Your board should consider how maintaining strong privacy principles aligns with your wider organisational goals, values, and risk reduction.
For example, your board can support its members' privacy by providing school-based email addresses and devices during their term of office.
Another good place to start is ensuring board policies and procedures meet the requirements set out in the Privacy Act (and associated privacy principles).
These should clearly document who has accountability for the oversight of privacy within the school (normally delegated to the privacy officer).
It’s also good practice to have regular board table discussions with the principal about privacy.
This will enable your board to identify privacy risks, gaps, or issues, and how they are documented and addressed, including resourcing staff appropriately.
The office of the Privacy Commissioner’s website has a lot of information to support your board.
Check out the 10 Poupou Matatapuopen_in_new (especially the governance pouopen_in_new) and the Children’s Privacy Guidance for the Education Sectoropen_in_new.
If your governance processes are focused on creating a culture of privacy and the careful handling of information, legal compliance should follow naturally.
Questions your board could ask
- Do we understand our obligation to collect, store, share, and dispose of everyone’s personal information in a transparent and respectful way?
- Does our board have policies and procedures in place to support this, including identifying and supporting the role of the privacy officer?
- Have we sought assurance from the principal that our policies and procedures are effective and fit for purpose?
- Do we allocate appropriate resources (database systems, devices, time, and money) to support our privacy policy implementation?
- What are our procedures when someone asks for their personal information and/or their child's information (privacy request)?
- Do our school procedures identify how to recognise a privacy breach and respond to it appropriately?
Templates, resources, and references
Click on the link(s) below to access this topic’s templates, resources, and references.
Depending on your device, these may download or open in a separate browser.
Ministry of Education
Office of the Privacy Commissioner
- Websiteopen_in_new
- Privacy Act 2020 and the 13 privacy principlesopen_in_new
- Free online learningopen_in_new
- Poupou Matatapu framework – Doing privacy wellopen_in_new
- Children’s Privacy Guidance for the Education Sectoropen_in_new
- IPP3A: notification requirements for indirect collection of personal informationopen_in_new