HomeBlogsThe NZ Privacy Act and Pentesting: What CTOs Need to Know in 2026

The NZ Privacy Act and Pentesting: What CTOs Need to Know in 2026

Updated: July 19, 2026|7 min read
The NZ Privacy Act and Pentesting: What CTOs Need to Know in 2026
NZ Privacy Act and Penetration Testing in 2026

DEFINITION: What the NZ Privacy Act requires of security

The Privacy Act 2020 is New Zealand's principal privacy legislation, in force since 1 December 2020, replacing the Privacy Act 1993. It is built around thirteen Information Privacy Principles that govern how agencies collect, store, use, and disclose personal information.

The principle most relevant to technical security is Information Privacy Principle 5, which requires that an agency holding personal information ensure it is protected by such security safeguards as are reasonable in the circumstances to prevent loss, unauthorised access, use, modification, or disclosure.

The operative phrase is "reasonable in the circumstances." The Act does not specify technologies, testing methods, or frequencies. It establishes a standard that scales with the sensitivity of the information held, the harm that would follow from its compromise, and what a comparable organisation could reasonably be expected to do.

This guide describes how that standard is commonly interpreted in practice. It is general information rather than legal advice, and organisations facing a specific privacy question should seek advice from a New Zealand privacy lawyer.

DEFINITION: What NZ Privacy Act penetration testing means

NZ Privacy Act penetration testing is security testing conducted to establish and evidence that an organisation's security safeguards meet the reasonableness standard in Information Privacy Principle 5. It is not a statutory requirement and appears nowhere in the Act.

Its function is evidentiary. When an organisation must demonstrate that its safeguards were reasonable, either to the Office of the Privacy Commissioner following a breach or in a claim before the Human Rights Review Tribunal, documented testing is among the most direct evidence available that safeguards were assessed rather than assumed.

The notifiable breach scheme and why it changes the calculation

The Privacy Act 2020 introduced mandatory privacy breach notification, which is the single most significant change from the 1993 Act for technical leaders.

Under the scheme, an agency that experiences a privacy breach likely to cause serious harm to an affected individual must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable after becoming aware of it.

This creates a specific dynamic that CTOs should understand clearly. Before 2020, a breach could be handled internally with limited external visibility. Under the current Act, a serious breach becomes a matter of record with the regulator, and the organisation will be asked what safeguards were in place. An organisation that can document a testing programme is answering a different question from one that cannot.

Failure to notify a notifiable privacy breach without reasonable excuse is an offence under the Act, carrying a fine. Separately, individuals who suffer harm may bring claims, and the Human Rights Review Tribunal has jurisdiction to award damages. New Zealand penalties are considerably lower than those under comparable overseas regimes, and overstating them would be inaccurate. The more material commercial exposure for most technology companies is reputational and contractual rather than the statutory fine itself.

What reasonable safeguards means in practice for a SaaS company

Defining reasonable security safeguards under the NZ Privacy Act

Because the Act sets a scaling standard rather than a fixed checklist, reasonableness is assessed against context. Four factors consistently shape that assessment.

  • The sensitivity of the information held: An agency holding health information, financial records, or identity documents is held to a materially higher standard than one holding business contact details.
  • The volume of individuals affected: Safeguards reasonable for a system holding a few hundred records may not be reasonable for one holding hundreds of thousands.
  • The foreseeability of the risk: A well-documented, widely known vulnerability class is more difficult to characterise as unforeseeable than a novel technique. This is the factor most directly addressed by testing, because a vulnerability that a routine test would have identified is difficult to describe as unforeseeable after the fact.
  • What comparable organisations do: Reasonableness is partly assessed against sector norms. As continuous testing becomes standard practice among New Zealand technology companies, the baseline of what is considered reasonable moves with it.
What am I risking by not acting?

Your Last Pentest Is Already Out of Date

Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.

Book a demo

For New Zealand CTOs who need to establish what a defensible testing position looks like for the specific personal information their systems hold, the practical step is mapping scope against actual data holdings. Book a demo with Capture The Bug and work through that mapping directly.

Where the annual testing model creates exposure

Risks of annual penetration testing for NZ Privacy Act compliance

Two specific problems arise when a New Zealand organisation relies on a single annual test to evidence reasonable safeguards.

The first is the currency gap. If a breach occurs in month nine of a twelve month cycle, the most recent evidence of safeguard assessment is nine months old, and covers a version of the system that has since changed. The organisation is evidencing that safeguards were reasonable at a point in the past rather than at the time of the incident.

The second is unassessed scope. Systems and features introduced after the annual test were never assessed. If a breach originates in one of them, the organisation cannot evidence that the affected system's safeguards were ever evaluated. A penetration testing service that brings new systems into coverage as they are introduced closes this specific gap.

What a defensible testing position looks like

Structuring a defensible security testing program in NZ

Four elements make a testing programme defensible under scrutiny.

  • Coverage aligned to data holdings: Testing scope should demonstrably include the systems that hold or process personal information, not only the most visible public-facing application.
  • Currency at the time of incident: Evidence should show that assessment was recent relative to when an incident occurred, which is a function of testing frequency rather than testing quality.
  • Documented remediation: Finding a vulnerability and not addressing it is materially worse than not having tested, because it evidences awareness without action. Every finding should show what was done and when.
  • Qualified assessors: Testing conducted by CREST-certified testers carries independent verification of competence, which strengthens the position that the assessment itself was adequate. A CREST-certified penetration testing service provides that verification directly.

What this means for your roadmap

The Privacy Act 2020 does not require penetration testing, and any vendor claiming it does is misstating New Zealand law. What the Act requires is security safeguards that are reasonable in the circumstances, assessed against sensitivity, volume, foreseeability, and sector practice. For a New Zealand technology company holding meaningful volumes of personal information, the practical question is not whether testing is legally mandated. It is whether the organisation could demonstrate, following an incident it must now notify, that its safeguards were assessed rather than assumed. Continuous testing answers that question with a dated record. An annual report answers it with a snapshot that may be months out of date at exactly the moment it matters.

Plan Security Better

Plan Your Annual Pentesting Strategy the Right Way

Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.

FAQ

Does the NZ Privacy Act require penetration testing?

No. The Privacy Act 2020 does not mention penetration testing. Information Privacy Principle 5 requires security safeguards that are reasonable in the circumstances. Penetration testing is one of the most direct methods of establishing and evidencing that those safeguards were assessed rather than assumed.

What is Information Privacy Principle 5?

IPP 5 requires that an agency holding personal information protect it with security safeguards reasonable in the circumstances to prevent loss, unauthorised access, use, modification, or disclosure. The standard scales with the sensitivity of the information and the potential harm from its compromise.

When must a New Zealand organisation notify a privacy breach?

Under the Privacy Act 2020, an agency must notify the Office of the Privacy Commissioner and affected individuals as soon as practicable after becoming aware of a privacy breach that has caused or is likely to cause serious harm. Failing to notify a notifiable breach without reasonable excuse is an offence.

What are the penalties under the NZ Privacy Act?

Failing to notify a notifiable privacy breach without reasonable excuse is an offence carrying a fine. Individuals who suffer harm may also bring claims, with the Human Rights Review Tribunal able to award damages. New Zealand penalties are substantially lower than those under comparable overseas privacy regimes, and for most technology companies the greater commercial exposure is reputational and contractual.

How often should a NZ SaaS company conduct penetration testing?

The Act specifies no frequency. Because reasonableness is assessed at the time of an incident, testing that is recent relative to when an incident occurs produces a stronger position than testing conducted many months earlier against a system version that has since changed.

Jitendra Kumar Singh

Jitendra Kumar Singh

Associate Director & Pentester • eWPTX

Cybersecurity professional & pentester | Associate Director @ CaptureTheBug | Securing web, APIs & networks one vulnerability at a time.

- 07 / RESOURCES

Read Industry Insights

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.