← WyzAZ Blog

Compliance · 8 min read · Published 15 April 2026 · Reviewed 17 August 2026

Privacy Act Training: What NZ and Australian Businesses Need to Know

Both countries overhauled their privacy laws in recent years. Here's what's actually required for staff training — and how to prove your team is compliant.

New Zealand updated its Privacy Act in 2020. Australia's Privacy Act has been under review since 2022, with significant amendments progressing through Parliament. Both countries now have mandatory breach notification requirements, stronger individual rights, and real enforcement teeth.

For small businesses, the practical question is: what does this mean for staff training? Who needs to be trained, on what, and how do you prove you've done it?

Why Staff Training Matters for Privacy Compliance

The Office of the Privacy Commissioner NZ and the Office of the Australian Information Commissioner (OAIC) have both issued guidance making clear that having a privacy policy isn't enough. Organisations need to demonstrate that staff understand and apply privacy principles in their day-to-day work.

Most privacy breaches aren't caused by hackers. They're caused by employees:

  • Sending personal information to the wrong recipient
  • Sharing customer data with unauthorised third parties
  • Storing information insecurely (open spreadsheets, personal email accounts)
  • Not recognising when they've had a reportable breach

Training doesn't eliminate these risks. But it significantly reduces them — and when something does go wrong, documented training is what separates a "we take privacy seriously and have controls in place" response from an "our staff didn't know" response.

The NZ Privacy Act 2020: What's New and What It Means

The Privacy Act 2020 replaced the 1993 Act with several material changes for businesses:

Mandatory breach notification. If a privacy breach causes or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected individuals. There's no minimum size threshold — this applies to any business holding personal information.

Updated Information Privacy Principles (IPPs). The Act contains 13 Information Privacy Principles governing how personal information must be collected, stored, used, and disclosed. Your staff need to understand these, not just know they exist.

Compliance notices and criminal penalties. The Commissioner can now issue compliance notices requiring specific action. Criminal penalties apply for certain offences, including up to $10,000 for obstruction.

What this means for training: Every staff member who handles customer or employee data needs to understand what "personal information" means under NZ law, when they can collect it, how to store it securely, and what to do when something goes wrong.

The Australian Privacy Act 1988: The Current Framework

Australia's Privacy Act applies to businesses with an annual turnover above AU$3 million — but many smaller businesses are also covered based on the type of data they handle (health information, credit reporting, etc.). The Act is currently being substantially reformed following the 2022 review, with amendments increasing penalties significantly.

The 13 Australian Privacy Principles (APPs) cover:

  • APP 1-5: Open and transparent management, anonymity options, collection of solicited and unsolicited information, notification of collection, use and disclosure
  • APP 6-8: Direct marketing, cross-border disclosure, adoption of government identifiers
  • APP 9-13: Quality of personal information, security, access, correction

The headline change from recent amendments: maximum civil penalties increased from AU$2.2 million to AU$50 million (or higher for serious repeated breaches). That's not a small business number — but it signals regulatory intent.

What this means for training: Australian businesses need to ensure staff understand the APPs relevant to their role, particularly around collection, storage, and disclosure. Health information and children's data carry additional obligations.

What Your Privacy Training Should Actually Cover

Good privacy training isn't a recitation of legislation. It's practical guidance on what staff should do differently in their daily work.

At minimum, cover:

What counts as personal information. Most people understand "name and address." Fewer understand that IP addresses, location data, device identifiers, and combinations of seemingly innocuous data can all constitute personal information. Make this concrete with examples from your business.

When you can collect it — and when you can't. Collection needs to be lawful, fair, and not unreasonably intrusive. Staff need to understand consent, purpose limitation, and why collecting "just in case we need it" is not acceptable.

How to store it securely. No personal data in shared spreadsheets with open access. No customer lists in personal email accounts. Clear guidance on approved tools and storage locations.

What to do when something goes wrong. Who to notify, how quickly, and what information to preserve. This is where most organisations fail — not in the breach itself, but in the response. Staff should know your breach response process before they need it.

Individual rights. Customers have rights to access and correct their data. Staff need to know how to handle these requests and who to escalate them to.

How to Prove Your Team Has Been Trained

For compliance purposes, a training conversation with your team is significantly less valuable than a documented training record.

What an auditor — or your legal counsel, or your insurer — wants to see:

  • Name of the person trained — who specifically completed the training
  • Date of completion — when did they do it
  • What was covered — the scope of the training, ideally linked to the specific principles covered
  • Evidence of understanding — a quiz score or assessment, not just "watched the video"
  • Certificate of completion — a formal record they can reference

WyzAZ generates PDF certificates automatically on course completion, with the learner's name, course name, date, and a unique verification code. For a privacy audit, you can export a full completion report showing every person, every module, every date, and every score in one CSV. That's the documentation that answers an auditor's questions before they ask them.

How Often Should You Retrain?

At minimum, annually. Privacy law and best practice evolve — annual retraining ensures your team's knowledge stays current.

Also retrain when:

  • There's a significant change in how you collect or use customer data
  • There's a legislative update that affects your obligations
  • You hire new staff (onboarding is the right time to cover privacy)
  • You've had a near-miss or breach — this is the most important training moment of all

Building Your Privacy Training Program

You don't need a lawyer to write your privacy training. You need:

  • A clear explanation of the principles most relevant to your team's daily work
  • Real scenarios from your business context (not abstract examples)
  • A short quiz to verify understanding (10 questions is plenty)
  • A certificate on completion

Start with the OAIC's privacy training resources and the NZ Privacy Commissioner's guidance documents as your source material. Both publish plain-language summaries of the relevant principles.

Build it once, assign it to your whole team, and schedule an annual refresh. That's a defensible, documented privacy training program.

See our guide on creating compliance training that people actually finish for practical advice on making this content engaging rather than excruciating.