Claude Training NZ, home

10 min read. Updated 6 October 2026

Claude and the Privacy Act 2020: what a New Zealand business must do

The Privacy Act 2020 does not mention Claude, and it does not need to. Once a prompt, an uploaded file or a reply contains information about an identifiable person, your business is handling personal information, and the information privacy principles apply to every step.

Illustration generated with AI.

Start from the information, not the tool

The Office of the Privacy Commissioner's starting point is plain: the Privacy Act 2020 applies to everyone using AI tools in New Zealand2. Its guidance on artificial intelligence and the information privacy principles, published on 21 September 2023, walks through how each principle applies across the life of an AI system, including generative tools such as Claude3.

For an owner or manager, that means the useful question is not whether Claude is allowed. It is which personal information will go in, why, who will see what comes out, and where it will be stored afterwards. A team that summarises supplier contracts has a very different privacy profile from one that drafts responses to customer complaints, even if both use the same Claude Project.

The obligations stay with you. When your business uses Claude under the Commercial Terms, Anthropic acts as your processor under its Data Processing Addendum, and you remain the controller10,11. Choosing a reputable vendor is part of meeting the Act. It does not hand the duty to someone else.

The Commissioner's expectations, applied to Claude

The Commissioner has set out what organisations should do before and while they use generative AI3. Each expectation maps onto a concrete step in a Claude rollout.

  • Get senior leadership approval, with the privacy officer in the room. In Claude terms, the person who becomes Primary Owner in Organization settings should not be the only person who decided to buy it3.
  • Ask whether the use is necessary and proportionate. Drafting a policy from your own templates needs no personal information at all; screening complaints might3.
  • Do a privacy impact assessment before rollout, and ask the provider how privacy is built in. Anthropic's Data Processing Addendum and data usage pages answer most of the vendor questions3,10,14.
  • Be open with customers and staff about how Claude is used, especially where it drafts something they will receive3.
  • Seek the views of people affected, including Māori, when the use touches decisions about them3.
  • Keep a person reviewing accuracy before anything Claude produced is acted on3.
  • Make sure the provider does not keep or disclose personal information beyond what you agreed. That is a plan and settings question, covered below3,13.

The principles you will meet in everyday Claude use

Principle 1 says you collect personal information only for a lawful purpose connected with your business, and principle 10 limits using it for something else1. If a client gave you their file to prepare a tax return, pasting it into Claude to prepare that return is a related purpose. Pasting it in to build a marketing persona is not.

Principle 3A is new. Since 1 May 2026, an agency that collects personal information from someone other than the person concerned must take reasonable steps to make that person aware of matters such as the fact of collection, the purpose and the intended recipients, unless an exception applies6. This matters for Claude because web search and Research can gather information about people from public sources. If staff use Claude to research a job applicant, a debtor or a complainant, treat it as indirect collection and check whether a notice is needed6. One exception covers information that is already publicly available, such as in a newspaper, a public register or on a website6.

Principle 5 requires reasonable security safeguards1. In Claude this means a commercial plan, single sign-on, sensible connector permissions and a clear rule on what never goes into a prompt. Principle 8 requires reasonable steps to check information is accurate before you use it1. Claude can be confidently wrong, so any reply that describes a person, a debt or an incident needs checking against the source before it lands in a letter or a record.

Principle 12 deals with disclosure outside New Zealand5. The Commissioner's guidance explains that, under section 11 of the Privacy Act 2020, an overseas provider that only stores or processes information on your behalf, and does not use it for its own purposes, is treated as your agent, so it is not a disclosure, but you remain responsible for what that provider does with it5. Anthropic contracts with New Zealand customers as Anthropic PBC under California law, and its privacy policy describes transfers to the United States11,12. Record that in your privacy impact assessment rather than leaving it implied.

Plan choice is a privacy decision

The most important control is the one made at purchase. On Claude's consumer plans, Free, Pro and Max, each person decides whether their chats are used to improve Anthropic's models, and data shared for that purpose can be kept for up to five years13. On Team, Enterprise and the API, Anthropic may not train models on customer content11.

A business that lets staff put client or employee information into personal consumer accounts will struggle to show it took reasonable security steps under principle 5 of the Privacy Act 20201,13. Move work onto a Team or Enterprise organisation first, then write the rules.

Retention also needs a decision. On Enterprise, owners set a custom retention period under Organization settings, then Data and Privacy, with a 30-day minimum; without one, chats and projects are kept indefinitely15. Incognito chats are not saved to history or memory and are not used for training, yet they are still kept for 30 days and appear in organisation exports16. Tell staff that incognito is not a way around the rules.

Privacy officer, breaches and your vendor

Any business that handles personal information must have a privacy officer, whose job includes encouraging compliance, handling access and correction requests, and working with the Commissioner during an investigation7. Give that person a seat in the Claude decision and a copy of the settings you chose.

If a privacy breach has caused or is likely to cause serious harm, you must notify the Commissioner and the affected people as soon as practicable4. The Commissioner's online NotifyUs tool walks you through whether a breach is notifiable4. Typical Claude-related incidents are an export of chats sent to the wrong person, a connector given wider access than intended, or client data pasted into a personal account that is later compromised.

Your contract helps here. Anthropic's Data Processing Addendum commits it to notify you of a security breach without undue delay and in any event within 48 hours10. Put that clause, and the name of whoever receives Anthropic's notices, into your incident plan.

Step by step: a privacy-ready Claude rollout

Work through these steps in order. Allow an hour or two for most steps; the assessment takes longer if Claude will touch health, financial or employment information.

  • List who already uses Claude and on which plan, including personal accounts paid for on company cards13.
  • Choose Team or Enterprise for any work involving personal information, so the Commercial Terms apply11.
  • Write a short privacy impact assessment: the purposes, the data classes, the overseas processing, and who reviews output3,5.
  • Sort information into three groups: fine to use, use only with care in a named Project, and never paste in.
  • Set Project instructions that remind Claude, and the user, of the review step for anything about a person.
  • On Enterprise, set retention to match your records policy15.
  • Check whether Claude-assisted research about people triggers a principle 3A notice under the Privacy Act 20206.
  • Update your privacy statement to say you use AI tools to help process information, and name the purposes3.
  • Train staff on the rules with their own examples, then review after the first month.

Worked example: a recruitment agency

Consider a generic Christchurch recruitment agency with around thirty staff that wants Claude to summarise CVs and draft shortlist notes for clients. The purpose is clear and connected to the business, so principle 1 is met if candidates were told their CVs would be assessed for roles1. The agency moves everyone onto Team, sets up a Project per client role, and writes a Project instruction that bans guesses about age, ethnicity, health or family status.

Two risks remain. First, accuracy: a shortlist note that misstates a candidate's experience could cost them a job, so a consultant checks every note against the CV before it goes to the client1,3. Second, indirect collection: if consultants ask Claude to search the web about a candidate, that is information gathered from a source other than the candidate, and principle 3A may require the agency to tell them6. The agency decides web search stays off in that Project and records why in its privacy impact assessment.

Staff, consultation and the public sector

Bringing Claude into a team changes how people work. Where a change could affect jobs, employers need genuine business reasons, must consult the employees affected and must follow a fair process; improved technology is one of the reasons Employment New Zealand lists9. Even when no roles are at risk, telling staff what admins can see, such as Enterprise audit logs and exports, is part of acting in good faith.

If you supply government agencies, expect them to ask how you use generative AI. The Government Chief Digital Officer's guidance for the public service covers governance, security, procurement, privacy and transparency for those tools8. MBIE's guidance for businesses points the private sector at the same building blocks: clear accountability, a privacy officer and risk-based governance7.

Related

  1. 1Role-based

    Claude for HR and people teams

    For HR and people leaders: policies, job descriptions, inductions and clear letters, with firm rules on employee information and fair decisions.

  2. 2Organisation

    Claude team rollout

    Move from a few keen users to a whole team using Claude well: plan and seats, Projects structure, usage rules, connectors, Skills and champions.

  3. 3Introductory

    Claude foundations workshop

    A hands-on first session for the whole team: prompts with real context, Projects, files, artifacts and the habit of checking answers.

Industries

Regions

More on privacy and security

See all guides.

Questions

Do we need customers' consent to use Claude on their information?

Not always. The Privacy Act 2020 is built on purpose and transparency rather than consent for everything. Use must fit the purpose you collected the information for, and the Commissioner expects you to be open about AI use1,3. Update your privacy statement and tell people when Claude drafts what they receive.

Is sending data to Anthropic in the United States a breach of principle 12?

Not by itself. A provider that only stores or processes information on your behalf, and does not use it for its own purposes, is treated as your agent, not a recipient of a disclosure, but you stay responsible for how it handles the information5. Anthropic acts as your processor under its Data Processing Addendum10.

Who should be our privacy officer for Claude?

The same person who is privacy officer for the rest of the business. Every business handling personal information needs one, and their role covers compliance, access and correction requests, and working with the Commissioner7.

Does a privacy impact assessment have to be long?

No. For a small business it can be a few pages covering purpose, information types, where data is processed, who reviews output and how people can access or correct records. The Commissioner expects one before generative AI is used with personal information3.

What if a staff member pasted client data into a personal Claude account?

Treat it as an incident. Find out what was shared and whether the account allowed model training, because consumer chats can be used for training when the person opted in13. If serious harm is likely, notify the Commissioner and the people affected4.

Train your team

  1. You tell us about the teamSize, where you are, the documents people work with, and what you would like to change.
  2. We suggest a course and formatBy email, with a few questions about the tasks and documents you want to train on.
  3. People practise on real workOn-site or remote. Everyone leaves with Claude set up for tasks they do every week.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with Anthropic.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources