New Zealand

Five Eyes founding member and Budapest Convention party pooling Pacific SIGINT from cable and satellite with its partners, though with no mandatory data retention and weak domestic enforcement

← Back to Privacy Law Directory

Overview

New Zealand is a founding member of the Five Eyes intelligence alliance (with Australia, Canada, the United Kingdom, and the United States). The GCSB (Government Communications Security Bureau) intercepts communications from the Southern Cross cable system and Pacific satellite coverage, sharing intelligence with the NSA, GCHQ, ASD, and CSE via XKeyscore. The former Waihopai satellite station (ECHELON/FLINTLOCK, decommissioned 2022) provided Pacific Intelsat interception; collection has shifted to fibre-optic cable access. TICSA (2013) requires all network operators to maintain built-in interception capability. Pacific island nations’ communications transit New Zealand-controlled infrastructure, making GCSB a collection platform for a far broader geographic footprint than NZ’s 5 million population suggests.[1][2]

New Zealand’s outward data-sharing runs through its alliances and treaties, each detailed below. As a Five Eyes member it shares raw signals intelligence by default with Australia, Canada, the United Kingdom, and the United States under the UKUSA Agreement, and it takes part in the M5 Five Eyes biometric-sharing programme. It is a party to the Budapest Convention on Cybercrime (2001).[28] Its mutual legal assistance runs under the MACMA framework, which designates seven prescribed foreign countries (Australia, Fiji, the Hong Kong SAR, Niue, the Republic of Korea, the United Kingdom, and the United States) and rests on bilateral MLA treaties with three of them: China, the Hong Kong SAR (suspended since 2020), and the Republic of Korea.[19][29] It also participates in Interpol and the Egmont Group of financial intelligence units, and a US CLOUD Act agreement is anticipated. These are the channels through which the domestic safeguards below are, in practice, bypassed.

The domestic framework is comparatively light-touch. The Privacy Act 2020 added mandatory breach notification and extraterritorial reach, but the Privacy Commissioner cannot impose fines (maximum criminal penalty NZD $10,000), and New Zealand has no mandatory data retention. That framework, the Commissioner’s reform agenda, and the November 2025 Biometric Processing Privacy Code are covered below.[3][4]

International Data Sharing Agreements

Mutual Legal Assistance: MACMA Framework

New Zealand’s mutual legal assistance is governed by the Mutual Assistance in Criminal Matters Act 1992 (MACMA). Crown Law serves as the central authority. The framework operates through three tiers, distinct from the small set of bilateral treaties that underpin them:[19]

Prescribed foreign countries (7): a MACMA designation set by regulation, giving these countries’ requests streamlined handling: Australia, Fiji, the Hong Kong SAR, Niue, the Republic of Korea, the United Kingdom, and the United States. This is a designation, not a treaty list.

Bilateral MLA treaties (3): New Zealand has standalone bilateral mutual-assistance treaties with the Republic of Korea, China, and the Hong Kong SAR. The Hong Kong agreement is suspended: after New Zealand suspended its extradition treaty with Hong Kong in July 2020 (the fourth Five Eyes state to do so, after the UK, Australia, and Canada), China reciprocally suspended the Hong Kong extradition and mutual legal assistance agreements with New Zealand in August 2020.[29]

Convention countries: Countries party to conventions listed in MACMA’s schedule, providing MLA coverage through multilateral instruments.

Ad hoc requests: Any country can make MLA requests to New Zealand, even without a treaty or convention basis.

New Zealand’s full set of bilateral treaties (mutual assistance, extradition, and others) is searchable in the Ministry of Foreign Affairs and Trade’s New Zealand Treaties Online database.

Budapest Convention on Cybercrime

New Zealand is a party to the Council of Europe Convention on Cybercrime (the Budapest Convention, 2001, ETS 185), the principal multilateral instrument for the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 the Budapest Convention has 82 parties: 45 Council of Europe member states (every one of the 46 members except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[28]

CLOUD Act: Anticipated Agreement

Following the UK (2022) and Australia (2024), New Zealand is anticipated to negotiate a CLOUD Act agreement with the United States, enabling direct data requests to US tech companies. The reciprocal agreement would allow US law enforcement to request data from NZ companies without NZ judicial oversight.

Five Eyes Intelligence Sharing: Founding Member

GCSB shares raw SIGINT with the other four Five Eyes members, Australia, Canada, the United Kingdom, and the United States (through their ASD, CSE, GCHQ, and NSA), by default under the UKUSA Agreement. NZ’s geographic position provides unique Pacific and Southeast Asian coverage. The framework creates a reciprocal surveillance bypass: partner agencies can collect on NZ persons and share with GCSB, circumventing Type 1 warrant requirements. No domestic legislation governs intelligence sharing; the legal underpinning remains “shrouded in mystery.”[20][21]

Five Power Defence Arrangements (FPDA)

New Zealand is a founding member of the Five Power Defence Arrangements (1971), the consultative defence pact joining New Zealand, the United Kingdom, Australia, Malaysia, and Singapore in a commitment to consult over any external threat to Malaysia or Singapore. Alongside its defence role it provides an intelligence-sharing channel (counter-terrorism and maritime security) linking the three Five Eyes members to the two Southeast Asian states, one of the few standing frameworks through which NZ intelligence engages the region outside the Eyes alliances.[30]

Five Eyes Biometric Sharing

M5 Fingerprint Sharing: NZ border authorities query Five Eyes fingerprint and immigration databases. NZ is “still considering” participation in an expanded proposal to query domestic criminal databases for immigration purposes.[22]

Multilateral Frameworks

Interpol I-24/7: NZ Police participate in the 195-country network. Egmont Group: NZ FIU shares financial intelligence across 164+ FIUs.

The Privacy Backdoor Effect

Despite the ISA 2017’s Type 1 warrant dual-authorisation for targeting NZ persons, international agreements create alternative pathways:

SIGINT Seniors of the Pacific (SSPAC)

New Zealand’s GCSB participates in SIGINT Seniors of the Pacific (SSPAC), the NSA-led Asia-Pacific counterterrorism SIGINT coalition established in 2005, whose ten members are the Five Eyes (the United States, the United Kingdom, Canada, Australia, and New Zealand) plus France, India, Singapore, South Korea, and Thailand. Counter-terrorism intelligence is exchanged over the CRUSHED ICE secure network.[31]

Surveillance and Intelligence

Intelligence and Security Act 2017

Consolidated GCSB and NZSIS legal frameworks with a dual-authorisation warrant system:[7]

Authorised activities include covert surveillance, communications interception, computer exploitation, tracking devices, and human intelligence operations.[8]

TICSA (2013)

The Telecommunications (Interception Capability and Security) Act (TICSA) also governs network security: under Part 3, the GCSB’s NCSC works with operators, and in 2018 the GCSB used TICSA to block Huawei 5G equipment from Spark’s network, giving the GCSB effective veto power over telecom equipment deployments.[9][10]

Intelligence Agencies

GCSB: Signals intelligence (SIGINT) and information assurance. Operates cable interception, the CORTEX cyber defence programme (preventing NZD $38.8M in harm annually, detecting 15–20 intrusions/month), and the NZD $326M sovereign data centre at Whenuapai (opened 2025). Former Waihopai station, decommissioned 2022, though the facility continues intelligence operations.[11][12][13]

NZSIS: Domestic security intelligence (HUMINT), counter-espionage, counter-terrorism, security vetting.

Oversight

IGIS (Inspector-General of Intelligence and Security): principal independent oversight body, reviews GCSB and NZSIS activities in secret. ISC (Intelligence and Security Committee): parliamentary oversight with classified access. Commissioner of Intelligence Warrants: retired judge, co-authorises Type 1 warrants. IGIS 2025–26 work programme includes reviewing Five Eyes partner requests and the Whenuapai data centre.[14]

Parliamentary Oversight: The Intelligence and Security Committee (ISC)

Governed by the Intelligence and Security Act 2017 (which replaced the 1996 committee statute after the Cullen-Reddy review prompted by the GCSB’s unlawful surveillance of Kim Dotcom), New Zealand’s ISC is the parliamentary counterpart to Canada’s NSICOP, the UK’s ISC, and Australia’s PJCIS. It examines the policy, administration, and expenditure of the GCSB and NZSIS, and it can ask the IGIS to inquire into the legality or propriety of a particular matter.[25][26]

By Five Eyes standards it is the weakest of the parliamentary committees, and for one structural reason above all: it is chaired by the Prime Minister. The committee is small (five to seven MPs: the Prime Minister, the Leader of the Opposition, and a handful of members nominated by each), and its statutory remit stops short of operational review. It cannot itself investigate intelligence operations, sources, or methods; where a propriety or legality question arises it must refer the matter to the IGIS rather than examine it directly. Critics note that placing the head of government in the chair of the body meant to scrutinise that same government’s agencies sits awkwardly with independent oversight, a contrast with the United Kingdom, where the 2013 reforms deliberately moved the chair away from Downing Street.[25][26]

Cable Surveillance and Pacific SIGINT

Southern Cross Cable

The Southern Cross Cable Network connects New Zealand to Australia and the United States, carrying the majority of NZ’s international traffic. GCSB has access to traffic passing through NZ landing points, intercepting communications between Australia and the US, as well as Pacific island traffic routing through Auckland. Communications between users in other countries may be intercepted if the routing path passes through NZ, subject to Type 2 warrants (ministerial only, no judicial approval).[15]

Pacific Island Monitoring

GCSB’s mandate includes monitoring communications from Pacific island nations (Fiji, Samoa, Tonga, Cook Islands, and others) whose international traffic routes through NZ-controlled infrastructure. This creates a diplomatic tension: NZ provides development aid and security assistance to these nations while conducting SIGINT collection on their governments and citizens under Type 2 warrants requiring only ministerial authorisation.[16]

XKeyscore Access

GCSB has access to the NSA’s XKeyscore system, contributing cable intercepts to the shared Five Eyes database and searching intelligence collected globally. Communications intercepted by GCSB are accessible to analysts in all Five Eyes countries.[17]

Encryption and Interception Capability

New Zealand has no compelled decryption law and no encryption backdoor mandate. Unlike Australia’s TOLA Act or the UK’s Technical Capability Notices, NZ law does not empower authorities to compel technology companies to build lawful access capabilities into encrypted products or to compel individuals to disclose encryption keys.

However, TICSA (2013) requires all network operators to maintain built-in interception capability, ensuring that networks can technically support lawful interception when authorised. This obligation applies to the network layer (requiring operators to be able to intercept communications when served with a warrant) but does not extend to requiring application-layer providers (messaging apps, email services) to defeat their own encryption. The practical effect is that NZ authorities can intercept unencrypted communications on the network but face the same “going dark” challenge as other Five Eyes members when end-to-end encryption is deployed at the application layer.[9]

Given NZ’s Five Eyes membership and GCSB’s access to XKeyscore, encrypted communications that cannot be intercepted domestically may still be accessible through alliance intelligence sharing, particularly where partner agencies with stronger legal mandates (Australia’s TOLA Act, the UK’s TCNs) have obtained access to the same communications through their own compulsory powers.

Recent Developments

GCSB Sovereign Data Centre (2025): NZD $326M facility at Whenuapai Air Force base for classified intelligence storage, designed for 25+ year lifespan. IGIS 2025–26 work programme will review how data is shared within Five Eyes from the new facility.[13]

Privacy Amendment Act 2025: Added IPP 3A (indirect collection notification, effective May 2026), motivated by preserving EU adequacy status. NZ holds adequacy since 2012, one of only 15 jurisdictions worldwide.[6]

Biometric Processing Privacy Code (November 2025): First biometric-specific rules in Asia-Pacific. Requires necessity/proportionality tests, mandates PIAs, restricts real-time facial recognition. Financial services AML/KYC liveness checks fall within scope. August 2026 compliance deadline.[4]

Commissioner’s Reform Agenda: Webster calls for multimillion-dollar civil fines, right of erasure, and AI/automated decision-making safeguards. Breach notifications surged 43% to ~600 in the latest period. 75% of New Zealanders support granting the Commissioner audit and fine powers.[3]

Social Media (Age-Restricted Users) Bill (2025–2026): The bill, introduced in May 2025 and modelled on Australia’s Online Safety Amendment (Social Media Minimum Age) Act, would prohibit social media services for users under 16. Platforms that fail to implement effective age-verification measures face fines up to NZD 2 million. In mid-May 2026 the Government confirmed it had paused work on the under-16 ban, even as a parliamentary committee recommended that age-assurance be required for social-media access; the bill has nonetheless become a model reference in Pacific discussions of under-16 bans. Privacy Commissioner Michael Webster has publicly cautioned that the proposal could trigger large-scale data collection, since verifying that no under-16s hold accounts effectively requires every user over 16 to prove their age, and that enforcing the ban would be “challenging in practice.”[23][24]

As of July 2026 the bill is not merely paused but deprioritised. It is a member’s bill, introduced by National MP Catherine Wedd, and Education Minister Erica Stanford has set it aside in favour of broader government legislation on reducing social-media harm, which will depart from the member’s bill rather than carry it forward. A final Cabinet paper was expected within weeks of the start of July 2026, with NZD 30.7 million allocated to the associated policy work and the government aiming to introduce the replacement before the parliamentary term ends. The select-committee inquiry that recommended age restrictions reported in March 2026; it was initiated by ACT MP Parmjeet Parmar, who then called the report “predetermined” and warned that New Zealanders should be alarmed that age-verified social media would mean increased surveillance. The shape of the eventual bill, and in particular whether it requires age assurance of all users, is therefore still unsettled.[27]

Privacy Framework

The Office of the Privacy Commissioner (OPC), under Commissioner Michael Webster (since July 2022), investigates complaints, issues compliance notices, and can publicly name non-compliant agencies, but has no fining power. Complaints reached 1,598 cases in 2024–2025 (21% increase). The Human Rights Review Tribunal can award damages in individual cases.[3]

The Privacy Act 2020 (in force December 1, 2020) contains 13 Information Privacy Principles governing the full data lifecycle, plus new IPP 3A (indirect collection notification, effective May 2026, added by the Privacy Amendment Act 2025 to preserve EU adequacy). The Act exempts intelligence agencies (GCSB and NZSIS), courts, Parliament, and news media. The Biometric Processing Privacy Code (November 2025) requires necessity/proportionality tests, PIAs, and restricts real-time facial recognition; agencies have until August 2026 to comply. Health agencies remain under the separate Health Information Privacy Code; GCSB/NZSIS are exempt.[5][4][6]

Data Retention

New Zealand has made a deliberate policy choice not to enact mandatory data retention, unlike neighbouring Australia’s two-year regime. Providers retain data according to their own commercial policies, creating an inconsistent landscape. Law enforcement relies on targeted processes: production orders (Search and Surveillance Act 2012), intelligence warrants (ISA 2017), and TICSA interception capability obligations. The absence of mandatory retention has been described as a “sleeping giant” of NZ privacy law.[18]

Pending Legislation

Sources

[1] Wikipedia: UKUSA Agreement – Five Eyes, NZ accession 1956
[2] Wikipedia: GCSB – SIGINT mandate, Pacific coverage, Waihopai, cable access
[3] Captain Compliance: NZ Privacy Act Turns Five – Commissioner reform agenda, 1,598 complaints, 43% breach surge
[4] OPC: Biometric Processing Privacy Code – Issued July 2025, in force November 2025, August 2026 compliance
[5] SecurePrivacy: Privacy Act 2020 Explained – 13 IPPs, compliance notices, breach notification
[6] OPC: Privacy Amendment Act 2025 – IPP 3A, EU adequacy preservation, May 2026 effective
[7] Wikipedia: Intelligence and Security Act 2017 – Type 1/2 warrants, dual authorisation
[8] NZ Legislation: Intelligence and Security Act 2017 – Authorised activities, warrant framework
[9] Wikipedia: TICSA 2013 – Interception capability, network security, NCSC
[10] GCSB: Decision on Spark 5G Proposal – Huawei equipment blocked under TICSA
[11] GCSB: CORTEX – NZD $38.8M harm prevented, 15-20 intrusions/month
[12] Wikipedia: Waihopai Station – ECHELON, FLINTLOCK, decommissioned 2022
[14] IGIS: Inspector-General of Intelligence and Security – 2025-26 work programme, Five Eyes partner requests review
[15] Wikipedia: Southern Cross Cable Network – NZ-Australia-US, primary international link
[16] RNZ: NZ Spying in the Pacific – Pacific island SIGINT, diplomatic tensions
[18] NZ Law Commission: Extradition and Mutual Assistance – No mandatory retention, targeted legal processes
[19] Crown Law: Mutual Assistance – MACMA 1992, prescribed countries, convention countries, ad hoc requests
[20] Privacy International: Five Eyes – UKUSA, default sharing, warrant bypass
[22] RNZ: Five Eyes Criminal Database Sharing – M5 fingerprints, NZ “still considering”
[23] Wikipedia: Social Media (Age-Restricted Users) Bill – NZ bill modelled on Australia’s Online Safety Amendment; under-16 prohibition; NZD 2M penalties; introduced May 2025
[24] Biometric Update: Social Media Age-Check Warning by NZ Regulator (June 2026) – Privacy Commissioner Michael Webster warns the Social Media (Age-Restricted Users) Bill could drive large-scale data collection because all users over 16 would need to verify age; calls under-16 enforcement “challenging in practice”
[25] Intelligence and Security Act 2017 (NZ) – Constitutes the Intelligence and Security Committee chaired by the Prime Minister (five to seven members including the Leader of the Opposition); functions limited to policy, administration and expenditure review; operational propriety/legality matters referred to the IGIS
[26] NZSIS: Oversight – Overview of New Zealand’s intelligence oversight architecture (ISC parliamentary committee, IGIS independent review, Commissioners of Intelligence Warrants)
[27] The Spinoff: The World’s Social Media Bans and NZ’s Plans Explained (July 1, 2026) – Social Media (Age-Restricted Users) Bill is a member’s bill introduced by National MP Catherine Wedd in May 2025; placed on hold and deprioritised by Education Minister Erica Stanford in favour of broader online-safety legislation that will depart from the member’s bill; final Cabinet paper expected within weeks; NZD 30.7 million allocated to the policy work; government aims to introduce revised legislation before the parliamentary term ends; select-committee inquiry into digital harm, initiated by ACT MP Parmjeet Parmar, reported in March 2026 recommending age restrictions
[28] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states, New Zealand among them)
[29] RNZ: Hong Kong Extradition Suspension, China and New Zealand (2020) – New Zealand suspended its extradition treaty with Hong Kong on July 28, 2020 (the fourth Five Eyes state to do so, after the UK, Australia and Canada); China reciprocally suspended the Hong Kong extradition and mutual legal assistance agreements with New Zealand in August 2020
[30] Wikipedia: Five Power Defence Arrangements – 1971 consultative defence pact among New Zealand, the UK, Australia, Malaysia, and Singapore; the five consult on any external threat to Malaysia or Singapore; Integrated Air Defence System; carries a counter-terrorism and maritime intelligence-sharing dimension
[31] The Intercept: The Powerful Global Spy Alliance You Never Knew Existed (March 1, 2018) – the NSA-led SIGINT Seniors coalitions; SIGINT Seniors of the Pacific founded 2005, comprising the Five Eyes plus France, India, Singapore, South Korea, and Thailand; counter-terrorism intelligence shared over the CRUSHED ICE secure network
← Back to Privacy Law Directory