New Zealand Biometric Privacy Rules: Facial Recognition and the Code

Facial recognition in shops, fingerprint scanners at work, and voiceprints on a phone line all collect biometric information, and New Zealand now has a specific set of privacy rules for it. The Biometric Processing Privacy Code 2025, issued by the Office of the Privacy Commissioner, sits on top of the Privacy Act 2020 and tightens what organisations can do with biometrics.
This is general information about New Zealand privacy law, not legal advice. For your own situation, consult a lawyer or your local Community Law centre.
What the Code covers
Biometric information is data about a person's physical or behavioural characteristics used to identify them, such as a facial image processed by facial recognition, a fingerprint, or a voiceprint. The Biometric Processing Privacy Code 2025 applies when an organisation processes that information through an automated system. Where it applies, its rules take the place of the standard information privacy principles in the Privacy Act 2020, tailored to the higher sensitivity of biometrics.
The proportionality test and transparency
The central requirement is proportionality. An organisation cannot collect biometric information simply because it is convenient; it must be able to show that the collection is necessary and effective for its purpose, and that the benefit outweighs the privacy intrusion, with safeguards in place. The Code also strengthens transparency, so a business using facial recognition in a store is expected to make that use clear, and it limits using biometric data for unrelated purposes.
What it means for facial recognition in retail and security
Retailers and security operators that use facial recognition to identify shoplifters or trespassers are squarely within the Code. They need to have assessed whether the system is proportionate, tell customers it is in use, and handle the data according to the Code rather than treating it like ordinary CCTV. For the full Privacy Act 2020 framework, including the information privacy principles and mandatory breach notification, see our New Zealand data privacy laws guide, and the wider New Zealand privacy section.
Frequently Asked Questions
When did the Biometric Processing Privacy Code start in New Zealand?
It came into force on 3 November 2025 for new biometric processing. Organisations that were already using biometric systems before then have until 3 August 2026 to comply. It was issued by the Office of the Privacy Commissioner under the Privacy Act 2020.
Can a shop use facial recognition on customers in New Zealand?
It is not banned, but it is regulated. Under the Biometric Processing Privacy Code, a retailer may only use facial recognition if it is necessary, effective, and proportionate for a legitimate purpose, and it must be transparent that the technology is in use. Whether a particular use meets that test depends on the facts, and the Office of the Privacy Commissioner can investigate complaints.
Does the Code ban collecting biometric information?
No. It does not ban biometrics; it sets conditions. An organisation must show that collecting the biometric information is necessary and effective for its purpose and proportionate to the privacy impact, with appropriate safeguards, and it must be open about the collection. Collecting biometric data without meeting those requirements can breach the Privacy Act 2020.