Generative AI can help professional services firms summarise documents, prepare drafts and reduce administrative work. But once personal information is entered into an AI tool, the exercise becomes a privacy and information-governance decision.
The Office of the Privacy Commissioner’s position is straightforward: the Privacy Act 2020 applies when organisations use AI tools in New Zealand. The Information Privacy Principles apply across the full AI lifecycle, including training data, user prompts, uploaded material, generated outputs and any action taken as a result.
For firms trusted with client and employee information, privacy must be a starting point for AI adoption, not a check completed after rollout.
Privacy law follows the information into the tool
Staff may paste correspondence, upload a contract, ask for a client-file summary or provide enough context to identify a person. Personal information can also appear in an AI-generated response, including inaccurate or fabricated information.
Each step can involve collecting, using, storing or disclosing personal information. A task may feel like ordinary drafting, while an external provider processes the information under terms the firm has not reviewed.
This is why a rule such as “do not enter confidential information” is rarely enough on its own. Staff need practical guidance on what counts as personal or confidential information, which tools are approved and what they should do when a legitimate use case requires client data.
A prompt is part of a wider data flow
Before approving an AI tool, a firm should understand where information goes, how long it is retained, who can access it, whether it may be used for training and how it can be deleted. Security controls, contractual commitments and offshore processing arrangements all matter.
Using an overseas technology provider to process information is not automatically an overseas disclosure under Information Privacy Principle 12 if the provider does not use that information for its own purposes. The details of the service and its terms still matter, and the firm remains responsible for protecting the information entrusted to the provider.
Accuracy is just as important. A fluent response is not evidence of reliability. Where an output may affect someone, human review must be meaningful. A reviewer needs the time, source material and authority to challenge it.
Complete the privacy work before rollout
The Privacy Commissioner expects organisations considering generative AI to obtain senior leadership approval, assess whether the use is necessary and proportionate, complete a Privacy Impact Assessment, be transparent with affected people and put effective review procedures in place. The guidance also calls for engagement with Māori about potential effects on Māori communities and taonga information.
A Privacy Impact Assessment should reflect the tool, use case and information involved, then be reviewed when the provider, model, settings or business process changes. It should also examine existing staff use, because privacy exposure may predate a formal AI programme.
There is now another consideration. Information Privacy Principle 3A came into force on 1 May 2026. It generally requires an organisation that collects personal information indirectly to take reasonable steps to notify the person, unless an exception applies. Whether IPP3A applies to an AI-enabled process will depend on how the information is obtained and used, but it makes data mapping, transparency and vendor arrangements even more important.
What good AI privacy governance looks like
A practical starting point is to:
- approve specific tools and use cases, with a named business owner
- set clear rules for personal, confidential and client information
- complete privacy and security due diligence before procurement or use
- test outputs for accuracy, bias and suitability in the New Zealand context
- maintain processes for transparency, human review, access and correction
- revisit the assessment when the tool or use case changes.
Our Take
AI privacy need not stop useful experimentation, but it should shape where and how that experimentation occurs. A prompt is information entering a new processing chain, not a private conversation with a drafting assistant.
For professional services firms, the trust risk can be as significant as the legal risk. The strongest approach combines approved technology, a clear policy, use-case assessment, staff training and ongoing oversight.

