New Zealand
Last reviewed: 2026-09-26
New Zealand health agencies need to apply the Health Information Privacy Code to health information. Other personal information may fall under the Privacy Act's information privacy principles. Assess the proposed use and each recipient before sharing a masked copy.
Where PHI Mask fits
Your file is masked in your browser and never sent to us. The Compliance page explains the masking workflow, browser storage and the separate handling of website and support information.
The service you send a masked copy to has its own purposes, settings, contracts and storage locations. Assess that service as part of your workflow.
Use the health-information rules
The Health Information Privacy Code modifies the Privacy Act principles for health agencies handling health information. Establish whether the agency, information and proposed task are within its scope.
Document the purpose and applicable collection, use and disclosure rules. Rule 3 covers notice when information is collected directly from the person or their representative.
Check notice for indirect collection
HIPC Rule 3A applies to health information collected indirectly on or after 1 May 2026. The agency must take reasonable steps to notify the person or their representative unless an exception applies.
The notice covers the fact and purpose of collection, intended recipients, collecting and holding agencies, any authorising law, and access and correction rights. Record when notice was given or which exception applies. Use the HIPC rule for health information; general IPP3A has broader scope.
Distinguish overseas disclosure from an agency service
Rule 12 addresses disclosure of health information outside New Zealand. The review needs to establish the permitted basis and applicable safeguards for the overseas recipient.
Sending information to an agent for storage or processing can be treated differently when the agent does not use it for its own purposes. Confirm the actual arrangement and continued responsibility before relying on that distinction.
Control access, retention and correction
Assess reasonable safeguards for the browser, device and selected service. Keep information only as long as a lawful purpose requires, while accounting for any applicable health-record retention duty.
Record how the agency will handle access and correction requests. Masked copies and recovery information need to be covered by those operating procedures.