All articlesCompliance

Privacy Act 2020: a practical checklist for advisers

Most advisers don't have a privacy problem until, suddenly, they very much do. A laptop goes missing on the way to a client meeting. An email containing a client's full medical history lands in the wrong inbox because Outlook helpfully autocompleted the address. A staff member leaves and nobody remembers they still had a shared login to the CRM. None of these are exotic. All of them are the kind of thing the Privacy Act 2020 expects you to have thought about before it happens, not after.

The good news: privacy compliance for an advice business isn't really about reading legislation. It's about a handful of practical habits applied to the data you already collect every day — names, dates of birth, IRD numbers, medical disclosures, financial positions. Get the habits right and compliance stops being a periodic scramble and becomes the default way you work. Here's a checklist to get there, organised around the actual life cycle of client data: collecting it, storing it, sharing it, and eventually getting rid of it.

Only collect what you can justify needing

The privacy principles start at the front door: collect only personal information you genuinely need for a lawful purpose connected to your work. For advisers that's a low bar — you do need medical history to place life and health cover, and you do need a financial position to advise on it. But "we might use it one day" is not a purpose. The fact-find that asks for everything because the template asks for everything is where a lot of businesses quietly over-collect.

Two habits make this easy. First, tell clients why you're collecting each category of sensitive information at the point you collect it — ideally in a short privacy statement they actually see, not buried in a terms-of-engagement PDF. Second, collect directly from the client where you can, and be transparent when you do go to an insurer or a previous adviser for information.

  • Name the purpose for sensitive fields (medical, financial, IRD) when you ask for them
  • Have a plain-English privacy statement clients can read in under a minute
  • Collect from the client directly where practical, and disclose any third-party sources
  • Resist keeping "nice to have" data with no clear use

Store it like it could be stolen tomorrow

Storage is where most real breaches happen, and it's also where you have the most control. The principle is simple: take reasonable steps to keep personal information secure against loss, misuse and unauthorised access. What "reasonable" looks like for a small FAP is mostly boring discipline, not enterprise security spend.

Start by knowing where client data actually lives. For most advice businesses the honest answer is: the CRM, the email inbox, a shared drive, a few spreadsheets, and someone's phone. Each of those is a place a breach can come from. The fastest wins are almost always the same — turn on multi-factor authentication everywhere, encrypt devices that leave the office, and stop letting client data accumulate in email and personal spreadsheets where it's invisible and unprotected.

  • Multi-factor authentication on email, CRM and anything else holding client data
  • Full-disk encryption on every laptop and phone that touches the business
  • Individual logins per staff member — never a shared account
  • Access scoped to role, so support staff can't see everything by default
  • One system of record, so data isn't scattered across inboxes and drives

This is the quiet argument for keeping client information in a purpose-built system rather than email threads and ad hoc files. When AdviserDesk holds the record, access is logged and permissions are per-user, so you can answer "who can see this client's medical disclosure?" without a forensic search. The point isn't the tool; it's that consolidation turns a dozen leaky surfaces into one you can actually defend.

Be deliberate about who you share with

Advice work is a sharing business. You send applications to insurers, instructions to providers, files to a new adviser when a client moves, and sometimes data to an offshore service or piece of software that processes it for you. Each of those is a disclosure, and a useful test is whether the client would reasonably expect it, given why you collected the information in the first place.

The habit here is to make sharing intentional rather than accidental. Most unauthorised disclosures aren't sinister — they're an autocompleted address, a reply-all, or a spreadsheet attached to the wrong message. A few defaults cut that risk sharply: send through secure links or portals rather than raw attachments, double-check recipients on anything sensitive, and keep a simple record of who you routinely share data with and why.

Pay particular attention to anyone who processes data on your behalf — your CRM, an AI tool, a paraplanning service, a cloud backup. You remain responsible for that information, so it's worth knowing where it's stored (including whether it leaves New Zealand) and what the provider commits to. You don't need to become a procurement department about it, but you should be able to name your key processors and say, in one sentence each, what they do with your clients' data.

Don't keep it forever

Holding data you no longer need is a liability dressed up as diligence. The principle is that you shouldn't keep personal information for longer than you require it for a lawful purpose. In practice you do need to retain advice records for a good while — your licensee and the conduct regime expect you to be able to reconstruct the advice you gave — so this is a balancing act, not a mandate to delete aggressively.

The practical move is to have a retention position you can articulate, rather than a default of keeping everything until the hard drive fills up. Decide roughly how long different categories of record need to live, and have some mechanism — even a calendar reminder and a quarterly tidy-up — to clear out what's genuinely past its purpose. How long advice records must be kept depends on your obligations, not just the Privacy Act, so confirm the specifics with your licensee or compliance adviser.

Give clients their information, and have a breach plan

Two obligations catch advisers off guard because they only matter occasionally. The first is access and correction: a client can ask to see the personal information you hold about them and to correct it if it's wrong, and you're expected to respond within a reasonable timeframe. If your data is scattered, that request becomes a genuine headache; if it lives in one place, it's a five-minute job. That alone is a decent reason to consolidate.

The second is notifiable privacy breaches. If something goes wrong and the breach has caused, or is likely to cause, serious harm, you're generally expected to notify the Privacy Commissioner and the affected people. The time to work out who decides, who you call, and what you say is not in the middle of the breach. Write a one-page response plan now — even a rough one — so a bad day stays a manageable day.

  • A named person responsible for privacy questions and breach decisions
  • A simple process for handling access and correction requests
  • A short, pre-written breach response plan you can actually follow under pressure
  • An annual ten-minute review to check the basics haven't drifted

None of this requires a compliance team or a consultant on retainer. It requires deciding, once, what good looks like for your business — collect less, store it securely, share it deliberately, keep it only as long as you need, and know what you'd do if it went wrong — then building those decisions into the tools and routines you already use. Make compliance the default and it stops being a chore you dread. If a specific obligation matters to your situation, confirm it with the Privacy Commissioner, the FMA, or your licensee — but most of the work is just good habits, applied consistently.

Run your book on AdviserDesk

The AI-powered CRM for NZ insurance advisers. Free for 30 days, cancel any time.

Start free trial