HomeKnowledge HubCodes & Schemes › Biometric Processing Privacy Code 2025 (NZ)

Statutory code of practice · Codes & Schemes

New Zealand’s Biometric Processing Privacy Code 2025 — a regulator’s rulebook for facial recognition

Issued 21 July 2025In force 3 November 2025Amendment No 1, March 2026

The BPPC is a code of practice made under New Zealand’s Privacy Act 2020 that substitutes its own thirteen rules for the Act’s information privacy principles where biometric processing is concerned. It is one of few standalone, binding biometrics codes we have found in a common-law jurisdiction, and its proportionality test and use limits are worth reading beside the UK’s approach.

Published by
Office of the Privacy Commissioner (OPC), New Zealand.
Type
Statutory code of practice under the Privacy Act 2020 — binding; its rules replace the information privacy principles for the processing it covers.
Versions and language
Code issued 21 July 2025; Amendment No 1 (March 2026), reflecting the new information privacy principle 3A, in force from 1 May 2026 — the version on the OPC site is labelled “in force from 1 May 2026”. English.
Jurisdiction
New Zealand.
Primary audience
Any agency using facial recognition, fingerprint, voice or behavioural biometrics; UK groups with New Zealand operations; practitioners looking for a worked proportionality model.
Topic tags
biometrics · facial recognition · proportionality · transparency · special category data · UK GDPR Art. 9 comparator
Availability
Free. Six OPC factsheets and full guidance accompany the Code.

Why it matters

Three rules do most of the work, and the OPC’s own overview factsheet states them plainly. Proportionality: an organisation must not collect biometric information unless it believes on reasonable grounds that the biometric processing is proportionate to the likely impacts on people — a test to be satisfied before collection, not a factor weighed afterwards. Openness: organisations generally need to let people know how their biometric information will be used and disclosed. Use limits: the Code limits what biometric information may be used for — for example, it may not be used to detect a person’s health information unless the person specifically authorises it. The Code applies to verification, identification and categorisation (inferring emotion or estimating age, for instance), and generally not to personal consumer devices.

The UK position. UK GDPR treats biometric data used for unique identification as special category data under Article 9, which requires a lawful basis plus an Article 9 condition, and, for most of the processing the Code covers, a DPIA under Article 35; the ICO’s biometric recognition guidance sets expectations, but there is no UK statutory code specific to biometrics. The New Zealand Code is therefore a comparator, not an equivalent — useful for the shape of a proportionality assessment and for the explicit use-limitation rules, neither of which UK law states as crisply.

Transition note: agencies already using biometrics had until 3 August 2026 to comply, so the Code is now fully operative. The OPC’s regulator profile sits in Regulators & Authorities.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 15 September 2026 · last verified 15 September 2026 — facts verified against privacy.org.nz (Code landing page read 11 September 2026; Factsheet 1 read 15 September 2026). Suggest a correction.