The Biometric Processing Privacy Code grace period ended on 3 August 2026. If your organisation scans faces, fingerprints or voices, the transitional relief you were relying on has now gone. Here is what the Code requires, who it covers, and what to check first.

The Biometric Processing Privacy Code is now fully in force
New Zealand has regulated biometrics for a while. However, the rules were general. They sat inside the Privacy Act 2020 and applied to biometric data the same way they applied to any other personal information.
That changed in 2025. The Privacy Commissioner issued a dedicated code of practice under section 202 of the Act. It came into force on 3 November 2025. As a result, biometric processing now has its own specific rulebook.
The Code did not land all at once, though. Organisations already running biometric systems received a nine-month transition period. That window closed on 3 August 2026. Consequently, every organisation in scope must now comply in full.
Two commencement dates, and only one still matters
Plenty of Biometric Processing Privacy Code guidance published last year separated the timeline into two tracks. It is worth restating them clearly, because the distinction has now collapsed.
- New biometric processing started after 3 November 2025. Compliance was required immediately, from the moment processing began.
- Biometric processing already underway on or before 3 November 2025. These activities had nine months to reach compliance. That grace period ended on 3 August 2026.
In other words, there is no longer a category of biometric processing that gets extra time. If you were relying on the transition, you are now simply late.
Does the Biometric Processing Privacy Code apply to you?
The Code covers biometric information used for biometric processing. That sounds circular, so it helps to look at real examples instead.

Broadly, you are in scope if you use an automated system to recognise or assess someone from a physical or behavioural characteristic. Facial recognition is the obvious case. Nevertheless, several less obvious systems also qualify.
- Fingerprint or palm readers used for building access
- Biometric time and attendance clocks
- Voice identification in a contact centre
- Iris or retina scanning
- Facial age estimation at a point of sale
- Facial matching against a watchlist in retail
Some things sit outside the Code. A staff photograph used only as a photograph is not biometric processing. Similarly, a written physical description is not covered. Health information does not become biometric simply because it is about a body. Even so, the Privacy Act and the information privacy principles still apply to all of it.
What the Biometric Processing Privacy Code actually requires
The Code layers extra obligations on top of the existing principles. Three of them drive most of the work.
A proportionality assessment, documented before you start
This is the centrepiece. You must be satisfied that biometric processing is proportionate in the circumstances. Therefore you need to weigh the benefits against the privacy impact, and you must consider whether a less intrusive option would work.
Crucially, this has to be more than a private conclusion. Regulators expect a written record. If you cannot show the reasoning, you cannot show proportionality.
Clear, specific notification
People need to know what is happening. The Code sets a higher bar than generic privacy policy wording. You must tell people that biometric processing is occurring, explain why, and describe how they can raise a concern.
Signage matters here. A small notice at an entrance rarely does the job on its own.
Limits on collection and secondary use
The Code restricts certain uses outright. For example, it constrains biometric classification that infers sensitive characteristics such as emotional state or health. In addition, you cannot quietly repurpose biometric data collected for one reason and use it for another.
Biometric Processing Privacy Code gaps we see most often
Across our assessments, the same Biometric Processing Privacy Code gaps recur. None of them are exotic.
Nobody owns the system. Biometric access control is often bought by facilities or operations. Privacy teams then discover it late. Because ownership is unclear, no proportionality assessment ever gets written.
The vendor is treated as the compliance answer. Suppliers will say their product is compliant. That claim covers their product, not your deployment. You remain accountable for the decision to use it.
Retention is indefinite by default. Many systems keep templates until someone deletes them. Consequently, organisations hold biometric data on people who left years ago.
Old systems were never revisited. This is the direct consequence of the grace period ending. A fingerprint reader installed in 2019 was in scope from 3 November 2025 and had to be uplifted by 3 August 2026.
Your Biometric Processing Privacy Code checklist
Start narrow and move fast. This Biometric Processing Privacy Code sequence works well.
- Build the inventory. List every system that touches biometric information, including door access, payroll clocks and contact centre voice tools.
- Confirm scope for each one. Decide whether the Code applies, and write down why.
- Write the proportionality assessment. Do this for each in-scope system, not once for the organisation.
- Fix notification. Update signage, privacy statements and onboarding material.
- Set retention and deletion rules. Then actually delete the historical templates you no longer need.
- Review your vendor contracts. Check where templates are stored and who can access them.
Above all, document as you go. The Code rewards organisations that can evidence their reasoning.
The wider direction of travel
The Biometric Processing Privacy Code fits a clear pattern. New Zealand is moving away from a light-touch posture. The New Zealand Cyber Security Strategy 2026 to 2030 points the same way, and a new indirect collection obligation under IPP 3A took effect on 1 May 2026.
So this is not an isolated compliance task. Rather, it is one piece of a tightening privacy regime. Organisations that build a repeatable assessment habit now will find the next change easier.
Getting help
Reading the Code is straightforward. Applying it to a live estate of door readers, payroll clocks and retail cameras is harder. Our team helps New Zealand organisations scope biometric systems, write defensible proportionality assessments and close the gaps that assessments reveal.
You can read the Code itself on the Office of the Privacy Commissioner website, and the underlying legislation sits in the Privacy Act 2020.
If you would like a second opinion on your own position, our cyber security services in New Zealand cover privacy and compliance work across the country, including teams in Wellington and Auckland. You can also explore our security and compliance advisory services, or simply get in touch.


