New Zealand rarely writes technology-specific privacy rules. For biometrics, it just did. The Biometric Processing Privacy Code came into force on 3 November 2025 with a nine-month transition for organisations already running biometric systems. That transition ends on 3 August 2026. If your organisation uses facial recognition, voice identification, fingerprint access, or any system that identifies people by their biology or behaviour, the grace period is nearly over.
What You Need to Know
- The Code is law under the Privacy Act, issued by the Privacy Commissioner. It applies to businesses, government agencies, and NGOs alike.
- From 3 August 2026 it covers existing systems, not just new ones. Anything deployed before November 2025 must comply from this date.
- The core test is proportionality. You must assess whether biometrics are effective and proportionate for your purpose, adopt safeguards, and be able to show your working.
- Notice is mandatory. People must be told a biometric system is in use before or at the point their data is collected. Quiet deployment is over.
What Counts as Biometric Processing
The Code covers using biometric information (face, voice, fingerprints, iris, gait, keystroke patterns) to identify or classify people. That's wider than security teams sometimes assume. Retail facial recognition is the headline case, but the Code also reaches:
- Voice identification in contact centres ("verifying you by your voice")
- Access control using fingerprints or face unlock on shared systems
- Workforce systems using biometric time-and-attendance
- AI products that classify people from images or audio, including inferring emotion, age, or demographic traits, where the Code draws some of its hardest lines
If you're building or deploying AI that touches human faces, voices, or bodies, assume you're in scope until a specific analysis says otherwise.
The Proportionality Test Is the Heart of It
The Code's first requirement is the one that changes behaviour: before using biometrics, an agency must assess that the processing is effective for its purpose, that the purpose justifies the privacy intrusion, and that less intrusive alternatives wouldn't do. Then it must implement safeguards proportionate to the risk.
This is the same discipline good AI governance already demands, applied with legal force. You cannot outsource it to a vendor's compliance page. The obligation sits with the deploying agency: your organisation, assessing your use, in your context, with a record you can produce when asked. If your data governance can't trace what biometric information you hold, where it flows, and who can access it, start there. As we've argued before, governance that can't trace its data is theatre.
The Practical Checklist for 3 August
- Inventory. List every system that processes biometric information, including AI features inside products you buy. Vendors' AI roadmaps have been adding these quietly; your inventory from 2024 is stale.
- Assess. Run the effectiveness-and-proportionality analysis for each use. Document it. "We assessed this and here's why it stands" is the artefact the Commissioner expects.
- Notify. Check every collection point tells people biometrics are in use, before or during collection. Signage, scripts, and UI copy are compliance surfaces now.
- Safeguard. Access controls, retention limits, and deletion paths for biometric data, matched to the sensitivity of what you hold.
- Decommission honestly. If a use fails the proportionality test, the compliant move is to switch it off. Some organisations will find that's the right answer, and finding it before August beats finding it in an investigation.
Why This Matters Beyond Biometrics
The Biometrics Code is New Zealand's first hard signal of how it will regulate high-risk technology: not with an omnibus AI act, but with targeted, enforceable codes where the risk is sharpest, sitting on top of principles-based law. Organisations that build the muscle now (inventory, proportionality assessment, notice, safeguards) are building exactly the capability the next code will assume. Trust, as always, is the compounding asset.