Client Confidentiality Policy Template for New Zealand

Generate a bespoke document

What is a Client Confidentiality Policy?

This Client Confidentiality Policy is designed for organizations operating in New Zealand that need to establish clear guidelines for protecting client information. The document becomes necessary when organizations handle sensitive client data and need to ensure compliance with the Privacy Act 2020 and other relevant New Zealand legislation. It serves as a comprehensive guide for staff members, outlining their obligations in maintaining client confidentiality, proper information handling procedures, and consequences of breaches. The policy is particularly important in the current digital age where data breaches and privacy concerns are increasingly significant, and organizations need to demonstrate their commitment to protecting client information through formal, documented procedures.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

New Zealand

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Client Confidentiality Policy

A Client Confidentiality Policy is a critical legal document that establishes your organization's framework for protecting client information in accordance with New Zealand law. This policy serves as both a compliance tool and a practical guide, ensuring that all staff members understand their legal obligations when handling sensitive client data under the Privacy Act 2020 and related legislation.

When do you need this document?

You need a Client Confidentiality Policy when your organization collects, stores, or processes any client information, particularly personal data covered by the Privacy Act 2020. This includes businesses in healthcare, legal services, financial planning, consulting, real estate, and any service industry where client trust is paramount. The policy becomes essential when onboarding new employees, contractors, or volunteers who will have access to client information. You'll also need this document to demonstrate compliance during privacy audits, when responding to client inquiries about data handling, or if you're preparing for business partnerships that involve data sharing arrangements.

Key legal considerations

Your policy must align with the 13 privacy principles outlined in the Privacy Act 2020, covering collection, use, disclosure, storage, and access to personal information. Key clauses should address purpose limitation, ensuring information is only used for specified purposes, and data minimization, collecting only what's necessary for your services. The policy must establish clear procedures for handling access requests, correction requests, and privacy complaints. Consider including breach notification procedures, as serious privacy breaches must be reported to the Privacy Commissioner. Address retention periods, secure disposal methods, and cross-border data transfer restrictions. The Fair Trading Act 1986 also requires that any representations about confidentiality practices are accurate and not misleading to clients.

Legal requirements in New Zealand

Under the Privacy Act 2020, your organization must have reasonable security safeguards to protect personal information from unauthorized access, use, disclosure, or modification. The policy must address the rights of individuals to access and correct their personal information, typically within 20 working days of a request. If you employ staff, the Employment Relations Act 2000 requires that confidentiality obligations be clearly communicated and form part of good faith employment relationships. For organizations with annual turnover over $3 million, or those handling health information, additional compliance requirements apply. The Contract and Commercial Law Act 2017 governs how confidentiality agreements with third parties should be structured, particularly for electronic communications and data processing arrangements. Your policy should also reference the Protected Disclosures Act 2022, which protects whistleblowers who report privacy breaches in good faith.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.