Educator reviewing school privacy settings and student-data decisions on a laptop

Quick answer

The Privacy Act 2020 applies to New Zealand schools when they collect, store, use, share, or correct personal information about students, whānau, and staff [1]. For everyday school decisions, the practical rule is simple: collect only what you need, explain why you need it, keep it secure, and make sure people know how to access or correct it.

This matters most when a school adopts a new app, AI tool, learning platform, attendance system, wellbeing survey, or communication channel. If a tool handles student information, treat it as a privacy decision before treating it as a classroom convenience.

What does the Privacy Act require schools to do?

The Privacy Act 2020 sets information privacy principles for New Zealand agencies, including schools [1]. Those principles cover the whole life cycle of personal information: collection, storage, access, correction, accuracy, use, disclosure, retention, and unique identifiers.

For educators, that usually comes down to six working habits:

  • collect student information for a clear school purpose, not because a form or app makes it easy
  • tell students, parents, or caregivers why the information is being collected when the context is not obvious
  • keep information secure and limit access to people who need it for their role
  • use information for the purpose it was collected for, unless another lawful basis applies
  • avoid sharing information with third parties until the school understands the privacy notice, contract, and data flow
  • give people a practical way to ask for access or correction when records are wrong [1][2]

The Office of the Privacy Commissioner describes these as practical obligations, not paperwork for its own sake. Schools need enough process to make good decisions before student data moves into a new system [2].

When should a classroom tool trigger a privacy check?

A privacy check is needed whenever a tool collects or processes information that can identify a student, staff member, parent, caregiver, or household. That includes names, school email addresses, learning records, assessment notes, behavioural notes, attendance data, photos, voice recordings, IP addresses, device identifiers, and sensitive wellbeing information [1][3].

The risk is higher when the tool is free, overseas-hosted, AI-enabled, or unclear about whether uploaded work can be reused for analytics or model training. The issue is not that schools should avoid every digital service. The issue is that someone should understand the trade-off before student information is uploaded.

Schools can use a Privacy Impact Assessment to work through those questions before adopting a tool or changing how an existing tool is used [3]. For a small classroom tool, that assessment may be short. For a whole-school platform, student wellbeing product, AI system, or tool handling sensitive information, it should be more formal.

What should a school check before collecting or sharing student information?

Use this as a working checklist before a new platform, form, survey, AI tool, or supplier goes live.

Can we explain the school purpose for collecting this information?
Have we told students, parents, or caregivers what is being collected and why?
Do we know who can access the information inside the school and inside the supplier?
Do we know where the information is stored and whether it can be used for another purpose?
Can students or whānau ask to see or correct the information later?
Teacher reviewing privacy settings on a school platform for NZ Privacy Act 2020 school checks

If the answer to any of these is unknown, pause the rollout. The right next step is usually to ask the supplier, check the privacy notice, involve school leadership, or complete a Privacy Impact Assessment [3].

How do access and correction rights work in a school setting?

Students and whānau can ask what personal information a school holds about them, and they can ask for correction if the information is wrong [1][4]. That might include contact details, learning support notes, incident records, attendance information, enrolment data, or information held in a platform the school uses.

Schools should make this process clear enough that a student or caregiver does not need to know legal language before asking. A useful internal rule is: if the request is about information that identifies the person, treat it as a privacy request and get the school's privacy lead or senior leadership involved.

Not every request will be straightforward. Some records include information about more than one person, and some situations involve safety or welfare concerns. That is exactly why the school needs a clear process rather than an ad hoc reply from the first staff member who receives the email [4].

What should staff do if student information is mishandled?

If student information has been sent to the wrong person, exposed in a public link, uploaded into the wrong tool, accessed by someone who should not have seen it, or lost through a compromised account, treat it as a possible privacy breach.

A practical first response is:

  1. record what happened, when it happened, and what information may be involved
  2. contain the issue, such as revoking a public link or removing the file from the wrong location
  3. tell the school's privacy lead, principal, or senior leadership team
  4. assess whether the people affected need to be told
  5. check whether the Privacy Commissioner needs to be notified [2]

Staff should avoid quietly fixing the visible problem and moving on. The school may need to preserve evidence, contact a supplier, update procedures, or support the student or whānau affected. If a digital account was involved, use the broader advice in Cyber Security for New Zealand Educators as part of the response.

How does this connect to AI and classroom technology?

AI tools raise familiar privacy questions in a sharper form. A prompt can include student work, names, behavioural details, learning needs, or family context. Once that information is submitted, the school needs to know whether it is stored, reviewed by humans, used to train models, or shared with other services.

Before staff use AI with student information, schools should set a simple rule: do not paste identifiable student information into an AI tool unless the school has approved that specific use. The same rule belongs in staff guidance, student guidance, and supplier review. The guide on using AI tools safely for school and teaching gives a wider classroom safety pathway.

The Privacy Act does not ban useful technology. It asks schools to know what information they are collecting, why they are collecting it, and what happens next [1]. That is a reasonable standard for any tool that handles young people's information.

Knowledge check

Q1A teacher wants to use a free quiz app that asks students to sign in with full names and school email addresses. What should happen first?tap to flip
Answer: The school should check what information the app collects, why it needs it, who can access it, and whether the privacy notice fits the school's purpose. If those answers are unclear, pause before using it [1][3].
Q2A parent says a school record about their child is wrong. Is that just an admin request?tap to flip
Answer: Treat it as a privacy request. People can ask to access and correct personal information held about them or their child, and the school should have a process for handling that request [1][4].
Q3A spreadsheet with student wellbeing notes was shared with the wrong group. What is the first response?tap to flip
Answer: Contain it first, then escalate internally. Revoke access, record what happened, tell the school's privacy lead or senior leadership, and assess whether affected people or the Privacy Commissioner need to be notified [2].

Sources and references

[1] New Zealand. Parliament. (2020). Privacy Act 2020. https://www.legislation.govt.nz/act/public/2020/0031/latest/whole.html

[2] New Zealand. Office of the Privacy Commissioner. (2025). Privacy tools for agencies. https://www.privacy.org.nz/responsibilities/privacy-tools-for-agencies/

[3] New Zealand. Office of the Privacy Commissioner. (2025). Privacy Impact Assessments. https://www.privacy.org.nz/responsibilities/privacy-impact-assessments/

[4] New Zealand. Office of the Privacy Commissioner. (2025). Children's privacy guidance for the education sector. https://www.privacy.org.nz/resources-and-learning/a-z-topics/protecting-children-and-young-peoples-privacy/childrens-privacy-guidance-for-the-education-sector/

Key takeaways

  • The Privacy Act 2020 applies when NZ schools collect, store, use, share, or correct student information.
  • A new classroom tool should not go live until the school understands its data collection, access, storage, retention, and reuse rules.
  • Student and whānau access or correction requests need a clear privacy process, not an improvised staff reply.
  • A possible student-data breach should be contained, recorded, escalated, and assessed for notification.
  • Bottom line: if a tool or process handles student information, run the privacy check before rollout and use Privacy in Education — What Teachers and Students Should Check as the practical companion checklist.

Start with the parent privacy surface at NZAI Security privacy policy for how this site handles personal information.

Use Privacy in Education — What Teachers and Students Should Check as the hands-on classroom checklist for this guide.

For classroom AI decisions, read Using AI Tools Safely for School and Teaching.

For account compromise and breach response, pair this with Cyber Security for New Zealand Educators.

For the wider public-data picture, read NZ Schools Cybersecurity 2026 Report.