AI Privacy Impact Assessment NZ

AI Privacy Impact Assessment NZ: What to Check Before Staff Use AI Tools

What to check before AI touches private business data

An AI Privacy Impact Assessment helps a New Zealand business decide what personal information an AI tool may access, why it is needed, where it goes, who reviews the output, and what must stay out of the workflow.

Run an AI Privacy Impact Assessment before staff paste customer data into ChatGPT, connect AI to CRM or inbox records, upload files to an AI tool, or let an agent prepare customer-facing work. The goal is not to create legal certainty; it is to make privacy risk visible before an AI workflow becomes normal.

If you are assessing a live workflow, use the $1,000 AI Agent Assessment to map data sources, permissions, privacy risks, approval gates, and whether to build now, prepare first, delay, or avoid the workflow.

What is an AI Privacy Impact Assessment?

An AI Privacy Impact Assessment is a practical review of how an AI tool or agent could collect, receive, use, store, expose, or generate personal data.

Plain-English definition for NZ businesses

For an owner or operator, the assessment answers six questions: what information is involved, why AI needs it, which tool receives it, where output goes, who checks it, and what AI must never do alone.

Privacy Impact Assessment vs AI policy vs AI risk register

An AI policy for small business NZ sets general staff rules. An AI risk register for NZ businesses using AI agents tracks workflow risks and owners. An AI Privacy Impact Assessment goes deeper on personal information, data minimisation, access, storage, sharing, and review.

For official privacy guidance, use the Office of the Privacy Commissioner as the primary source. Its Privacy Impact Assessment Toolkit is the place to start for formal review.

When should a business run one?

Run the assessment before the AI workflow becomes operational.

Before staff paste customer data into AI tools

Customer names, contact details, emails, chat transcripts, health details, financial information, complaints, contracts, or identity information should not be copied into an AI tool just because it is convenient. First decide whether the data is needed, can be removed or masked, and uses an approved tool.

Before connecting AI to CRM, inboxes, files, finance, or support systems

A connected agent can access more than a person intends. Before connecting systems, define the records it may read, folders it must avoid, fields it may prepare, and actions it cannot take. Pair this with the AI Agent Permissions Checklist.

Before AI drafts customer-facing replies or public copy

Even when AI only drafts text, privacy risk can appear in the output. A customer reply, proposal, support answer, website update, or report summary may reveal private details, quote the wrong source, or include confidential context. Put a human approval point before anything leaves the business.

What an AI Privacy Impact Assessment should check

Keep the first assessment focused on the workflow, not the whole business. A narrow review is more useful than a broad document no one maintains.

What personal information is involved

Name the data categories: customer contact details, enquiry notes, staff records, supplier contacts, payment context, health or legal information, account history, support tickets, emails, attachments, or private documents.

Why the AI needs that information

Ask whether each data type is necessary. If the agent is drafting a stock exception summary, it may not need customer names. If it is preparing a sales follow-up draft, it may need the enquiry topic but not unrelated private notes.

Which tool receives or stores it

List whether the information goes into a public chatbot, business AI account, Microsoft or Google workspace tool, custom workflow, CRM plugin, document tool, or internal agent. Record whether prompts, files, or outputs are retained.

Who can access the output

Decide who can see AI-prepared summaries, drafts, notes, and logs. A useful internal summary can still create risk if it is copied into the wrong channel.

What the agent may read, draft, update, send, or never touch

Separate preparation from authority. The safest early pattern is read approved sources, prepare drafts or exception notes, and require human approval before updates, messages, exports, system changes, or publication.

How exceptions and approvals are logged

Record uncertainty, escalations, approvals, rejected outputs, and accidental exposure. Logging makes early pilots easier to review.

Practical red, amber, green data rules

A simple colour system helps staff make better decisions before using AI.

Green: public or approved business information

Green data is public or approved for the workflow: website pages, product information, approved service descriptions, published policies, non-sensitive templates, and generic process notes.

Amber: customer or operational data needing controls

Amber data may be useful but needs approval, minimisation, masking, or a controlled environment. Examples include CRM notes, support tickets, sales call summaries, operational reports, internal spreadsheets, supplier notes, and customer history.

Red: passwords, secrets, sensitive records, legal, health, or finance data without explicit controls

Red data should stay out of casual AI use. Passwords, API keys, bank details, employment matters, sensitive customer records, legal correspondence, health information, private financials, and confidential contracts need explicit controls before any AI use is considered.

The AI Data Readiness Checklist can help turn these rules into source, permission, and approval checks.

Bounded access

Example: assessing a customer-service AI workflow

A customer-service AI workflow is a good test case because it can help staff prepare replies while creating obvious privacy and trust risks.

What data is needed

The agent may need the customer question, approved help material, order status category, product information, and prior interaction summary. It may not need full account history, payment details, identity documents, or unrelated notes.

What should be minimised

Remove or mask information that does not change the draft answer. Use customer IDs instead of full personal details where possible. Keep source documents narrow and current.

Where human approval belongs

A person should review the answer before sending, especially when it involves refunds, complaints, delivery promises, pricing, legal wording, privacy wording, or a frustrated customer. For the operating pattern, compare AI Approval Gates for Business Automation.

How the AI Agent Assessment turns privacy risk into a build decision

Privacy review should produce a decision, not just a warning.

Build now

Build now when the workflow is narrow, data is approved, personal information is minimised, access is controlled, and a named person reviews outputs before action.

Prepare first

Prepare first when staff need clearer AI rules, data needs cleanup, sensitive fields need masking, tool access is unclear, or approval ownership is missing.

Wait or do not automate

Wait when the workflow is changing or outputs cannot be reviewed consistently. Do not automate when the tool would expose sensitive information, make trust-sensitive decisions, or act without accountable human approval.

Frequently asked questions

What is an AI Privacy Impact Assessment?

An AI Privacy Impact Assessment reviews how an AI tool or agent may access, use, store, expose, or generate personal information. It helps a business decide whether the workflow is safe enough to test and what controls are needed first.

Does every NZ business need an AI Privacy Impact Assessment?

Not for every low-risk AI use. A business should run one when AI touches customer data, staff information, CRM records, inboxes, files, finance context, support tickets, sensitive workflows, or customer-facing outputs.

What data should not be entered into AI tools?

Do not enter passwords, API keys, bank details, sensitive customer or staff records, legal correspondence, health information, confidential contracts, private financials, or unpublished strategy unless the business has explicit controls and approval.

Is an AI Privacy Impact Assessment legal advice?

No. This article is operational guidance, not legal advice or a compliance guarantee. Use official Office of the Privacy Commissioner resources and qualified privacy or legal advice when obligations need formal interpretation.

How does an AI Privacy Impact Assessment relate to an AI Agent Assessment?

The privacy assessment checks data risk. The AI Agent Assessment turns that risk into an implementation decision: build now, prepare first, wait, or do not automate, with permissions and approval gates mapped before implementation.

Next step

Pick one workflow, identify personal information, minimise what AI can see, block risky permissions, and define who reviews the output.

Book the $1,000 AI Agent Assessment to decide which AI workflows are safe to test, which need privacy and data preparation first, and where human approval gates belong.