This file is Bob's plain-language reference for the New Zealand statutes that shape how we ask questions, capture answers, and handle personal and health information. It covers the Contracts of Insurance Act 2024 (CoIA), the Privacy Act 2020 and its Information Privacy Principles (including the cross-border principle IPP 12), the Health Information Privacy Code 2020, and the AML/CFT Act 2009, plus the Privacy Impact Assessment practice. It is written for engineering and advice context, not as legal advice; where a claim could not be tied to an exact section it is flagged [VERIFY].
Contracts of Insurance Act 2024: the new consumer duty (reasonable care)
For consumer insurance contracts (cover bought mainly for personal, domestic, or household purposes, which includes most retail income protection), CoIA 2024 replaces the old common-law and statutory "duty of disclosure" with a narrower consumer duty: the policyholder must take reasonable care not to make a misrepresentation to the insurer before entering into or varying the contract. The practical shift is large. Under the old law the consumer had to volunteer anything a prudent insurer would consider material, even if never asked. Under CoIA the consumer is no longer obliged to volunteer information; their job is to answer the insurer's questions honestly and carefully. The standard is what a reasonable policyholder in the circumstances would do, judged objectively; a dishonest answer is treated as evidence of a failure to take reasonable care. This is why Bob's job at capture is to ask good questions, not to expect the applicant to guess what matters.
Source: New Zealand Legislation, Contracts of Insurance Act 2024 (https://www.legislation.govt.nz/act/public/2024/46/en/latest/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
CoIA 2024: how the new duty differs from the old duty of disclosure
The old regime (rooted in the Marine Insurance Act 1908 duty of utmost good faith and the Insurance Law Reform Act 1977) put the burden on the consumer to disclose all material facts a prudent insurer would want, whether or not asked. A single innocent omission could let an insurer avoid the whole policy and decline a claim. CoIA flips the model toward the insurer's questions: the consumer answers what is asked, and the consumer-facing test becomes whether they took reasonable care not to misrepresent. For Bob this means the legal risk surface moves onto question design and capture quality. If we ask vague questions and an applicant answers reasonably, a later "gotcha" decline is much harder for an insurer to sustain. Logging the exact question wording, in context, protects both the client and the adviser-in-the-loop.
Source: Minter Ellison NZ, "Contracts of Insurance Act 2024: Dissecting the new duty" (https://www.minterellison.co.nz/insights/contracts-of-insurance-act-2024-dissecting-the-new-duty) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
CoIA 2024: proportionate remedies for misrepresentation
When a consumer does breach the duty (a "qualifying misrepresentation"), CoIA replaces the old all-or-nothing avoidance with proportionate remedies that depend on the consumer's state of mind and on what the insurer would have done with accurate information. A misrepresentation that was deliberate or reckless lets the insurer avoid the contract entirely, decline all claims, and (generally) keep the premium. A misrepresentation that was merely careless triggers a "what would the insurer have done" test: if the insurer would not have offered cover at all, it may avoid but must refund premium; if it would have written the policy on different terms, the contract is treated as if those terms applied; if it would only have charged a higher premium, the insurer proportionately reduces the claim payment by the ratio of premium actually charged to the premium it would have charged. Bob should never imply a claim outcome to a client, but the system must capture enough provenance (what was asked, what was answered, when) for an insurer and the adviser to apply these remedies fairly. The precise statutory wording should be confirmed against the Act before any production logic relies on it. [VERIFIED-AI 2026-06-21: CoIA's proportionate remedies for a qualifying misrepresentation are set out in Schedule 2 of the Contracts of Insurance Act 2024 (No 46) (not a numbered "remedy table"). The Act commences by Order in Council (backstop 15 Nov 2027), so it may not yet be fully in force. Source: legislation.govt.nz, Contracts of Insurance Act 2024 No 46.] [VERIFY] the exact Schedule 2 wording and the Act's in-force status at time of use.
Source: Hesketh Henry, "Contracts of Insurance Act: what's in store for you?" (https://www.heskethhenry.co.nz/insights-opinion/contracts-of-insurance-act-whats-in-store-for-you/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
CoIA 2024: the insurer's duty to ask clear, specific questions (exact-question capture)
CoIA pairs the consumer's reasonable-care duty with pressure on insurers to ask clear, specific questions, because a consumer can only be held to answers they were actually and clearly asked for. NZ case law already runs this way: courts decide objectively what a question meant (what a reasonable applicant would understand it to ask), reward insurers who ask targeted, unambiguous questions, and find no misrepresentation where the question was unclear or the online form differed from the standard wording. This is the legal basis for Bob's "exact-question" capture: we store the verbatim question text that was put to the applicant, tied to the code version that generated it (question id @ version), so that months or years later we can prove exactly what was asked, in what words, and in what order. If a dispute turns on what the applicant "should have disclosed," the answer is bounded by the question we can show we asked. Whether CoIA imposes an explicit standalone statutory "duty to ask clear questions" (versus this being the practical effect of the reasonable-care test plus case law) should be confirmed against the Act text. [VERIFIED-AI 2026-06-21: CoIA 2024 frames this as a factor, not a standalone "duty to ask clear questions". Section 13 sets the policyholder's duty to take reasonable care not to make a misrepresentation; section 14 lists matters relevant to whether that duty was met, including s14(1)(c) "how clear, and how specific, any questions the insurer asked the policyholder were". So the clarity of the insurer's questions is a statutory factor in judging the consumer's care (mirroring the UK CIDRA model), which is exactly the basis for Bob's verbatim-question capture. Source: legislation.govt.nz Contracts of Insurance Act 2024, ss 13-14.]
Source: Minter Ellison NZ, "Dissecting the new duty" (case law on objective meaning and clear questions) (https://www.minterellison.co.nz/insights/contracts-of-insurance-act-2024-dissecting-the-new-duty) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
CoIA 2024: commencement and transition timing
CoIA 2024 received Royal assent and passed into law on 15 November 2024, but it does not all switch on at once. Provisions commence on dates set by Order in Council, and anything not brought into force earlier must commence by 15 November 2027 (three years after enactment). MBIE is developing supporting regulations, and the FMA has signalled it will monitor and enforce CoIA using Financial Markets Conduct Act tools once commenced. For Bob this means: design to the new duty now (insurers are already aligning to it), but treat the in-force date for any given provision as "by 15 November 2027 at the latest, earlier if set by Order in Council," and re-check the commencement schedule before relying on a specific provision being live.
Source: MBIE, "Contracts of Insurance Act 2024: commencement and regulations" (https://www.mbie.govt.nz/dmsdocument/31357-contracts-of-insurance-act-2024-commencement-and-regulations-proactiverelease-pdf) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Privacy Act 2020: the Information Privacy Principles relevant to Bob
The Privacy Act 2020 governs personal information through 13 Information Privacy Principles (IPPs). The ones Bob touches most are the collection set (IPP 1: collect only for a lawful purpose connected to your function; IPP 2: collect from the individual directly where reasonable; IPP 3: tell the person you are collecting, why, who will get it, and their access/correction rights; IPP 4: collect by lawful, fair, non-intrusive means), IPP 6 (individuals can request access to their own personal information), IPP 11 (limits on disclosing personal information to others), and IPP 12 (limits on sending personal information outside NZ). IPP 5 (security/storage), IPP 8 (accuracy before use), IPP 9 (don't keep longer than needed), IPP 10 (use only for the purpose collected), and IPP 13 (unique identifiers) also apply. Note IPP 3A, an indirect-collection notification rule inserted by the Privacy Amendment Act 2025, came into force on 1 May 2026 and now applies to Bob whenever it collects personal information about an individual from a source other than that individual. Because Bob collects sensitive answers conversationally, IPP 1, 3, and 4 shape how the agent must open a capture flow (clear purpose, clear notice, fair means).
Source: Office of the Privacy Commissioner, Information Privacy Principles (https://www.privacy.org.nz/privacy-act-2020/privacy-principles/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
Privacy Act 2020: IPP 12 (cross-border disclosure) and data residency
IPP 12 is new in the 2020 Act and is the principle that gates Bob's data residency and model routing. It applies when an agency discloses personal information to a person or entity outside New Zealand (sending it offshore for processing counts). Before doing so, the agency must satisfy at least one safeguard, broadly: the overseas recipient is subject to privacy law that provides comparable protection to NZ's; or the recipient agrees by contract (e.g. model clauses) to comparable safeguards; or the recipient is subject to a binding scheme or is in a country prescribed as having comparable protection; or the recipient carries on business in NZ and is reasonably believed to be subject to the NZ Act; or the individual is expressly told the information may not be comparably protected offshore and authorises the disclosure anyway. Note that using a cloud or AI provider purely as an agent/processor that does not use the data for its own purposes may be treated differently from a true "disclosure," but the safe design is to assume IPP 12 applies whenever data leaves NZ. This is why model routing must prefer NZ/AU-resident or comparably-safeguarded endpoints, and why offshore routing has to be justified against one of these gateways before it is allowed.
Source: Office of the Privacy Commissioner, IPP 12: Disclosure outside New Zealand (https://www.privacy.org.nz/privacy-act-2020/privacy-principles/12/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
Privacy Act 2020: the notifiable privacy breach scheme
The 2020 Act introduced a mandatory breach-notification regime. If an agency has a privacy breach (unauthorised access, disclosure, loss, or inability to access personal information) that has caused, or is likely to cause, serious harm, it must notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable. Guidance treats notification as expected promptly (the OPC points to acting within about 72 hours of becoming aware that a breach is notifiable, even while investigation continues), and affected people should be told as soon as the agency can. "Serious harm" is assessed on factors including the sensitivity of the information, who got it and whether the agency still controls it, the kinds of harm possible (physical, psychological, financial, reputational, cultural), and the likelihood and severity of harm. Because Bob holds sensitive health and financial answers, its breach-response runbook must default toward notification, and its logging must make breach scope quickly assessable. The exact statutory timing wording (Part 6 of the Act) should be confirmed against the legislation before encoding hard deadlines. [VERIFIED-AI 2026-06-21: confirmed against the statute. Privacy Act 2020 s114 requires an agency to notify the Commissioner "as soon as practicable after becoming aware that a notifiable privacy breach has occurred", and s115 uses the same "as soon as practicable" trigger for affected individuals. The phrase "72 hours" does NOT appear in the Act; the 72-hour figure is OPC guidance, not a statutory deadline, so it must not be encoded as a hard legal cutoff. Source: legislation.govt.nz Privacy Act 2020, ss 114-115 (Part 6).]
Source: Office of the Privacy Commissioner, Notify us of a privacy breach (https://www.privacy.org.nz/responsibilities/privacy-breaches/notify-us/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Health information: the Health Information Privacy Code 2020 and fail-closed routing
Health information about an identifiable person is regulated by the Health Information Privacy Code 2020 (HIPC), a code of practice issued under the Privacy Act that modifies and replaces the standard IPPs with health-specific rules for "health agencies." Health agencies include direct providers (doctors, nurses, pharmacists, etc.), and sector bodies such as ACC, the Ministry of Health, and, relevantly for Bob, health insurers. The HIPC adapts the principles to clinical and insurance-health contexts (collection, use, disclosure, access to records, and storage/retention of sensitive data). The core reason this matters to Bob is sensitivity: medical conditions, diagnoses, treatment, and mental-health information are among the most damaging categories if exposed, and they are exactly what income-protection underwriting asks about. That sensitivity is why Bob's routing should fail closed for health data: if a request involves health information and the system cannot positively confirm a compliant, comparably-safeguarded (ideally NZ/AU-resident) processing path, it must refuse or downgrade rather than risk an offshore or unverified route. Whether Bob is itself a "health agency" under the HIPC, or handles health information on behalf of one, should be confirmed before relying on specific HIPC rules. [VERIFIED-AI 2026-06-21: HIPC 2020 scope confirmed. A "health agency" is an agency referred to in clause 4(2); clause 4(2)(h) (heading "Health insurance, etc") expressly binds "an agency which provides health, disability, accident or medical insurance, or which provides claims management services in relation to such insurance, but only in respect of providing that insurance or those services". So an entity collecting health information to provide (or manage claims for) such insurance is a health agency bound by the HIPC for that activity. Source: privacy.org.nz, HIPC 2020 cl 4(2)(h) and Definitions.] [VERIFY] the precise application to Bob's own advice/distribution model (bound directly, or as handling health information on behalf of the insurer/FAP), which is a legal classification.
Source: Office of the Privacy Commissioner, Health Information Privacy Code 2020 (https://www.privacy.org.nz/privacy-act-2020/codes-of-practice/hipc2020/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
AML/CFT Act 2009: customer due diligence in a financial-advice/insurance context
The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 places obligations on "reporting entities," which includes financial advisers and certain life insurers operating in NZ. The cornerstone obligation is customer due diligence (CDD): under section 11 a reporting entity must conduct CDD on its customer, on any beneficial owner of the customer, and on anyone acting on the customer's behalf. CDD comes in tiers, broadly standard (verify identity), simplified (lower-risk customers/entities), and enhanced (higher-risk situations, requiring source-of-wealth/funds checks). Around CDD, reporting entities must complete a written risk assessment, maintain an AML/CFT compliance programme, file suspicious activity reports, keep records, and report to a supervisor. There are three supervisors: the FMA (for advisers, fund managers, and similar), the Reserve Bank (banks, life insurers, NBDTs), and the DIA (other sectors). For Bob, the live question is which obligations attach to its specific advice/distribution model and which to the insurer; identity/CDD capture and any AML flags should be designed so the responsible reporting entity can meet section 11 without re-asking the client. The exact triggers for occasional transactions and the CDD thresholds should be confirmed against the Act and supervisor guidance before encoding rules. [VERIFIED-AI 2026-06-21: s11 CDD scope confirmed (customer, beneficial owner, person acting on behalf; s11(2) deems an individual acting only for themselves to be their own beneficial owner). "Occasional transaction" is defined in s5 of the Act, but the monetary threshold sits in the AML/CFT (Definitions) Regulations 2011, not the Act: the prescribed occasional-transaction (cash, outside a business relationship) threshold is NZ$9,999.99, the wire-transfer threshold (s27) is NZ$1,000, and the beneficial-owner threshold is "more than 25%". Sources: legislation.govt.nz AML/CFT Act 2009 ss 5, 11, 27 + AML/CFT (Definitions) Regulations 2011.] [VERIFY] the exact NZ$9,999.99 occasional-transaction threshold against the current Definitions Regulations 2011 before encoding it as load-bearing.
Source: New Zealand Legislation, AML/CFT Act 2009, s11 customer due diligence (https://www.legislation.govt.nz/act/public/2009/0035/latest/whole.html) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Privacy Impact Assessment (PIA): what it is and when expected
A Privacy Impact Assessment is a structured way to identify and reduce the privacy risks of a project that collects, uses, or shares personal information, using the IPPs as the framework. The Office of the Privacy Commissioner recommends a PIA for any project that involves personal information or that could intrude on privacy, and offers a short "privacy analysis" template to decide whether a full PIA is warranted. A PIA is not a blanket statutory requirement for private firms, but it is strongly expected as good practice for higher-risk initiatives, and for Bob the risk profile (sensitive health and financial data, an AI capture agent, offshore model-routing questions, append-only audit) clearly puts it in PIA territory. A PIA checks the project against privacy law, maps where personal information flows, identifies risks such as over-collection or breach exposure, and records mitigations. It should be done early (before build/launch) and revisited when the data flows, processors, or model-routing change.
Source: Office of the Privacy Commissioner, Privacy Impact Assessments (https://www.privacy.org.nz/responsibilities/privacy-impact-assessments/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft