← Back to blog
4 August 2026Project 24/7

AI tools, their tiers, and the NZ Privacy Act

The plan someone is on decides whether your client data ends up training a model. Here is where each of the main platforms draws that line, and what you can safely put into them.

Someone on your team is on the free plan. A client sends an awkward email, they paste the thread into a chatbot to help with the reply, and they think nothing of it. Nobody told them otherwise, because nobody had worked out the rules yet.

That is what most privacy trouble with AI looks like in a small New Zealand business. There is no attacker anywhere in the story.

The same product from the same company can be fine on one plan and a problem on another, and you cannot see which from inside the chat window. So it helps to know where each platform draws the line, and what you can safely put in on either side of it.

This is a practical guide rather than legal advice. Plan names and data policies shift constantly, so check the provider's current terms before you lean on any of it.

Processing for you, or using it for themselves

Under the Privacy Act 2020 there is a big difference between a supplier processing information on your behalf and a supplier using your information for its own purposes.

Section 11 of the Act says that when someone holds personal information as your agent, whether that's a cloud host, a processor, or a SaaS platform doing a job you asked for, the law treats that information as still held by you. Handing it over isn't a "disclosure" at all. IPP 12, the rule about sending personal information overseas, never gets triggered.

The moment a provider uses that information for its own purposes, most obviously by training its models on it, the agent argument falls over. You have now disclosed personal information to an overseas company, and you need a lawful basis under IPP 12 to have done it. That distinction is what separates the free tier from the business tier on nearly every platform.

"Personal information" in New Zealand is broader than most people assume, covering any information about an identifiable person. A first name plus a job title plus a company qualifies. So does a phone number, a photo, a booking history, or a complaint about a staff member. You don't need a full ID document for the Act to apply.

Where each platform draws the line

ChatGPT OpenAI
  • Free / Go / Plus / Pro Consumer terms. Roughly US$0, $8, $20, then $100 and $200 for the two Pro levels. Your content can be used to train OpenAI's models unless you find and switch off the setting in data controls. Free and Go now carry ads in some markets, which is a second data pathway to think about.
  • Business Around US$20 to $30 per seat. Business data is not used for training by default. Admin console, shared workspace, and the beginnings of a paper trail you can point to.
  • Enterprise / API Custom pricing. No training by default, plus at-rest data residency in selected regions and zero data retention on eligible API projects. Australia is on the residency list. New Zealand is not.

Fine on a free or Plus plan

  • Rewriting your own website copy, a job ad, or a blog draft that mentions no real people
  • Asking how to build a spreadsheet formula, using made-up numbers
  • Summarising a public document, like a council consultation PDF
  • Drafting an internal policy, checklist or template from scratch
  • Working through a client scenario with the names stripped out, so "Client A, a Hamilton engineering firm, owes us for three invoices"

Not on a free or Plus plan

  • Pasting a real client email thread in to get help writing the reply
  • Uploading CVs or job applications to sort or shortlist candidates
  • Dropping in a customer list, an aged receivables report, or an invoice with names on it
  • Uploading anything about someone's health, ACC claim or personal circumstances
  • Screenshots of your CRM, booking system or payroll, which carry more identifying detail than people expect
  • Summarising notes from a performance conversation or a complaint about a staff member

Moving to Business lets you do all of the same tasks with real names in them, because training is off by default and there is a contract behind it. Check the retention clause while you're there, keep health and biometric information out unless the work truly needs it, and remember that residency still lands offshore for New Zealand customers.

Claude Anthropic
  • Free / Pro / Max Consumer terms. Free, then US$20 for Pro and US$100 or $200 for the two Max levels. Training is opt-in here, which is a better default than most. Switch it on and chats can be retained in de-identified form for up to five years.
  • Team Around US$25 to $30 per seat with a five-seat minimum. Not used for model training by default, with admin controls over the workspace.
  • Enterprise / API Custom pricing. No training by default, longer context, and the contractual terms you need to treat the provider as a processor acting on your behalf.

Fine on a free or Pro plan

  • Working through a long internal process document that describes roles rather than named people
  • Reviewing code, config or a technical spec with no real customer records in it
  • Drafting a proposal structure, a scope of work, or a set of terms
  • Analysing an anonymised extract where names and contact details have been swapped for IDs
  • Checking your own writing for tone and gaps before it goes out

Not on a free or Pro plan

  • Assuming that training being off means nothing is stored. Deleted chats clear the backend in about 30 days, and content flagged by safety systems can be held up to two years
  • Uploading a client contract with signatories, addresses and commercial terms in it
  • Feeding in a support inbox export, a membership list or a tenancy file
  • Leaving the model improvement setting on while doing anything work-related, because five years is a long time
  • Relaxing because the default is better, when the five-year window applies the moment someone switches training on

Team and Enterprise give you real business documents under commercial terms, with training off by default and an audit trail. This is the tier that lets you tell a client you use AI to help draft their responses and have it land as a process decision.

Gemini Google
  • Consumer app Free, AI Plus, AI Pro and AI Ultra, spanning about US$0 to $200. Google's own guidance is blunt about this one. Don't enter confidential information, because human reviewers may read it. Conversations picked up for human review can be kept for up to three years, and deleting your activity does not pull those back. Even with Gemini Apps Activity switched off, chats persist for around 72 hours.
  • Workspace Business Gemini features are now bundled into Workspace plans. Your content is not used to train models outside your organisation, is not human reviewed, and is covered by the Workspace data processing terms.
  • Workspace Enterprise / Vertex AI The same protections plus data regions, stronger admin controls, and the ability to run models against your own data under a proper processing agreement.

Fine on the consumer app

  • General research, explanations and how-to questions
  • Drafting content that has no client or staff information in it
  • Summarising something already public, like a competitor's pricing page
  • Personal admin on your own account and your own information
  • Image or video generation that doesn't involve a real person's likeness

Not on the consumer app

  • Anything you would be uncomfortable having a Google reviewer read, which is Google's own test
  • Opening a work document in a personal Google account and asking Gemini about it
  • Pasting client details and then deleting the chat, since the human review copy can outlive the delete by years
  • Leaning on "activity off" as a privacy control, given the 72-hour window and the review exceptions
  • Letting it summarise a Meet call with clients on it before you have sorted out consent and notification

Workspace puts the same brand on a very different privacy footing. Gemini in Gmail, Docs and Meet works on real business content with no training and no human review. Watch Meet transcripts and recordings, which collect information about everyone on the call and land you squarely in IPP 3 and IPP 3A territory.

Copilot Microsoft
  • Free consumer Copilot Runs in Microsoft's public consumer cloud. It has no access to your tenant, so no Teams chats, no SharePoint and no mailbox. None of your organisation's protections apply to what you type into it either.
  • Copilot Pro Adds capability to the consumer product and leaves the terms where they are. The most misunderstood product on this page, by a distance.
  • Microsoft 365 Copilot Signed in with a work account, you get Enterprise Data Protection. Prompts and responses sit under the same commercial terms as your Exchange mail and SharePoint files, and are not used to train foundation models. Those protections have been on by default since late 2024.

Fine on free or Pro

  • Learning how to do something in Excel or Word, using sample data
  • Drafting generic content, agendas or outlines
  • Web-grounded research questions with nothing of yours in the prompt
  • Formatting or rewriting text you wrote yourself that names nobody

Not on free or Pro

  • Copying content out of a work file and pasting it into a consumer Copilot window, which is the most common version of this mistake
  • Signing in with a personal Microsoft account on a work machine and assuming the company licence covers you
  • Buying Copilot Pro and treating it as the business tier
  • Pasting Teams messages or meeting notes in for a tidy-up

Microsoft 365 Copilot works on your real mail, files and Teams content under enterprise terms. The trade is that it will faithfully surface everything the signed-in user can technically access, including the folder that was shared too broadly in 2022 and never fixed. Audit your sharing permissions before you switch it on.

The AI features in tools you already pay for Everyone else
  • Free standalone tools Perplexity, Grok, Meta AI, DeepSeek and the rest. Each has its own answer and several free tiers train on input by default. Some are hosted in jurisdictions that will change how the IPP 12 conversation goes.
  • Bolt-on AI in your SaaS The AI buttons quietly appearing in your CRM, help desk, accounting system and job management app. The sneakiest category of the lot, because nobody re-reads a data processing agreement when a vendor ships a new feature.
  • Meeting note-takers Otter, Fireflies, Fathom and friends. Recording devices that collect information about everyone on the call, usually from a third party rather than from the person themselves.

Reasonable

  • Using the AI feature inside a system on data already in that system, for the purpose it was collected
  • Asking the vendor in writing whether the feature changes how your data is stored, used or shared
  • Running a note-taker on internal meetings where everyone in the room has agreed to it
  • Using a free research tool for questions that are already public

Not reasonable

  • Switching on a new AI feature across client data without checking whether the terms moved
  • Adding a bot to a client call without telling the people on it and recording that you did
  • Connecting a free AI tool to your Drive, mailbox or file shares to see what it can do
  • Using a browser extension that reads whatever page you're on, including your CRM
  • Letting an AI enrichment tool build profiles of people who have never heard of you

If a tool touches client information and nobody in your business can name the plan, the vendor and the retention period, treat it as unapproved and go and find those three answers.

Where this trips people up

Training gets all the attention. The quieter problems cause more trouble.

Switching off model training doesn't mean nothing is stored. Logs and safety systems keep their own copies on their own clocks, sometimes for years, and those clocks are frequently longer than the retention period you promised your own customers. Some of that content gets read by people, too. Anything flagged by a safety system or submitted with feedback can end up in front of a human reviewer. That is sensible engineering on the provider's part, and it is also a disclosure you probably haven't mentioned in your privacy statement.

Connectors bring their own trouble. Point an AI assistant at your Drive or SharePoint and it will surface everything the signed-in user can technically reach, which usually includes a folder someone shared far too widely in 2022 and never tidied up. The oversharing was already sitting there, and the assistant surfaces it in seconds.

Then there are the note-takers. A bot sitting in a call is collecting personal information about everyone present, and collecting it from a third party rather than from the people themselves, which brings IPP 3 into play and, since 1 May 2026, the new IPP 3A on indirect collection as well.

The biggest gap in most businesses is the tools nobody has written down. Staff working on personal accounts, on plans nobody chose, covered by no agreement. It is almost never malicious. People are trying to get through the day with the tools in front of them.

One more thing that catches people. The output is personal information too. A chat log discussing a named customer is information you now hold, which makes it subject to access requests under IPP 6 and to the accuracy obligation in IPP 8. A confidently wrong AI summary that goes on to shape a decision about someone can do real damage. And stripping the name out is weaker protection than it feels, because an address, a date and a job title will still point at one person in a town of four thousand.

What the Privacy Commissioner expects

The Office of the Privacy Commissioner published guidance on generative AI in September 2023, and it is short and readable. The expectations, condensed.

  • Get senior leadership sign-off before deploying AI, based on a real look at the risks.
  • Ask whether AI is necessary and proportionate, or whether something simpler does the job.
  • Do a Privacy Impact Assessment before you deploy, including engagement with Māori where Māori information or interests are involved.
  • Be transparent. If AI touches customer information, tell people how, when and why, in plain language.
  • Have accuracy procedures, and a way to handle access and correction requests.
  • Keep a human in the loop, reviewing outputs before anyone acts on them.
  • Keep personal and confidential information out of any tool unless the provider has confirmed it won't be retained or used for training.

That last expectation carries most of the weight, and it is the one people skip.

The principles that come up

All 13 information privacy principles apply, since the Act is technology-neutral. In day-to-day use these are the ones that come up.

  • IPP 1 and 3. Collect only what you need for a lawful purpose, and tell people you're collecting it.
  • IPP 3A. New from 1 May 2026. If you collect personal information about someone from a source other than that person, you must take reasonable steps to make them aware, as soon as reasonably practicable. Enrichment tools, scrapers and meeting recorders all live here.
  • IPP 5. Security. Choosing a tier that trains on your data is a storage and security decision as much as a purchasing one.
  • IPP 6. Access. If it sits in a chat log, someone can ask for it.
  • IPP 8. Accuracy. Check before you act.
  • IPP 9. Don't keep information longer than you need it, which is hard to honour when your provider's retention clock runs longer than yours.
  • IPP 10 and 11. Limits on use and disclosure. Feeding data collected for one purpose into a tool that repurposes it is exactly what these cover.
  • IPP 12. Overseas disclosure, and back to the agent question at the top.

When it does go wrong, a breach likely to cause serious harm has to be notified to the Privacy Commissioner and to the affected people as soon as practicable. Failing to notify without reasonable excuse is an offence carrying a fine up to $10,000, and the Human Rights Review Tribunal can award damages up to $350,000 to an individual. For most businesses the conversation with the client costs more than either number.

What to do about it this week

  1. Write down which tier every tool is on, and under which account, since the plan is where the risk lives. Most of it becomes visible the moment this list exists.
  2. Move anyone touching client data onto a business or enterprise plan. It is the cheapest control you will ever buy.
  3. Retire the personal accounts. Same tool, work login, admin oversight.
  4. Check the training and retention settings on every consumer plan you can't move yet, and keep a dated screenshot.
  5. Set one rule staff can remember. Ours is short. No client personal information into any tool that isn't on the approved list.
  6. Review your connectors and permissions before switching on anything that reads your Drive, mailbox or file shares.
  7. Update your privacy statement to say you use AI tools, and roughly what for.
  8. Do the PIA for anything that makes or shapes decisions about people.
  9. Get the data processing agreement and read the retention clause as well as the training clause.
  10. Decide your position on meeting recorders before someone else decides it for you.

Most of that is an afternoon's work.

Our take

We build automations and internal tools for New Zealand businesses, and AI is part of most of them now. The privacy work costs an hour at the start of a project. What costs weeks is finding out six months in that client data has been flowing through a free tier nobody approved.

So we sort it early. Pick the tier, pin down retention, keep personal information out of anything that doesn't need it, and write down what was decided so the answer still exists when somebody asks in a year.

Not sure where your data is going? Have a chat with us.

Tell us what’s slowing you down.

A short conversation, then a clear plan for what we’d build. No pitch, no jargon.