Under the Privacy Act 2020, your business is the agency collecting a caller's personal information, whether a person or an AI picks up the phone. The AI provider processes that information on your behalf. So you need to tell callers what is happening, know where the recording and transcript go, keep them only as long as you need, and choose a provider that protects them properly. This guide walks through what that means in practice. It is general information, not legal advice.
What counts as personal information on a call
The caller's name, phone number and address, obviously. Also the reason they rang, the appointment they booked, their voice on the recording, and the transcript of the conversation. If the call is transferred to a staff member, the recording holds their personal information too. An AI receptionist produces more of this than a human one, because every call is transcribed and summarised by default.
Whose responsibility it is
The Act applies to "agencies", a term that covers businesses of any size, including sole traders. Your business collects the information; the AI provider handles it for you. The Privacy Commissioner's guidance on artificial intelligence and the information privacy principles, published on 21 September 2023, puts it directly: before using AI tools you need to understand enough about how they work to be confident you are upholding the principles, and if in doubt, do not use AI tools to handle personal information.
That does not make AI answering risky. It makes it something you set up deliberately, like any other system that holds customer details.
The principles that matter most
The 13 information privacy principles sit in section 22 of the Act. The Privacy Commissioner publishes a plain-English guide to each one. Six of them do most of the work for a phone line.
Principle 1: only collect what you need
Collect personal information only for a lawful purpose connected with your business, and only what is needed for it. If you need a name and a callback number, do not have the agent ask for a date of birth. Every field you add to the agent's script is a collection decision.
Principle 3: tell people what is going on
When you collect information directly from someone, principle 3 says they should know why it is being collected, who will receive it, whether giving it is voluntary or compulsory, and what happens if they do not provide it. On a phone call, that is your greeting plus the privacy statement on your website. A greeting that says the caller is speaking with an AI assistant, and that the call is recorded so the details are captured correctly, covers the first part. The privacy statement covers the rest.
A new principle 3A applies to information collected indirectly from 1 May 2026, for example when a caller gives you someone else's details. If your agent takes third-party details, such as a tenant's number from a landlord, your privacy statement should cover that too.
Principle 5: keep it secure, including at your providers
Principle 5 requires security safeguards that are reasonable in the circumstances against loss, unauthorised access, use, modification or disclosure. Where a third party holds the information for you, you must do everything reasonably within your power to prevent them misusing or disclosing it. In practice that means choosing a provider with proper contractual terms and access controls, and not sending call summaries to a shared inbox the whole team can read from their phones. If there is a serious breach, the Commissioner's guidance is that it should be reported within 72 hours.
Principle 9: do not keep it forever
Principle 9 says an organisation should not keep personal information longer than it is required for the purpose it may lawfully be used. Recordings of every call since 2024 are not required for anything. Set a retention period that matches how you use the records, and make sure your provider deletes on schedule.
Principles 11 and 12: who you share it with, especially overseas
Principle 11 limits disclosure to the purposes you collected for. Principle 12 adds a test for sending personal information outside New Zealand. You may do so where the recipient is subject to the Privacy Act because they do business here, will adequately protect the information, for example through model contract clauses, or is subject to privacy laws with comparable safeguards. If none of those apply, you need the person's express permission after telling them their information may not get the same protection as under the New Zealand Act.
This principle matters for AI receptionists because most speech recognition, voice synthesis and language model providers process data in the United States. That is allowed under principle 12, but only with the protections in place. Ask your provider which ground it relies on and what its contracts say.
What the Privacy Commissioner expects of AI users
The Commissioner's expectations for generative AI, set out on 15 June 2023, were written with large organisations in mind, but they translate cleanly to a small business putting an AI on the phone:
- Senior leadership approval. In a small business, that is you. Decide deliberately, not by default.
- Necessity and proportionality. Be clear on why you are doing it. Missed calls and after-hours coverage are good reasons.
- A privacy impact assessment. For a small business, one page: what the agent collects, where it goes, who can see it, how long it is kept, and what could go wrong.
- Transparency. If the tool affects customers and their personal information, they must be told how, when and why. That is the greeting and the privacy statement again.
- Accuracy and access procedures. Know how you would correct a wrong transcript or give a caller a copy of their information if they asked.
- Human review before acting on outputs. Read the call summary before you turn up to the job or send the invoice. Summaries are good; they are not the caller.
- Do not put personal information into a tool unless the provider has confirmed it is not retained or disclosed beyond what you have agreed. Get that confirmation in writing.
The September 2023 guidance adds four questions worth asking any provider: whether the training data behind the tool is relevant, reliable and ethical; whether your use is related to the purpose the information was collected for; how accuracy and fairness are tested; and how new risks from the tool are tracked and managed.
Eight questions to ask your AI receptionist provider
- Which companies process the audio, the transcript and the summary, and what does each one do?
- In which countries is that processing done?
- Which ground under principle 12 do you rely on for overseas disclosure, and what do your contracts with those providers say?
- How long are recordings and transcripts kept, and can I delete them earlier myself?
- Who at your company can listen to my calls, and when?
- Is caller data used to train any AI model, yours or a provider's?
- How is the data encrypted, and what is your breach notification process?
- If a caller asks me for a copy of their information, can you give it to me within the 20 working days the Act allows?
What KiwiAgent does
Our privacy policy answers those questions in full. In short: calls are carried by Twilio, transcribed by Deepgram, voiced by ElevenLabs, and understood by language models from OpenAI and Anthropic. Most of those providers process information outside New Zealand, mainly in the United States, and we rely on contractual data protection terms to meet principle 12. Recordings and transcripts are kept for 30 days on Starter, 90 days on Pro, and until you delete them on Business and Enterprise, and you can delete any call record earlier at any time. We do not sell personal information. We apply security safeguards including encryption, and we notify the Privacy Commissioner of any notifiable breach as the Act requires. Access and correction requests are handled within 20 working days. If you want the answers to the eight questions above in writing for your own records, ask through our contact form and we will send them.
Your checklist
- Update your privacy statement to say that an AI assistant answers calls, that calls are recorded and transcribed, and that processing happens overseas with safeguards.
- Put the AI disclosure and the recording notice in the greeting. Our greeting scripts have examples.
- Limit what the agent asks for to what you need for the job.
- Set the shortest retention period that still works for you.
- Decide who reads transcripts and summaries, and keep it to them.
- Know how you would handle an access or correction request.
- Keep your provider's written answers on file. That is most of your privacy impact assessment.
Call recording specifically, including the Crimes Act side, is covered in our guide to call recording law in NZ.
Sources
- Privacy Act 2020, section 22: information privacy principles (as at 1 May 2026)
- Office of the Privacy Commissioner: the privacy principles, including the pages for principle 3, principle 5, principle 9 and principle 12
- Office of the Privacy Commissioner: artificial intelligence and the information privacy principles (21 September 2023)
- Office of the Privacy Commissioner: generative artificial intelligence expectations (15 June 2023)
Next step
If you want an AI receptionist set up with the greeting, retention and disclosures already sorted, tell us about your business and we will configure a free pilot for you. To hear what a compliant greeting sounds like first, talk to the demo agent on our homepage.