Back to Blog
Compliance

AI Receptionists and the Privacy Act 2020: What Happens to Your Callers' Data

KiwiAgent Team
8 min read

Under the Privacy Act 2020, your business is the agency collecting a caller's personal information, whether a person or an AI picks up the phone. The AI provider processes that information on your behalf. So you need to tell callers what is happening, know where the recording and transcript go, keep them only as long as you need, and choose a provider that protects them properly. This guide walks through what that means in practice. It is general information, not legal advice.

What counts as personal information on a call

The caller's name, phone number and address, obviously. Also the reason they rang, the appointment they booked, their voice on the recording, and the transcript of the conversation. If the call is transferred to a staff member, the recording holds their personal information too. An AI receptionist produces more of this than a human one, because every call is transcribed and summarised by default.

Whose responsibility it is

The Act applies to "agencies", a term that covers businesses of any size, including sole traders. Your business collects the information; the AI provider handles it for you. The Privacy Commissioner's guidance on artificial intelligence and the information privacy principles, published on 21 September 2023, puts it directly: before using AI tools you need to understand enough about how they work to be confident you are upholding the principles, and if in doubt, do not use AI tools to handle personal information.

That does not make AI answering risky. It makes it something you set up deliberately, like any other system that holds customer details.

The principles that matter most

The 13 information privacy principles sit in section 22 of the Act. The Privacy Commissioner publishes a plain-English guide to each one. Six of them do most of the work for a phone line.

Principle 1: only collect what you need

Collect personal information only for a lawful purpose connected with your business, and only what is needed for it. If you need a name and a callback number, do not have the agent ask for a date of birth. Every field you add to the agent's script is a collection decision.

Principle 3: tell people what is going on

When you collect information directly from someone, principle 3 says they should know why it is being collected, who will receive it, whether giving it is voluntary or compulsory, and what happens if they do not provide it. On a phone call, that is your greeting plus the privacy statement on your website. A greeting that says the caller is speaking with an AI assistant, and that the call is recorded so the details are captured correctly, covers the first part. The privacy statement covers the rest.

A new principle 3A applies to information collected indirectly from 1 May 2026, for example when a caller gives you someone else's details. If your agent takes third-party details, such as a tenant's number from a landlord, your privacy statement should cover that too.

Principle 5: keep it secure, including at your providers

Principle 5 requires security safeguards that are reasonable in the circumstances against loss, unauthorised access, use, modification or disclosure. Where a third party holds the information for you, you must do everything reasonably within your power to prevent them misusing or disclosing it. In practice that means choosing a provider with proper contractual terms and access controls, and not sending call summaries to a shared inbox the whole team can read from their phones. If there is a serious breach, the Commissioner's guidance is that it should be reported within 72 hours.

Principle 9: do not keep it forever

Principle 9 says an organisation should not keep personal information longer than it is required for the purpose it may lawfully be used. Recordings of every call since 2024 are not required for anything. Set a retention period that matches how you use the records, and make sure your provider deletes on schedule.

Principles 11 and 12: who you share it with, especially overseas

Principle 11 limits disclosure to the purposes you collected for. Principle 12 adds a test for sending personal information outside New Zealand. You may do so where the recipient is subject to the Privacy Act because they do business here, will adequately protect the information, for example through model contract clauses, or is subject to privacy laws with comparable safeguards. If none of those apply, you need the person's express permission after telling them their information may not get the same protection as under the New Zealand Act.

This principle matters for AI receptionists because most speech recognition, voice synthesis and language model providers process data in the United States. That is allowed under principle 12, but only with the protections in place. Ask your provider which ground it relies on and what its contracts say.

What the Privacy Commissioner expects of AI users

The Commissioner's expectations for generative AI, set out on 15 June 2023, were written with large organisations in mind, but they translate cleanly to a small business putting an AI on the phone:

  • Senior leadership approval. In a small business, that is you. Decide deliberately, not by default.
  • Necessity and proportionality. Be clear on why you are doing it. Missed calls and after-hours coverage are good reasons.
  • A privacy impact assessment. For a small business, one page: what the agent collects, where it goes, who can see it, how long it is kept, and what could go wrong.
  • Transparency. If the tool affects customers and their personal information, they must be told how, when and why. That is the greeting and the privacy statement again.
  • Accuracy and access procedures. Know how you would correct a wrong transcript or give a caller a copy of their information if they asked.
  • Human review before acting on outputs. Read the call summary before you turn up to the job or send the invoice. Summaries are good; they are not the caller.
  • Do not put personal information into a tool unless the provider has confirmed it is not retained or disclosed beyond what you have agreed. Get that confirmation in writing.

The September 2023 guidance adds four questions worth asking any provider: whether the training data behind the tool is relevant, reliable and ethical; whether your use is related to the purpose the information was collected for; how accuracy and fairness are tested; and how new risks from the tool are tracked and managed.

Eight questions to ask your AI receptionist provider

  1. Which companies process the audio, the transcript and the summary, and what does each one do?
  2. In which countries is that processing done?
  3. Which ground under principle 12 do you rely on for overseas disclosure, and what do your contracts with those providers say?
  4. How long are recordings and transcripts kept, and can I delete them earlier myself?
  5. Who at your company can listen to my calls, and when?
  6. Is caller data used to train any AI model, yours or a provider's?
  7. How is the data encrypted, and what is your breach notification process?
  8. If a caller asks me for a copy of their information, can you give it to me within the 20 working days the Act allows?

What KiwiAgent does

Our privacy policy answers those questions in full. In short: calls are carried by Twilio, transcribed by Deepgram, voiced by ElevenLabs, and understood by language models from OpenAI and Anthropic. Most of those providers process information outside New Zealand, mainly in the United States, and we rely on contractual data protection terms to meet principle 12. Recordings and transcripts are kept for 30 days on Starter, 90 days on Pro, and until you delete them on Business and Enterprise, and you can delete any call record earlier at any time. We do not sell personal information. We apply security safeguards including encryption, and we notify the Privacy Commissioner of any notifiable breach as the Act requires. Access and correction requests are handled within 20 working days. If you want the answers to the eight questions above in writing for your own records, ask through our contact form and we will send them.

Your checklist

  • Update your privacy statement to say that an AI assistant answers calls, that calls are recorded and transcribed, and that processing happens overseas with safeguards.
  • Put the AI disclosure and the recording notice in the greeting. Our greeting scripts have examples.
  • Limit what the agent asks for to what you need for the job.
  • Set the shortest retention period that still works for you.
  • Decide who reads transcripts and summaries, and keep it to them.
  • Know how you would handle an access or correction request.
  • Keep your provider's written answers on file. That is most of your privacy impact assessment.

Call recording specifically, including the Crimes Act side, is covered in our guide to call recording law in NZ.

Sources

Next step

If you want an AI receptionist set up with the greeting, retention and disclosures already sorted, tell us about your business and we will configure a free pilot for you. To hear what a compliant greeting sounds like first, talk to the demo agent on our homepage.

Frequently asked questions

Does the Privacy Act 2020 apply to my small business?
Yes. The Act applies to agencies, which includes businesses of every size and sole traders. If your business collects personal information from callers, the information privacy principles apply to you, whether a person or an AI answers the phone.
Do I have to tell callers that an AI is answering?
Principle 3 requires people to know why their information is collected, who receives it, and related details, and the Privacy Commissioner's generative AI expectations say customers must be told how, when and why an AI tool is used. Saying it in the greeting, with a recording notice if calls are recorded, is the simplest way to meet that.
Can an AI receptionist send my callers' data overseas?
Yes, if principle 12 is met. The overseas recipient must be subject to the Privacy Act, adequately protect the information through measures such as model contract clauses, or be covered by comparable privacy law. Otherwise you need the caller's express permission. Ask your provider which ground it relies on.
How long can I keep call recordings and transcripts?
Only as long as you need them for the purpose you collected them, under principle 9. Pick a retention period that matches how you use the records and make sure your provider deletes on schedule. KiwiAgent keeps them for 30 days on Starter and 90 days on Pro, and you can delete any record earlier.
privacy act 2020ai receptionist privacycall recording privacy nzoverseas disclosure ipp 12small business nz

About KiwiAgent Team

KiwiAgent Team writes practical guides for New Zealand businesses on answering calls, handling after-hours enquiries, and setting up an AI receptionist properly. Every statistic links to its source.

Ready to stop missing calls?

Start with a free pilot: 30 minutes of AI call answering every month, no credit card, and we set it up for you. Tell us about your business and we will reply by email.

More articles