Balance — New Zealand Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every New Zealand resident covered by this Annex; the privacy officer under s 201 of the Privacy Act 2020 (NZ); the designated contact point for the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu) ("OPC NZ"), the Department of Internal Affairs — Digital Safety Group, NetSafe, the Commerce Commission, and the Office of Film and Literature Classification ("OFLC") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Privacy Act 2020 (NZ) ("Privacy Act") — in force from 1 December 2020 and replacing the Privacy Act 1993 (NZ) — including any amendment to the 13 Information Privacy Principles ("IPPs") at s 22, to the cross-border-disclosure regime at IPP 12 + s 22 + the Privacy (Cross-border Information) Regulations if and when prescribed under s 214, or to Part 6 (Notifiable Privacy Breaches scheme — ss 112–119); (b) any prescribed regulation under s 214 of the Privacy Act 2020 designating a "prescribed country" for the purposes of IPP 12(1)(f); (c) any code of practice issued by the Privacy Commissioner under ss 32–46 of the Privacy Act 2020; (d) any decision of the Human Rights Review Tribunal under Part 5 of the Privacy Act 2020 (ss 88–104); (e) any Order / compliance notice / access direction / prosecution by the Privacy Commissioner under Privacy Act ss 79–87, 99, 105, 211, 212, 213; (f) any judgment of the High Court of New Zealand / Court of Appeal of New Zealand / Supreme Court of New Zealand that materially affects the privacy-related tort of intrusion upon seclusion (recognised in C v Holland [2012] NZHC 2155) or the privacy-related tort of publication of private facts (recognised in Hosking v Runting [2004] NZCA 34 / [2005] 1 NZLR 1) or that materially changes the interpretation of any IPP; (g) any amendment to the Harmful Digital Communications Act 2015 (NZ) ("HDCA"); (h) any amendment to the Films, Videos, and Publications Classification Act 1993 (NZ) ("FVPCA") or its associated Films, Videos, and Publications Classification (Interim Restriction Orders) Amendment Act 2021 + Films, Videos, and Publications Classification (Urgent Interim Classification of Publications and Prevention of Online Harm) Amendment Act 2021; (i) any amendment to the Crimes Act 1961 (NZ) in particular ss 124, 124A, 131, 131A, 131B, 132, 134, 144A (extraterritorial child sex offences), 144C, 216H–216N (intimate visual recordings); (j) any amendment to the Unsolicited Electronic Messages Act 2007 (NZ) ("UEM Act") or its associated regulations; (k) any amendment to the Search and Surveillance Act 2012 (NZ) ("SSA"), the Telecommunications (Interception Capability and Security) Act 2013 (NZ) ("TICSA"), or the Customs and Excise Act 2018 (NZ); (l) any amendment to the Consumer Guarantees Act 1993 (NZ) ("CGA"), the Fair Trading Act 1986 (NZ) ("FTA"), or the Credit Contracts and Consumer Finance Act 2003 (NZ); (m) any amendment to the Oranga Tamariki Act 1989 (NZ) (formerly the Children, Young Persons, and Their Families Act 1989) or to the Children's Act 2014 (NZ); (n) the European Commission rescinding or modifying Commission Implementing Decision 2013/65/EU of 19 December 2012 — on the adequate protection of personal data by New Zealand (the New Zealand EU adequacy decision, in force at the Effective date); (o) New Zealand's accession to the Council of Europe Convention 108 or Convention 108+ (not in force at the Effective date — New Zealand has been invited to accede but has not formally acceded); (p) any amendment to a sub-processor's New Zealand data-handling posture under our sub-processor register; (q) the bringing into force of any post-Effective-date New Zealand regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — New Zealand row).
- Children's Privacy Notice § 14 (Country annexes — New Zealand row).
- Child Safety Standards § 13 (Country annexes — New Zealand row).
- Terms of Service § 19 (NZ consumer-protection carve-out under the CGA + FTA).
- Subscription Terms § 20 (NZ consumer-rights overlay — CGA s 28 reasonable care and skill + FTA s 9 misleading or deceptive conduct + FTA s 26A unfair contract terms).
- Data Retention & Deletion Policy § 14 (NZ OPC complaint route).
- our breach-notification runbook § 9 (NZ Notifiable Privacy Breaches scheme route under Privacy Act 2020 Part 6).
- our international-transfer pack § 6 (IPP 12 cross-border-disclosure treatment + accountability paperwork + EU adequacy + onward-flow contractual paperwork).
This Annex is the canonical New Zealand-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a New Zealand resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a New Zealand resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. New Zealand's official languages are te reo Māori, English, and New Zealand Sign Language (Māori Language Act 2016 (NZ); New Zealand Sign Language Act 2006 (NZ); English by convention and constitutional inheritance). Te reo Māori translation is queued for the Phase-2 locale rollout per our internal compliance tracker, consistent with the Privacy Commissioner's obligation under Privacy Act 2020 s 7(1)(b) to take account of cultural perspectives of Māori in the exercise of the Commissioner's functions and powers. Where this Annex is read by a Māori-speaking resident of Aotearoa New Zealand and a discrepancy arises between the English and the queued te reo Māori versions once published, the resident may choose the operative language.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is Aotearoa New Zealand ("New Zealand" or "Aotearoa NZ"), including:
- the 16 regions of New Zealand (Northland, Auckland, Waikato, Bay of Plenty, Gisborne, Hawke's Bay, Taranaki, Manawatū-Whanganui, Wellington, Tasman, Nelson, Marlborough, West Coast, Canterbury, Otago, Southland), plus
- the Realm of New Zealand associated territories — Tokelau (a non-self-governing territory of New Zealand), the Cook Islands (a self-governing state in free association with New Zealand), Niue (a self-governing state in free association with New Zealand), and the Ross Dependency (NZ Antarctic claim). For the Cook Islands and Niue, the Privacy Act 2020 does not automatically apply (Privacy Act 2020 s 4 + s 5 + s 6 read with the Constitution Act 1986 (NZ) + the Constitution of the Cook Islands + the Niue Constitution Act 1974); a Cook Islands or Niuean resident relying on this Annex is treated on the most-protective reading and receives the equivalent protections set out below. The Annex protections extend to Tokelau and Ross Dependency residents on the same most-protective reading.
We determine country of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies New Zealand as the country of residence, this Annex applies, even if the other signals are non-New-Zealand. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The Privacy Act 2020 has extraterritorial effect under s 4: it applies to "an overseas agency that, in the course of carrying on business in New Zealand", collects or holds personal information. The High Court of New Zealand in Director of Human Rights Proceedings v Christchurch City Council [2018] NZHRRT 21 and the Privacy Commissioner's published guidance confirm that targeting New Zealand-resident consumers from outside New Zealand satisfies the "carrying on business in New Zealand" limb. Balance squarely targets New Zealand residents through Google Play New Zealand, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to New-Zealand-resident parents and kids; the Privacy Act 2020 applies in full.
2. Statutory framework — what applies
The New Zealand personal-information-protection regime is dominated by the Privacy Act 2020 and its 13 Information Privacy Principles ("IPPs"). The Privacy Act 2020 sits at the intersection of: the New Zealand Bill of Rights Act 1990; the customary and common-law privacy torts (intrusion upon seclusion per C v Holland [2012] NZHC 2155; publication of private facts per Hosking v Runting [2004] NZCA 34); the Harmful Digital Communications Act 2015 (NZ); the Films, Videos, and Publications Classification Act 1993 (NZ); the Crimes Act 1961 (NZ); the Oranga Tamariki Act 1989 (NZ); the Care of Children Act 2004 (NZ); the Unsolicited Electronic Messages Act 2007 (NZ); the Consumer Guarantees Act 1993 (NZ); the Fair Trading Act 1986 (NZ); and the Treaty of Waitangi / Te Tiriti o Waitangi read into Privacy Act 2020 s 7(1)(b). New Zealand holds an EU adequacy decision since 2012 — one of only nine non-EU/EEA jurisdictions (and the only South-Pacific jurisdiction) to hold one as of the Effective date.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| New Zealand Bill of Rights Act 1990 (NZ) | NZBORA — s 21 (right to be secure against unreasonable search or seizure); s 14 (freedom of expression); s 19 (freedom from discrimination); s 28 (other rights and freedoms not affected — including the unenumerated right to privacy as recognised by the Hosking v Runting line of authority) | The principal human-rights instrument. NZBORA is not entrenched and is interpreted as a guide to the construction of other statutes; s 6 requires that, where a statute is open to two interpretations, the rights-consistent interpretation is preferred. | Applies as the constitutional / human-rights layer. Treatment in §§ 3, 6, 13 below. |
| Privacy Act 2020 (NZ) | Privacy Act — in force 1 December 2020, replacing the Privacy Act 1993 (NZ). Substantive sections: s 3 purpose; s 4 (overseas agencies — extraterritorial application limb); s 5 (Act binds the Crown); s 6 (agency definition); s 7 (Privacy Commissioner's functions including s 7(1)(b) duty to take account of cultural perspectives of Māori); s 8 (privacy officer of an agency); s 22 (13 Information Privacy Principles — IPP 1 purpose of collection; IPP 2 source of personal information; IPP 3 collection of information from individual; IPP 4 manner of collection; IPP 5 storage and security; IPP 6 access; IPP 7 correction; IPP 8 accuracy of personal information; IPP 9 retention; IPP 10 use limits; IPP 11 disclosure limits; IPP 12 disclosure of personal information outside New Zealand — cross-border disclosure; IPP 13 unique identifiers); ss 23–31 (codes of practice); ss 32–55 (privacy codes that are in force at the Effective date — Health Information Privacy Code 2020; Credit Reporting Privacy Code 2020; Telecommunications Information Privacy Code 2020; Justice Sector Unique Identifier Code 2020; Civil Defence National Emergencies (Information Sharing) Code 2020; Superannuation Schemes Unique Identifier Code 2020); ss 56–67 (information matching programmes); ss 68–77 (access and correction); s 75 (response to access requests — 20 working days); ss 78–87 (Privacy Commissioner's powers — investigation, compliance notice, access direction); ss 88–104 (Part 5 — proceedings before the Human Rights Review Tribunal); ss 105–111 (Privacy Commissioner's powers to make decisions and orders); ss 112–119 (Part 6 — Notifiable Privacy Breaches scheme — in force since 1 December 2020 as part of the Act's commencement; s 112 notifiable-breach definition serious-harm test; s 114 OPC notification "as soon as practicable"; s 115 affected-individual notification "as soon as practicable"; s 117 carve-outs; s 118 offence to fail to notify — up to NZ$10,000 fine); ss 120–123 (information privacy principles relating to law enforcement); ss 124–168 (further functions and powers of the Privacy Commissioner); ss 169–212 (general — including s 211 offence + s 213 criminal liability of officers + s 214 prescribed countries Order in Council under IPP 12(1)(f)); s 215 (regulations). | The principal statute. Applies in full to Balance as an "overseas agency carrying on business in New Zealand" (s 4). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Privacy Regulations | At the Effective date, no Order in Council has been made under s 214 of the Privacy Act 2020 prescribing a "prescribed country" for the purposes of IPP 12(1)(f). The European Commission's adequacy decision (Commission Implementing Decision 2013/65/EU) is recognised by New Zealand as a substantively-equivalent regime via the Privacy Act IPP 12(1)(a) "comparable safeguards" route. | The cross-border-disclosure regulation layer. | Applies as the operational layer for IPP 12. |
| Privacy Commissioner Codes of Practice | The Privacy Commissioner's binding codes — Health Information Privacy Code 2020; Credit Reporting Privacy Code 2020; Telecommunications Information Privacy Code 2020; Justice Sector Unique Identifier Code 2020; Civil Defence National Emergencies (Information Sharing) Code 2020; Superannuation Schemes Unique Identifier Code 2020. | Sets binding interpretive layer for specific sectors. | Not engaged — Balance is not a health agency, credit reporter, telecommunications agency, justice-sector agency, civil-defence agency, or superannuation scheme. Applies as a context-setting fact. |
| OPC NZ Guidance | The Privacy Commissioner's published guidance — Privacy Trust Mark, AskUs Knowledge Base, Guidance for Agencies, the Notifiable Privacy Breach Self-Assessment Tool, the Cross-Border Disclosure Decision-Making Tool, the Children and Young Persons Privacy guidance, the Te Tiriti o Waitangi and Privacy guidance, the body of OPC NZ casenotes and Commissioner's Reports published at https://www.privacy.org.nz/. |
Sets the OPC NZ's binding interpretive layer on the Privacy Act 2020 + IPPs. | Applies. Balance's posture is operationalised consistently with the OPC NZ's published guidance — in particular the Children and Young Persons Privacy guidance and the Cross-Border Disclosure Decision-Making Tool. |
| Harmful Digital Communications Act 2015 (NZ) | HDCA — establishes the civil-enforcement regime and the criminal offence of causing harm by posting digital communication (s 22). Defines 10 communication principles at s 6. Designates an Approved Agency under s 8 — NetSafe (operating as Netsafe / Te Pataka Tukatuka) is the approved agency. Civil enforcement at the District Court (ss 12–21). Criminal offence at s 22 — up to 2 years imprisonment + up to NZ$50,000 fine (individuals) / NZ$200,000 (body corporate). | The principal online-harms statute. Applies primarily to communications made by individuals; online content hosts (s 4) have a safe-harbour at s 24 conditional on a notice-and-takedown response. Balance is not an "online content host" within s 4 — Balance does not provide a service that enables a person to make digital communications available to other persons in a public-facing sense; the proof-media payload is end-to-end-encrypted and is delivered only to the kid's paired parent device(s). The s 24 safe-harbour mechanism does not engage Balance directly because there is no public-facing surface to which the notice-and-takedown machinery applies. | Applies as a context-setting fact. Cross-reference in Child Safety Standards § 8 + § 14 below. |
| Films, Videos, and Publications Classification Act 1993 (NZ) | FVPCA — establishes the Office of Film and Literature Classification ("OFLC") and the Chief Censor; criminalises possession and distribution of objectionable publications under s 124 + ss 131–131B + s 132 + s 134 + s 144A. The Films, Videos, and Publications Classification (Urgent Interim Classification of Publications and Prevention of Online Harm) Amendment Act 2021 added an urgent interim classification power + takedown notice power at s 119(2). The Films, Videos, and Publications Classification (Interim Restriction Orders) Amendment Act 2021 added interim restriction orders. The Chief Censor is the principal NZ authority on CSAM classification. | Sets the CSAM / objectionable-publications classification and criminalisation regime. The Department of Internal Affairs — Digital Safety Group is the principal enforcement agency for online CSAM offences (cross-reference Crimes Act 1961). | Applies. Cross-reference in Child Safety Standards § 8 + § 14 below. |
| Crimes Act 1961 (NZ) | Crimes Act — s 124 (distribution of obscene matter); s 124A (indecent communication with young person under 16); s 131 (sexual conduct with dependent family member under 18); s 131A (sexual conduct with consent induced by coercive use of authority); s 131B (meeting young person under 16 following sexual grooming); s 132 (sexual conduct with child under 12); s 134 (sexual conduct with young person under 16); s 144A (sexual conduct with children and young people outside New Zealand — extraterritorial child sex offences); s 144C (organising or promoting child sex tours); ss 216H–216N (intimate visual recordings); s 252 (accessing computer system without authorisation); s 249 (accessing computer system for dishonest purpose). | The principal NZ criminal statute for CSAE, online-grooming, and intimate-image offences. | Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below. |
| Unsolicited Electronic Messages Act 2007 (NZ) | UEM Act — regulates the sending of commercial electronic messages ("CEMs") to or from a New Zealand-link computer. Requires consent (express or inferred), identification of the sender, and a functional unsubscribe facility. Enforced by the Department of Internal Affairs — Anti-Spam Compliance Unit. Civil pecuniary penalties up to NZ$200,000 for an individual / NZ$500,000 for a body corporate (s 45). | Regulates commercial electronic messages. | Applies. Balance does not send commercial electronic messages to New Zealand residents; the only email Balance sends is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). Treatment in § 12.3 below. |
| Search and Surveillance Act 2012 (NZ) | SSA — the principal lawful-search-and-surveillance statute. Sets the procedural rules for search warrants, surveillance device warrants, residual warrants, and the production order regime at ss 71–78. | The lawful-access framework for criminal investigations. | Applies. Treatment in § 13 below. |
| Telecommunications (Interception Capability and Security) Act 2013 (NZ) | TICSA — the telecommunications lawful-intercept and network-security regime. Applies to network operators (s 3) — Balance is not a network operator. | The lawful-intercept framework for telecommunications. | Not engaged directly. Applies as a context-setting fact. |
| Customs and Excise Act 2018 (NZ) | Customs Act — Part 4 + Part 6 — applies to seizure of objectionable publications at the border. | The border-seizure regime for objectionable publications including CSAM. | Applies as a context-setting fact. |
| Oranga Tamariki Act 1989 (NZ) | Oranga Tamariki Act — formerly the Children, Young Persons, and Their Families Act 1989; renamed by the Children, Young Persons, and Their Families (Oranga Tamariki) Legislation Act 2017. Establishes the Ministry for Children — Oranga Tamariki + the framework for children's-and-young-persons' welfare, care, and protection. Definitions — child is under 14; young person is 14 to under 18 (s 2). Best-interest principle at ss 4–5. | The principal child-welfare statute. | Applies. Treatment in § 5 + § 14 below. |
| Children's Act 2014 (NZ) | Children's Act — establishes the Children's Commissioner (now the Ministry for Children — Oranga Tamariki + the Children's and Young People's Commission); requires children's worker safety checks; requires children's-agency child protection policies. | Sets the child-safeguarding policy and personnel-screening framework for "children's services". | Applies as a context-setting fact (Balance is not a "children's service" within the s 6 sense — Balance does not employ "children's workers" who are face-to-face with NZ children). |
| Care of Children Act 2004 (NZ) | Care of Children Act — establishes the doctrine of guardianship (s 15 — care for the child + contribute to the child's intellectual, emotional, physical, social, cultural, and other personal development); guardianship is the NZ statutory equivalent of parental authority / patria potestas. The Act applies until age 18 (s 26 — guardianship continues until age 18). | The principal NZ parental-authority statute. | Applies as the doctrinal anchor for the parent's consent on behalf of the kid. Treatment in § 7 below. |
| Consumer Guarantees Act 1993 (NZ) | CGA — implies into every consumer-services contract the guarantees of: s 28 (reasonable care and skill); s 29 (fitness for particular purpose); s 30 (reasonable time for supply); s 31 (reasonable price). Non-excludable (s 43); collective consumer rights in s 43A; remedies of repair / replacement / refund per ss 32–39. | The principal NZ consumer-services-protection statute. | Applies in full. Treatment in § 16 below. |
| Fair Trading Act 1986 (NZ) | FTA — s 9 (misleading or deceptive conduct in trade); s 10 (false or misleading representations in connection with goods); s 11 (false or misleading representations in connection with services); s 13 (false or misleading representations about price or value); s 26A (unfair contract terms in standard form consumer contracts; void to the extent of unfairness); ss 36–43 (consumer information standards and product safety standards). Enforced by the Commerce Commission. | The principal NZ fair-trading statute. | Applies in full. Treatment in § 16 below. |
| Credit Contracts and Consumer Finance Act 2003 (NZ) | CCCFA | Applies only to credit contracts. | Not engaged — Balance does not provide credit. Applies as a context-setting fact. |
| EU adequacy | Commission Implementing Decision 2013/65/EU of 19 December 2012 — on the adequate protection of personal data by New Zealand under (then-)Directive 95/46/EC Art 25(6), now GDPR Art 45(9) — in force at the Effective date. New Zealand is one of only nine non-EU/EEA jurisdictions to hold an EU adequacy decision; the decision recognises that the level of protection of personal data ensured by New Zealand is essentially equivalent to the level guaranteed within the EU under the GDPR. | Allows the bidirectional flow of personal data between the EU/EEA and New Zealand without supplementary transfer instruments. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to New Zealand under the 2013/65/EU adequacy decision. | Applies as a context-setting fact (Balance's backend is in the US, not in NZ — see § 9 below — so the EU adequacy is relevant only in the alternative). |
| Convention 108 / Convention 108+ | Not applicable. New Zealand has been invited to accede to the Council of Europe Convention 108 but has not formally acceded at the Effective date. | Applies as a context-setting fact. | The Council-of-Europe layer is not engaged for the NZ-resident flows. |
| Te Tiriti o Waitangi / Treaty of Waitangi | The foundational document of the partnership between the Crown and Māori (signed 6 February 1840). Article 2 / Te Tuarua guarantees Māori tino rangatiratanga (full chieftainship / self-determination) over their taonga (treasured possessions), which the Waitangi Tribunal in Wai 262 (Ko Aotearoa Tēnei) found to include personal information of Māori. Privacy Act 2020 s 7(1)(b) requires the Privacy Commissioner to take account of cultural perspectives of Māori in the exercise of the Commissioner's functions and powers. | The constitutional partnership document. | Applies as the constitutional partnership layer. Balance honors te Tiriti's principles in respect of Māori personal information by: (i) commitment to the te reo Māori translation queued in Phase 2; (ii) recognition of taonga status of Māori personal information; (iii) consultation with the OPC NZ's Māori Reference Group on any matter the Commissioner refers under s 7(1)(b). |
(Any prospective New Zealand regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date OPC NZ guidance in that area, any Algorithm Charter for Aotearoa New Zealand (the Department of Internal Affairs + Stats NZ voluntary charter, applies only to government agencies and is voluntary), any future AI Bill before the New Zealand Parliament, and any successor regulation — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such New Zealand regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 OPC NZ — Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu
The principal supervisory authority is the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu) ("OPC NZ"), established under the Privacy Act 1993 (continuing in office under the Privacy Act 2020). The OPC NZ is led by the Privacy Commissioner — an Officer of Parliament appointed by the Governor-General on the recommendation of the House of Representatives.
| Field | Value |
|---|---|
| Name | Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu (OPC NZ) |
| Headquarters | PO Box 10094, The Terrace, Wellington 6143 + Level 8, 109–111 Featherston Street, Wellington 6011 |
| Auckland office | PO Box 466, Shortland Street, Auckland 1140 + Level 8, 21 Queen Street, Auckland 1010 |
| Website | https://www.privacy.org.nz/ |
| Complaint channel | OPC NZ online complaint form at https://www.privacy.org.nz/your-rights/making-a-complaint/online-complaint-form/, by mail to the Wellington or Auckland office, or by phone at 0800 803 909 (toll-free within New Zealand) |
| Breach-notification channel | OPC NZ online Notifiable Privacy Breach form per Privacy Act 2020 s 114 at https://privacybreach.privacy.org.nz/ (the NotifyUs portal) |
| Privacy Commissioner | At the Effective date — Michael Webster (or successor as published at the OPC NZ website) |
The OPC NZ is the first-line forum for any Privacy-Act-grounded complaint from any New Zealand resident. A New Zealand resident may petition the OPC NZ without first raising the matter with Balance. We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the privacy officer under Privacy Act 2020 s 201) and respond within the Privacy Act 2020 timelines (see § 6 below).
A New Zealand resident may also pursue private remedies against Balance via Part 5 of the Privacy Act 2020 (proceedings before the Human Rights Review Tribunal); via the common-law privacy torts (intrusion upon seclusion per C v Holland + publication of private facts per Hosking v Runting); via the ordinary District / High Courts; or via the criminal route under the Crimes Act 1961 or Privacy Act 2020 s 211 / s 213 where criminal offences are engaged.
3.2 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| Department of Internal Affairs — Digital Safety Group (formerly DIA Censorship Compliance Unit) | FVPCA enforcement; online CSAM; collaboration with NetSafe + NZ Police + OFLC | https://www.dia.govt.nz/Digital-Safety |
| NetSafe / Te Pataka Tukatuka | HDCA approved agency under s 8; INHOPE member; online-harms triage and mediation | https://netsafe.org.nz/ |
| Office of Film and Literature Classification (OFLC) | Classification of films, videos, and publications; CSAM classification | https://www.classificationoffice.govt.nz/ |
| Department of Internal Affairs — Anti-Spam Compliance Unit | UEM Act enforcement | https://www.dia.govt.nz/Spam |
| Commerce Commission | FTA + CGA enforcement | https://comcom.govt.nz/ |
| Ministry for Children — Oranga Tamariki | Child welfare under Oranga Tamariki Act | https://www.orangatamariki.govt.nz/ |
| NZ Police National Cyber Crime Unit (NCCU) | Cybercrime investigation including CSAE | https://www.police.govt.nz/ |
| Children's and Young People's Commission (Mana Mokopuna) | Children's rights monitoring | https://www.manamokopuna.org.nz/ |
3.3 The privacy officer
Privacy Act 2020 s 201 requires every agency (including overseas agencies that carry on business in New Zealand) to designate one or more individuals as "privacy officers" whose responsibilities are to (a) encourage compliance with the IPPs; (b) deal with requests made to the agency under the Act; (c) work with the Privacy Commissioner in relation to investigations conducted under the Act; (d) ensure the agency's compliance.
The Balance privacy officer is:
- , Director, BabaYaga Program, TOO —
.
The privacy officer's contact details are published in this Annex and in the global Privacy Policy (Privacy Policy § 1).
4. Lawful bases — IPPs + s 22 framework
The Privacy Act 2020 does not use the GDPR "lawful bases" taxonomy. Instead, the IPPs at s 22 set: (i) purpose limits on collection (IPP 1); (ii) collection from the individual (IPP 2 + IPP 3 + IPP 4); (iii) storage and security (IPP 5); (iv) access and correction (IPP 6 + IPP 7); (v) accuracy (IPP 8); (vi) retention (IPP 9); (vii) use and disclosure limits (IPP 10 + IPP 11); (viii) cross-border disclosure (IPP 12); (ix) unique identifiers (IPP 13).
Balance processes personal information of New Zealand residents on the following IPP mapping:
| Processing purpose | IPP basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | IPP 1 (collection for a lawful purpose connected with the agency's function) + IPP 2 + IPP 3 + IPP 4 (collection from the parent — the individual concerned — by fair and lawful means) + IPP 10 (use limit — for the primary purpose of providing the parental-control service) + IPP 11 (disclosure limit — only to authorised recipients) | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal information | IPP 1 + IPP 2 (collection from the kid via the kid app + collection from the parent via the parent app, both with the parent's authorisation under the Care of Children Act 2004 guardianship doctrine) + IPP 3 + IPP 4 + IPP 10 + IPP 11 + OPC NZ Children and Young Persons Privacy guidance on capacity test | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | IPP 10 (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | IPP 5 (storage and security — reasonable security safeguards) + IPP 11(1)(b) (disclosure necessary to maintain the law including for the detection, investigation, or prosecution of any offence) + IPP 11(1)(e) (disclosure to prevent or lessen a serious threat to the life or health of any individual) | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | IPP 11(1)(d) (disclosure required or authorised by or under any enactment) + IPP 10(1)(d) (use required or authorised by or under any enactment) | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | IPP 1 + IPP 3 — collection of the parent's information for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | IPP 1 — necessary for the agency's function of providing the subscription service; CGA + FTA overlay in § 16 below | H4; § 16 below |
Balance does not assign or use a unique identifier in the IPP 13 sense (a number, letter, name, or any other sequence of characters or symbols designed to identify a unique individual that is assigned to the individual to which the unique identifier was first assigned). Balance assigns an internal user ID that is not derived from any government-issued or commonly-used unique identifier. IPP 13 is therefore not engaged.
5. Children's rights overlay
New Zealand does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the Privacy Act 2020 IPPs read with the OPC NZ's Children and Young Persons Privacy guidance (case-by-case capacity assessment) and the Privacy Commissioner's reference to Gillick / Hewer v Bryant / Marion's Case on capacity; (ii) the Care of Children Act 2004 (NZ) — the guardianship doctrine; (iii) the Oranga Tamariki Act 1989 (NZ) — best-interest principle (ss 4–5) + cooperation routes; (iv) the UN Convention on the Rights of the Child (NZ ratified 6 April 1993, with reservations on Arts 32(1) and 37(c)); (v) NZBORA s 28 + Mana Mokopuna — Children's and Young People's Commission Act 2023.
5.1 Definitions
For the purposes of this Annex:
- Child: every person under the age of 14 (Oranga Tamariki Act 1989 s 2 — child means a boy or girl under the age of 14 years).
- Young person: every person 14 to under 18 (Oranga Tamariki Act 1989 s 2 — young person means a person of or over the age of 14 years but under 18 years).
- Minor (general): the age of majority in New Zealand is 20 for certain purposes (Age of Majority Act 1970) but 18 for most contemporary statutory purposes including the Privacy Act 2020.
5.2 Verifiable Parental Consent (VPC) for New Zealand kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every New Zealand kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for New Zealand residents itemises the categories of personal information being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the Privacy Act 2020.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of IPP 1 + IPP 3 + IPP 4 + IPP 10 + the OPC NZ Children and Young Persons Privacy guidance + Care of Children Act 2004 s 15 (guardianship).
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the OPC NZ's interpretive position on direct marketing to children; (ii) the Advertising Standards Authority Children and Young People's Code (the ASA Children's Code); (iii) NZBORA s 14 freedom of expression read with NZ's CRC Art 17 obligations on protection from harmful media. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal NZ child-protection bodies are: (i) the Ministry for Children — Oranga Tamariki — the principal child-welfare agency; (ii) NZ Police National Cyber Crime Unit (NCCU) — the principal law-enforcement node for online CSAE; (iii) Department of Internal Affairs — Digital Safety Group — the principal enforcement agency for online CSAM under FVPCA + Crimes Act; (iv) NetSafe / Te Pataka Tukatuka — the HDCA approved agency + INHOPE member; (v) OFLC — the classification authority; (vi) the Children's and Young People's Commission (Mana Mokopuna) — children's-rights monitoring; (vii) Kidsline — NZ's helpline for children up to age 18; (viii) Youthline — NZ's helpline for young people. Balance cooperates with each on incidents involving NZ kids — see § 14 below.
6. Privacy Act 2020 rights catalogue
6.1 The rights catalogue
A New Zealand resident has the following rights under the Privacy Act 2020 + IPPs as in force at the Effective date.
- IPP 6 — Right of access. Every individual is entitled to confirmation of whether the agency holds personal information about the individual and to access to that information. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary. - IPP 7 — Right of correction. Every individual is entitled to request the correction of personal information held about the individual. Honored in-app at Settings → Account → Edit and at
. - IPP 11 — Disclosure limits. The right not to have personal information disclosed except for the purpose for which it was collected or for a directly related purpose or with the consent of the individual or under one of the IPP 11 carve-outs.
- IPP 12 — Cross-border disclosure limit. The right not to have personal information disclosed to a foreign person or entity except under one of the IPP 12 lawful bases (see § 8 below).
- Privacy Act 2020 s 75 — Response timing. The agency must respond to an access or correction request as soon as reasonably practicable and not later than 20 working days after the day the request is received.
- Privacy Act 2020 s 99 — Privacy Commissioner compliance notice. Where the Commissioner has reasonable grounds to believe that an agency is acting in breach of the Act, the Commissioner may issue a compliance notice requiring the agency to act.
- Privacy Act 2020 s 105 — Access direction. Where the Commissioner believes an agency has unjustifiably refused access, the Commissioner may direct the agency to provide access.
- Privacy Act 2020 Part 5 — Proceedings before the Human Rights Review Tribunal. A complainant may proceed to the Human Rights Review Tribunal under s 96 (after an OPC NZ investigation) or s 98 (where the Commissioner declines to investigate). The Tribunal may award damages up to NZ$350,000 per complainant.
- Common-law privacy torts. Intrusion upon seclusion per C v Holland [2012] NZHC 2155; publication of private facts per Hosking v Runting [2004] NZCA 34. Heard by the District Court or High Court.
6.2 Timeline
- IPP 6 access: 20 working days from the day the request is received (Privacy Act 2020 s 75 + s 66).
- IPP 7 correction: 20 working days (same window, by analogy + OPC NZ guidance).
- OPC NZ complaint: the OPC NZ's published target is to resolve complaints within 6 months; complex matters may take longer.
- Human Rights Review Tribunal: standard tribunal timelines.
Where the request would be vexatious or where one of the withholding grounds at ss 49–53 applies (national security; maintenance of the law; protection of trade secrets; legal professional privilege; etc.), Balance may refuse to act on the request; the requestor is told the reason and informed of the right to complain to the OPC NZ.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.
6.4 No cost
The exercise of the IPP 6 access right is free of charge (Privacy Act 2020 s 66(2) — agencies may charge a reasonable fee only in limited circumstances; Balance does not charge in practice).
6.5 Language
A request may be submitted in English or te reo Māori. The OPC NZ accepts complaints in both official languages.
7. Children's data — IPPs + OPC NZ Children and Young Persons Privacy + Care of Children Act 2004
Balance processes personal information of New Zealand kids under the following layered framework:
- Privacy Act 2020 IPPs read with the OPC NZ's Children and Young Persons Privacy guidance — case-by-case capacity assessment using Gillick / Hewer v Bryant / Marion's Case approach; for younger children, parental authorisation is required; for older young persons with sufficient capacity, self-authorisation may be appropriate.
- Care of Children Act 2004 (NZ) s 15 — guardianship doctrine — guardianship of a child means having (and being entitled to exercise) the duties, powers, rights, and responsibilities that a parent of the child has in relation to the upbringing of the child — including the responsibility to contribute to the child's intellectual, emotional, physical, social, cultural, and other personal development. Guardianship continues until the child reaches the age of 18 (s 26).
- Oranga Tamariki Act 1989 (NZ) ss 4–5 — best-interest principle (the welfare and interests of the child or young person are the first and paramount consideration).
- UN Convention on the Rights of the Child (NZ ratified 6 April 1993, with reservations on Arts 32(1) and 37(c)) — internalised through Mana Mokopuna — Children's and Young People's Commission Act 2023 (NZ) s 10.
- Children's Act 2014 (NZ) — sets the policy-and-personnel-screening framework for children's services; not directly engaged for Balance (see § 2 above).
- Te Tiriti o Waitangi — Privacy Act 2020 s 7(1)(b) requires the Privacy Commissioner to take account of cultural perspectives of Māori; Balance honors taonga status of Māori personal information.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (te reo Māori queued for Phase 2 locale rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from New Zealand — IPP 12
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every New Zealand resident's personal information leaves New Zealand at the point of being uploaded to the Balance backend.
8.1 The New Zealand-to-US transfer mechanism — IPP 12
IPP 12 governs cross-border disclosure. An agency may disclose personal information to a foreign person or entity only if at least one of the following applies (Privacy Act 2020 s 22 — IPP 12(1)(a)–(f)):
- IPP 12(1)(a) — the agency believes on reasonable grounds that the foreign person or entity is subject to comparable safeguards to those in the Act;
- IPP 12(1)(b) — the foreign person or entity is required to protect the information in a way that, overall, provides comparable safeguards to those in the Act, by means of an enforceable agreement between the agency and the foreign recipient;
- IPP 12(1)(c) — the foreign person or entity is participating in a prescribed binding scheme;
- IPP 12(1)(d) — the foreign person or entity is subject to a law that requires the recipient to protect the information in a way that, overall, provides comparable safeguards to those in the Act;
- IPP 12(1)(e) — the foreign person or entity is in a prescribed country under s 214 of the Privacy Act 2020 — i.e., a country prescribed by Order in Council on the basis that the country has comparable safeguards. No country has been prescribed under s 214 at the Effective date.
- IPP 12(1)(f) — the individual expressly authorises the disclosure to the foreign person or entity after being informed by the agency that the foreign person or entity may not be required to protect the information in a way that, overall, provides comparable safeguards.
Balance relies on the following stack to satisfy IPP 12 for the New Zealand → US transfer:
- IPP 12(1)(b) enforceable contract. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that contractually requires the recipient to protect New Zealand-resident personal information in a way that, overall, provides comparable safeguards to those in the Privacy Act 2020. The full transfer pack is in our international-transfer pack § 6. The contractual safeguards are reinforced by EU SCC substance + UK IDTA substance + APP-aligned substance as substantive overlays.
- IPP 12(1)(f) express authorisation. As a belt-and-braces overlay, the parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the US recipient may not be subject to a privacy regime with safeguards comparable to those in the Privacy Act 2020, and identifies the country of destination and the categories of recipients. Cross-reference: Privacy Policy § 12 + the in-app consent screen.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of New Zealand-resident personal information to a third country outside the IPP 12 framework without the controller's prior written authorisation.
8.2 The EU-to-NZ axis (incoming transfers) — EU adequacy decision
Commission Implementing Decision 2013/65/EU of 19 December 2012 finds that New Zealand provides an adequate level of protection for personal data. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to New Zealand under the 2013/65/EU adequacy decision.
For Balance, the EU adequacy is relevant only in respect of any EU/EEA-resident data that transits through (or is processed in) New Zealand — which is not part of Balance's current data-flow architecture (Balance's backend is in the United States, not in New Zealand). The EU adequacy is therefore a context-setting fact, not a transfer mechanism for the Balance flows.
8.3 The NZ-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on the OPC NZ's recognised "comparable safeguards" list (because no country has been prescribed under s 214 at the Effective date), the NZ-KZ axis is covered by the IPP 12(1)(b) enforceable-contract route + IPP 12(1)(f) parent's express authorisation. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
9. Data residency for New Zealand residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any New Zealand resident's personal information held in New Zealand? | No. Every New Zealand resident's personal information is held in the United States. The IPP 12 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there a New Zealand establishment? | No. Balance has no permanent establishment in New Zealand. The Privacy Act 2020 s 4 extraterritorial reach (overseas agency carrying on business in NZ) is the basis for Balance's Privacy Act compliance. |
| Where is the supervisory authority? | New Zealand — OPC NZ + the regulatory bodies in § 3.2 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. New Zealand does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Health Information Privacy Code 2020 under the Privacy Act 2020 — health-information handling; not applicable to Balance because Balance does not collect health information).
10. Sub-processors touching New Zealand-resident data
| Sub-processor | Role | Location of processing | NZ transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | IPP 12(1)(b) enforceable contract with comparable-safeguards clauses + IPP 12(1)(f) parent's express authorisation on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
IPP 12(1)(b) enforceable contract (Google Cloud Data Processing Addendum) + IPP 12(1)(f) parent's express authorisation; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
IPP 12(1)(b) enforceable contract (Google Cloud Data Processing Addendum) + IPP 12(1)(f) parent's express authorisation; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to NZ kid + parent devices | United States | IPP 12(1)(b) enforceable contract + IPP 12(1)(f) parent's express authorisation; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | IPP 12(1)(b) + IPP 12(1)(f) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | IPP 12(1)(b) + IPP 12(1)(f) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to NZ parent users | United States | IPP 12(1)(b) enforceable contract + IPP 12(1)(f) parent's express authorisation. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + IPP 5 (storage and security). The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — Privacy Act 2020 Part 6 (Notifiable Privacy Breaches scheme)
Privacy Act 2020 Part 6 (ss 112–119) sets the breach-notification regime — in force since 1 December 2020 with the Act's commencement:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| OPC NZ | A notifiable privacy breach has occurred — defined at Privacy Act 2020 s 112 as a privacy breach that it is reasonable to believe has caused serious harm to an affected individual or individuals or is likely to do so (the "serious harm" test at s 113 — assessed against any action taken to reduce the risk of harm; the sensitivity of the information; the nature of the harm; etc.). | As soon as practicable after the agency becomes aware that a notifiable privacy breach has occurred (Privacy Act 2020 s 114). Balance internal anchor: 72 hours (consistent with the GDPR Art 33 benchmark; faster than the Privacy Act "as soon as practicable" floor). | OPC NZ online NotifyUs portal at https://privacybreach.privacy.org.nz/ |
| Affected individuals | Same trigger as the OPC NZ notification. | As soon as practicable after the agency becomes aware of the breach (Privacy Act 2020 s 115). Balance internal anchor: 72 hours. | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English (te reo Māori on request). |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | DIA Digital Safety Group + NZ Police NCCU + OFLC + NetSafe. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, OPC NZ notification within the 72-hour Balance internal anchor, affected-individual notification at the same point unless the s 116 carve-outs (delay in notification permitted where the delay is in the interests of the public; where there is reasonable apprehension that notification would prejudice law enforcement; where notification would risk further harm) apply.
11.1 Minimum content of the OPC NZ NotifyUs notification (Privacy Act 2020 s 116)
The OPC NZ notification states:
- the name of the agency and the privacy officer contact (, named individual: );
- a description of the breach;
- when the breach occurred and when it was discovered;
- the personal information that was the subject of the breach;
- the affected individuals (or the categories of affected individuals if not yet identified);
- the steps the agency has taken or is taking to mitigate;
- whether the agency has notified or intends to notify the affected individuals;
- any other matters the Commissioner may require.
The English-language template lives in our breach-notification runbook § 8.1.
11.2 Offence to fail to notify (Privacy Act 2020 s 118)
A failure to notify the Privacy Commissioner of a notifiable privacy breach without reasonable excuse is an offence punishable on summary conviction by a fine not exceeding NZ$10,000 (Privacy Act 2020 s 118).
12. Cookies, spam, and electronic direct marketing
New Zealand does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) IPP 1 + IPP 3 + IPP 4 + IPP 10 + IPP 11 for any cookie that processes personal information; (ii) the OPC NZ's published guidance on online cookies and tracking technologies; (iii) the Unsolicited Electronic Messages Act 2007 (NZ) for commercial electronic messages; (iv) FTA s 9 misleading-or-deceptive-conduct for any cookie practice that misleads consumers; (v) ASA Codes.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages within the meaning of UEM Act 2007 s 6 to New Zealand residents. The only email Balance sends to NZ parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications, all of which fall outside the UEM Act's "commercial electronic message" definition (which requires the message to promote or solicit the supply of goods or services). If Balance ever introduces a marketing channel, we will comply with UEM Act s 9 (consent — express or inferred), s 10 (sender identification), and s 11 (functional unsubscribe facility).
13. Lawful-access requests and the encryption posture
New Zealand authorities may serve a lawful-access request on Balance via:
- A judicial production order under the Search and Surveillance Act 2012 (NZ) ss 71–78 — the principal mechanism for compelling production of stored personal information.
- A judicial search warrant under the SSA ss 6–10.
- A judicial surveillance device warrant under the SSA ss 45–70 (where Balance is not the surveillance target but holds the data — uncommon).
- An order of the District Court under the HDCA ss 18–19 (where the request is in the civil-enforcement context).
- A judicial production order under the Mutual Assistance in Criminal Matters Act 1992 (NZ), where the request comes from a foreign state.
- An OPC NZ investigation request under Privacy Act 2020 ss 79–87 (the Commissioner has the power to require any person to produce information).
- A Tribunal direction of the Human Rights Review Tribunal under Part 5 of the Privacy Act 2020.
- An ordinary District / High Court production order or subpoena duces tecum under the District Court Rules 2014 (NZ) or the High Court Rules 2016 (NZ).
- A judicial order under the Cybercrime Convention Act equivalent — New Zealand is a party to the Budapest Convention on Cybercrime (signed 23 November 2001; ratified 18 July 2023; in force for NZ from 1 November 2023).
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage New Zealand counsel to assess the validity of the request and the appropriate response under IPP 11(1)(d) (use or disclosure required or authorised by or under any enactment); 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the NZ Police NCCU, the DIA Digital Safety Group, NetSafe, and the OFLC on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure order, we will inform the affected parent of the request (IPP 3 + IPP 8). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the SSA Part 4 subpart 7, or under the Crimes Act 1961 s 312L), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — New Zealand / Aotearoa NZ
A New Zealand resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English (te reo Māori on request). - NetSafe / Te Pataka Tukatuka — INHOPE member; HDCA approved agency under s 8. Online:
https://netsafe.org.nz/. Phone: 0508 638 723 (toll-free within NZ). The principal NZ INHOPE-affiliated CSAE intake point. - Department of Internal Affairs — Digital Safety Group (formerly DIA Censorship Compliance Unit) — the principal enforcement agency for online CSAM under FVPCA + Crimes Act. Online:
https://www.dia.govt.nz/Digital-Safety. Phone: 0800 257 887. - NZ Police — emergency 111 (Triple One); non-emergency 105 (One-Oh-Five). NZ Police National Cyber Crime Unit (NCCU) for cyber-CSAE.
- NZ Police — Online Reporting at
https://www.police.govt.nz/use-105. - Crime Stoppers New Zealand —
https://www.crimestoppers-nz.org/; phone 0800 555 111. Anonymous reporting. - Kidsline — NZ's 24/7 helpline for children up to age 18. Phone: 0800 543 754 (0800 KIDSLINE). Online:
https://www.kidsline.org.nz/. - Youthline — NZ's helpline for young people aged 12–25. Phone: 0800 376 633 (0800 YOUTHLINE). Text: 234. Online:
https://www.youthline.co.nz/. - Office of Film and Literature Classification (OFLC) — Chief Censor — for classification queries on suspected objectionable material. Online:
https://www.classificationoffice.govt.nz/. - Ministry for Children — Oranga Tamariki — for child-welfare concerns. Phone: 0508 326 459 (0508 FAMILY). Online:
https://www.orangatamariki.govt.nz/. - Children's and Young People's Commission (Mana Mokopuna) — for child-rights complaints. Online:
https://www.manamokopuna.org.nz/. - ECPAT Child ALERT —
https://ecpat.org.nz/. Anti-CSEC NGO. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. NZ coordination via NZ Police + INTERPOL Wellington.
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A New Zealand resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Office of the Privacy Commissioner / Te Mana Mātāpono Matatapu (OPC NZ) | Privacy Act 2020 + IPPs | PO Box 10094, The Terrace, Wellington 6143; https://www.privacy.org.nz/; phone 0800 803 909 |
| NetSafe / Te Pataka Tukatuka | HDCA + online-harms triage | https://netsafe.org.nz/; phone 0508 638 723 |
| Department of Internal Affairs — Digital Safety Group | FVPCA + Crimes Act CSAM | https://www.dia.govt.nz/Digital-Safety; phone 0800 257 887 |
| Office of Film and Literature Classification (OFLC) | Classification under FVPCA | https://www.classificationoffice.govt.nz/ |
| Commerce Commission | FTA + CGA enforcement | https://comcom.govt.nz/; phone 0800 943 600 |
| DIA Anti-Spam Compliance Unit | UEM Act | https://www.dia.govt.nz/Spam |
| Disputes Tribunal of New Zealand | Consumer-protection disputes up to NZ$30,000 | https://www.disputestribunal.govt.nz/ |
| Human Rights Review Tribunal | Privacy Act 2020 Part 5 + Human Rights Act 1993 | https://www.justice.govt.nz/tribunals/human-rights/ |
| District Court of New Zealand | HDCA civil enforcement + ordinary civil claims | https://www.districtcourts.govt.nz/ |
| High Court of New Zealand | Common-law privacy torts + judicial review of OPC NZ | https://www.courtsofnz.govt.nz/ |
| Children's and Young People's Commission (Mana Mokopuna) | Children's-rights complaints | https://www.manamokopuna.org.nz/ |
| Ministry for Children — Oranga Tamariki | Child-welfare concerns | https://www.orangatamariki.govt.nz/; phone 0508 326 459 |
A New Zealand resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the privacy officer under Privacy Act 2020 s 201). We will respond within the Privacy Act 2020 timelines. Raising the matter with us first is not a precondition to complaining to the OPC NZ; the OPC NZ accepts complaints directly, though it often refers complainants back to the agency in the first instance.
16. Consumer rights — the CGA + FTA overlay
The Consumer Guarantees Act 1993 (NZ) and the Fair Trading Act 1986 (NZ) apply to Balance's subscription flow as a consumer-services contract — the parent is a consumer within the meaning of CGA s 2 (acquiring services of a kind ordinarily acquired for personal, domestic, or household use). Treatment is implemented in Subscription Terms § 20.
16.1 Consumer guarantees as to services (CGA ss 28–31)
The CGA implies into every consumer-services contract three non-excludable consumer guarantees:
- s 28 — Reasonable care and skill. The services must be carried out with reasonable care and skill.
- s 29 — Fitness for particular purpose. Where the consumer makes known to the supplier any particular purpose for which the services are required, the services must be reasonably fit for that purpose, unless the consumer does not rely on the supplier's skill or judgement.
- s 30 — Reasonable time for supply. Where the time for supply is not fixed, the services must be supplied within a reasonable time.
- s 31 — Reasonable price. Where the price is not determined, a reasonable price.
Failure to comply with a consumer guarantee triggers the substantial character analysis at CGA ss 36–38 and a consumer's right to remedy (repair, replacement, refund, or compensation).
16.2 Misleading or deceptive conduct (FTA s 9)
A person must not, in trade, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. The Balance marketing copy at balance.babayagaprogram.com and on the Google Play Store listing is drafted to avoid each FTA s 9 risk.
16.3 False or misleading representations about services (FTA s 11)
A person must not, in trade, make a false or misleading representation about a service. Civil pecuniary penalties up to NZ$200,000 (individual) / NZ$600,000 (body corporate) under FTA s 40A. Criminal penalties under FTA s 40 for knowing offences.
16.4 Unfair contract terms (FTA s 26A)
In a standard form consumer contract, a court may declare a term to be unfair and therefore void to the extent of the unfairness. A term is unfair if it: (a) would cause a significant imbalance in the parties' rights and obligations; (b) is not reasonably necessary to protect the legitimate interests of the party advantaged by it; and (c) would cause detriment (whether financial or otherwise) to a party if it were to be applied or relied on. The 2022 amendment (in force from 16 August 2022) extended the unfair-contract-terms regime to small trade contracts and increased the Commerce Commission's enforcement powers. Civil pecuniary penalties up to NZ$200,000 (individual) / NZ$600,000 (body corporate) under FTA s 40A. The Balance Terms of Service (Terms of Service) are drafted to avoid each FTA s 26A unfair-term risk.
16.5 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the CGA or the FTA to the prejudice of the NZ consumer are unenforceable under CGA s 43 (which voids contracting out of the consumer guarantees) and FTA s 5C (which preserves the application of the FTA).
16.6 Disputes Tribunal
The Disputes Tribunal of New Zealand offers a low-cost, no-lawyer-required forum for consumer-protection disputes up to NZ$30,000 (s 10 Disputes Tribunals Act 1988). The Balance subscription value never approaches NZ$30,000.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — written processor agreements with IPP 12(1)(b) comparable-safeguards clauses on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA) — confirms the New Zealand EU adequacy (2013/65/EU) under GDPR Art 45.
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the Privacy Act 2020 (NZ) — including any amendment to the 13 IPPs or to Part 6 (Notifiable Privacy Breaches scheme) — triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- A new Order in Council under Privacy Act 2020 s 214 prescribing a "prescribed country" for IPP 12(1)(e) triggers an off-cycle update to § 8 + § 10 of this Annex.
- A new code of practice issued by the Privacy Commissioner under Privacy Act 2020 ss 32–46 that materially affects Balance's posture triggers an off-cycle update.
- A material amendment to the HDCA, the FVPCA, or any associated regulation triggers an off-cycle update to § 5 + § 14.
- A material amendment to the Crimes Act 1961 (in particular ss 124, 124A, 131B, 132, 134, 144A) triggers an off-cycle update to § 13 + § 14.
- A material amendment to the UEM Act 2007, the SSA 2012, the TICSA 2013, or the Customs and Excise Act 2018 triggers an off-cycle update to the relevant operational section.
- A material amendment to the CGA, the FTA, or any associated regulation triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to the Oranga Tamariki Act 1989, the Children's Act 2014, the Care of Children Act 2004, or the Mana Mokopuna — Children's and Young People's Commission Act 2023 triggers an off-cycle update to § 5 + § 7 + § 14.
- A material judgment of the Supreme Court of New Zealand or the Court of Appeal of New Zealand on the common-law privacy torts (Hosking v Runting, C v Holland) or on any Privacy Act 2020 provision triggers an off-cycle update.
- A material OPC NZ casenote, Commissioner's Report, compliance notice, or access direction that materially affects Balance's posture triggers an off-cycle update.
- The European Commission rescinding or modifying Decision 2013/65/EU (the NZ EU adequacy decision) triggers an immediate off-cycle update to § 8 + § 9.
- New Zealand's accession to the Council of Europe Convention 108 or Convention 108+ triggers an off-cycle update to § 2 + § 8.
- A material change to a sub-processor's IPP-12-aligned status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The privacy officer signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The authoritative te reo Māori translation is queued for the Phase-2 locale rollout per our internal compliance tracker.
End of New Zealand Country Annex / Whakamutunga o te Tāpiritanga ā-whenua mō Aotearoa.