compliant facial recognition
author Watchlist Teamdate 06 Jul 2026

Compliant Facial Recognition: What NZ Organisations Need to Know in 2026

Facial recognition technology has arrived in New Zealand in a serious way. Retailers, logistics companies, commercial landlords and public sector agencies are either actively deploying it or evaluating it. But 2026 marks a turning point: this is the year the legal framework catches up with the technology and compliance is no longer optional.

If your organisation is using facial recognition software or planning to here is what you need to understand.

The Regulatory Baseline Has Changed

New Zealand's Biometric Processing Privacy Code 2025 (the Code) came into force on 3 November 2025. It was issued under the Privacy Act 2020 and establishes 13 specific rules governing how organisations collect, store, use and delete biometric information including facial images processed through automated systems.

Two compliance dates matter:

• New systems deployed from 3 November 2025 onward must comply immediately

• Systems already in use before 3 November 2025 have until 3 August 2026 to achieve compliance

That second deadline is imminent. Any organisation running facial recognition software that predates November 2025 has a limited window to bring its practices, policies and governance into line with the Code.

What the Code Requires

The Code is built around necessity, proportionality and accountability. At a practical level, this means organisations must:

Conduct a Proportionality Assessment before deployment. This assessment must weigh the benefits of biometric processing against the privacy risks and explicitly consider cultural factors, including potential impacts on Maori individuals and communities.

Complete a Privacy Impact Assessment (PIA). A PIA is mandatory before any biometric processing begins. It must document the risks and the mitigations in place.

Provide meaningful notification. Individuals must be clearly informed that biometric technology is in use and how their information may be processed. This goes beyond a generic privacy policy.

Offer genuine alternatives where applicable. In workplace or access-control scenarios, individuals must generally be offered a non biometric alternative to enrolment unless a specific exemption applies.

Implement deletion and retention controls. Images of individuals who do not match a watchlist must be deleted immediately. Retention periods for matched data must be defined, justified and enforced.

Enable access, correction and complaint handling. Individuals have rights under the Privacy Act 2020 to access and correct information held about them. Your systems and processes need to support this.

What the Privacy Commissioner Has Said

The Office of the Privacy Commissioner has been active in shaping how the Code is applied in practice. Its inquiry into Foodstuffs North Island's facial recognition trial which involved scanning more than 226 million faces across 25 supermarkets found the use justified, but only because of the specific safeguards in place: immediate deletion of non-matched images, exclusion of minors and vulnerable individuals from watchlists and mandatory human verification of every match before any action was taken.

The Commissioner's message to the broader market is clear: the technology can be used lawfully, but the safeguards need to be real, documented and independently verifiable.

High-Risk Uses Face Extra Scrutiny

The Code specifically flags certain uses as higher risk, including real-time facial recognition in public spaces and profiling individuals based on biometric data. These applications face stricter requirements and will receive closer attention from regulators.

This doesn't mean they're prohibited it means they require stronger justification, more robust safeguards and more careful governance than lower-risk applications like access control for secure premises.

Why Responsible Biometric Deployment Matters Beyond Compliance

Compliance is the floor, not the ceiling. Organisations that treat the Code purely as a compliance checklist will find themselves revisiting their frameworks every time the regulatory environment shifts. Organisations that embed responsible biometric deployment as a genuine operating principle designing privacy in from the start, maintaining audit trails, reviewing watchlist criteria regularly and being transparent with affected communities will be better positioned for the long term.

This matters especially in New Zealand's operating environment, where public trust in biometric technology is still being formed. The organisations that get this right in 2026 will have an advantage that compounds over time.

How Watchlist.nz Supports Compliance

Watchlist.nz's facial recognition platform is built for the NZ regulatory environment. The platform supports:

•  Proportionality and Privacy Impact Assessment documentation

•  Automated deletion of non-matched images

•  Configurable retention periods with full audit trails

•  Human review workflows before any alert triggers action

•  Watchlist governance controls including exclusion criteria for minors and vulnerable individuals

If your organisation is approaching the August 2026 deadline and needs to assess whether your current facial recognition software meets the Code's requirements, we can help.