Your Face Is Not Your Password: The Biometric Code Deadline NZ Boards Just Ran Out of Runway On
Two hundred and twenty-five million faces. To be exact, 225,972,004 of them, scanned across twenty-five North Island supermarkets in seven months. That was the Foodstuffs North Island facial recognition trial, and in June 2025 the Privacy Commissioner ruled that it complied with the law as it then stood. The trial ran, the cameras worked, an independent evaluator found it had prevented more than one hundred cases of serious harm, and the regulator signed it off.
Now hold that number in your mind and change one thing: the date. Run the same trial today and it fails a completely different test. Not because the technology changed, but because on 3 August 2026, in less than three weeks, the rules that govern every organisation using biometric technology in New Zealand stop being a transition project and start being enforceable.
This is the article the Cyber News Cycle has not yet written, and the one most boards have not yet read. The New Zealand Biometric Processing Privacy Code 2025 has existed since it was issued on 6 August 2025. It came into force for any new biometric processing on 3 November 2025. What arrives on 3 August 2026 is the end of the nine-month runway for everyone who was already using the technology before that date. From that Monday, the Code's thirteen Rules apply in full, and enforcement begins against organisations that have been in breach throughout the transition period.
The board question is not "what does the Code say?" The Code has been published, guided, and explained for eleven months. The board question is sharper and more uncomfortable: can we produce the documented proportionality assessment right now, including our Māori cultural impact analysis, if the Privacy Commissioner asks for it on 4 August?
The wall in the first week of August
The Biometric Code deadline does not arrive alone. It sits inside a concentrated compliance wall, three board-owned obligations landing five days apart, in a calendar week when many boards will not be in formal session.
On 29 July 2026, the Governance of Biometric and Space Infrastructure regime brings a registration obligation with an entity fine of two hundred and fifty thousand dollars for non-registration. On 2 August 2026, the European Union Artificial Intelligence Act's Article 50 transparency obligations become operative for New Zealand organisations with European exposure. On 3 August 2026, the Biometric Code's existing-user compliance deadline falls. Three deadlines, one week, three different regulators.
The Biometric Code has received far less board attention than the health-sector breach narrative or the fining-powers debate that this series covered in earlier articles. That is the gap. The Code exists, the deadline is imminent, and the governance work most boards needed to complete before 3 August has either not started or not finished. This is where the runway closed while everyone was looking at something else.
The case the regulator has already run
The Foodstuffs North Island trial matters because it is not hypothetical. It is the closest thing New Zealand has to a worked example of how the regulator engages with a large biometric deployment, and the numbers are worth stating in full.
The trial ran across twenty-five supermarkets from roughly February to September 2024. During those seven months, the system scanned 225,972,004 faces. It generated 1,742 alerts, of which 1,208 were confirmed matches. An independent evaluator concluded the trial had prevented more than one hundred cases of serious harm, including assaults on staff. In June 2025 the Privacy Commissioner found the use was justified by that harm-reduction evidence under the Privacy Act 2020 as it then stood.
Read the conditions the Commissioner attached, because they are a preview. Before the technology could be used permanently or expanded, the regulator wanted more accurate testing on the New Zealand population, because the system had not been trained on New Zealand data. It wanted documented measures to address bias risk for Māori and Pacific peoples, where false-positive rates were identified as a concern. It wanted stronger transparency for customers at the point of entry, and more rigorous governance over who goes on a watchlist, for how long, and on what basis.
Every one of those conditions is now a Rule. What the Commissioner asked for as an improvement in 2025 the Code requires as a baseline in 2026. Run the Foodstuffs trial today and, before a single camera switches on, you need a documented proportionality assessment with a Māori cultural impact analysis, visible signage at the door, a genuine opt-out pathway, active watchlist governance, and encryption and audit controls. Good intentions and a harm-reduction case are no longer enough on their own. The documentation is the obligation.
What the Code governs, and what it does not
Boards need to know quickly whether they are in scope, and the exclusions matter as much as the inclusions.
The Code applies to any organisation subject to the Privacy Act 2020 that collects and uses biometric information through automated processing to identify, verify, or categorise individuals. Biometric information here means data derived from physical, physiological, or behavioural characteristics: facial recognition, fingerprint scanning, voice recognition, gait analysis, and similar. It applies regardless of size or sector, to businesses, government agencies, and non-government organisations alike.
What sits outside it is narrower than most directors assume. Consumer devices used purely for personal purposes are excluded: your phone's facial sign-in, a fitness tracker, a smartwatch. Manual collection without automated processing is excluded. Brain-activity measurement is excluded. Health information processed by health agencies for clinical purposes falls under the Health Information Privacy Code instead. Certain national security agencies are excluded by schedule.
The boundary that catches people is the healthcare one. A hospital's clinical use of biometrics belongs to the Health Information Privacy Code. But the same hospital's fingerprint scanner on the staff entry door, used for building access rather than clinical identification, falls under the Biometric Code. The distinction is the purpose, not the setting. This reading is drawn from the regulator's factsheets and consistent law-firm analysis rather than a single direct statement, so treat it as the settled professional consensus it is, and confirm your own edge cases.
The three obligations that cannot be retrofitted in days
The Code contains thirteen Rules, each modifying the equivalent Information Privacy Principle. Three of them impose obligations that are materially harder than the principles they replace, and none can be produced overnight.
Rule 1, proportionality. An organisation must be able to demonstrate, on reasonable grounds, that its biometric processing has a lawful purpose, that it is necessary in the sense of being effective with no less-invasive alternative reasonably available, and that the privacy impact is proportionate to the benefit, taking into account the cultural impacts and effects on Māori as a mandatory factor. The regulator's recommended vehicle is a Privacy Impact Assessment. A proper one identifies the system and its data flows, documents evidence of effectiveness, assesses the alternatives that were rejected and why, and includes a cultural impact assessment specific to Māori. That work takes weeks, not days, and a Rule 1 breach does not need a complaint to trigger an inquiry.
Rule 3, transparency and alternatives. Before or at the point of collection, the organisation must tell people biometric data is being collected, state the purpose, and disclose whether a non-biometric alternative exists. In practice, a workplace fingerprint scanner needs a working swipe-card or PIN option that is genuinely available in operation, not merely written into a policy. A retail facial recognition camera needs prominent signage at the entrance, not a privacy-policy link. Amendment No 1 to the Code, made in March 2026 to align with Information Privacy Principle 3A, added an indirect-collection notification obligation for the common case where a camera captures a face without direct interaction.
Rule 10, retention and disposal. Biometric information must be deleted or de-identified once the purpose it was collected for is achieved or no longer needs it. A facial template linked to a named person on a retail watchlist may not sit there indefinitely; each entry requires active review of whether retention is still justified. A watchlist that grew unchecked through the transition period is a Rule 10 breach from 3 August. The other Rules cover fairness, security safeguards, access and correction rights, accuracy, use limits, disclosure, and overseas transfer. The Code also bans using biometrics to infer emotion, health, or ethnicity outside narrow permitted contexts.
The uses most organisations have not thought about
Ask a board where its biometric exposure sits and most will point at cameras. The more common exposure is the fingerprint scanner on the timekeeping clock and the access door.
Fingerprint-based timekeeping and physical access control are in scope, and they are among the least-governed deployments in the country. For an employer, Rule 1 is a genuine hurdle here: swipe cards, PIN entry, and proximity cards are readily available, lower-privacy alternatives for both timekeeping and access, so the proportionality case for fingerprints needs specific justification, such as a documented fraud or accuracy problem that less-invasive methods failed to solve. Rule 3 requires a real alternative offered to staff. The mandatory Māori cultural impact assessment applies, and for organisations with significant Māori workforces that means genuine engagement, not a tick-box.
There is a direct line to the board table. A director who signs off the annual payroll-system renewal after 3 August, where that system is integrated with biometric timekeeping, and who has not confirmed Code compliance, has a documented governance gap on the record.
Financial services carry their own version. Biometric liveness checks in anti-money-laundering onboarding, the video selfie paired with a document scan, are in scope. The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 provides the lawful purpose, but it does not satisfy the Code. The two regimes are cumulative, not alternatives: identity verification is the purpose, and the Code still requires documented proportionality, customer notification, retention limits on facial templates, and security safeguards on top. That the Code applies in addition to the anti-money-laundering regime rather than being displaced by it is an analytical reading of both instruments, since no regulator has issued direct guidance on the intersection, but it is the safe reading for a board to plan against. For deposit-takers, there is a further layer forming: the Reserve Bank's Operational Resilience Standard, released in exposure-draft form for consultation in June 2026, is drafted to require documented board-level tolerance levels for critical operations, and its draft guidance contemplates assessing whether an artificial intelligence failure or bias could impair a critical operation. The standard's existence and the consultation are settled; the exact wording of that clause is still draft. A deposit-taker's board that has addressed neither its biometric obligations nor its resilience tolerances is carrying two open exposures, not one.
Where the Cultural Security Envelope stops being a metaphor
For years I have argued that cultural values, including Te Tiriti obligations, belong inside security and technology governance rather than beside them. I called that the Cultural Security Envelope. The Biometric Code is the first New Zealand privacy instrument to put that principle into a specific, enforceable Rule.
Rule 1's proportionality assessment must include the cultural impacts and effects of biometric processing on Māori. This is not advisory language, and it is not a statement of values in a preamble. It is an element of a substantive compliance obligation, and failure to document it is a breach. For any biometric system operating where Māori staff or customers are present, the assessment has to address algorithmic bias risk, the same higher false-positive concern flagged in the Foodstuffs trial, and it has to consider that biometric data can be understood as taonga under Māori data sovereignty frameworks.
During the Code's development, a higher standard was on the table. Some Māori data sovereignty advocates argued that free, prior, and informed consent should be a standalone requirement for biometric processing affecting Māori. The Code's authors classified it as a safeguard consideration rather than a substantive requirement. I raise that as a factual description of how the instrument was built, not to adjudicate it; that debate is contested and it is not the board's to settle. The governance point is simpler and it is squarely within a board's remit: the mandatory cultural impact assessment is the floor the Code sets, and an organisation is free to hold itself to a higher standard than the floor if it chooses. Treating Rule 1's cultural requirement as a compliance chore to be minimised is the reading most likely to age badly.
The enforcement gap, and the direction of travel
Here is the part that lulls boards into complacency, and why that is a mistake.
The current enforcement pathway is modest. The regulator receives a complaint or opens its own inquiry, investigates, and can issue a compliance notice requiring the organisation to act or stop. Failure to comply with that notice without reasonable excuse is a criminal offence under section 127 of the Privacy Act 2020, carrying a maximum fine of ten thousand dollars. Serious matters can be referred to the Human Rights Review Tribunal, which can order remedies and award damages. Ten thousand dollars is not a number that changes board behaviour, and everybody knows it.
Now read it against the trajectory. In June 2026 the Privacy Commissioner stated publicly that he wants the Privacy Act rewritten to allow penalties "running into the millions for the worst cases, the kind of number that forces a board to take data security seriously before something goes wrong rather than after." That is the clearest statement yet of where the office wants to go, and it came in the same month the regulator issued compliance notices in a prominent health-sector inquiry, showing it will use the tools it already has against organisations that matter. To be clear about the analysis: no reform is enacted or committed, and framing whether it should be is not a board's job or mine. The governance inference is the one that follows from the sequence. A compliance notice issued in August 2026 creates a durable record of non-compliance. If a stronger penalty regime is later enacted, that record is the foundation any retrospective action would build on. This is what the Fiduciary Risk Exposure framework has always described: the real cost of a missing proportionality assessment on 3 August is not the ten-thousand-dollar exposure, it is the entry in the enforcement record that exists when the law changes underneath you.
Where New Zealand sits, and why offshore boards should care
New Zealand's Code occupies a middle position internationally, and for boards with cross-border operations the comparison is not academic, because foreign obligations stack on top of the Code rather than replacing it.
The European Union is materially stricter. Article 5 of its Artificial Intelligence Act, in force since February 2025, prohibits real-time remote biometric identification in public spaces for law-enforcement purposes except in three narrow, judicially authorised cases, and bans systems that infer ethnicity, political opinion, or similar traits from biometrics, along with emotion recognition in workplaces and schools. New Zealand regulates retail facial recognition rather than banning it, and prohibits inference of emotion and ethnicity across all uses. Australia has no standalone biometric code yet; its Privacy Act treats biometric data as sensitive information requiring heightened protection, which currently makes New Zealand's regime the more specific of the two. The United Kingdom requires proportionality and documentation broadly comparable to ours, but with penalties reaching seventeen and a half million pounds or four per cent of global turnover. The United States has no federal biometric law; the strongest state regime, Illinois, allows individuals to sue directly. The comparison that follows, that New Zealand's Code is currently the more demanding instrument in its immediate region, is an analytical reading of the public facts rather than a figure from a single comparative study, but it holds. A New Zealand retailer with Australian stores answers to both regimes. A New Zealand financial-technology firm with European customers answers to the Article 5 prohibitions as well as the Code. Cumulative, not either-or.
The sovereignty question sits one layer beneath the compliance question, and it turns a privacy matter into a procurement one. Facial recognition algorithms are largely built offshore and trained on populations that do not resemble New Zealand's. The United States National Institute of Standards and Technology, the NIST, runs the Face Recognition Vendor Test, and its demographic study found false-match rates varying by a factor of between ten and one hundred across ethnic groups. For a board that is not an abstract fairness point. It is a data-residency question: which vendor holds the matching capability, on whose soil the biometric templates are processed, and under whose lawful-access regime they sit. A template that leaves New Zealand is an operational dependency a proportionality assessment has to name rather than assume away. Sovereign control of identity infrastructure is not a slogan; it is a line item in the Rule 1 evidence file.
None of this is retrievable retroactively. A complaint that lands on 4 August cannot be answered by starting the assessment on 5 August. This is the Once-Only Resilience principle in regulatory form: the governance has to exist before the moment that tests it, because the deployment that ran without documentation through the transition period has already accrued the debt. Retrofitting proportionality assessments, vendor reviews, opt-out mechanisms, and retention schedules now is the interest payment on architecture that went in without the governance that is now mandatory.
So the exercise for your next board meeting is not a briefing on biometric technology. Your people already know the systems exist. The exercise is to answer one question with evidence rather than assurance: if the Privacy Commissioner asked your board on 4 August to produce your documented proportionality assessment, including your Māori cultural impact analysis and your vendor's data-residency position, what would you actually hand over, and how long ago was it written?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
References
[1] Office of the Privacy Commissioner. "Biometric Processing Privacy Code 2025." Issued 6 August 2025; in force 3 November 2025. https://www.privacy.org.nz/responsibilities/biometric-processing-privacy-code/
[2] Office of the Privacy Commissioner. "Biometrics: Who and what does the Code apply to, and Factsheets 1 and 2." October 2025 guidance updates. https://www.privacy.org.nz/responsibilities/biometrics/
[3] Office of the Privacy Commissioner. "Inquiry into Foodstuffs North Island facial recognition technology trial: results statement." June 2025. https://www.privacy.org.nz/publications/statements-media-releases/
[4] 1News. "Privacy Commissioner rules on supermarket facial recognition trial." 4 June 2025. https://www.1news.co.nz/
[5] Simpson Grierson. "New Zealand's Biometric Processing Privacy Code: what organisations need to do." November 2025. https://www.simpsongrierson.com/
[6] Bell Gully. "Biometric Processing Privacy Code: privacy penalties and personal liability." 2026. https://www.bellgully.com/
[7] MinterEllisonRuddWatts. "Biometrics regulation in New Zealand: the new Code explained." November 2025. https://www.minterellison.co.nz/
[8] Parliamentary Counsel Office. "Privacy Act 2020, section 127 (offence to fail to comply with compliance notice)." https://www.legislation.govt.nz/act/public/2020/0031/latest/whole.html
[9] NewsWire New Zealand. "Privacy Commissioner calls for multi-million-dollar fining powers." June 2026. https://www.newswire.co.nz/
[10] European Union. "Artificial Intelligence Act, Article 5 (prohibited practices)." In force February 2025. https://artificialintelligenceact.eu/article/5/
[11] Reserve Bank of New Zealand. "Operational Resilience Standard: exposure draft and consultation (Deposit Takers Act Tranche 3)." June 2026. https://www.rbnz.govt.nz/
[12] National Institute of Standards and Technology. "Face Recognition Vendor Test Part 3: Demographic Effects (NISTIR 8280)." https://www.nist.gov/programs-projects/face-recognition-vendor-test-frvt

