NZTeco Limited | ZKTeco Supplier
Article

Biometric Privacy in New Zealand: Let’s Clear the Air

Clear guidance on biometric privacy in New Zealand, including the Biometrics Code, ZKTeco’s official claims, configurable photo and encryption features, hosting and responsibilities.

NZTeco Biometric Privacy in New Zealand

Table Of Contents

What you really need to know about biometric privacy compliance, data, and separating fact from fiction

At NZTeco, we believe transparency builds trust. In an age where facial recognition, fingerprint scanners, and biometric attendance are becoming more common, many New Zealanders are asking: "Where does my data go? Who sees it? Is it safe?" — This article aims to clear that up.

TL;DR

Biometric privacy in NZ — the short version

Biometric systems don't simply keep a photo of your face or fingerprint. They convert biometric characteristics into an encrypted mathematical template, while businesses still need to handle that information properly under New Zealand privacy requirements.

Templates, not photos Faces, fingerprints and palms are converted into encrypted biometric templates rather than stored as ordinary images.
You choose where it is hosted Data can remain on the device, on your own server, or with a chosen cloud provider — it isn't automatically sent overseas.
Privacy responsibilities still apply Organisations collecting biometric information need appropriate security, access controls and privacy processes.
People should know it's being used Staff and visitors should be informed about biometric collection, and businesses need processes for handling privacy requests.

Biometric privacy in New Zealand is not just about where data is hosted. It also depends on how biometrics are used, what information the system collects, which features are enabled, how the system is secured, how long information is retained, and who is responsible for it.

At NZTeco, we believe clear information builds trust. Facial recognition, fingerprint readers, and palm-based access systems can offer security and convenience, but they need to be selected, configured, and managed carefully. This article explains what New Zealand organisations should know, what ZKTeco officially says about its technology, and which details must be confirmed for each deployment.

Quick facts

  • A biometric template is different from a photograph or raw fingerprint image, but it is still biometric information and personal information under New Zealand privacy law.
  • ZKTeco products commonly use templates for biometric matching. Some products can also store or transfer user photos, biometric photos, and event snapshots.
  • Encryption and secure communications depend on the product, software, firmware, and configuration. HTTPS is optional and configurable on some ZKTeco devices.
  • Systems may be deployed on a device, on a customer-managed server, through on-premises software, or through a cloud service. The actual data location must be confirmed for the chosen deployment.
  • The Privacy Act 2020 and the Biometric Processing Privacy Code 2025 can apply. A supplier statement about an encrypted template does not, by itself, make a deployment compliant.

New Zealand’s biometric privacy rules

The Biometric Processing Privacy Code 2025 establishes specific privacy rules for organisations that collect biometric information for automated verification, identification, or categorisation. The Code came into force on 3 November 2025. The transition period for organisations already using covered biometric systems ended on 3 August 2026.

Before collecting biometric information, an organisation generally needs to establish that:

  • collection serves a lawful purpose connected with its functions or activities;
  • biometric processing is necessary for that purpose;
  • reasonable privacy safeguards have been adopted and implemented; and
  • the benefit is proportionate to the privacy risks and impacts, including cultural impacts and effects on Māori.

Organisations also need to tell people clearly that biometric information is being collected, explain each purpose of collection, and state whether a non-biometric alternative is available. The Code also covers security, access, correction, retention, use, disclosure, and disclosure outside New Zealand. The Office of the Privacy Commissioner provides detailed biometrics guidance and examples. Organisations should consider completing a Privacy Impact Assessment before deploying or materially changing a biometric system.

What ZKTeco officially says

ZKTeco publishes Guidelines on the Use of Biometric Data. In that guidance, ZKTeco states that its biometric algorithms extract selected feature points for matching rather than collecting complete biometric features. It also says that its hardware and software apply encryption techniques, and that templates are deleted from hardware and software permanently according to the applicable situation.

ZKTeco’s guidance also places important responsibilities on the organisation using the system. It says the data user is responsible for informing people, collecting templates lawfully and fairly, avoiding unnecessary retention, and controlling any new use of information. These are ZKTeco’s official statements. They should be read alongside the documentation for the exact device, software version, and deployment; they do not substitute for checking the actual configuration or meeting New Zealand legal obligations.

Templates, photos, and event snapshots are not the same thing

During enrolment, a biometric system obtains a sample—such as a face scan or fingerprint—and extracts information used to create a template for matching. That does not mean every ZKTeco system operates on template data alone. Official ZKTeco specifications show that some devices have separate capacities for face templates, user photos, and event photos, and may support event snapshots. ZKTeco software documentation also describes transferring and retrieving user photos and biometric photos in supported configurations.

For that reason, the right questions are:

  • Does the model retain an enrolment image or user photo?
  • Is event snapshot capture supported and enabled?
  • Can photos be uploaded or downloaded from management software?
  • Which information is stored on a device, server, backup system, or cloud service?
  • What is deleted when a person is removed, including from backups and exported files?

The answers vary by model, firmware, software, and configuration.

Encryption and secure communications

ZKTeco’s current ZKBio CVSecurity product information claims 256-bit AES data protection. Some ZKTeco device specifications also list encrypted HTTPS communications, but on certain models HTTPS is described as optional. ZKTeco’s support guidance instructs administrators to select HTTP or HTTPS to match the software configuration.

This means it is not accurate to assume every ZKTeco system is encrypted at every stage automatically. A deployment review should confirm:

  • whether HTTPS is supported and enabled between devices, software, and browsers;
  • whether information is encrypted at rest and which component performs the encryption;
  • how encryption keys and certificates are created, stored, renewed, and revoked;
  • whether backups, exports, APIs, and mobile integrations receive equivalent protection;
  • which administrator roles can view, export, or delete biometric and identity information; and
  • whether device and software versions remain supported and current.

Encryption is an important safeguard, but it is one part of a broader security and privacy programme.

Where information can be stored

Depending on the selected system, information may be held:

  • locally on a biometric terminal;
  • on software installed on a customer-managed server;
  • in a private-cloud environment operated for the customer;
  • in a vendor or third-party cloud service; or
  • in backups, exports, integrations, or connected workforce-management systems.

For example, ZKTeco describes ZKBio Time as web-based software that can operate as a private cloud, while ZKBio Time Cloud is a separate AWS-based service. An AWS reference alone does not establish the country or region in which a particular customer’s data is stored. Before deployment, organisations should document the real data flow and confirm every hosting region and service provider contractually.

If biometric information is disclosed outside New Zealand, rule 12 of the Biometric Processing Privacy Code may require additional grounds and protections.

Who is responsible for the information?

Responsibility depends on the roles each party performs—not simply on who manufactured or installed the equipment. Under the Office of the Privacy Commissioner’s section 11 guidance, a provider that stores or processes personal information solely for a customer may be acting on the customer’s behalf. The customer can still be treated as holding the information and remain responsible for meeting privacy obligations. If a provider also uses or discloses information for its own purposes, both organisations may have responsibilities.

Contracts should therefore identify who controls the information, who can access it, what each party may do with it, how incidents are managed, and what happens when the service ends. NZTeco’s role can differ between supply-only, installation, support, and hosted-service arrangements. Responsibilities and data flows should be documented for the actual service provided.

Privacy-relevant features may vary and be configurable

Official ZKTeco documentation shows that features vary between products and may require configuration:

  • User and profile photos: Supported by some models and software. Display of a user photo can be enabled in device settings on supported products.
  • Event photos and snapshots: Some facial and fingerprint terminals list event-photo capacity or an Event Snapshot feature.
  • HTTP or HTTPS: HTTPS is optional and configurable on some products and must be enabled consistently with server configuration.
  • Remote face enrolment and photo transfer: Available only on supported device, firmware, and software combinations.
  • User-ID masking and verification-name display: Supported devices can expose settings controlling which identifying information appears after verification.
  • Server connectivity: Device settings can specify a customer server or cloud/ADMS endpoint.
  • Authentication methods: Face, fingerprint, palm, card, and PIN options depend on the device and can be selected to suit the use case.

These controls are useful, but availability should never be assumed. NZTeco recommends recording the device model, firmware, software version, and agreed configuration during installation handover.

Correcting common biometric privacy myths

Myth: “A biometric terminal always stores my photograph forever.”

Reality: Many systems use biometric template matching, but some devices and software can also retain user photos, biometric photos, and event snapshots. Retention depends on product configuration. An organisation should disclose what is collected, why it is needed, and when it will be deleted.

Myth: “A template cannot be abused, so a breach would not matter.”

Reality: Templates are intended to be different from raw images, and ZKTeco describes its template process as non-reversible. However, biometric information remains sensitive. A compromised password can be changed; a person’s face or fingerprint generally cannot. Organisations must still prevent unauthorised access, use, disclosure, and linking of biometric information.

Myth: “All ZKTeco information is automatically stored in China.”

Reality: Storage location depends on the chosen device, software, hosting service, and integrations. Some deployments are entirely on-premises; other services use cloud infrastructure. The actual hosting country, backups, and overseas support access must be confirmed for each deployment.

Myth: “If a system is encrypted, it is automatically compliant.”

Reality: Encryption is only one safeguard. New Zealand’s rules also address lawful purpose, necessity, proportionality, transparency, alternatives, access, correction, retention, use, and disclosure.

A practical deployment checklist

  1. What is the exact purpose, and is biometric processing necessary and proportionate?
  2. Is a workable non-biometric alternative available?
  3. Which samples, templates, photos, identifiers, and logs are collected?
  4. Which optional photo, snapshot, cloud, and integration features are enabled?
  5. Where is each category of information stored and backed up?
  6. Is HTTPS enabled on every supported connection, and what other encryption applies?
  7. Who has administrator access, and how are privacy breaches handled?
  8. Are firmware, software, architecture, and configuration records maintained?

NZTeco’s role

NZTeco can help customers identify appropriate ZKTeco products, document relevant product capabilities, and configure supported security and privacy features for the agreed deployment. Depending on the project, this can include:

  • confirming device, firmware, and software versions;
  • documenting whether photos, event snapshots, and cloud connectivity are enabled;
  • configuring HTTPS and role-based access where supported;
  • supporting on-premises or agreed hosted architectures;
  • providing administrator handover and product documentation; and
  • helping customers understand matters that require their own privacy, employment, or legal assessment.

No supplier, product, or certificate can guarantee compliance for every use case. Compliance depends on the organisation’s purpose, decisions, configuration, and ongoing operation of the system.

Frequently asked questions

Yes. When it relates to an identifiable person, it is personal information. Under the Biometric Processing Privacy Code, both biometric samples and biometric templates can be biometric information.

No universal rule can be applied to every product and configuration. Many systems create templates for matching, but ZKTeco devices and software can also support user photos, biometric photos, and event snapshots. Check the exact model and enabled features.

Individuals can request access to and correction of biometric information; a correction request can include a request for deletion. Whether and how an organisation must act depends on the applicable law and circumstances. Organisations must not retain biometric information longer than it may lawfully be used.

Often, but the available options depend on the selected product and service. Confirm the primary region, backups, disaster recovery, integrations, and any overseas support access before deployment.

Generally, organisations covered by the Code must provide clear information before biometric information is collected, including that collection is occurring, the purposes, and whether an alternative is available. Additional details may also be required under rule 3.

No. Authorisation may be relevant in some situations, but it does not replace the need to establish lawful purpose, necessity, proportionality, safeguards, transparency, and compliance with other applicable rules.

Final thoughts

Biometric systems can improve access control, attendance, and security, but privacy depends on the complete deployment—not a single feature or marketing statement. The best approach is to document the purpose, select the least intrusive effective option, understand exactly what the chosen product collects, configure it securely, and review it throughout its lifecycle.

Need help assessing a ZKTeco deployment? Contact NZTeco to discuss the device, software, hosting, and configuration that fit your site.

Primary sources

Need help choosing the right setup?

From access control, time attendance and turnstiles to CCTV, smart locks, vehicle access, digital signage and automation, NZTeco helps match the right technology to the job.

Send us the details and we’ll help you work out the best next step.

About the author:

Reynardt Badenhorst

I'm the Managing Director of NZTeco, leading our mission to bring advanced security and access control systems to New Zealand. I specialize in biometric technologies, surveillance systems, and robust security setups designed to keep people, properties, and data secure. I’m passionate about delivering reliable, tech-driven solutions that solve real-world problems. My focus is on efficiency, innovation, and maintaining a customer-first approach in every project we undertake.
[sil_seo_links count="6" min_confidence="0.5" prioritize_cornerstone="yes" show_schema="yes" title="Explore Related Topics"]

Related Articles

Biometric time and attendance system using contactless palm recognition to prevent buddy punching

Buddy Punching: How It Costs Businesses Money (and How Biometrics Stop It)

Overview: Buddy punching quietly costs businesses thousands each year. Learn what it is, how it happens, and how biometric time & ...
Talk to our sales team

Your projectstarts here.

Whether you need a solution for your site or reseller pricing, we'll help you find the right option.
I'm enquiring about...*

By submitting, you agree to our Privacy Policy and Terms. This site is protected by Google reCAPTCHA (PrivacyTerms).

Sent directly to the NZTeco sales team. Your details stay private.

ReachOut

Copyright © 2026

Get the Right Turnstile Quote

Send us a few details and we’ll recommend the best option for your site.
You selected: Full-Height Turnstiles

By submitting, you agree to our Privacy Policy and Terms. This site is protected by Google reCAPTCHA (PrivacyTerms).

We’re a Licensed Security Company!
NZTeco Limited is officially licensed under the Private Security Personnel Licensing Authority (PSPLA).
License Number: 24-121944
License Classes: Security Technician & Security Consultant
Expiry Date: 22-11-2029

What does this mean?
It confirms that we meet the legal standards to provide professional and secure services in New Zealand, ensuring your peace of mind and trust in our solutions.
Being licensed ensures compliance with industry regulations, ethical practices, and accountability in delivering Access Control, CCTV, and other security solutions.

For more about the PSPLA and why choosing a licensed provider matters, visit the official PSPLA information page: https://www.pspla.govt.nz/ (opens in a new tab).

New Zealand Security Association (NZSA) logo
Official ZKTeco Partner in New Zealand

Contact us

Follow us

Fast Response Form

By submitting, you agree to our Privacy Policy and Terms. This site is protected by Google reCAPTCHA (PrivacyTerms).