As the official ZKTeco partner in New Zealand, NZTeco welcomes ZKTeco’s Official Compliance Announcement and the additional visibility it gives customers evaluating biometric and access-control technology.
The announcement outlines ZKTeco’s stated approach to privacy, data security and governance. It is useful supplier information for New Zealand organisations, but it does not replace the site-specific privacy, security and legal work required for each deployment.
What ZKTeco announced
On 4 September 2025, ZKTeco published an announcement stating that it has aligned its operations with major international privacy frameworks, including GDPR, CCPA/CPRA, BIPA, APPI, PIPL, PIPA, PIPEDA and Singapore’s PDPC requirements.
ZKTeco also describes privacy-by-design practices, encryption and cryptographic protocols including AES-256, RSA-2048, SHA-512 and TLS 1.2, security reviews and third-party assessments, role-based access controls, audit trails, and staff training.
ZKTeco’s Official Compliance Announcement
These are ZKTeco’s stated organisation-wide commitments. The protections available in a particular installation depend on the specific product, firmware, software version, configuration, hosting arrangement and operational controls.
What this means for New Zealand organisations
The announcement can support supplier due diligence, procurement evaluations and internal security discussions. It gives organisations a useful starting point when asking how a solution handles biometric templates, access logs, user permissions, data transmission and software updates.
However, a supplier announcement alone does not make a deployment compliant. Each organisation remains responsible for how it collects, uses, stores, secures and discloses personal information in its own environment.
The New Zealand privacy context
For biometric deployments, New Zealand organisations should consider the Privacy Act 2020 and the Biometric Processing Privacy Code 2025.
The Code applies to many organisations that use automated biometric processing to verify, identify or categorise people. It requires organisations to consider whether biometric processing is necessary and proportionate, implement appropriate safeguards, and give people the information they need about the collection and use of their biometric information.
The Code took effect on 3 November 2025. Organisations already using biometric systems have until 3 August 2026 to align their existing deployments with its requirements.
Practical next steps for NZ sites
- Map personal-data flows
Identify where biometric information, access logs and user data are collected, stored, backed up and transmitted. Confirm who can access each system and whether information is transferred overseas. - Assess whether biometrics are necessary
Document the purpose of the system and consider whether there is a reasonably effective alternative with less privacy risk. A Privacy Impact Assessment is often a sensible starting point. - Configure the system securely
Use supported firmware and software, enable secure communications where available, apply strong credential policies, limit administrator access and isolate management interfaces appropriately. - Set clear retention and access rules
Apply least-privilege access, set sensible retention periods, maintain audit records and establish processes for access, correction and deletion requests where applicable. - Prepare deployment documentation
Keep product documentation, architecture diagrams, configuration records, privacy notices and relevant supplier statements together for audits, tenders and incident response. - Keep the deployment current
Schedule firmware and software updates, review security settings regularly, and reassess the deployment when products, integrations or business processes change.
How NZTeco can help
NZTeco can help customers understand the practical deployment considerations for ZKTeco products in New Zealand. This may include product documentation, secure-configuration guidance, administrator handover, and advice on maintaining supported firmware and software.
For privacy and legal obligations, organisations should assess their own use case and obtain appropriate professional advice where needed.







