Skip to content

The hazards, marked before you sail into them.

A badly built automation creates legal exposure for you, not for the agency that sold it. These are the rules we design against from the first workflow.

Anti-spam — Unsolicited Electronic Messages Act 2007

Every email and text our systems send — yours and ours — is built around consent, sender identification, and an unsubscribe path from day one.

The Unsolicited Electronic Messages Act 2007 (UEMA) governs every email, and mobile text message your automations send. It does not cover voice calls, which we treat separately below.

Consent basis. Consent can be express, inferred, or deemed. Deemed consent exists where an electronic address is conspicuously published in a business or official capacity, there’s no statement saying the holder doesn’t want unsolicited messages, and the message genuinely relates to that person’s business role. This is the legal basis for compliant B2B outreach in New Zealand — but if a business’s own site says “no unsolicited emails,” that address is off-limits, full stop.

What every message must carry. Accurate identification of who authorised the message, accurate contact information, a New Zealand postal address, and a functional unsubscribe facility. We keep records of every consent basis — express, inferred, or deemed — for every list we build.

What we won’t do. Address-harvesting software to build contact lists is prohibited under UEMA, and it’s exactly the kind of tooling a lot of offshore automation agencies sell as standard. We build lists from manual research, public directories, and association member lists instead.

Why it matters to your build. Any reactivation or win-back automation we build includes consent-state tracking as standard, and onboarding always confirms the consent basis for your existing customer list before we touch it. Penalties for non-compliance reach up to $500,000, and the burden of proof sits with the sender — so we build the paper trail in from day one.

Privacy Act 2020 and the new IPP 3A

Notification obligations for any automation that pulls personal information about someone from a source other than the person themselves.

New Zealand has taken a light-touch approach to AI regulation, relying on the existing Privacy Act 2020 rather than AI-specific rules. The Privacy Commissioner has been clear that organisations remain responsible for decisions made using AI tools — automated systems don’t displace Privacy Act obligations, and meaningful human oversight should exist for any decision that significantly affects someone.

IPP 3A. The Privacy Amendment Act 2025 introduced Information Privacy Principle 3A, in force from 1 May 2026. It requires an agency collecting personal information about someone from a source other than that person to take reasonable steps to make sure they’re aware of specified matters. It applies to information collected on or after 1 May 2026, and the duty to notify can’t be contracted away.

Where this bites. This lands directly on lead-enrichment, list-building, and any automation that pulls personal information about individuals from third-party sources. If a workflow enriches a contact list with data it didn’t collect directly from the person, notification obligations are live.

Transparency. People should be told when they’re interacting with AI, and human review is expected for decisions that affect them. Every voice and chat automation we build discloses that it’s AI at first contact — see the voice AI section below.

Voice AI — disclosure and house rules

UEMA doesn't cover voice calls, so we hold ourselves to house rules that go further than the law requires.

UEMA explicitly doesn’t cover voice telemarketing calls, which means a voice agent isn’t legally bound by the same consent and unsubscribe requirements as email or text. That doesn’t make it a free-for-all — we apply these as non-negotiable house rules on every voice deployment:

  • Always disclose it’s an AI at the start of the call. This matches the Privacy Commissioner’s transparency expectations, and it’s simple commercial sense — being caught pretending an AI is human damages your reputation and ours.
  • Always offer a path to a human, on request, at any point in the call.
  • Never let a voice agent make a decision that materially affects someone — approving credit, making a clinical judgement, agreeing to a contract variation.
  • We check the Marketing Association’s name-removal and do-not-call service and honour suppression lists.
  • We record and review calls, with disclosure and consent, for the first month of every deployment.

Voice AI is the most impressive part of any demo and the highest-risk part of any deployment — a bad voice interaction fails loudly and publicly. We deploy it inbound-first, tested extensively against New Zealand accents, and only add outbound calling once inbound is proven and trusted.

Our own hygiene

  • Professional indemnity and cyber liability insurance carried at all times.
  • Written contracts covering scope, third-party outage exclusions, consent and list legality, IP ownership, and offboarding.
  • A written AI use policy available on request — standard for clients in professional services.

Questions

Who is responsible if a workflow sends a non-compliant message?
Our contracts assign responsibility for the legality of a supplied contact list to the client, while we build consent-state tracking and sender-identification requirements into every list-based workflow as standard. We also carry professional indemnity and cyber liability insurance.
Do you have a written AI use policy?
Yes. Clients in professional services — accountants, clinics, law firms — often ask for it during procurement, and we provide it as a standard part of onboarding.

Handling sensitive data or regulated clients?

Talk to us before anything gets built. Compliance is far cheaper to design in than to retrofit.