Home / Resources / AI Policy Template
A practical framework for New Zealand businesses to develop responsible AI and data governance policies.
In today's digital landscape, responsible and ethical use of AI and data is crucial for business success and maintaining trust with customers. This guide provides a comprehensive framework for small and medium-sized enterprises in New Zealand to develop an effective AI & Data Usage Policy.
It outlines key principles of data privacy, security, and AI ethics, along with practical steps for policy implementation, training, and compliance with relevant laws and regulations. By following this guide, SMEs can harness the power of AI and data while mitigating risks and fostering innovation.
This template is intended as a general resource and starting point. It reflects best practices and standard guidelines but is offered "as-is" without guarantees of completeness or suitability for specific regulatory needs. It is not a substitute for tailored legal advice. We strongly recommend consulting a qualified legal professional to review and adapt this policy to meet the unique requirements of your business.
When developing your policy, prioritise these six areas.
Maintain clear communication with customers about data collection, usage, and protection practices.
Clearly outline roles and responsibilities for data governance and AI ethics within your organisation.
Implement robust security measures to protect data from unauthorised access and breaches.
Ensure your AI systems are free from bias and promote fair treatment for all.
Design AI systems that are understandable to users, providing clear explanations of their functionality.
Stay informed about relevant laws and regulations to ensure your policy reflects current legal standards.
Understanding these is essential for building a compliant AI & data policy.
The foundation of New Zealand's privacy laws, setting clear rules on how personal information is collected, used, and stored. With AI often handling large amounts of personal data, the Act ensures people's rights are protected. It includes 13 Information Privacy Principles (IPPs) that outline responsible practices, from collection through to disposal of data.
Problem it solves: Addresses the risks of data misuse and breaches that can undermine public trust. By following these principles, businesses demonstrate respect for individual privacy and strengthen trust with clients and regulators.
Regulates electronic marketing, a common channel for AI-driven customer interactions. It requires businesses to obtain consent before sending marketing messages, protecting individuals from spam and unwanted marketing.
Problem it solves: Sets a clear framework for ethical communication, emphasising transparency and consent in customer relations, which is essential for long-term business and customer loyalty.
Governs the handling of credit information, which is sensitive and requires strong protection. For AI policies, compliance with this code is critical if AI systems are processing financial or credit-related data.
Problem it solves: Reduces the risk of financial data misuse, enforces transparency, and allows individuals to access and correct their information, promoting accountability in data-driven financial decisions.
Provides specific guidelines on handling health data, one of the most sensitive forms of personal information. For AI applications that involve health data, strict compliance is essential to protect patient privacy and ensure data security.
Problem it solves: Ensures patient data is treated responsibly, supporting trust in health services and aligning with ethical standards in healthcare.
Offers practical advice on implementing privacy best practices within New Zealand's public sector and useful for private organisations. Particularly relevant for AI policies that require clear privacy protocols to manage potential risks.
Problem it solves: Helps businesses design privacy-protective systems, minimising the likelihood of breaches and ensuring compliance with established privacy norms.
Established in July 2020, primarily designed for government agencies to promote transparency, accountability, and fairness in the use of algorithms. While not mandatory for private sector entities, the principles offer valuable guidance for SMEs developing AI and data usage policies.
Key commitments:
Each section covers a specific aspect of data and AI governance. Expand each to see guidance and example text.
This policy outlines [Your Company Name]'s commitment to responsible data handling and ethical AI practices in pursuit of [specific AI goals]. This includes:
We value your privacy. We only gather the information we need to run our business and provide you with the best possible service. This aligns with our commitment to:
We are excited about the potential of AI but aware of the risks. Our AI systems are designed with fairness, transparency, and accountability in mind. We train our models properly, verify outputs, monitor performance, and ensure critical decisions made by AI are overseen by a human. Our AI systems undergo regular monitoring and auditing for bias, accuracy, and fairness.
We are committed to complying with all relevant laws and regulations in Aotearoa, including the Privacy Act 2020, the Unsolicited Electronic Messages Act 2007, any industry-specific regulations, and, if applicable, international laws like the GDPR and CCPA.
While your business may primarily operate in New Zealand, be aware of international data protection laws like the GDPR and CCPA. These have extraterritorial reach and may apply if you handle personal data of individuals in the EU or California. Key principles include:
We comply with the Privacy Act 2020, the Unsolicited Electronic Messages Act 2007, and the Algorithm Charter for Aotearoa New Zealand, among others. Regular legal review helps us stay updated and ensures that our AI practices align with current legislation, maintaining a high standard of ethical conduct.
We invest in our people. Everyone at [Your Company Name] receives regular training on data privacy, AI ethics, and this policy. Training is conducted annually using a range of methods including online courses and in-person workshops. We maintain records of training activities to track participation and compliance.
We take this policy seriously. [Designated Person/Department] is responsible for enforcement. We conduct regular audits using specific procedures including data sampling, interviews, and documentation review. Non-compliance may result in disciplinary action, retraining, or other measures as appropriate.
We encourage an open and honest environment. If you have concerns about data privacy or AI ethics, please contact [Designated Person/Department] using our established reporting channels. We treat all concerns confidentially and individuals who report in good faith are explicitly protected from retaliation. You can also choose to report concerns anonymously.
XYZ Company, a small online retailer, experienced a data breach affecting approximately 1,000 customers. Compromised data included names, email addresses, and purchase history. They followed their response plan:
Applies to all external vendors, partners, and service providers offering AI, data analytics, or related services.
We believe in making our AI systems as transparent as possible. We use explainable AI techniques to make our systems understandable and provide clear explanations of how they work. We offer insights into how AI arrives at its conclusions and encourage users to provide feedback on AI explainability to enhance transparency.
A healthcare company uses edge computing for real-time diagnostics on mobile devices. To address privacy they implement data minimisation (only essential data transferred), encryption in transit and at rest, strong authentication, and data stored only as long as necessary before secure deletion.
This guide provides the framework. The next step is making it yours. Customise the content to reflect your company's values, culture, and AI objectives. Engage key stakeholders throughout the process and consult legal professionals for tailored advice.
Our team can help you develop, customise, and implement an AI & data governance framework tailored to your business.