September 2022
Executive Summary
The Restaurant Association believes that all hospitality patrons should feel safe in knowing their private information is being protected to the highest standards. We are also acutely aware that the hospitality industry is deeply interconnected internationally through the use of bespoke reservations and CRM software which is why we are supportive of the Government’s efforts to align our privacy frameworks with those of other jurisdictions—particularly those with which we have strong business and trade relationships.
Relationships have always been at the heart of the success of our restaurants and cafés as integral parts of our communities, so we believe that in the age of the digital economy, robust privacy measures are crucial to strengthening trust between businesses and customers.
While we support the principles behind the proposed changes to information sharing requirements, we are concerned these changes have the potential to drastically increase the administrative burden on small and medium sized businesses in New Zealand, of which many of our businesses are.
The Restaurant Association would welcome the opportunity to work with officials to establish a framework which would protect consumers and ensure that all businesses operating in the digital economy are aware of their duty to protect the data of their patrons.
As such, the Restaurant Association makes the following recommendations:
- Recommendation 1: that any changes or new requirements – particularly for small businesses—must be as simple and cost-neutral as possible
- Recommendation 2: of the options provided, the Association recommends the implementation of a new IPP requirement
- Recommendation 3: that the amendment contain an exemption for small businesses
- Recommendation 4: that should indirect notification be required – that Government provide adequate resources, tool kits, and education campaigns to aid hospitality businesses to come into compliance
- Recommendation 5: that the draft amendment be circulated for consultation. 2 of 10
Introduction
The Restaurant Association of New Zealand (the Restaurant Association) welcomes the opportunity to make a submission on the potential changes to the notification rules for collecting personal information under the Privacy Act 2020.
While we support the intent of the proposed changes to the Privacy Act 2020 (the Act) we are concerned about the disproportionate impact these changes will have on our small and medium-sized businesses.
We believe that transparency in the collection, use, and disclosure of personal information is fundamental to protecting individuals’ privacy rights as well as their dignity and autonomy—particularly as the evolution of business models and technology in the past few years has seen a rise in the indirect collection of personal information.
We also appreciate the Government’s efforts to align our privacy framework with those of our international counterparts, especially the European Union, to preserve Aotearoa New Zealand’s international credibility.
Although supportive of the principles behind these proposed amendments, we are concerned these changes have the potential to drastically increase the administrative burden on small and medium sized businesses across New Zealand.
It is important for the Government to keep in mind the direct and indirect impacts of the pandemic on many industries when developing or amending legislation – in particular those sectors that are still recovering from the pandemic, such as hospitality and tourism.
Timing
Acknowledging the pandemic has also thrown the Government’s legislative agenda off course, we put on record our concern at the rate and pace of legislative change currently being advanced.
Despite the Act being less than two years old, feedback is once again being sought on proposed privacy-related changes. This sits alongside the sweeping legislative reforms across both employment and immgration, compounding the pressure felt by many sectors.
For a sector that is currently walking a tightrope between recovery from the pandemic and ensuring long-term sustainability, the short turn-around times for consultation on extremely complex topics—that are not immediately relevant to our sector—is often out of touch with the realities of running a business.
Within our membership, many businesses are constantly adapting their operations to meet ever-evolving compliance standards in light of the rapid and drastic changes that have occurred in the privacy space over the past two years.
The Hospitality sector is doing all it can to ensure a just, sustainable recovery from the impacts of COVID-19 with the already limited resources at its disposal.
With severe time, resource, and staff shortages, we implore the Government to adopt a pragmatic approach to changes of these kinds, prioritising only those changes or new requirements for the private sector that are as simple and cost-neutral to implement as possible—particularly for small business.
Question 1 – What factors do you think are most important when considering changes to indirect collection of personal information?
The Association submits that the most pertinent considerations regarding changes to indirect collection of personal information are:
- increased administrative burden on hospitality businesses
- significant compliance costs at a time where business remain time and resource strained, and
- potential customer fatigue related to online third-party platforms bombarding users with privacy related notifications.
Increased administrative burden and compliance costs:
The majority of the hospitality sector would fall into the ‘small’ category of business if defined by the proposed revenue scale of <$20m.
Given the natural limits on small businesses regarding their capacity and available resources, we maintain that the government should make it as simple as possible to comply with any proposed amendments to the Privacy Act 2020.
Throughout our recovery from the pandemic, hospitality businesses have also faced record-high levels of inflation, and a rapidly changing legislative environment that increasingly demands more of them.
It is no secret that the hospitality industry has undergone drastic changes since COVID-19 arrived on our shores. Business owners have become increasingly reliant on the digital economy, in order to meet shifting customer behaviours and ensure continued trade during COVID-19 restrictions.
Furthermore, for hospitality businesses, data collection is a critical tool for business growth, development, and the improving customer experience.
Hospitality owners often rely on multiple third-party platforms for taking online bookings, orders and deliveries. For example, there are a range of SaaS softwares (such as Quandoo, Restaurant Hub and Kitomba) used by a range of hospitality businesses in New Zealand to make table reservations and place online orders, where the details provided by patrons are stored (where permitted) by the third-party booking system, and not by the business in question.
Some larger hospitality businesses may receive and store these details themselves in their own CRM, but where this is the case, these are usually businesses of a size that there are staff—either employed directly or contracted as part of an external agency—with the sole responsibility for communications functions.
Therefore, the requirement to notify customers of indirect data collection would come with a disproportionate administrative burden and compliance cost to smaller hospitality businesses.
If information sharing of this kind within the broadening of Privacy Act’s notification rules, we recommend that the Government support the development of opt-in software integrations be explored as a first step to prevent additional administrative requirements of small business owners and operators. An example of this working well in recent years was the approach taken by Inland Revenue Department (IRD) to integrate the Xero and MYOB payroll systems into IRD payday filing.
In the end, if regulatory burdens on micro-SMEs are too high, consumer safety will not improve in practice. It is therefore essential that any changes or new requirements for the private sector—particularly for small businesses—must be as simple and cost-neutral as possible.
Customer fatigue:
As referenced in page three of the Ministry of Justice’s consultation document, an important consideration when proposing changes to the current notifications requirement under the Privacy Act 2020, is the potential for notification fatigue – resulting in individuals feeling simply tuning out rather than trying to understand how their personal information is being collected.
Although the consultation document highlighted the impact notification fatigue can have on individuals it failed to recognise the impact it will have on businesses.
The hospitality industry uses many external services in its operations, so consumers may come across several different privacy notifications when engaging with a hospitality business online platforms.
As a result, patrons may feel discouraged from engaging with these platforms due to notification fatigue, which would be detrimental to our sector’s recovery. Ensuring that future requirements do not force businesses to bombard consumers with notifications to the point of preventing online utility must be a top priority.
Question 2 – What are the advantages or benefits of broadening the notification requirements, for both individuals and agencies? What might the disadvantages be?
The Association believes broadening New Zealand’s notification requirements could be advantageous on two key fronts.
The first is that these changes would align us with many of our international counterparts who have already adopted similar legislative reforms which would strengthen the cross-border flow of information and in turn, New Zealand’s position in the international digital economy.
The second is that the continued rise of misinformation and disinformation, protecting users’ through robust privacy law and data sovereignty is important. However, this should not come at the expense of the business.
At the same time, the advantages must be balanced with the additional administrative requirements of companies who only operate domestically and may not be as well resourced to implement these changes. These include:
- financial cost of compliance
- significant administrative and time burden on small businesses
- customer notification fatigue and aversion to engaging in online platforms
- small businesses may be subjected to complaints simply for lacking the knowledge and resources to make their operations compliant with the Act.
Question 3 – What form do you think the proposed changes to notification rules under the Privacy Act should take?
The Restaurant Association submits that these changes would be best placed in the form of a new Information Privacy Principle (IPP).
In the hospitality context, details provided by patrons are stored (where permitted) by the third-party booking system, and not by the business in question. As a result, extending IPP3 may be impractical. 1
Furthermore, businesses will be required to implement even longer privacy notices, which users are less likely to read. It would be unlikely to give individuals any more autonomy over their own data.
Similarly, amending IPP11 would merely cause significant administrative workload for already spread out small business who often utilise multiple downstream service providers in their operations.
The consequence would be that businesses with direct relationships with individuals would have to continuously update their privacy notices whenever they swap or work with new downstream service providers – to the determinant of their revenue and time.
Moreover, amending IPP2 may significantly affect the routine processing of data – 3 a critical aspect of contemporary hospitality operations whose operations depend heavily on data exchanges.
The Restaurant Association submits that for the purpose of clarity and accessibility, a new IPP principle would be the best step forward. However, for the 4 new principle to be equitable and effective in practice—it is essential that stakeholders are adequately consulted.
Furthermore, the Restaurant Association submits that a new IPP principle should include an exemption for small businesses. While not provided for in the European
1 From MoJ Consultation Document: ‘an amendment to IPP 3 to introduce a notification requirement for all agencies covered by the Act. IPP 3 would be broadened so that it no longer applies only when an agency collects personal information directly from the individual concerned. It would apply when the agency collects the personal information indirectly from other sources’.
2 From MoJ Consultation Document: ‘an amendment to IPP 11 to require a disclosing agency to notify the individual concerned that their information has been disclosed to a third party (regardless of whether or not the disclosure itself is allowed).
3 From MoJ Consultation Document: ‘introducing an amendment to IPP 2 to narrow exceptions that allow agencies not to collect information directly from the individual concerned (i.e. that allow agencies to collect the information indirectly).’
4 From MoJ Consultation Document: ‘introducing a new separate privacy principle dealing with notification of indirect collection.’
Union’s General Data Protection Regulation (GDPR), a similar exemption is provided in the California Consumer Privacy Act (CCPA) .5
The Association submits this would be the most equitable and practicable step forward so that small businesses are not placed with the same compliance burdens of a large business who has the time and resources to adjust to these amendments.
Question 4 – If you are a New Zealand business or agency, are there any practical implementation issues you can identify in complying with the proposed changes?
A key issue in regards to implementation that is true for not just the hospitality industry but small business at large, is that business owners simply do not have the capacity to keep up to date with the constantly changing legislative environment.
A survey on the impact on the preparedness of SMEs for the GDPR found that: 6 ○ 28% were not familiar with the GDPR
- more than half believe the GDPR is too complex for small and medium businesses and for middle market business (51%).
Our concern is that smaller operators may be unfairly sanctioned for non-compliance simply because they are unaware of changes or lack the required resourcing to update their systems.
Question 5 – Are there any other risks or mitigations to the proposed changes you can identify that are not mentioned in this document?
In light of the COVID-19 tracing requirements, the public has become increasingly suspicious about how their information is stored. Unfortunately for hospitality, café and restaurants have been on the receiving end of much of the public’s distrust and frustration as they were on the frontline of enforcing COVID-19 contact tracing requirements.7
Therefore, the Restaurant Association remains concerned at the possibility of vexatious and unwarranted complaints targeted at the hospitality sector as a result of a heightened sense of distrust by the public. This is especially true since
5 California Consumer Privacy Act of 2018 s1798.140 (C)
6 How the GDPR impacts and suffocates small and medium businesses
7‘A breach of privacy’: Government issues reminder to hospitality sector over contact tracing details hospitality businesses often run multiple loyalty programs or marketing campaigns for which customers sign up without a great deal of thought.
The Ministry of Justice could help mitigate this with a comprehensive education campaign for the general public, that outlines what kind of behaviour warrants a complaint and how to better understand their rights when it comes to the collection of their private information.
To combat customer fatigue, the Restaurant Association submits that a more effective way to report and record privacy breaches is for the Government to create a central register where relevant details of a breach can be provided by businesses and checked by consumers. This register could then be integrated with RealMe accounts, through which individuals are notified of any breaches.
Question 6 – Should the proposed changes only apply to personal information collected indirectly from individuals overseas, or should they also apply to personal information collected indirectly from individuals in New Zealand?
Given New Zealand’s hospitality industry attracts numerous overseas visitors, many who often book their dining experiences from overseas – this separation would be unnecessarily administratively burdensome. The Restaurant Association submits that if an amendment is made – it should apply to information collected both domestically and overseas for clarity and consistency.
Question 7 – Is there any other feedback you would like to provide on these proposed changes? If so, please provide this feedback.
The Restaurant Association welcomes the Government’s work to update our data privacy frameworks and appreciates the Government’s efforts to align our privacy framework with those of our international counterparts.
We believe that transparency in the collection, use, and disclosure of personal information is fundamental to protecting individuals’ privacy rights as well as their dignity and autonomy—particularly as the evolution of business models and technology in the past few years has seen a rise in the indirect collection of personal information.
However, we are concerned these changes have the potential to drastically increase the administrative burden and compliance cost to small and medium sized businesses in New Zealand.
While we agree with the objectives of this proposal, we urge the Government to consider our submission and adopt practical, sensible measures to mitigate these concerns.