Governance for a small NZ business is a short list of decisions you make once, so the software you've started letting act on its own doesn't quietly create a problem you find out about three months later. Not a policy binder, just a handful of decisions written down where your team can see them.
It matters more now because the tools changed shape. A year ago ChatGPT and Claude were a chat box you opened occasionally. Now they draft and send emails, write to your CRM, update invoices in Xero, and run on a schedule. Once software acts on your behalf, you need to have decided what it can do, what it can see, and who's accountable when it gets something wrong.
What the Privacy Act actually asks of you
I'm not a lawyer, but the Privacy Act 2020 is short and readable, and most owners I work with have never checked what it asks of them.
The core of it: you're accountable for the personal information you collect, including after it leaves your laptop, which covers pasting a customer's details into a US-hosted model. The Act doesn't ban that. It asks you to know who can access the data, where it's stored, and whether you've told the people it belongs to.
In practice that's four questions you should be able to answer without stalling. Have you told customers, in your privacy notice, that you use tools that may process their information? Do you know which vendors you use and where they host data? Could you tell a customer tomorrow what you'd done with their information? And if something went wrong, would you find out fast enough to act?
That last one has a real obligation behind it. If a breach is likely to cause serious harm, the Act requires you to notify the Privacy Commissioner and the affected people "as soon as practicable" (sections 112 to 117). There's no fixed 72-hour law here, that's the European GDPR rule, not ours. The Office of the Privacy Commissioner's guidance is to notify within about 72 hours of becoming aware, even mid-investigation. So notice a serious breach within days, not months.
If any answer is "I'd have to think about it", you don't have a compliance failure yet. You have a gap, and it widens every time you add another tool.
Where your data goes when you use a US-hosted model
This surprises owners. When someone pastes a customer email into ChatGPT or asks Claude to summarise a contract, that text goes to servers in the US, sometimes Europe, and is processed there. Whether a copy sticks around depends on your plan, and the defaults changed recently.
Paid no longer means private by default. In August 2025 Anthropic updated its consumer terms so Claude's Free, Pro and Max plans use your chats for training unless you opt out; only the commercial plans, Claude for Work and API access, are excluded. OpenAI runs a similar split: consumer ChatGPT can use your conversations unless you switch training off, while its Team, Enterprise and API products don't. The plan decides what happens to what you type, and most owners have never checked which one their team is on.
So make it a deliberate choice. Match the plan to how sensitive the work is, turn training off where the tool offers it, and write that down where the team can see. Most of the exposure I run into comes from the team not knowing where the line is, not from the line being wrong.
Read the vendor contract once, look for four things
If you pay for a tool that touches anything sensitive, you have a vendor contract whether you've read it or not. Read it once and check four things.
Where the data lives. You want the country, not the city. Most US vendors will say "US-hosted, EU residency on enterprise plans" or similar. That line is what you need for your own privacy notice.
Whether they train on your data. It should be spelled out in the data-processing terms. If it isn't, assume training-on and go find the setting.
Who sits underneath them. Vendors use sub-processors: a hosting provider, sometimes a separate model maker. The contract should name them, and you inherit risk from each.
How fast they tell you if they're breached. Quick enough that you can still meet your own "as soon as practicable" obligation if their problem becomes yours.
You don't need a lawyer for a $30-a-month subscription. You do for an annual contract touching financial or health data, or any tool that sees customer data where you're paying more than a few thousand a year.
Governing an agent that takes action
This is where the risk changes in 2026. A chat box is a data-handling question. An agent that sends, writes to systems, and moves money on a schedule is a different category, because its mistakes leave the building on their own.
The line I keep coming back to: separate what the agent can do unsupervised from what needs a human to sign off. Where that line sits differs by business. How you draw it doesn't.
Fine to run unsupervised in most small businesses: drafting follow-ups and queuing them for a person to send, sorting and flagging incoming leads or tickets, tidying data in an internal spreadsheet, summarising the week for the owner to read.
Always behind a human approval step: anything going to a customer with a number in it (a quote, a price, a date), anything that moves money, anything that creates or changes a contract, anything that edits a customer record you can't cleanly undo.
The agent isn't less useful for it. It does the 80% that doesn't need judgement and a human keeps the 20% that does. If you're still working out which tasks sit on which side, that's the same question as what to automate first, and the scope you draw there is the governance.
Low-stakes, reversible work runs on its own. High-stakes, hard-to-reverse work goes through a person. That's the whole shape of agent governance for a small business.
A governance baseline small enough that you'll actually do it
Most governance frameworks are written for organisations with a compliance team. Copy one into a 12-person firm and you get a document nobody reads. Here's the version I hand clients.
One page, one row per tool. For each tool, write down what it is and does, who owns it (one name, not a department), what data it sees and which categories are off-limits, whether it can act on its own or only draft for review, and what happens if it goes wrong: who finds out, who tells the customer, who turns it off.
Then three habits that keep the page honest. Once a quarter, each tool's owner spends 20 minutes on what it's been doing, flagging anything odd and switching off anything unused. Keep a one-line log whenever you change a prompt or a permission or add an automation; that log is the difference between debugging a problem and guessing at it. And for every agent that acts, know how to switch it off inside five minutes. If you can't, you've given it more authority than you meant to.
One document, a quarterly habit, a kill switch. It covers most of the realistic risk a small NZ business carries running this stuff.
What it looks like for a six-person firm
Picture a six-person services firm using ChatGPT for drafting and meeting notes, an agent for qualifying leads and drafting follow-ups, and a couple of automations moving data between Xero and their CRM. Four tools.
Their whole governance artefact is one page: each tool, its owner, the data it touches, whether it can act unsupervised. None can, because every customer-facing message goes past the admin lead before it sends. A 20-minute review each quarter. A page that took an hour to write. Not absent, just proportionate, and far cheaper than one bad message sent without a human seeing it, or a Privacy Act enquiry you can't answer cleanly.
If you want help working out which controls matter for your situation, what belongs in a vendor contract, and where the human-in-the-loop steps go on your agent work, that's what I do. Start at AI consulting, or if you're already at the agent stage, AI agent implementation.
Want us to map yours?
Get in touch →Tags
Written by
Ben Anderson
Founder, Nelson AI
Ben builds practical AI and automation for New Zealand businesses — internal tools, web apps, and workflow automations scoped to what the work actually needs.
Get in touch