NZ social media ban puts tech insurance cover under pressure

A single age-verification failure could simultaneously trigger regulatory penalties, privacy claims and allegations against directors. D&O, cyber and technology E&O policies may each respond to part of that picture - and disagree about who pays for which part

NZ social media ban puts tech insurance cover under pressure

Insurance News

By Mav Rodriguez

Prime Minister Christopher Luxon introduced the Online Safety (Minimum Age and Child Safety Risk Assessment) Bill to Parliament on Monday, requiring social media platforms to take reasonable steps to verify that users are over 16, with penalties of up to 10% of global revenue for non-compliance.

Platforms named in Luxon's announcement - Instagram, TikTok, Snapchat and Facebook - would be required to use existing account information, facial age estimation, digital identity services or formal identification to determine whether users meet the age threshold. An online safety regulator would be established within the Department of Internal Affairs.

The bill's passage is far from certain. Both ACT and NZ First - the National Party's coalition partners - have said they will vote against it, meaning Luxon needs Labour's support to pass the legislation. Labour leader Chris Hipkins said the party had not yet decided how it would vote and would wait until it had reviewed the bill's full text. Parliament is also expected to dissolve ahead of the 2026 general election before a vote could be held, adding further uncertainty to the timeline.

Luxon said he could no longer accept the harm being done to a generation of New Zealand children. "One in three children aged between 13 and 17 are now spending at least five hours on social media a day," he said. Education Minister Erica Stanford confirmed no penalties were proposed for children, their parents or caregivers.

The insurance question that exists independently of the vote

Whether or not the bill passes in its current form, it defines the direction of regulatory travel for social media platforms operating in New Zealand - and the insurance implications of age-verification obligations are already live, because the liability risk does not wait for legislation to be enacted before it starts to shape underwriting scrutiny.

A failure in an age-assurance system creates three distinct legal exposures simultaneously. The platform faces potential regulatory action for non-compliance with any applicable online safety obligation. Users whose data was collected and then inadequately protected face privacy claims under the Privacy Act 2020. And the directors who signed off on the platform's compliance systems face potential allegations that they failed to put adequate governance in place.

Those three exposures land across three different policy lines: management liability for the directors' conduct, cyber and privacy for the data protection failure, and technology errors and omissions for the design and operation of the age-verification system itself. The risk is not that any one policy fails to respond - it is that each responds to a different part of the same event, with different exclusions, different retention levels and different coverage limits, and that the boundaries between them become contested when a single incident triggers all three simultaneously.

Australia's experience shows the exposure is operational, not just theoretical

New Zealand is not legislating in isolation. Australia's social media minimum-age rules took effect in December 2025, and the eSafety Commissioner subsequently raised compliance concerns over several major platforms, including cases where children reportedly made repeated attempts at age assurance until they obtained a result showing they were 16 or older.

That experience reveals the specific liability question the insurance market needs to be asking: not whether a data breach occurred, but whether the design, accuracy and operation of the age-verification technology itself meets the required standard. A system that was compliant at launch but failed in operation is a technology E&O question. A system that was never adequate is a D&O question about who approved it. A system that was breached is a cyber question. In practice, a single regulatory finding may involve elements of all three.

New Zealand's biometric privacy layer adds further complexity

The biometric dimension of facial age estimation intersects with a separate compliance obligation. New Zealand's Biometric Processing Privacy Code, administered by the Privacy Commissioner, covers technologies including facial analysis used for age determination. The transition period for organisations already using biometric systems ended on August 3, 2026 - meaning platforms that deployed facial age estimation before the code took effect are now required to be fully compliant with it.

A social media platform using facial technology for age verification therefore has to satisfy both any online safety age-assurance requirement and the Privacy Commissioner's biometric processing obligations simultaneously. Where a platform relies on a third-party specialist for facial analysis or document verification, liability for a system failure may depend on the contractual indemnities and liability caps in the service agreement - and on whether the technology E&O policy extends to cover loss arising from an outsourced component of a system the insured is ultimately responsible for operating.

For brokers advising technology companies, digital identity providers or social media platforms with New Zealand operations, the bill's introduction is the prompt to review where age-verification liability sits across their current programme - not to wait for the legislation to pass.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!