Privacy Ready
Free diagnostic tool · Vendor risk

Vendor Due-Diligence Scorecard

Assess any vendor — including ones not in our processor catalogue — against APP 8 and APP 11 in six questions.

Under APP 8 of the Privacy Act 1988 (Cth), you remain responsible for how an overseas vendor handles your customers' personal information — a vendor's own privacy policy doesn't satisfy this obligation. This scorecard checks whether a Data Processing Agreement is in place, whether sub-processors are disclosed, and whether the vendor meets APP 11 security expectations, then scores the vendor Low, Medium, or High risk.

Last updated: 3 July 2026

Free diagnostic tool

Vendor due-diligence scorecard

Answer six questions about any vendor — including ones not in our processor catalogue — and get an instant risk score with the specific gaps to close, at a permanent URL you can bookmark or share.

Question 1 of 6

Does this vendor store or process your data outside Australia?

Question 2 of 6

Have you reviewed or signed a Data Processing Agreement (DPA) with this vendor?

Question 3 of 6

Does the vendor publicly disclose its sub-processors?

Question 4 of 6

Will this vendor handle sensitive information (health, financial, biometric, or children's data)?

Question 5 of 6

Does the vendor have a security certification (e.g. ISO 27001, SOC 2) or equivalent commitment?

Question 6 of 6

Has this vendor and its overseas transfer been disclosed in your privacy policy?

When to score a vendor

  • You're evaluating a new SaaS tool before rolling it out
  • The vendor isn't one of the 40+ tools already covered by our Third-Party Processor Checker
  • A client or the OAIC has asked you to demonstrate vendor due diligence
  • You're building a vendor register and need a consistent scoring method
Free diagnostic tools

Relevant free tools

Frequently asked questions

What is a vendor due-diligence scorecard for the Privacy Act?

A vendor due-diligence scorecard assesses a single supplier against the Privacy Act 1988 (Cth) obligations that attach to using them — mainly APP 8 (cross-border disclosure) and APP 11 (security). It scores the vendor Low, Medium, or High risk based on whether a Data Processing Agreement is in place, whether sub-processors are disclosed, and whether the vendor has a security certification.

What counts as a Data Processing Agreement (DPA)?

A DPA is a contract or click-through agreement with a vendor that sets out how they will handle personal information on your behalf. Most major SaaS vendors — Google, Microsoft, Stripe, HubSpot — offer one through their admin console. Executing a DPA is one of the "reasonable steps" APP 8 requires before disclosing personal information to an overseas recipient.

Do I need to assess vendors that don't store data overseas?

Yes, at a lighter level. APP 11 security obligations apply regardless of where a vendor is located. APP 8 cross-border disclosure obligations only apply when the vendor stores or processes data outside Australia, so the scorecard weights that gap more heavily for overseas vendors.

Want to check a vendor against our catalogue of 40+ common Australian SaaS tools instead? Try the processor checker.

Check my SaaS stack →
Free tool · APP 1.3

Don't have a privacy policy yet?

Generate a custom, APP 1.3-compliant privacy policy draft — including the automated decision-making disclosure required from 10 December 2026 — in about 60 seconds. Free, no account required.

Generate my privacy policy →