Vendor Due-Diligence Scorecard
Assess any vendor — including ones not in our processor catalogue — against APP 8 and APP 11 in six questions.
Under APP 8 of the Privacy Act 1988 (Cth), you remain responsible for how an overseas vendor handles your customers' personal information — a vendor's own privacy policy doesn't satisfy this obligation. This scorecard checks whether a Data Processing Agreement is in place, whether sub-processors are disclosed, and whether the vendor meets APP 11 security expectations, then scores the vendor Low, Medium, or High risk.
Last updated: 3 July 2026
Vendor due-diligence scorecard
Answer six questions about any vendor — including ones not in our processor catalogue — and get an instant risk score with the specific gaps to close, at a permanent URL you can bookmark or share.
When to score a vendor
- — You're evaluating a new SaaS tool before rolling it out
- — The vendor isn't one of the 40+ tools already covered by our Third-Party Processor Checker
- — A client or the OAIC has asked you to demonstrate vendor due diligence
- — You're building a vendor register and need a consistent scoring method
Relevant free tools
Frequently asked questions
What is a vendor due-diligence scorecard for the Privacy Act?
A vendor due-diligence scorecard assesses a single supplier against the Privacy Act 1988 (Cth) obligations that attach to using them — mainly APP 8 (cross-border disclosure) and APP 11 (security). It scores the vendor Low, Medium, or High risk based on whether a Data Processing Agreement is in place, whether sub-processors are disclosed, and whether the vendor has a security certification.
What counts as a Data Processing Agreement (DPA)?
A DPA is a contract or click-through agreement with a vendor that sets out how they will handle personal information on your behalf. Most major SaaS vendors — Google, Microsoft, Stripe, HubSpot — offer one through their admin console. Executing a DPA is one of the "reasonable steps" APP 8 requires before disclosing personal information to an overseas recipient.
Do I need to assess vendors that don't store data overseas?
Yes, at a lighter level. APP 11 security obligations apply regardless of where a vendor is located. APP 8 cross-border disclosure obligations only apply when the vendor stores or processes data outside Australia, so the scorecard weights that gap more heavily for overseas vendors.
Want to check a vendor against our catalogue of 40+ common Australian SaaS tools instead? Try the processor checker.
Check my SaaS stack →Don't have a privacy policy yet?
Generate a custom, APP 1.3-compliant privacy policy draft — including the automated decision-making disclosure required from 10 December 2026 — in about 60 seconds. Free, no account required.
Generate my privacy policy →