Is It Legal to Store Customer Data Overseas?
Why APP 8 makes you accountable for your SaaS vendors, what section 16C means in practice, and the free tools to check your stack.
Yes, but APP 8 of the Privacy Act 1988 (Cth) makes you accountable for it. Before disclosing personal information to an overseas recipient — including via a cloud tool hosted offshore — you must take reasonable steps to ensure the recipient doesn't breach the Australian Privacy Principles. Under section 16C, a breach by the overseas recipient is treated as your own breach.
Last updated: 2 July 2026
The accountability chain
| Governing principle | APP 8 — Cross-border disclosure of personal information |
| Core obligation | Take reasonable steps before disclosing data to an overseas recipient |
| Liability rule | Section 16C — overseas recipient's breach is treated as your breach |
| Common exceptions | Informed consent, or a binding scheme with equivalent protections |
Why this catches businesses out
Most businesses don't consciously "disclose data overseas" — they sign up for a CRM, email platform, or accounting tool without checking where the servers are. APP 8 applies regardless of intent: if a SaaS vendor stores or processes Australian customer data outside Australia, that's a cross-border disclosure.
The accountability doesn't transfer to the vendor. Section 16C means your business remains on the hook if the overseas recipient mishandles the data, unless you can show reasonable steps were taken — typically evidenced by a Data Processing Agreement or the vendor's own compliance certifications.
Relevant free tools
Related Privacy Act questions
When to check your overseas exposure
- — You've never checked where your CRM, email or accounting vendor stores data
- — You don't have a Data Processing Agreement with any of your SaaS providers
- — A client or vendor due-diligence questionnaire has asked about overseas storage
- — You're adding a new SaaS tool and haven't assessed its data residency
- — You're newly covered by the 1 July 2026 exemption removal and haven't audited your vendor stack
Frequently asked questions
Is it legal to store customer data overseas?
Yes, but APP 8 of the Privacy Act 1988 (Cth) makes you accountable for it. Before disclosing personal information to an overseas recipient — including via a cloud tool hosted offshore — you must take reasonable steps to ensure the recipient doesn't breach the Australian Privacy Principles. Under section 16C, a breach by the overseas recipient is treated as your own breach.
Am I responsible if my overseas SaaS provider has a breach?
Generally yes. Section 16C of the Privacy Act 1988 (Cth) deems an act or practice of an overseas recipient that would breach the APPs to be a breach by the disclosing entity itself, unless a specific exception applies, such as informed consent or an equivalent binding scheme.
Do I need a Data Processing Agreement with overseas tools?
It's the practical way to demonstrate the "reasonable steps" APP 8 requires. A DPA that binds the overseas recipient to APP-equivalent protections helps establish that reasonable steps were taken, and is standard due-diligence evidence in an OAIC review.
Which common SaaS tools store data overseas?
Many mainstream CRM, email marketing, and accounting platforms host data in the United States, Europe, or Asia-Pacific data centres outside Australia. Each vendor's data residency and DPA status needs to be checked individually — it varies by tool and sometimes by plan tier.
Run the free processor checker to see the overseas storage and DPA status of the SaaS tools you already use.
Check my SaaS tools →