Privacy Ready
← Learn

APP 8: Cross-Border Disclosure of Personal Information

Last updated 22 July 2026 · Reviewed by The PrivacyReady compliance team

The short answer

Australian Privacy Principle 8 requires that before disclosing personal information to an overseas recipient — including storing it in a cloud service hosted outside Australia — you take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles. Under s 16C of the Privacy Act, if the overseas recipient breaches the APPs, you are treated as if you had breached them yourself. This applies to almost every Australian business using US-headquartered SaaS tools such as Google Workspace, Stripe, HubSpot, or Mailchimp.

Governing provision Privacy Act 1988 (Cth), Schedule 1, APP 8; accountability under s 16C
Trigger Disclosing personal information to any entity located outside Australia
Your liability You remain accountable for the overseas recipient's handling (s 16C)
Reasonable steps Review vendor terms; execute a DPA where available
Privacy policy Must disclose likely overseas disclosure and the countries involved (APP 1.4)

What counts as an overseas disclosure

APP 8 applies whenever personal information is disclosed to a recipient located outside Australia. In practice, for most small businesses this happens continuously and often invisibly: cloud storage and email hosted offshore, CRM and marketing platforms with US infrastructure, payment processors, and AI tools that process customer data on overseas servers.

Under s 16C, if that overseas recipient does something with the information that would breach the APPs had you done it yourself, you are taken to have breached the APPs. You cannot discharge this obligation simply by pointing to the vendor's own privacy policy — the accountability sits with you as the Australian APP entity.

What "reasonable steps" looks like

APP 8.1 requires reasonable steps before disclosure, not a guarantee of the recipient's conduct. In practice this typically includes: reviewing the vendor's privacy and data processing terms; executing a Data Processing Agreement (DPA) where the vendor offers one — most major platforms do, through their admin console; considering whether the destination country has comparable privacy protections; and, for sensitive data, considering AU-region hosting options where available.

Common SME failure modes

  • No awareness of which tools are overseas recipients — many businesses have never mapped their SaaS stack against this question.
  • No DPA executed even where the vendor offers one for free.
  • Privacy policy silent on overseas disclosure despite using US-based tools for email, CRM, or payments.
  • Assuming an Australian-registered vendor means no APP 8 exposure — many AU-registered SaaS companies use overseas sub-processors (e.g. AWS US, Google Cloud US) for underlying infrastructure.

Practical compliance steps

  1. Inventory every third-party tool that touches personal information and identify where it is hosted or headquartered.
  2. For each overseas recipient, check for a DPA and execute it if not already in place.
  3. Update your privacy policy to disclose the categories of overseas recipients and the countries involved.
  4. For sensitive or high-volume data, consider AU-region hosting options where the vendor offers them.
  5. Review new vendors against this checklist before adoption, not after.

Frequently asked questions

Does the vendor having its own privacy policy satisfy my APP 8 obligation?

No. The vendor's privacy policy does not, on its own, discharge your obligation to take reasonable steps ensuring the recipient handles Australian personal information consistently with the APPs — reviewing their terms and executing a DPA where available is the expected minimum.

What if the vendor doesn't offer a DPA?

A vendor handling personal information with no DPA and weak privacy commitments makes APP 8 compliance difficult, and materially increases your exposure under s 16C. For sensitive data in particular, this is a reason to reconsider the vendor.

Does using an Australian data centre avoid APP 8 entirely?

Not necessarily. APP 8 turns on where the recipient is located, not only where the data is physically stored — an overseas-headquartered company using Australian infrastructure may still be an "overseas recipient" depending on where control of the data sits (edge cases here are unconfirmed — check current OAIC guidance).

Use the free Third-Party Processor Checker to identify which tools in your stack create APP 8 obligations and whether you've taken the right steps, across 55+ common Australian tools.

Check my SaaS obligations →