Privacy Ready
← Learn

Which SaaS Tools Create Australian Privacy Act Obligations for My Business?

The short answer

Under APP 8 of the Privacy Act 1988 (Cth), any time you disclose personal information to an overseas recipient — including storing it in a cloud service hosted outside Australia — you remain responsible for ensuring that recipient handles the information consistently with the APPs. This applies to almost every Australian business using US-based tools like Google Workspace, Stripe, HubSpot, Mailchimp, or Shopify.

Relevant law APP 8, Privacy Act 1988 (Cth)
Trigger Disclosing personal information to any overseas recipient
Common destinations United States, European Union, India
Your liability You remain accountable for the overseas recipient's handling
Privacy policy Must disclose overseas disclosure and countries (APP 1.4)
Reasonable steps Review vendor terms; execute a DPA where available
Free diagnostic tool

Vendor due-diligence scorecard

Answer six questions about any vendor — including ones not in our processor catalogue — and get an instant risk score with the specific gaps to close, at a permanent URL you can bookmark or share.

Question 1 of 6

Does this vendor store or process your data outside Australia?

Question 2 of 6

Have you reviewed or signed a Data Processing Agreement (DPA) with this vendor?

Question 3 of 6

Does the vendor publicly disclose its sub-processors?

Question 4 of 6

Will this vendor handle sensitive information (health, financial, biometric, or children's data)?

Question 5 of 6

Does the vendor have a security certification (e.g. ISO 27001, SOC 2) or equivalent commitment?

Question 6 of 6

Has this vendor and its overseas transfer been disclosed in your privacy policy?

What counts as "disclosing to an overseas recipient"?

APP 8 applies when you transfer personal information to any entity located outside Australia. In the SaaS context, this includes:

  • Cloud storage — uploading customer files to Google Drive, OneDrive, or Dropbox if those services store data on overseas servers
  • Email — using Gmail or Microsoft 365 where data is routed through or stored on offshore infrastructure
  • CRM and marketing — HubSpot, Mailchimp, ActiveCampaign — all US-based, processing Australian customer data
  • Payments — Stripe, PayPal, Square — transactional data processed offshore
  • Project management — Notion, Asana, Monday.com — predominantly US infrastructure
  • AI tools — OpenAI, Anthropic, Google Gemini — Australian customer data processed on US servers

If personal information — customer names, email addresses, transaction records — passes through these services, APP 8 applies.

What does APP 8 require you to do?

APP 8.1 requires that before disclosing personal information to an overseas recipient, you take reasonable steps to ensure that recipient does not breach the APPs. If they do breach the APPs, you are taken to have breached them as well — you cannot outsource your privacy obligation by pointing to a vendor's privacy policy.

"Reasonable steps" can include:

  1. Reviewing the vendor's privacy and data processing terms — what do they commit to regarding Australian personal information?
  2. Executing a Data Processing Agreement (DPA) — most major SaaS vendors offer these through their admin consoles; Google, Microsoft, Stripe, and HubSpot all have DPAs available
  3. Considering the destination country's privacy laws — comparable protections are a relevant factor
  4. Selecting products with Australian data residency options — AWS ap-southeast-2 Sydney, Google Cloud Sydney, Azure Australia East

How the major tools compare

ToolHeadquartersAU data residencyDPA available
Google WorkspaceUSAYes (Google Cloud Sydney)Yes
Microsoft 365USAYes (Azure Australia East)Yes
XeroNew ZealandAU + NZ primaryYes
StripeUSANo AU-specific storageYes
HubSpotUSANoYes
MailchimpUSANoYes
ShopifyCanadaNoYes
SlackUSANoYes

What must your privacy policy say about overseas transfers?

APP 1.4 requires your privacy policy to disclose whether you are likely to disclose personal information to overseas recipients and, if so, which countries. For most Australian SMBs, this means a statement along the lines of:

"We use third-party service providers including Google, Stripe, and Mailchimp that may store or process your personal information in the United States. We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles."

You do not need to list every sub-processor, but the main categories of overseas recipients and the countries involved should be identified.

What about AI tools that process customer data?

Using ChatGPT, Claude, Gemini, or similar AI tools with customer personal information as input creates APP 8 obligations — the data is processed by an overseas entity. Before using AI tools with customer data:

  • Review the vendor's privacy and data processing terms; confirm whether submitted data is used for model training (most enterprise tiers allow you to opt out)
  • Update your privacy policy to reflect AI tool usage and overseas transfer
  • Consider whether ADM disclosure (from 10 December 2026) is also required if the AI output influences significant decisions about individuals

Frequently asked questions

The SaaS vendor has its own privacy policy. Doesn't that mean I'm covered under APP 8?

No. The vendor having a privacy policy does not satisfy your APP 8 obligation. You need to take reasonable steps to ensure they handle Australian personal information consistently with the APPs — which means reviewing their terms, executing a DPA where one is available, and disclosing the overseas transfer in your own privacy policy.

Do I need separate contracts with every SaaS tool I use?

Not necessarily bespoke contracts, but you should review each vendor's data processing terms and sign or agree to their DPA where one exists. Many DPAs are click-through agreements in the vendor's admin console. Document that you have reviewed and accepted them.

What if the vendor doesn't offer a DPA?

A vendor that handles personal information with no DPA and inadequate privacy terms makes APP 8 compliance difficult. For sensitive data — health, financial, children's information — using a vendor with no privacy commitments creates significant exposure and should be reconsidered.

Does the location of the company matter, or the location of the data?

Both. APP 8 applies when you disclose to an "overseas recipient" — an entity located outside Australia. Even if data is stored on an Australian server, if the controlling company is offshore, APP 8 can still apply. An overseas company using Australian data centres may still be an overseas recipient depending on where control of the data sits.

We only use Australian-registered tools. Do we still have APP 8 concerns?

Possibly. Australian-registered SaaS vendors often use overseas infrastructure providers such as AWS US or Google US as sub-processors. Check each vendor's sub-processing list in their data processing terms. If overseas sub-processors handle your data, the transfer still occurs — though the vendor's own DPA may address this on your behalf.

Use the free Third-Party Processor Checker to identify which tools in your stack create APP 8 obligations and whether you've taken the right steps.

Check my SaaS obligations →