Which of My SaaS Tools Are a Problem?
Select the tools your business uses. Get an instant check of overseas storage and DPA status across 55+ common Australian SaaS tools.
Under APP 8 of the Privacy Act 1988 (Cth), disclosing personal information to an overseas recipient — including storing it in a cloud service hosted outside Australia — makes your business accountable for how that recipient handles it. Most common SaaS tools default to overseas storage. Select the tools you use below to see which ones need attention.
Last updated: 1 July 2026
How each tool is scored
| Result | Meaning |
|---|---|
| Onshore | Hosts Australian customer data in Australia by default — APP 8 overseas disclosure risk is low |
| Overseas, DPA available | Stores data overseas by default, but the vendor publishes a standard Data Processing Addendum you can rely on as a "reasonable step" |
| Overseas, no DPA | Stores data overseas by default with no standard vendor DPA available — highest APP 8 risk of the three |
Why "overseas" doesn't mean "non-compliant"
Using an overseas-hosted SaaS tool doesn't automatically breach APP 8 — almost every Australian business uses at least one. The obligation is to take reasonable steps before disclosing personal information overseas, and to remain accountable for how the recipient handles it afterwards. Executing the vendor's DPA is the most common reasonable step available to a small business.
Your privacy policy also needs to keep up — APP 1.4 requires you to specify, where practicable, the countries your information is likely to be disclosed to. A policy that doesn't name the countries your SaaS stack actually uses is itself a gap.
Third-party processor checker
Select every tool your business uses. You'll get an instant overseas-storage and DPA-status report, grouped by risk, at a permanent URL you can revisit or share.
Stores data in US/global data centres by default. Google publishes a standard Data Processing Amendment you can accept online.
Plus a full tool-by-tool report across every tool you select, grouped by risk — generated from your selections below.
When you need a processor check
- — You've never audited which of your SaaS tools store data overseas
- — You're updating your privacy policy's overseas disclosure section (APP 1.4)
- — You're newly covered by the Privacy Act following the 1 July 2026 threshold removal
- — An enterprise client's vendor due diligence questionnaire is asking about your sub-processors
- — You're deciding between two SaaS vendors and want to know the privacy risk difference
Frequently asked questions
Which of my SaaS tools are a Privacy Act problem?
Any tool that stores or processes your Australian customers' personal information overseas triggers APP 8. Most common business tools default to overseas storage. Risk is higher again if the vendor doesn't publish a standard DPA you can rely on.
What is APP 8 of the Australian Privacy Principles?
APP 8 requires reasonable steps before disclosing personal information to an overseas recipient, and keeps your business accountable for how that recipient handles it — including a cloud vendor or SaaS provider.
Do I need a DPA with every SaaS vendor?
A DPA is one of the reasonable steps the OAIC expects for APP 8 compliance when a vendor stores data overseas. Most major vendors publish one online; smaller or open-source tools sometimes don't, which raises your risk.
What does the free third-party processor checker check?
It checks the tools you select against a catalogue of 55+ tools commonly used by Australian businesses, flagging default overseas storage, Australian data residency availability, and standard DPA availability.
Is my privacy policy required to disclose overseas SaaS tools?
Yes. APP 1.4 requires your privacy policy to specify the countries personal information is likely to be disclosed to, where practicable — most commonly the United States for a typical AU SaaS stack.
Select your SaaS tools above to get an instant overseas-storage and DPA-status report.
Get my processor report →