Sending data offshore usually means one of two distinct things, and the difference matters: the data is either physically stored on servers located outside Australia, or it stays stored in Australia but is accessed and processed by staff located outside Australia. These are not the same arrangement, and they carry different practical risk profiles even though both can trigger the same Australian Privacy Principle 8 (APP 8) obligations.
What does "sending data offshore" actually mean technically?
Storage location determines which country's law enforcement and government access regimes could theoretically apply to the data at rest, and which jurisdiction's data centre security standards govern the physical and network security of the storage itself. Processing access, who can log in, view, edit or export the data regardless of where it is stored, determines the practical, day-to-day privacy exposure: an overseas team accessing Australian-hosted data remotely still constitutes a disclosure of personal information to an overseas recipient under APP 8, even though the data never physically left Australia. A business evaluating an outsourcing arrangement needs to ask both questions separately: where does the data live, and who, physically located where, can actually access it.
What's the difference between disclosure and use, and why does it matter?
Disclosure means personal information moves to another entity, or becomes accessible to people outside the entity that originally collected it, which is the trigger for APP 8's cross-border rules. Use means the entity that already holds the information applies it for a purpose, without that information moving to a separate party. This distinction matters because an outsourcing arrangement is almost always a disclosure: an offshore team, even one contracted to work exclusively on the Australian business's behalf, is a different entity or at minimum a separate physical and legal presence gaining access to the information.
The New Zealand position offers a useful contrast here. Under the NZ Privacy Act 2020's IPP12, sending data overseas purely for safe custody or processing on the agency's own behalf, where the offshore provider does not use the data for its own separate purposes, may not constitute a "disclosure" under IPP12 at all, a materially more permissive service-provider exception than Australia's APP 8 offers. Australia has no equivalent exception; engaging an overseas outsourcing provider to process personal information is explicitly treated as a disclosure requiring reasonable steps, regardless of how narrowly the provider's role is scoped.
What are "reasonable steps" in practice, not just in legal theory?
Reasonable steps are the practical, documented measures a business takes to satisfy itself that an overseas recipient will not breach the Australian Privacy Principles, and they need to be specific enough to actually be checked, not a generic assurance. In practice, this typically includes contractual clauses binding the offshore provider to APP-equivalent obligations regardless of where they are located, defined and audited access controls (who at the offshore provider can access what data, under what authentication requirements), data minimisation (the offshore team only receives the fields actually necessary for the task, not a full unrestricted export), encryption in transit and at rest, and a contractual breach notification obligation with a defined timeframe that flows back to the Australian entity fast enough for the entity to meet its own Notifiable Data Breaches scheme obligations.
The OAIC's guidance on sending personal information overseas and its APP 8 chapter frame reasonable steps as fact-specific to the arrangement, the sensitivity of the information, and the recipient's own regulatory environment, rather than a fixed checklist. This is precisely why a generic template contract clause saying "the provider will comply with Australian privacy law" is weak evidence of reasonable steps on its own; what actually holds up is a data processing agreement with specific, checkable obligations matched to the real technical arrangement.
What should a data processing agreement with an offshore provider actually contain?
It should name the specific personal information categories being disclosed, rather than describing the arrangement in vague terms. It should specify where data is stored physically, and separately, who is permitted to access it and from where, since as covered above these are different questions. It should bind the offshore provider to handle the information consistently with the Australian Privacy Principles as if it were itself an APP entity, with defined consequences for breach.
It should set out access control requirements concretely: role-based access, multi-factor authentication for anyone touching the data, logging of access for audit purposes, and a defined offboarding process when an offshore staff member leaves the account. It should include a breach notification clause with an actual timeframe, tight enough that the Australian business can meet its own obligations under the Notifiable Data Breaches scheme, which applies to entities with turnover over $3m and some smaller entities regardless of turnover, generally assessed within a 30-day window. And it should specify what happens to the data at the end of the engagement, deletion, return, or ongoing retention under what terms, since an agreement silent on offboarding leaves a genuine gap. Our cybersecurity services page and data processing services page cover how these access-control and processing obligations are actually implemented operationally, not just documented on paper.
How does this play out differently for storage-only versus active-processing arrangements?
A storage-only arrangement, where offshore infrastructure hosts data but no offshore staff actively work on it, still triggers APP 8 if any overseas party or system could access the information, but the reasonable-steps focus shifts toward infrastructure security, data centre certification, and contractual access restrictions preventing the hosting provider's own staff from viewing content. An active-processing arrangement, where an offshore team is doing the actual work, shifts the reasonable-steps focus toward the human side: who specifically has access, what training they have had, how their access is monitored and revoked, and how disputes or errors get escalated back to the Australian business.
Most outsourcing arrangements are the second kind, and it is worth being precise about that rather than letting "our data is stored on secure servers" stand in for the whole compliance picture; secure storage does not address the separate question of who is actively working with the data day to day. A business setting up any outsourced operation into Australia or New Zealand should treat these as two separate technical and contractual questions to resolve, not one. See our set up in Australia and New Zealand guide for how this fits into a broader market-entry compliance checklist, and our financial services and fintech industry page for where this scrutiny is typically highest.