Skip to content
Corpshore Australia

Compliance and regulation

Privacy Act 1988 and offshoring: what the Australian Privacy Principles actually require

By Corpshore Australia Insights Team8 min read

APP 8 requires reasonable steps before sending personal data overseas, and accountability never transfers with it. Here is what that actually means for offshoring.

Offshoring personal information is legal in Australia. It is also the single area where getting the legal detail wrong creates the most exposure, because the obligation does not end when the data leaves the country. This is grounded directly in the Office of the Australian Information Commissioner's own published guidance, and it is worth reading carefully before signing anything with an offshore provider.

What does APP 8 actually require before you disclose data to an offshore provider?

Australian Privacy Principle 8, together with section 16C of the Privacy Act 1988, requires an Australian entity to take reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles, before that entity discloses personal information to that recipient. This applies explicitly to engaging an overseas outsourcing provider to process data, not just to selling or sharing data with a third party for its own purposes.

The obligation sits with the Australian business, not the offshore provider. It is triggered at the point of disclosure, which means the reasonable-steps assessment needs to happen before a contract is signed and data starts flowing, not retrospectively once an issue has already occurred. The Office of the Australian Information Commissioner's own guidance on sending personal information overseas and its APP 8 chapter are the primary sources for this obligation, and any business considering offshore delivery should read them directly rather than rely on a summary alone.

What is section 16C, and why does accountability not transfer offshore?

Section 16C means that if an overseas recipient breaches an Australian Privacy Principle while handling data on an Australian entity's behalf, the Australian entity is treated as if it committed that breach itself. This is the point that gets missed in commercial conversations about offshoring: the accountability for the data does not move with the workload.

Engaging a well-run offshore provider does not discharge this obligation on its own. It reduces the risk of a breach occurring, which is valuable, but the legal responsibility for the outcome stays with the Australian business that made the disclosure. This has a direct practical consequence for how an offshoring relationship should be structured: the Australian business needs its own visibility into how the provider actually handles data, not just a contractual promise that it will.

For a business handling client data in a regulated sector, this is one reason data processing work is often structured with tighter access controls and reporting than general customer service work, and why sectors carrying additional regulatory weight, financial services in particular, tend to build more oversight into an offshore arrangement from the start. It is a relevant consideration for any financial services and fintech business assessing an offshore provider.

What does "reasonable steps" actually look like in practice?

"Reasonable steps" is a fact-specific standard rather than a fixed checklist, and the Office of the Australian Information Commissioner deliberately does not prescribe one universal list. What can be said, staying within what the OAIC's own guidance supports, is that the assessment sits with the disclosing business and needs to happen before data flows, and that exceptions exist where the individual has given informed consent, or where the overseas recipient is subject to a law that is substantially similar to the APPs and has enforcement mechanisms an individual could actually use.

In practice this means an Australian business should be assessing things like what contractual protections are in place with the offshore provider, what security and access controls the provider applies to Australian client data, and what visibility the Australian business retains once the data is in the provider's systems. This is a genuine legal question with real consequences, and a business handling anything beyond low-sensitivity data should treat this assessment as something requiring its own legal advice rather than something that can be fully resolved by reading a vendor's marketing page, including this one.

How does the Notifiable Data Breaches scheme interact with offshoring?

The Notifiable Data Breaches scheme requires notification of an "eligible data breach" likely to cause serious harm, and it applies to Australian Government agencies and to private and not-for-profit entities with annual turnover over $3 million, plus some smaller entities regardless of turnover, including health service providers, credit reporting bodies and organisations that handle tax file numbers. General practice allows a 30-day window to assess whether a breach is notifiable. The Office of the Australian Information Commissioner's Notifiable Data Breaches page is the primary source for the scheme's mechanics.

This scheme does not distinguish between a breach that occurs in an onshore system and one that occurs inside an offshore provider's systems while processing data on the Australian entity's behalf. If personal information the Australian entity is responsible for is compromised, the notification obligation still runs to that entity. This is another expression of the same principle behind section 16C: the location where the data is processed does not change who has to answer for what happens to it.

What should an Australian business actually do before signing an offshore outsourcing contract?

Staying strictly within what the source material supports, an Australian business should be able to answer three questions before disclosing personal information to an offshore provider: what reasonable steps have been taken to assess whether that provider will meet the Australian Privacy Principles, whether an exception genuinely applies (informed consent, or a substantially similar overseas law with real enforcement), and what the business's own process is for detecting and responding to an eligible data breach wherever in the delivery chain it occurs.

None of this is a reason to avoid offshoring. It is a reason to structure it properly, with the reasonable-steps assessment done up front rather than treated as paperwork. A provider that can speak to its own security posture and access controls in specific terms, rather than in general reassurances, makes that assessment considerably easier to complete. Businesses handling regulated or sensitive data should also weigh how a provider's cybersecurity practices and access controls are structured before extending any offshore engagement to that data, and should treat a first conversation with a provider, whether through a discovery call or a written scope, as the point to raise these questions rather than something to work out after the contract is signed.

Frequently asked questions

Does the Privacy Act 1988 prohibit sending personal data offshore?

No. It permits it, but requires the disclosing Australian entity to take reasonable steps to ensure the overseas recipient will not breach the Australian Privacy Principles, under APP 8 and section 16C. The obligation sits with the Australian business, not the offshore provider.

If an offshore provider causes a data breach, who is legally responsible?

Under section 16C of the Privacy Act 1988, the Australian entity is treated as if it committed the breach itself. Accountability does not transfer to the overseas provider simply because the provider was handling the data at the time.

What counts as 'reasonable steps' under APP 8?

It is a fact-specific standard rather than a fixed checklist, assessed by the disclosing business before data is sent overseas. Exceptions exist where the individual has given informed consent or where the overseas recipient is subject to a law substantially similar to the APPs with real enforcement mechanisms.

Does the Notifiable Data Breaches scheme apply if the breach happens inside an offshore provider's systems?

Yes, if the Australian entity is responsible for the personal information involved and the breach is likely to cause serious harm, the scheme's notification obligations still apply. The location of the breach does not change who has to notify.

Which businesses are covered by the Notifiable Data Breaches scheme?

Australian Government agencies, and private or not-for-profit organisations with annual turnover over $3 million, are covered, along with some smaller entities regardless of turnover such as health service providers and credit reporting bodies. General practice allows a 30-day window to assess whether a breach meets the notification threshold.

Should we get legal advice before signing an offshore outsourcing contract?

Yes, for anything beyond low-sensitivity data. The reasonable-steps assessment under APP 8 is a genuine legal judgement specific to your data and your provider, and it should be made with proper legal advice rather than relying solely on a vendor's own description of its practices.

Build your team with Corpshore

Tell us the work, the delivery location and the coverage you need. You will have a considered response within six hours, or book a discovery call now.

Looking for a role rather than a partner? Explore careers at Corpshore