Almost every Australian small business sends personal information overseas, and most of them believe they do not.
Your mailing list is on a US platform. Your payments run through a processor with servers abroad. Your website is hosted somewhere, your backups are somewhere else, your helpdesk and your accounting software are cloud services with data centres in several countries. None of that feels like “sending data overseas”. Under the Privacy Act, a good deal of it is.
What APP 8 actually requires
Before you disclose personal information to an overseas recipient, APP 8.1 requires you to take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles in relation to it.
The sting is in what follows. Under section 16C, if that overseas recipient mishandles the information, you are treated as having breached the APPs. The obligation does not transfer with the data. You remain accountable for it.
And what your policy has to say
Separately from APP 8, APP 1.4 requires your privacy policy to state whether you are likely to disclose personal information to overseas recipients and, if so, the countries those recipients are located in: named, where it is practicable to name them.
“We may transfer your information overseas” does not meet that. It is the sentence most templates use, and it is the one that tells a reader least.
Where to look in your own business
Work through what you actually use, rather than trying to recall it:
- Email and marketing. Your mail platform, your newsletter tool, your CRM.
- Payments. Your processor, and anything that stores a customer record.
- Hosting and backups. Including the backup you set up once and forgot.
- Everyday software. Accounting, scheduling, helpdesk, file storage, e-signature, project tools, transcription and meeting-notes tools.
- Anything with AI in it. If customer information goes into it, it counts.
- Contractors. A bookkeeper or VA working from another country is an overseas disclosure as surely as a cloud service is.
Most providers publish where they store data, usually in a sub-processor list or a trust page. It is tedious to assemble once and then rarely changes.
Two things that are not overseas disclosure
It is worth knowing what you can leave out, because over-disclosing is its own kind of inaccuracy:
- An Australian-hosted service run by a foreign company. What matters is where the information goes and who can reach it, not where the company is incorporated.
- Routing, rather than storage. A content delivery network passing traffic through is treated differently from a service that holds your customer records. If you are not sure which one you have, ask the provider.
The practical risk
This is not a theoretical obligation. Since 10 June 2025 Australia has had a statutory tort for serious invasions of privacy, and a person bringing a claim does not have to prove they suffered loss. The question of who was accountable for information held by a third party is no longer only a regulator’s question.
General information, not advice. This is general information about Australian law, the same for every reader. It is not advice about your situation, and AegorIQ is not a law practice. If you are unsure which parts apply to you, your accountant or a lawyer can tell you.