Privacy policies

Sending information overseas, mostly without meaning to.

Your mailing list, your payment processor, your hosting, your backups. Almost every Australian small business discloses personal information overseas, and most believe they do not.

Almost every Australian small business sends personal information overseas, and most of them believe they do not.

Your mailing list is on a US platform. Your payments run through a processor with servers abroad. Your website is hosted somewhere, your backups are somewhere else, your helpdesk and your accounting software are cloud services with data centres in several countries. None of that feels like “sending data overseas”. Under the Privacy Act, a good deal of it is.

What APP 8 actually requires

Before you disclose personal information to an overseas recipient, APP 8.1 requires you to take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles in relation to it.

The sting is in what follows. Under section 16C, if that overseas recipient mishandles the information, you are treated as having breached the APPs. The obligation does not transfer with the data. You remain accountable for it.

You stay responsible for what happens to it. Choosing a well-known provider is not the same as having taken reasonable steps, and neither is a contract nobody read.

And what your policy has to say

Separately from APP 8, APP 1.4 requires your privacy policy to state whether you are likely to disclose personal information to overseas recipients and, if so, the countries those recipients are located in: named, where it is practicable to name them.

“We may transfer your information overseas” does not meet that. It is the sentence most templates use, and it is the one that tells a reader least.

Where to look in your own business

Work through what you actually use, rather than trying to recall it:

Most providers publish where they store data, usually in a sub-processor list or a trust page. It is tedious to assemble once and then rarely changes.

Two things that are not overseas disclosure

It is worth knowing what you can leave out, because over-disclosing is its own kind of inaccuracy:

The practical risk

This is not a theoretical obligation. Since 10 June 2025 Australia has had a statutory tort for serious invasions of privacy, and a person bringing a claim does not have to prove they suffered loss. The question of who was accountable for information held by a third party is no longer only a regulator’s question.

General information, not advice. This is general information about Australian law, the same for every reader. It is not advice about your situation, and AegorIQ is not a law practice. If you are unsure which parts apply to you, your accountant or a lawyer can tell you.

The builder

It asks which countries, because the policy has to name them.

The builder works through where your information actually goes (your mail platform, your payment processor, your hosting, your backups) and writes the disclosure that APP 8 and APP 1.4 require.

Common questions

Does using a US email platform count as sending data overseas?

Generally yes. If personal information is disclosed to a recipient outside Australia (a mailing platform, CRM, helpdesk, file storage or payment processor holding customer records), that is a cross-border disclosure under APP 8, whether or not it feels like one.

What does APP 8 require?

Before disclosing personal information to an overseas recipient, you must take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles in relation to it. Under section 16C, if the overseas recipient mishandles the information you are treated as having breached the APPs yourself. The accountability does not transfer with the data.

Does my privacy policy have to name the countries?

APP 1.4 requires the policy to state whether you are likely to disclose personal information to overseas recipients and, if so, the countries those recipients are located in, where it is practicable to name them. 'We may transfer your information overseas' does not meet that.

Is an Australian-hosted service run by a foreign company an overseas disclosure?

What matters is where the information goes and who can access it, not where the company is incorporated. A service that stores your data in Australia is a different question from one that stores it abroad, and a content delivery network routing traffic is treated differently from a service holding customer records. If you are unsure which you have, ask the provider.

Do overseas contractors count?

Yes. A bookkeeper, virtual assistant or developer working from another country and accessing customer information is an overseas disclosure as surely as a cloud service is.