Do conveyancers disclose client data overseas via PEXA, screening or cloud software?
Possibly, and your providers' own policies answer it. Disclosing client personal information to an overseas recipient triggers APP 8.1: reasonable steps to ensure that recipient does not breach the APPs (other than APP 1). PEXA and Sympli each state their e-conveyancing infrastructure sits in Australia, but Sympli's policy also names the United States and Vietnam for other personal information, so read your screening and cloud tools rather than assume.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What does APP 8 require?
APP 8 deals with cross-border disclosure. Before an APP entity discloses personal information to an overseas recipient, defined in APP 8.1 as a person not in Australia "who is not the entity or the individual", it must take reasonable steps to ensure the recipient doesn't breach the APPs (other than APP 1). Section 16C adds accountability: the recipient's act is taken to be your act and your breach. But s 16C(1)(b) bites only where "Australian Privacy Principle 8.1 applies to the disclosure", and APP 8.2 says subclause 8.1 "does not apply" once an exception is made out, so an exception takes s 16C with it (OAIC APP Guidelines 8.61 and 8.63). One exception is narrower than it sounds: APP 8.2(b) requires you to expressly inform the individual that APP 8.1 will not apply, and only then obtain consent. Does your collection notice say that?
For a conveyancer, this now matters because the AML-connected data you hold (identity documents, screening results, source-of-funds evidence) is exactly the kind you'd least want mishandled overseas.
Where might a conveyancer's data go overseas?
The honest answer is "it depends on your stack," and two arrangements aren't APP 8 disclosures at all. Your own overseas office or offshore employee isn't an "overseas recipient": APP 8.1(b) excludes "the entity or the individual" (OAIC APP Guidelines 8.6). And handing an overseas contractor the information can be a use, not a disclosure, where a binding contract keeps its handling under your "effective control" (8.14), though you still hold it and APP 11 still applies (8.15). Map the rest:
| Tool / recipient | Typically | APP 8 relevance |
|---|---|---|
| PEXA / Sympli (ELNOs) | ELN infrastructure stated onshore | Sympli names the US and Vietnam for other data |
| Land titles / registry portals | Operated by state/territory governments, onshore | Lower |
| PEP / sanctions screening | May draw on offshore data sources | Check where data is sent and stored |
| Cloud matter-management software | May store data offshore | Check the provider's data location |
| General cloud, email, storage | Varies widely | Check: this is the easy one to miss |
The pattern: the conveyancing rails keep settlement data onshore on the providers' own written commitments, and Sympli names the United States and Vietnam for anything outside Land Information. The general-purpose tools (cloud storage, some screening vendors, email) are where offshore disclosure quietly happens.
Who's accountable if an overseas provider mishandles data?
The reason APP 8 and s 16C matter isn't paperwork for its own sake. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, on the way to a A$5.8m civil penalty, the Federal Court counted "the overreliance that ACL placed on third party service providers" among the relevant circumstances, at paragraph 52(g). That was an APP 11 security case against an ASX-listed pathology company, not this. What carries across: relying on a provider is not itself a reasonable step, and APP 8.1 asks for steps you can show.
What should you do?
- Map your providers. List the tools that touch client personal information and note, for each, whether data leaves Australia.
- Read the overseas clause, not the marketing. The OAIC generally expects an enforceable contract requiring the recipient to handle the information in accordance with the APPs, and to bind its subcontractors too (APP Guidelines 8.16).
- Cover it in your policy and notices. Your privacy policy should be honest about whether you disclose information overseas, and your collection process should reflect it.
- Prefer onshore where you sensibly can for the most sensitive data; it narrows your APP 8 exposure.
This is the same accountability logic that runs through the rest of your obligations: know what data you hold, know where it goes, and be able to show you handled it responsibly.
Common questions
Does using PEXA send client data overseas?
PEXA's policy states that "Any infrastructure forming part of our ELN system and in which personal information is stored, is located within Australia." Sympli's May 2025 policy says the same of its ELNO System and Land Information, then names service providers in the United States and Vietnam for other personal information. Confirm each provider's current policy rather than assume: the APP 8.1 reasonable-steps obligation is yours.
Am I responsible if an overseas provider mishandles my client's data?
Potentially. Section 16C(1) makes an overseas recipient's act your act and your breach, but only where APP 8.1 applied, so an APP 8.2 exception removes the accountability with it. And note what reasonable steps don't do: OAIC APP Guidelines 8.62 says an entity may be liable "even where the entity has taken reasonable steps to ensure the overseas recipient complies with the APPs". They are the APP 8.1 obligation, not a defence to s 16C.
What's the biggest overseas-disclosure risk for a conveyancer?
Usually the general-purpose tools (cloud storage, email, and some screening vendors) rather than the conveyancing-specific platforms. They're the easiest to overlook when you map where data goes.
Do I have to mention overseas disclosure in my privacy policy?
Yes, and it is a "must". APP 1.4(f) requires the policy to state whether you are likely to disclose personal information to overseas recipients, and APP 1.4(g) the countries those recipients are likely to be in, where practicable to specify. Does yours name a country?
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC, APP Guidelines Chapter 8 (APP 8: cross-border disclosure); Privacy Act 1988 (Cth), authorised text; OAIC, privacy guidance for reporting entities under the AML/CTF Act; PEXA, Privacy Policy; Sympli, Privacy Policy (May 2025).