Can a real-estate business use an offshore virtual assistant or an overseas admin team?
Yes. Nothing in the Privacy Act prohibits it. Whether APP 8 applies turns on two things people skip: whether the overseas person is a separate entity from you, and whether what you are doing is a disclosure or a use. Your own overseas employee is generally not an "overseas recipient" at all, so APP 6 and APP 11 govern instead. Where APP 8 does apply, you must take reasonable steps to ensure the recipient does not breach the APPs, and you should know whether s 16C accountability actually attaches, because it does not attach in every case.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Which arrangement do you actually have?
Three set-ups look identical from the office and are not the same in law.
- An offshore VA who is your own employee, working in your systems. This is generally not an APP 8 case, because APP 8.1(b) excludes a recipient "who is not the entity or the individual". Your obligations run through APP 6 for use and APP 11.1 for security. Check the paperwork first: if the VA is engaged through an offshore agency or an employer of record, your contract is with that entity and the next case applies.
- An offshore VA firm or a contractor, meaning a separate legal entity. APP 8 is engaged, and it is engaged even where the other entity is a related body corporate.
- Somewhere in between. Giving information to an overseas provider to perform services for you can be a use rather than a disclosure, but only where you never release it from your effective control: a binding contract limiting them to those purposes, the same obligations passed down to any subcontractor, and your right to access, change, retrieve and delete the information (OAIC APP Guidelines 8.14). In most circumstances it is still a disclosure (8.12), so treat the use argument as a fallback you can evidence. It is not an escape either. You still hold the information, so mishandling in the provider's hands can breach the APPs as your own act (8.15).
The practical exposure is the same in all three: an overseas person can see identity documents, income evidence, arrears histories and entry schedules for occupied homes. Scope system permissions to the work, and use named individual logins so you can tell who saw what.
Sources: Privacy Act 1988 (Cth), APP 6, APP 8.1 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.5, 8.6, 8.10, 8.12, 8.14 and 8.15 · OAIC APP guidelines
What do we actually have to do before we onboard an offshore VA firm?
A defensible package for a small business is not exotic:
- Know which country the person works from, and where the data they touch is stored.
- Put APP-consistent obligations in the written agreement: confidentiality, permitted use, security, breach notification to you, and return or destruction at the end.
- Scope access to the minimum the role needs, with named individual logins rather than a shared one.
- Require that identity documents and application files are not downloaded to local devices.
- Update your privacy policy and your collection notices to disclose overseas disclosure. Both have a second limb that is easy to miss: the countries where recipients are likely to be located, if it is practicable to specify them (APP 1.4(f) and 1.4(g), APP 5.2(i) and 5.2(j)).
- Diarise a review, because reasonable steps are assessed at the time and arrangements drift.
What is reasonable scales with the sensitivity of the information and the risk, so an offshore team processing tenancy applications with identity documents attracts more than one doing diary management.
Sources: Privacy Act 1988 (Cth), APP 1.4(f) and (g), APP 5.2(i) and (j), APP 8.1 (Schedule 1) · OAIC APP Guidelines chapters 1, 5 and 8 · OAIC APP guidelines
Why does breach notification from the provider matter so much?
Because their delay spends your clock. Your obligation under the Notifiable Data Breaches scheme runs from the point you have reasonable grounds to suspect an eligible data breach, and s 26WH(2) then requires a "reasonable and expeditious" assessment completed within 30 days. Relying on the provider's own view is not assessing. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court imposed A$800,000 for the s 26WH(2) failure alone, where the entity relied on a third party's conclusion that there had been no eligible data breach, knowing that party had done only a limited assessment.
So put a short, specific notification deadline in the contract, well inside your own. A provider who tells you three weeks late has left you with days.
Sources: Privacy Act 1988 (Cth), Part IIIC, s 26WH(2) · OAIC notifiable data breaches
Are we automatically responsible for what the overseas provider does?
Not automatically. Section 16C(1) makes you accountable for an overseas recipient's acts only where three further conditions are all met: APP 8.1 applies to the disclosure, meaning no APP 8.2 exception is in play (s 16C(1)(b)); the APPs do not already apply to the overseas recipient (s 16C(1)(c)); and the act would breach an APP other than APP 1 (s 16C(1)(d)).
Two things follow that are worth knowing before you sign anything.
First, an Australian link on its own does not switch s 16C off, and this is the point most often stated too generously. The OAIC APP Guidelines put it broadly at 8.63, that "a recipient that has an 'Australian link' will be covered by the Privacy Act". The sections are narrower. Section 5B(1A) does extend the Act to an act done outside Australia by an organisation or a small business operator with an Australian link, including under s 5B(3)(b) (carrying on business in Australia). But s 6C(1) excludes a small business operator from the meaning of "organisation", and s 15 binds only APP entities. So where the provider is a small business operator the APPs still do not apply to it, the second condition above is met, and s 16C does operate. Two questions settle it: is your provider's annual turnover above A$3,000,000 (s 6D(1)), and does it fall into any of the exceptions in s 6D(4)(a) to (f)? If neither, work on the basis that accountability attaches.
Second, relying on an APP 8.2 exception switches off s 16C as well, not just the reasonable-steps duty, because APP 8.2 provides that subclause 8.1 "does not apply" and s 16C(1)(b) bites only where APP 8.1 does. On the consent exception in APP 8.2(b), note what it takes: you must expressly inform the individual, before they consent, that APP 8.1 will not apply, and the OAIC says that statement should at a minimum also explain that you will not be accountable under the Act and that they will not be able to seek redress under it (APP Guidelines 8.32). In a tenancy context that is a difficult conversation to have well, which is usually why reasonable steps is the better route.
Sources: Privacy Act 1988 (Cth), ss 5B(1A), 5B(3)(b), 6C(1), 6D(1), 6D(4), 15 and 16C, and APP 8.1 and 8.2 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.31 to 8.33 and 8.60 to 8.63 · OAIC APP guidelines · See also overseas disclosure and offshore CRMs
→ Can you name the country your VA works from, whose entity employs them, and every system they can open? The free 2-minute audit asks those three questions and scores the answers.