Skip to content

Can a real-estate business use an offshore virtual assistant or an overseas admin team?

Yes, and many do. Whether APP 8 applies turns on two things people skip: whether the overseas person is a separate entity from you, and whether what you are doing is a disclosure or a use. Your own overseas employee is generally not an "overseas recipient" at all, so APP 6 and APP 11 govern instead. Where APP 8 does apply, you must take reasonable steps to ensure the recipient does not breach the APPs, and you should know whether s 16C accountability actually attaches, because it does not attach in every case.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Which arrangement do you actually have?

Three set-ups look identical from the office and are not the same in law.

The practical exposure is the same in all three: an overseas person can see identity documents, income evidence, arrears histories and entry schedules for occupied homes. Scope system permissions to the work, and use named individual logins so you can tell who saw what.

Sources: Privacy Act 1988 (Cth), APP 6, APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.5, 8.6, 8.10, 8.12 and 8.14 · OAIC APP guidelines

What do we actually have to do before we onboard an offshore VA firm?

A defensible package for a small business is not exotic:

What is reasonable scales with the sensitivity of the information and the risk, so an offshore team processing tenancy applications with identity documents attracts more than one doing diary management.

Sources: Privacy Act 1988 (Cth), APP 1.4(f) and (g), APP 5.2(i) and (j), APP 8.1 (Schedule 1) · OAIC APP Guidelines chapters 1, 5 and 8 · OAIC APP guidelines

Why does breach notification from the provider matter so much?

Because their delay spends your clock. Your obligation under the Notifiable Data Breaches scheme runs from the point you have reasonable grounds to suspect an eligible data breach, and s 26WH(2) then requires all reasonable steps to complete the assessment within 30 days, which the OAIC treats as a ceiling rather than a target.

So put a short, specific notification deadline in the contract, well inside your own. A provider who tells you three weeks late has left you with days.

Sources: Privacy Act 1988 (Cth), Part IIIC, s 26WH(2) · OAIC notifiable data breaches

Are we automatically responsible for what the overseas provider does?

Not automatically. Section 16C makes you accountable for an overseas recipient's acts only where three conditions are all met: APP 8.1 applies, meaning no APP 8.2 exception is in play; the APPs do not already apply to the overseas recipient; and the act would breach an APP other than APP 1.

Two things follow that are worth knowing before you sign anything.

First, an Australian link on its own does not switch s 16C off, and this is the point most often stated too generously. Section 5B(1A) does extend the Act to an overseas entity's acts where it has an Australian link under s 5B(3)(b) (carrying on business in Australia). But s 6C(1) excludes a small business operator from the meaning of "organisation", and s 15 binds only APP entities. So the APPs still do not apply to a small offshore provider even where it carries on business here, the second condition above is satisfied, and s 16C does operate. Offshore VA firms are overwhelmingly small businesses, so on these facts the working assumption should be that accountability attaches rather than that it does not. The switch-off is real, but it belongs to a recipient that is genuinely covered, which in practice means a large one.

Second, relying on an APP 8.2 exception switches off s 16C as well, not just the reasonable-steps duty. If you are thinking of using the consent exception in APP 8.2(b), note how demanding it is: you must expressly tell the individual, before they consent, that APP 8.1 will not apply, that you will not be accountable, and that they may not be able to seek redress under the Act. In a tenancy context that is a difficult conversation to have well, which is usually why reasonable steps is the better route.

Sources: Privacy Act 1988 (Cth), ss 5B(1A), 5B(3)(b), 6C(1), 15 and 16C, and APP 8.1 and 8.2 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.31 to 8.33 and 8.60 to 8.63 · OAIC APP guidelines · See also overseas disclosure and offshore CRMs

→ Not sure where your data actually goes? The free 2-minute audit covers offshore access, which is one of the exposures agencies most often miss.