Skip to content

Can a real-estate business use an offshore virtual assistant or an overseas admin team?

Yes. Nothing in the Privacy Act prohibits it. Whether APP 8 applies turns on two things people skip: whether the overseas person is a separate entity from you, and whether what you are doing is a disclosure or a use. Your own overseas employee is generally not an "overseas recipient" at all, so APP 6 and APP 11 govern instead. Where APP 8 does apply, you must take reasonable steps to ensure the recipient does not breach the APPs, and you should know whether s 16C accountability actually attaches, because it does not attach in every case.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Which arrangement do you actually have?

Three set-ups look identical from the office and are not the same in law.

The practical exposure is the same in all three: an overseas person can see identity documents, income evidence, arrears histories and entry schedules for occupied homes. Scope system permissions to the work, and use named individual logins so you can tell who saw what.

Sources: Privacy Act 1988 (Cth), APP 6, APP 8.1 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.5, 8.6, 8.10, 8.12, 8.14 and 8.15 · OAIC APP guidelines

What do we actually have to do before we onboard an offshore VA firm?

A defensible package for a small business is not exotic:

What is reasonable scales with the sensitivity of the information and the risk, so an offshore team processing tenancy applications with identity documents attracts more than one doing diary management.

Sources: Privacy Act 1988 (Cth), APP 1.4(f) and (g), APP 5.2(i) and (j), APP 8.1 (Schedule 1) · OAIC APP Guidelines chapters 1, 5 and 8 · OAIC APP guidelines

Why does breach notification from the provider matter so much?

Because their delay spends your clock. Your obligation under the Notifiable Data Breaches scheme runs from the point you have reasonable grounds to suspect an eligible data breach, and s 26WH(2) then requires a "reasonable and expeditious" assessment completed within 30 days. Relying on the provider's own view is not assessing. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court imposed A$800,000 for the s 26WH(2) failure alone, where the entity relied on a third party's conclusion that there had been no eligible data breach, knowing that party had done only a limited assessment.

So put a short, specific notification deadline in the contract, well inside your own. A provider who tells you three weeks late has left you with days.

Sources: Privacy Act 1988 (Cth), Part IIIC, s 26WH(2) · OAIC notifiable data breaches

Are we automatically responsible for what the overseas provider does?

Not automatically. Section 16C(1) makes you accountable for an overseas recipient's acts only where three further conditions are all met: APP 8.1 applies to the disclosure, meaning no APP 8.2 exception is in play (s 16C(1)(b)); the APPs do not already apply to the overseas recipient (s 16C(1)(c)); and the act would breach an APP other than APP 1 (s 16C(1)(d)).

Two things follow that are worth knowing before you sign anything.

First, an Australian link on its own does not switch s 16C off, and this is the point most often stated too generously. The OAIC APP Guidelines put it broadly at 8.63, that "a recipient that has an 'Australian link' will be covered by the Privacy Act". The sections are narrower. Section 5B(1A) does extend the Act to an act done outside Australia by an organisation or a small business operator with an Australian link, including under s 5B(3)(b) (carrying on business in Australia). But s 6C(1) excludes a small business operator from the meaning of "organisation", and s 15 binds only APP entities. So where the provider is a small business operator the APPs still do not apply to it, the second condition above is met, and s 16C does operate. Two questions settle it: is your provider's annual turnover above A$3,000,000 (s 6D(1)), and does it fall into any of the exceptions in s 6D(4)(a) to (f)? If neither, work on the basis that accountability attaches.

Second, relying on an APP 8.2 exception switches off s 16C as well, not just the reasonable-steps duty, because APP 8.2 provides that subclause 8.1 "does not apply" and s 16C(1)(b) bites only where APP 8.1 does. On the consent exception in APP 8.2(b), note what it takes: you must expressly inform the individual, before they consent, that APP 8.1 will not apply, and the OAIC says that statement should at a minimum also explain that you will not be accountable under the Act and that they will not be able to seek redress under it (APP Guidelines 8.32). In a tenancy context that is a difficult conversation to have well, which is usually why reasonable steps is the better route.

Sources: Privacy Act 1988 (Cth), ss 5B(1A), 5B(3)(b), 6C(1), 6D(1), 6D(4), 15 and 16C, and APP 8.1 and 8.2 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.31 to 8.33 and 8.60 to 8.63 · OAIC APP guidelines · See also overseas disclosure and offshore CRMs

→ Can you name the country your VA works from, whose entity employs them, and every system they can open? The free 2-minute audit asks those three questions and scores the answers.