Can a real-estate business use an offshore virtual assistant or an overseas admin team?
Yes, and many do. Whether APP 8 applies turns on two things people skip: whether the overseas person is a separate entity from you, and whether what you are doing is a disclosure or a use. Your own overseas employee is generally not an "overseas recipient" at all, so APP 6 and APP 11 govern instead. Where APP 8 does apply, you must take reasonable steps to ensure the recipient does not breach the APPs, and you should know whether s 16C accountability actually attaches, because it does not attach in every case.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Which arrangement do you actually have?
Three set-ups look identical from the office and are not the same in law.
- An offshore VA who is your own employee, working in your systems. This is generally not an APP 8 case, because an "overseas recipient" does not include the entity itself. Your obligations run through APP 6 for use and APP 11.1 for security. Those are real duties, just different ones.
- An offshore VA firm or a contractor, meaning a separate legal entity. APP 8 is engaged, and it is engaged even where the other entity is a related body corporate.
- Somewhere in between. Giving information to an overseas provider to perform services for you can be a use rather than a disclosure, where you retain effective control through a binding contract limiting them to your purposes with rights over access, correction, security and deletion. In most circumstances it will be a disclosure, so plan for APP 8 and treat the use argument as a fallback you can evidence, not an assumption.
The practical exposure is the same in all three: an overseas person can see identity documents, income evidence, arrears histories and entry schedules for occupied homes. Scope system permissions to the work, and use named individual logins so you can tell who saw what.
Sources: Privacy Act 1988 (Cth), APP 6, APP 8 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.5, 8.6, 8.10, 8.12 and 8.14 · OAIC APP guidelines
What do we actually have to do before we onboard an offshore VA firm?
A defensible package for a small business is not exotic:
- Know which country the person works from, and where the data they touch is stored.
- Put APP-consistent obligations in the written agreement: confidentiality, permitted use, security, breach notification to you, and return or destruction at the end.
- Scope access to the minimum the role needs, with named individual logins rather than a shared one.
- Require that identity documents and application files are not downloaded to local devices.
- Update your privacy policy and your collection notices to disclose overseas disclosure. Both have a second limb that is easy to miss: the countries where recipients are likely to be located, if it is practicable to specify them (APP 1.4(f) and 1.4(g), APP 5.2(i) and 5.2(j)).
- Diarise a review, because reasonable steps are assessed at the time and arrangements drift.
What is reasonable scales with the sensitivity of the information and the risk, so an offshore team processing tenancy applications with identity documents attracts more than one doing diary management.
Sources: Privacy Act 1988 (Cth), APP 1.4(f) and (g), APP 5.2(i) and (j), APP 8.1 (Schedule 1) · OAIC APP Guidelines chapters 1, 5 and 8 · OAIC APP guidelines
Why does breach notification from the provider matter so much?
Because their delay spends your clock. Your obligation under the Notifiable Data Breaches scheme runs from the point you have reasonable grounds to suspect an eligible data breach, and s 26WH(2) then requires all reasonable steps to complete the assessment within 30 days, which the OAIC treats as a ceiling rather than a target.
So put a short, specific notification deadline in the contract, well inside your own. A provider who tells you three weeks late has left you with days.
Sources: Privacy Act 1988 (Cth), Part IIIC, s 26WH(2) · OAIC notifiable data breaches
Are we automatically responsible for what the overseas provider does?
Not automatically. Section 16C makes you accountable for an overseas recipient's acts only where three conditions are all met: APP 8.1 applies, meaning no APP 8.2 exception is in play; the APPs do not already apply to the overseas recipient; and the act would breach an APP other than APP 1.
Two things follow that are worth knowing before you sign anything.
First, an Australian link on its own does not switch s 16C off, and this is the point most often stated too generously. Section 5B(1A) does extend the Act to an overseas entity's acts where it has an Australian link under s 5B(3)(b) (carrying on business in Australia). But s 6C(1) excludes a small business operator from the meaning of "organisation", and s 15 binds only APP entities. So the APPs still do not apply to a small offshore provider even where it carries on business here, the second condition above is satisfied, and s 16C does operate. Offshore VA firms are overwhelmingly small businesses, so on these facts the working assumption should be that accountability attaches rather than that it does not. The switch-off is real, but it belongs to a recipient that is genuinely covered, which in practice means a large one.
Second, relying on an APP 8.2 exception switches off s 16C as well, not just the reasonable-steps duty. If you are thinking of using the consent exception in APP 8.2(b), note how demanding it is: you must expressly tell the individual, before they consent, that APP 8.1 will not apply, that you will not be accountable, and that they may not be able to seek redress under the Act. In a tenancy context that is a difficult conversation to have well, which is usually why reasonable steps is the better route.
Sources: Privacy Act 1988 (Cth), ss 5B(1A), 5B(3)(b), 6C(1), 15 and 16C, and APP 8.1 and 8.2 (Schedule 1) · OAIC APP Guidelines chapter 8, paragraphs 8.31 to 8.33 and 8.60 to 8.63 · OAIC APP guidelines · See also overseas disclosure and offshore CRMs
→ Not sure where your data actually goes? The free 2-minute audit covers offshore access, which is one of the exposures agencies most often miss.