Skip to content

Overseas disclosure and offshore CRMs: APP 8 for real-estate agencies

If your agency is covered by the Privacy Act and a CRM, cloud service or overseas contractor holds client data outside Australia, APP 8.1 generally applies: you must take steps reasonable in the circumstances to ensure the overseas recipient does not breach the APPs (other than APP 1). Section 16C then makes the recipient's breach your breach. Both fall away together if an APP 8.2 exception applies, because s 16C(1)(b) only bites where APP 8.1 applied.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Whether the Privacy Act applies, and how, depends on your agency's circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

When does a real-estate agency's data actually go overseas?

Ask it of your own stack: which of your systems holds client personal information, and where does that system actually keep it? An agency sends personal information overseas whenever a tool that holds that information stores or processes it outside Australia. The three common routes are: a CRM or trust/PM platform hosted overseas (check your own vendor's data-residency terms); general cloud services (email, file storage, e-signature, screening add-ons) whose default region isn't Australia; and overseas contractors or virtual assistants, engaged as separate people, who access your systems from another country. One line decides a lot here: an "overseas recipient" under APP 8.1(b) is a person who is not your entity, so your own overseas office or employee is not an APP 8 disclosure (OAIC APP Guidelines 8.5-8.6), while a contractor or a vendor is. The first practical move is knowing where each system keeps its data, because you can't manage an exposure you can't see.

For the labour-and-access side of this specifically (offshore VAs and property-management providers), see offshore VAs and overseas data under APP 8. This page focuses on the software and hosting side.

What does APP 8 require, and what is the s 16C accountability rule?

APP 8 governs cross-border disclosure of personal information. Before an APP entity discloses personal information to an overseas recipient, it "must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information" (Privacy Act 1988 (Cth) Sch 1, APP 8.1). Behind it sits section 16C, and it is cumulative: where APP 8.1 applied to the disclosure (s 16C(1)(b)), the APPs do not otherwise reach the recipient (s 16C(1)(c)), and the recipient does something that would breach the APPs other than APP 1 (s 16C(1)(d)), that act "is taken ... to have been done ... by the APP entity" and to be the entity's own breach (s 16C(2)). Sending data offshore does not send the responsibility with it. Which is why "we just use whatever CRM the office has always used" is not an answer to the only question APP 8.1 asks: what steps did you take?

Does hosting client data on an overseas server count as "disclosure"?

Usually yes, but not automatically, and the exception is a contract test you can run yourself. OAIC's position is that where an entity engages an overseas contractor, "in most circumstances, the provision of personal information to that contractor is a disclosure" (APP Guidelines 8.12). But para 8.14 carves out overseas cloud storage kept under your effective control: it "may be a use, rather than a disclosure", and then "the entity would not need to comply with APP 8". Three things have to be true, so read your vendor contract for them: it binds the provider to handle the data only for the limited storage and access purposes you set; it binds any subcontractor to the same obligations; and it gives you effective control of how the data is handled, including the right to access, change, retrieve and permanently delete it. Miss one and you are in APP 8. Meet all three and you still "hold" the information, so APP 11 security applies either way (8.15).

Are the APP 8.2 exceptions a reliable get-out?

Two exceptions matter for agencies, and neither is automatic. APP 8.2 says "subclause 8.1 does not apply", and that cuts twice: it also switches off s 16C, which only operates where "Australian Privacy Principle 8.1 applies to the disclosure" (s 16C(1)(b)). Under APP 8.2(a) you must reasonably believe both that the recipient is subject to a law or binding scheme protecting the information "at least substantially similar" to the APPs, and that "there are mechanisms that the individual can access to take action to enforce that protection". Under APP 8.2(b) you must "expressly inform the individual that if he or she consents to the disclosure of the information, subclause 8.1 will not apply to the disclosure", and the individual must consent after being so informed. The trap is reading 8.2(a) as satisfied because a country "has a privacy law": both limbs have to hold, for that recipient. For most agencies the cleaner path is APP 8.1 itself, meaning due diligence plus a contract binding the provider to APP-equivalent handling.

What must your privacy policy and collection notices disclose?

If you're likely to send personal information overseas, you generally have to say so, in two places. Your privacy policy must state whether you are likely to disclose personal information to overseas recipients and, if practicable, the countries where they're located (APP 1.3–1.4). Your collection notice given at the point you collect the information must, where you're likely to disclose overseas, tell the individual that, and generally identify the likely countries where practicable (APP 5). So a "no overseas disclosure" line in your policy while your CRM runs on US servers is a mismatch worth fixing. Being straight about where data goes isn't just an APP 8 issue; it's part of the transparency the Privacy Act expects (see privacy policy vs collection notice and the APP 5 collection notice).

Is a small agency even caught by this?

Not every small agency is an APP entity, but the exceptions are wide, so check before assuming you're out. Under section 6D, a business whose annual turnover for the previous financial year was A$3 million or less is generally a small business (s 6D(1)). That exemption still exists (a broader removal has been proposed but is not law). But you are not a small business operator if you have ever had turnover over A$3m in a financial year since you started (s 6D(4)(a), a one-way ratchet that a later fall in turnover does not undo), if you trade in personal information (s 6D(4)(c)-(d)), if you are a Commonwealth contracted service provider (s 6D(4)(e)), if you are related to a body corporate that is not a small business (s 6D(9)), or if you opt in (s 6EA). AML/CTF works differently again: it is a carve-in, not a removal of the exemption. Agencies providing designated real-estate services have been AUSTRAC reporting entities since 31 March 2026, and section 6E(1A) then applies the Privacy Act "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if you were an organisation. Note what that is scoped to: those activities, not a list of data fields and not your whole business. So where an overseas-hosted tool sits inside an AML/CTF activity, APP 8 can reach it below the $3m threshold. See does the Privacy Act apply to real-estate agents and ID documents, AUSTRAC and privacy.

Practical steps: find out where your CRM stores data, then close the gap

Reasonable steps are a short sequence, not a signature. You don't need a data-protection department; you need to know where your data lives and to have documented the steps you took. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court found it unreasonable for the entity to rely on a third-party provider's conclusion when it knew that provider had carried out only a limited assessment. Taking the vendor's word for it was the step that failed.

StepWhat to doWhy it matters
1. Map your toolsList every system that holds client personal information (CRM, PM/trust software, email, cloud storage, e-sign, screening add-ons)You can't manage exposure you haven't found
2. Ask "where is the data hosted?"Check each provider's data-location / hosting terms; some publish this. Ask the vendor directly if it isn't clearLocation is what puts APP 8 in play; the contract decides whether it is engaged
3. Prefer Australian data regions where offeredSome providers let you choose an Australian hosting regionNarrows APP 8 exposure for your most sensitive data
4. Read the contract and safeguardsCheck it for the three APP Guidelines 8.14 terms: purpose limits, subcontractor flow-down, and your right to access, change, retrieve and deleteDecides use vs disclosure, and evidences your reasonable steps under APP 8.1
5. Fix your disclosuresMake sure your privacy policy and collection notices honestly reflect overseas disclosureAPP 1.3–1.4 and APP 5 obligations
6. Lock down accessLeast-privilege, named logins, MFA, no bulk export for offshore staffShrinks both breach risk and the liability gap
7. Record and reviewKeep a short record; reassess when you change or add a toolShows ongoing, defensible compliance

This is general guidance on a defensible order of operations, not a legal determination for your agency.

Next steps

Two ways to get a grip on overseas disclosure:

→ Start the free 2-minute self-audit

Common questions

Does using a US-hosted real-estate CRM breach the Privacy Act?

Not by itself. In most circumstances providing personal information to an overseas contractor is a disclosure that engages APP 8.1 (OAIC APP Guidelines 8.12), which requires steps reasonable in the circumstances to ensure the provider does not breach the APPs, plus honest disclosure in your policy and notices. Where the contract keeps the handling under your effective control it may instead be a use, and APP 8 does not apply (8.14). Either way it is a manageable obligation, not an automatic breach.

How do I find out whether my CRM stores data overseas?

Check the provider's data-location, hosting or security documentation, and if it isn't clear, ask them directly and get the answer in writing. Some providers offer an Australian hosting region you can select. Ask for the contract terms at the same time: location tells you whether APP 8 is in play, and the effective-control terms tell you whether the arrangement is a disclosure or a use (OAIC APP Guidelines 8.14).

Is my agency responsible if an overseas provider mishandles client data?

Potentially yes. Section 16C applies where you disclosed personal information to an overseas recipient, APP 8.1 applied to that disclosure (s 16C(1)(b)), the APPs do not otherwise apply to the recipient (s 16C(1)(c)), and the recipient does something that would breach the APPs other than APP 1 (s 16C(1)(d)). The act is then "taken ... to have been done ... by the APP entity" and to be that entity's own breach (s 16C(2)). If an APP 8.2 exception applies, APP 8.1 does not, so s 16C does not either. Taking reasonable steps under APP 8.1, backed by a contract binding the provider to APP-equivalent handling, is the ordinary path.

Do I have to mention overseas disclosure in my privacy policy?

If you're likely to disclose personal information overseas, your privacy policy should say so and, where practicable, identify the likely countries (APP 1.3–1.4), and your collection notice should reflect it too (APP 5). A "we don't send data overseas" line while your software runs on offshore servers is a mismatch worth correcting.

We're a small agency under $3 million turnover, does APP 8 still apply?

It can. The $3m small-business exemption under section 6D still exists, and being an AML/CTF reporting entity does not remove it (it is not one of the s 6D(4) grounds). Section 6E(1A) works differently: since 31 March 2026 agencies providing designated real-estate services have been reporting entities, and 6E(1A) applies the Privacy Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, as if you were an organisation. So where an overseas-hosted tool sits inside those activities, APP 8 can reach it even below the threshold. The AML/CTF obligations themselves, including AUSTRAC enrolment, commenced 1 July 2026.

Yes, but APP 8.2(b) is exact about both the wording and the order. You must "expressly inform the individual that if he or she consents to the disclosure of the information, subclause 8.1 will not apply to the disclosure", and the individual must consent after being so informed (APP 8.2(b)(i)-(ii)). Note what that consent switches off: APP 8.1, and s 16C with it, because s 16C(1)(b) needs 8.1 to have applied. A line buried in a policy does not meet the express-information requirement. For most agencies the cleaner path is APP 8.1 itself.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Whether an APP 8.2 exception applies, or whether a particular arrangement is a "use" or a "disclosure", depends on your circumstances and on an overseas country's laws; get advice before relying on an exception. Sources: OAIC, APP 8 cross-border disclosure (APP Guidelines, Chapter 8); OAIC, APP 1 and APP 5 guidelines; Privacy Act 1988 (Cth) ss 6D, 6E(1A), 16C and APP 5 & APP 8; AUSTRAC, real estate professionals.

Last reviewed: 22 July 2026.