Buyers agents, offshore VAs and cloud tools: your APP 8 overseas-disclosure duty
Yes. If you send a client's identity or financial data to an offshore virtual assistant, or store it in an overseas-hosted cloud tool, APP 8 can apply. Privacy Act s 6E(1A) applies the Act to a small business operator that is a reporting entity "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act, so the scoping is by activity, not by a list of documents. Before you disclose that personal information to a recipient outside Australia who is not you and not the individual, APP 8.1 requires you to take such steps as are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, other than APP 1. Where APP 8.1 applied and no APP 8.2 exception did, s 16C(2) treats the overseas recipient's act as done by you and as your breach.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
First, when APP 8 actually applies to you
APP 8 is not a duty that lands on your whole practice. It rides in on the same route as the rest of your privacy obligations. Brokering the purchase or transfer of real estate on behalf of a buyer or transferee, in the course of carrying on a business, is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)), and Table 5 commenced on 31 March 2026, so a buyers agent providing that service has been an AUSTRAC reporting entity from that date, with the AML/CTF program, customer due diligence, reporting and record-keeping obligations deferred to 1 July 2026. Privacy Act s 6E(1A) then applies the Privacy Act to a small business operator that is a reporting entity "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act and the regulations and AML/CTF Rules under it, "as if the small business operator were an organisation", regardless of the A$3 million small-business threshold. If your practice is not a small business operator, for example because its annual turnover has been more than A$3 million (s 6D), it is already an organisation and the APPs, APP 8 included, apply across the whole business rather than only to the AML/CTF activities.
APP 8 is one of those thirteen principles. The s 6E(1A) scoping is activity-based rather than a list of documents: it reaches the activities carried on for the purposes of, or in connection with, activities relating to the AML/CTF Act, which is wider than the copied identity document alone. The OAIC's stated position is that where personal information is collected for an AML/CTF purpose as well as a non-AML/CTF purpose, the Privacy Act applies to that information, so a client record that serves both your buy-side service and your customer due diligence is caught rather than excluded. What sits outside is personal-information handling that does not relate to your AML/CTF obligations, such as a newsletter list or property alerts. If you were relying on the small-business exemption before, the APPs had no grip on you at all. Read: does becoming an AML reporting entity trigger the Privacy Act?
That scope point matters in practice, because the same offshore VA who books your inspections and drafts your buyer reports may also touch the identity documents. Personal information you handle in the course of your AML/CTF activities carries the APP 8 duty with it wherever you send it, and on the OAIC's position a record collected for that purpose as well as for your ordinary buy-side service is caught too. Handling that does not relate to your AML/CTF obligations sits outside the s 6E(1A) route unless a separate trigger applies, so the boundary is drawn by the activity, not by which folder the file sits in.
What "reasonable steps" looks like for an offshore VA
APP 8.1 does not ban sending personal information overseas. Before an APP entity discloses personal information about an individual to a person who is not in Australia or an external Territory and "who is not the entity or the individual", the entity "must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information". For a small buyers agency using an offshore assistant, "reasonable steps" is a practical, provable set of actions, not a legal opinion:
- A written contract with the VA or their agency that binds them to APP-consistent handling, confidentiality, security and a ban on repurposing the data.
- A defined, minimal scope of access. The VA sees only the identity or financial data they genuinely need to do the task, not the whole client file. Restricting who can reach a record you already hold is part of the APP 11.1 duty to take such steps as are reasonable in the circumstances to protect it "from unauthorised access, modification or disclosure", and it carries through the APP 3.2 rule that an organisation must not collect personal information unless it is "reasonably necessary for one or more of the entity's functions or activities".
- Security you can point to: access controls, no downloading to personal devices, secure transfer rather than email attachments, and prompt removal of access when the engagement ends.
- A record that you took these steps, so that if a client or the OAIC ever asks, you can show what you did rather than assert it.
The standard is what is reasonable for a practice your size handling data this sensitive, not what a bank would do. But because a buyers agent concentrates high-value identity and financial-capacity data on few clients, the sensitivity of the data raises what "reasonable" looks like. Read: VOI and source-of-funds privacy rules
The accountability trap: you can stay on the hook
This is the part that surprises people. Section 16C applies where an APP entity discloses personal information to an overseas recipient, APP 8.1 applied to the disclosure, the APPs do not apply under the Act to the recipient's own act, and the recipient does something that would breach an APP other than APP 1. Where those conditions are met, the overseas recipient's act "is taken, for the purposes of this Act: (a) to have been done, or engaged in, by the APP entity; and (b) to be a breach of those Australian Privacy Principles by the APP entity" (Privacy Act 1988 (Cth) s 16C(2)). In plain terms, outsourcing the task does not outsource the responsibility. Whether the notification scheme in Part IIIC is also engaged is a separate question that turns on whether you hold the information, which s 6(1) defines as having "possession or control of a record that contains the personal information", and on the breach being an eligible data breach under s 26WE.
That is exactly why the "reasonable steps" above are worth doing properly. They are not box-ticking. They are the difference between a supplier's mistake staying the supplier's problem and it landing on you. Read: your data-breach response plan
APP 8.2 sets out the exceptions, and it works by switching off the reasonable-steps duty: "Subclause 8.1 does not apply to the disclosure". Because s 16C(1)(b) applies only where APP 8.1 applies to the disclosure, an APP 8.2 exception removes the cross-border accountability rule with it. The two that arise most often are APP 8.2(a), where the entity reasonably believes the recipient is subject to a law or binding scheme protecting the information in a way that is "overall, at least substantially similar" to the APPs and that there are mechanisms the individual can access to enforce it, and APP 8.2(b), where the entity "expressly informs the individual that if he or she consents to the disclosure of the information, subclause 8.1 will not apply to the disclosure" and the individual then consents. That express warning is part of the exception, not an optional courtesy, so a consent tucked into a form does not meet it. APP 6 and APP 11 continue to apply to the disclosure either way, so treat the exceptions as narrow and build to the reasonable-steps standard instead.
Overseas-hosted cloud tools count too
APP 8 is not only about a human assistant in another country. It also reaches the software you run. A CRM, a document-storage tool, a VOI or identity-verification service or a client portal can put your caught personal information in the hands of a person outside Australia, and APP 8.1 turns on whether you disclose the information to a recipient "who is not the entity or the individual", not on where a server happens to sit. Where a mainstream tool stores and processes data offshore, the practical first step is to establish, tool by tool, where your caught data goes and who can reach it.
One honest nuance. There is a real distinction in privacy law between disclosing personal information to an overseas recipient and merely using an overseas provider to store or process it on your behalf under your control. This matters more than it sounds: APP 8.1 is expressed as a duty that arises "Before an APP entity discloses", so if the arrangement is a use rather than a disclosure, APP 8.1 is not engaged, and s 16C cannot apply either, because it requires that APP 8.1 applied to the disclosure. Your APP 6 and APP 11 obligations still apply to the handling. Which side of the line a given arrangement falls on is genuinely fact-specific and turns on the contract and the control you keep, so do not assume either way. The safe posture is to know where each tool stores your caught data, and to hold that provider to the same APP-consistent standard you would a VA.
What your privacy policy and collection notice have to say
Overseas disclosure is not just an operational duty, it is a disclosure duty. Two of your documents have to reflect it:
- Your privacy policy (APP 1) must state whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries involved. If you use an offshore VA or an overseas-hosted tool for caught data, your policy cannot stay silent on it. Read: the buyers agent privacy policy
- Your collection notice (APP 5), given at engagement when you collect the client's identity and financial data, should tell the client if their information is likely to go to overseas recipients and, where you can, which countries. Read: the collection notice you need at engagement
APP 1.4(f)-(g) and APP 5.2(i)-(j) ask about your own likely overseas recipients and, where practicable, the countries they are in, so these lines cannot be filled in generically: they have to describe the arrangements a buy-side broker using an offshore assistant actually has. That is the kind of scope-fit a buyers-agent-specific document set is built to cover.
Common questions
I use a virtual assistant in the Philippines for admin. Do I need to worry about APP 8?
If that assistant touches personal information you handle in the course of your AML customer-due-diligence activities, then yes, APP 8 applies to it. Put a written contract in place, limit what the VA can see to what the task needs, keep the data secure in transit and at rest, and record that you did so. On the OAIC's position a record collected for that purpose as well as for your ordinary buy-side service is caught too, so the safe assumption is that a shared client file is in scope. Purely non-AML admin that does not relate to your AML/CTF obligations sits outside the s 6E(1A) route, and good practice is to hold all client data to a consistent standard anyway.
Does APP 8 stop me using overseas software or offshore help altogether?
No. APP 8 does not ban overseas disclosure. It requires reasonable steps to ensure the overseas recipient handles the data consistently with the APPs. You can keep using an offshore VA or an overseas-hosted tool, provided you have contracted for APP-consistent handling, minimised the data they see, secured it and documented the arrangement.
If my offshore assistant leaks a client's identity documents, is that my problem or theirs?
It can become your problem, and s 16C sets out exactly when. Where you disclosed the information to an overseas recipient, APP 8.1 applied to that disclosure, the APPs do not apply under the Act to the recipient's own act, and the recipient does something that would breach an APP other than APP 1, s 16C(2) treats that act as done by you and as your breach of the Australian Privacy Principles. Whether you also have a notification obligation depends on whether you hold the information, which s 6(1) defines as "possession or control of a record that contains the personal information", and on the breach being an eligible data breach under s 26WE. That is the reason to take the reasonable steps up front rather than trust the arrangement.
Can I just get the client to consent to overseas disclosure and skip the reasonable steps?
Consent is one of the exceptions in APP 8.2, but the paragraph has two limbs and both must be met: you must "expressly inform the individual that if he or she consents to the disclosure of the information, subclause 8.1 will not apply to the disclosure", and the individual must consent "after being so informed" (APP 8.2(b)). A consent tucked into a form, without that express warning, does not engage the exception. It is fragile to rely on and easy to get wrong, so treat consent as a narrow exception rather than your default, and build to the reasonable-steps standard.
Where do I find out which country my cloud tool stores data in?
Check the provider's privacy policy, data-processing terms or data-residency documentation, and ask them directly if it is not clear. You need to know this to complete your own privacy policy and collection notice honestly, and to judge what reasonable steps the arrangement calls for.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.