Buyers agents, offshore VAs and cloud tools: your APP 8 overseas-disclosure duty
Yes, if you send a client's identity or financial data to an offshore virtual assistant, or store it in an overseas-hosted cloud tool, APP 8 applies to the AML/KYC data that Privacy Act s 6E(1A) already brings under the Australian Privacy Principles. Before that data leaves Australia you must take reasonable steps to ensure the overseas recipient handles it consistently with the APPs, and in most cases you stay accountable if they do not.
By Jon Oates, Founder of Privaproof · Last updated
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
First, when APP 8 actually applies to you
APP 8 is not a duty that lands on your whole practice. It rides in on the same narrow route as the rest of your privacy obligations. Because you broker property purchases, you become an AUSTRAC reporting entity from 1 July 2026 (brokering the purchase of real estate is a designated service (Table 5 item 1, AML/CTF Act s 6(5A))), and Privacy Act s 6E(1A) then switches the APPs on for the customer-due-diligence data you collect for those checks, regardless of the A$3 million small-business exemption.
APP 8 is one of those thirteen principles. So it reaches the identity, verification, source-of-funds and beneficial-ownership data that s 6E(1A) caught, not your general buyer CRM, your newsletter list or your property alerts. If you were relying on the small-business exemption before, APP 8 had no grip on you at all. Now it grips the AML/KYC data specifically. Read: does becoming an AML reporting entity trigger the Privacy Act?
That scope point matters in practice, because the same offshore VA who books your inspections and drafts your buyer reports may also touch the identity documents. The data that came in for the AML check carries the APP 8 duty with it wherever you send it. The rest of that VA's work does not, unless a separate trigger applies.
What "reasonable steps" looks like for an offshore VA
APP 8.1 does not ban sending personal information overseas. It requires that, before you disclose it to a recipient outside Australia, you take reasonable steps to ensure the recipient does not breach the APPs in how they handle it. For a small buyers agency using an offshore assistant, "reasonable steps" is a practical, provable set of actions, not a legal opinion:
- A written contract with the VA or their agency that binds them to APP-consistent handling, confidentiality, security and a ban on repurposing the data.
- A defined, minimal scope of access. The VA sees only the identity or financial data they genuinely need to do the task, not the whole client file. This is APP 3 collection minimisation carried through to who can see it.
- Security you can point to: access controls, no downloading to personal devices, secure transfer rather than email attachments, and prompt removal of access when the engagement ends.
- A record that you took these steps, so that if a client or the OAIC ever asks, you can show what you did rather than assert it.
The standard is what is reasonable for a practice your size handling data this sensitive, not what a bank would do. But because a buyers agent concentrates high-value identity and financial-capacity data on few clients, the sensitivity of the data raises what "reasonable" looks like. Read: VOI and source-of-funds privacy rules
The accountability trap: you can stay on the hook
This is the part that surprises people. Under the Privacy Act's cross-border accountability rule, if your overseas VA or cloud provider mishandles the personal information you disclosed to them, you can be treated as having breached APP 8 yourself . In plain terms, outsourcing the task does not outsource the responsibility. A breach at the offshore end can become your breach, and your data-breach notification obligation, back in Australia.
That is exactly why the "reasonable steps" above are worth doing properly. They are not box-ticking. They are the difference between a supplier's mistake staying the supplier's problem and it landing on you. Read: your data-breach response plan
There are limited exceptions in APP 8.2 where the accountability rule does not apply, for example where the recipient is subject to a law or binding scheme that protects the data in a substantially similar way and the client can enforce it, or where you have told the client and they have expressly consented to the overseas disclosure. Consent has to be genuine and informed, not a line buried in a form, so do not lean on it as your default. Treat the exceptions as narrow, and build to the reasonable-steps standard instead.
Overseas-hosted cloud tools count too
APP 8 is not only about a human assistant in another country. It also reaches the software you run. A CRM, a document-storage tool, a VOI or identity-verification service, or a client portal that stores its data on servers outside Australia is an overseas disclosure of any caught data you put into it. Many mainstream tools host in the United States, the EU or Asia, so this catches more small practices than they expect.
One honest nuance. There is a real distinction in privacy law between disclosing personal information to an overseas recipient and merely using an overseas provider to store or process it on your behalf under your control. Depending on the arrangement, routing data through a cloud host you control can sit closer to "use" than "disclosure", which changes how APP 8 applies. This is genuinely fact-specific and turns on the contract and the control you keep, so do not assume either way. The safe posture is to know where each tool stores your caught data, and to hold that provider to the same APP-consistent standard you would a VA.
What your privacy policy and collection notice have to say
Overseas disclosure is not just an operational duty, it is a disclosure duty. Two of your documents have to reflect it:
- Your privacy policy (APP 1) must state whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries involved. If you use an offshore VA or an overseas-hosted tool for caught data, your policy cannot stay silent on it. Read: the buyers agent privacy policy
- Your collection notice (APP 5), given at engagement when you collect the client's identity and financial data, should tell the client if their information is likely to go to overseas recipients and, where you can, which countries. Read: the collection notice you need at engagement
A generic template or a selling-agency kit will not carry these lines in a way that fits a buy-side broker who uses an offshore assistant. That is the kind of scope-fit a buyers-agent-specific document set is built to cover.
Common questions
I use a virtual assistant in the Philippines for admin. Do I need to worry about APP 8?
If that assistant touches the identity, verification or financial-capacity data you collect for your AML customer-due-diligence checks, then yes, APP 8 applies to that data. Put a written contract in place, limit what the VA can see to what the task needs, keep the data secure in transit and at rest, and record that you did so. For the VA's non-AML admin work, APP 8 does not bite through the s 6E(1A) route, though good practice is to hold all client data to a consistent standard.
Does APP 8 stop me using overseas software or offshore help altogether?
No. APP 8 does not ban overseas disclosure. It requires reasonable steps to ensure the overseas recipient handles the data consistently with the APPs. You can keep using an offshore VA or an overseas-hosted tool, provided you have contracted for APP-consistent handling, minimised the data they see, secured it and documented the arrangement.
If my offshore assistant leaks a client's identity documents, is that my problem or theirs?
In most cases it can become your problem. Under the Privacy Act's cross-border accountability rule, if the overseas recipient mishandles data you disclosed to them, you can be treated as having breached APP 8, and the data-breach notification obligation is yours . That is the reason to take the reasonable steps up front rather than trust the arrangement.
Can I just get the client to consent to overseas disclosure and skip the reasonable steps?
Consent is one of the limited exceptions in APP 8.2, but it has to be genuine and informed, given after the client is properly told about the overseas disclosure, not tucked into a form. It is fragile to rely on and easy to get wrong, so treat consent as a narrow exception rather than your default, and build to the reasonable-steps standard.
Where do I find out which country my cloud tool stores data in?
Check the provider's privacy policy, data-processing terms or data-residency documentation, and ask them directly if it is not clear. You need to know this to complete your own privacy policy and collection notice honestly, and to judge what reasonable steps the arrangement calls for.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.