Skip to content

Car dealers, offshore finance and cloud tools: your APP 8 duty

If your dealer management system, CRM, finance-aggregation platform, marketing tool or back-office processing puts customer data in the hands of someone outside Australia who is not you and not the customer, APP 8.1 applies: before you send it you must take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles (other than APP 1). And where APP 8.1 applies, s 16C treats that recipient's breach as yours. Which of your systems could you name the hosting country for today?

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Where a dealership's data goes offshore

It is easy to miss how often dealership data crosses the border:

Most of these are disclosures of customer personal information overseas, and APP 8 governs them. Two are not automatic: your own overseas office or employee is not an "overseas recipient", since APP 8.1(b) excludes a person "who is not the entity or the individual" (OAIC 8.6); and giving an overseas contractor the data can be a use rather than a disclosure where a binding contract keeps its handling under your effective control (8.14), though you still hold it and APP 11 still applies (8.15).

The rule: reasonable steps, and when you stay on the hook

Under APP 8.1, before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs (other than APP 1). The teeth are in s 16C(2): the recipient's breaching act is treated as done by you, and as your breach. Note the limit on reasonable steps. OAIC APP Guidelines 8.62 says an entity may be liable "even where the entity has taken reasonable steps to ensure the overseas recipient complies with the APPs", so they are the APP 8.1 obligation, not a defence. That is why "it is just our software provider" does not offload it, least of all for finance and identity data.

There are limited exceptions (APP 8.2), for example where you reasonably believe the recipient is subject to a law or binding scheme substantially similar to the APPs with a mechanism the customer can access to enforce it, or where the customer is expressly told APP 8.1 will not apply and only then consents. An exception is worth more than it looks: s 16C(1)(b) bites only where APP 8.1 applies, and APP 8.2 says subclause 8.1 "does not apply", so an exception takes the accountability with it (OAIC 8.63). Work your basis out deliberately rather than assume one.

What reasonable steps look like

Common questions

Our DMS is a big overseas cloud platform. Are we disclosing overseas?

Usually yes: your DMS vendor is a separate person, so if the platform stores or processes customer data outside Australia, APP 8.1 applies however well known the platform is. Get that from the provider's own privacy policy or contract rather than assume where a big brand hosts, because that single fact is what the APP 8 analysis turns on. Can you point to the document that names the country your DMS sits in?

The finance platform sends applications through overseas servers. Does that count?

If a buyer's finance data goes to an overseas recipient, APP 8.1 applies, and unless an APP 8.2 exception is made out, s 16C makes that recipient's breach yours. Finance and identity data is not "sensitive information" as s 6(1) defines that term, but it is the data a buyer would least want mishandled, so it is the arrangement worth working out first.

Is there a list of "safe" countries we can send data to freely?

No. Nothing in APP 8 runs off a prescribed country list. The closest thing is the APP 8.2(a) exception, and it puts the assessment on you: it turns on whether you reasonably believe the recipient is subject to a law or binding scheme substantially similar to the APPs, with a mechanism the customer can access to enforce it. So the basis is worked out arrangement by arrangement, and written down.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether an APP 8 exception applies to your arrangement depends on the facts. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading