Offshore recruiters and overseas screening: your APP 8 duty over candidate data
If you use an offshore recruiter, a virtual assistant overseas, an applicant-tracking system hosted outside Australia, or an overseas background-check provider, candidate data is being disclosed overseas, and APP 8 applies. Before you send it, you must take reasonable steps to ensure the overseas recipient handles it consistently with the Australian Privacy Principles. And in many cases you remain accountable for what that recipient does with it, as if you had done it yourself.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
Where candidate data crosses the border
It is easy to miss how often recruitment data leaves Australia:
- an offshore virtual assistant or sourcer who screens CVs, schedules or does data entry,
- an overseas parent or group you share candidate records with,
- an applicant-tracking system, CRM or cloud storage hosted overseas,
- an overseas background, identity or reference-checking provider.
Each of those is a disclosure of candidate personal information overseas, and APP 8 governs it.
The rule: reasonable steps, and you stay on the hook
Under APP 8.1, before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs in handling it. The practical teeth are in the accountability rule (s 16C): broadly, an act done by the overseas recipient that would breach the APPs is treated as if you did it, so a mishandling offshore can become your breach. That is why "we just use an overseas VA" is not a way to offload the obligation.
There are limited exceptions (APP 8.2), for example where the recipient is subject to a law or binding scheme that is substantially similar to the APPs with a way to enforce it, or where the candidate is expressly informed that the reasonable-steps protection will not apply and consents. These are specific and fact-dependent, so do not assume one applies, work out your basis deliberately.
What "reasonable steps" looks like in practice
- Know where your data actually is. Map which providers and systems hold candidate data and in which countries, including where your ATS and cloud tools are hosted.
- Bind your providers by contract to handle the data consistently with the APPs (purpose limits, security, breach notification, no further disclosure).
- Limit what goes offshore. Send only what the offshore function needs, not the whole candidate file.
- Tell candidates. APP 5 requires your collection notice to disclose that you are likely to disclose information overseas and, where practicable, the countries. Read: the candidate collection notice
- Cover a breach. If offshore-held candidate data is breached, it still engages the Notifiable Data Breaches scheme. Read: a data-breach response plan for recruitment agencies
Common questions
Our ATS is a big overseas SaaS. Are we disclosing overseas?
If the provider stores or processes candidate data outside Australia, then yes, candidate data is going overseas and APP 8 is engaged, even though it is a routine cloud tool. Confirm the hosting location and handle it on the APP 8 basis rather than assuming a well-known vendor takes you out of scope.
Does using an overseas provider need the candidate's consent?
Not necessarily. The default obligation is to take reasonable steps to ensure the recipient meets the APPs, and you stay accountable. Consent is one specific route (with its own conditions), not the general rule. Work out your APP 8 basis rather than defaulting to a consent tick-box.
We only send de-identified data offshore. Does APP 8 still apply?
If the data is genuinely de-identified so no individual is reasonably identifiable, it is not personal information and APP 8 does not apply to it. But candidate screening data is often re-identifiable, so be sure it is truly de-identified before relying on that.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether an APP 8 exception applies to your arrangement depends on the facts. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.