Skip to content

Offshore recruiters and overseas screening: your APP 8 duty over candidate data

If you use an offshore recruiter, an overseas background-check provider, an overseas parent or group company, or an applicant-tracking system hosted outside Australia, candidate data is leaving the country and APP 8 decides who answers for it. Where the recipient is a different entity, APP 8.1 makes you take reasonable steps before you disclose, and s 16C then treats that recipient's breach as your breach. Your own overseas office is not an 'overseas recipient' at all (APP 8.1(b)), and a provider you keep under effective control is a use rather than a disclosure, but you still hold the data either way.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Where candidate data crosses the border

It is easy to miss how often recruitment data leaves Australia:

Each of those puts candidate personal information outside Australia. Whether it is a disclosure engaging APP 8, or a use you stay responsible for, turns on one question: have you released the subsequent handling from your effective control (OAIC APP Guidelines 8.8 and 8.14)?

The rule: reasonable steps, and you stay on the hook

Under APP 8.1, before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs in handling it. The teeth are in s 16C: where APP 8.1 applied to the disclosure (s 16C(1)(b)), an act by the overseas recipient that would breach the APPs is taken to have been done by you, and to be your breach (s 16C(2)). OAIC APP Guidelines 8.62 says an entity may be liable "even where" it has "taken reasonable steps", and where the recipient's own subcontractor is the one that breaches. That is why "we just use an overseas VA" is not a way to offload the obligation.

APP 8.2 does not soften subclause 8.1, it disapplies it: where you reasonably believe the recipient is subject to a law or binding scheme substantially similar to the APPs with mechanisms the individual can access to enforce it (APP 8.2(a)), or where you expressly inform the candidate that subclause 8.1 will not apply and they then consent (APP 8.2(b)). Section 16C applies only where "Australian Privacy Principle 8.1 applies to the disclosure" (s 16C(1)(b)), so an exception that removes 8.1 takes the accountability rule with it (OAIC APP Guidelines 8.63). No country or binding scheme has been prescribed under the APP 8.2(aa) limb, so nothing is white-listed. Work out your basis deliberately rather than assuming one applies.

What "reasonable steps" looks like in practice

Common questions

Our ATS is a big overseas SaaS. Are we disclosing overseas?

Not automatically. OAIC APP Guidelines 8.14 says that where you have not released the subsequent handling of the information from your effective control, providing it to an overseas provider can be a use rather than a disclosure, and "the entity would not need to comply with APP 8". Overseas cloud hosting is the Guidelines' own example, on three conditions: a binding contract limiting the provider to those purposes, the same obligations flowing down to subcontractors, and the contract giving you effective control. Miss those and it is a disclosure. Meet them and you still hold the data, so APP 11 and the NDB scheme still sit with you (8.15). Does your ATS contract carry those three terms?

Not necessarily. The default is APP 8.1 reasonable steps plus s 16C accountability. Consent is a specific route with a precondition most tick-boxes miss: under APP 8.2(b) you must expressly inform the candidate that if they consent, subclause 8.1 will not apply, and only then can they consent. A box reading "I consent to my information being sent overseas" does not do that, so it leaves you on APP 8.1 anyway. Does yours say what the candidate is giving up?

We only send de-identified data offshore. Does APP 8 still apply?

If no individual is reasonably identifiable, it is not personal information under s 6(1) and APP 8 does not apply to it. The test is the whole of what you send, in the hands of whoever receives it: a CV with the name removed still carries employer history, dates and qualifications. Strip the name and check whether the file still points to one person before relying on this.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether an APP 8 exception applies to your arrangement depends on the facts. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading