Skip to content

Offshore recruiters and overseas screening: your APP 8 duty over candidate data

If you use an offshore recruiter, a virtual assistant overseas, an applicant-tracking system hosted outside Australia, or an overseas background-check provider, candidate data is being disclosed overseas, and APP 8 applies. Before you send it, you must take reasonable steps to ensure the overseas recipient handles it consistently with the Australian Privacy Principles. And in many cases you remain accountable for what that recipient does with it, as if you had done it yourself.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Where candidate data crosses the border

It is easy to miss how often recruitment data leaves Australia:

Each of those is a disclosure of candidate personal information overseas, and APP 8 governs it.

The rule: reasonable steps, and you stay on the hook

Under APP 8.1, before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs in handling it. The practical teeth are in the accountability rule (s 16C): broadly, an act done by the overseas recipient that would breach the APPs is treated as if you did it, so a mishandling offshore can become your breach. That is why "we just use an overseas VA" is not a way to offload the obligation.

There are limited exceptions (APP 8.2), for example where the recipient is subject to a law or binding scheme that is substantially similar to the APPs with a way to enforce it, or where the candidate is expressly informed that the reasonable-steps protection will not apply and consents. These are specific and fact-dependent, so do not assume one applies, work out your basis deliberately.

What "reasonable steps" looks like in practice

Common questions

Our ATS is a big overseas SaaS. Are we disclosing overseas?

If the provider stores or processes candidate data outside Australia, then yes, candidate data is going overseas and APP 8 is engaged, even though it is a routine cloud tool. Confirm the hosting location and handle it on the APP 8 basis rather than assuming a well-known vendor takes you out of scope.

Not necessarily. The default obligation is to take reasonable steps to ensure the recipient meets the APPs, and you stay accountable. Consent is one specific route (with its own conditions), not the general rule. Work out your APP 8 basis rather than defaulting to a consent tick-box.

We only send de-identified data offshore. Does APP 8 still apply?

If the data is genuinely de-identified so no individual is reasonably identifiable, it is not personal information and APP 8 does not apply to it. But candidate screening data is often re-identifiable, so be sure it is truly de-identified before relying on that.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether an APP 8 exception applies to your arrangement depends on the facts. Privaproof's recruitment documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading