Privacy Act Australia
Definition
Privacy Act Australia
Privacy Act Australia refers to the Privacy Act 1988 and the thirteen Australian Privacy Principles it carries, which govern how covered entities may handle data. Offshoring does not end your accountability, because the discloser answers for its recipient’s conduct.
The Act is old by privacy standards and has been amended repeatedly, most substantially by legislation that received assent in December 2024.
Australian organisations offshore heavily, particularly to the Philippines and India, which makes one principle unusually important here.
That principle is APP 8, and its companion provision in the Act is the reason Australian buyers negotiate offshore contracts the way they do.
Key takeaways
- There are thirteen Australian Privacy Principles, and APP 8 governs cross-border disclosure.
- Section 16C makes the disclosing entity accountable for the overseas recipient’s conduct.
- Accountability applies even where the entity took reasonable steps and the breach was inadvertent.
- A statutory tort for serious invasions of privacy commenced in June 2025.
How it works
APP 8 sets the obligation before data leaves. An entity must take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs in relation to that information.
Reasonable steps usually means an enforceable contract requiring APP compliance. What is reasonable varies with sensitivity, the relationship, the consequences of mishandling and the safeguards already in place.
Then comes the sting — section 16C provides that an entity disclosing personal information overseas is accountable for an act of the overseas recipient that would breach the APPs.
| Stage | What the Act expects |
|---|---|
| Before disclosure | Reasonable steps, usually an enforceable APP compliance contract |
| Choice of recipient | Assessment proportionate to sensitivity and consequence |
| During the arrangement | Security under APP 11 against misuse, loss and unauthorised access |
| After a recipient’s breach | Accountability under section 16C as if you had acted |
| Individual complaints | Handled by you, not deflected to the provider |
The practical effect is severe. The recipient’s breaching conduct is treated as if the disclosing entity committed it, so liability can attach even when precautions were taken.
APP 11 runs alongside — an entity must take reasonable steps to protect personal information it holds from misuse, interference, loss and unauthorised access, modification or disclosure.
Examples
Australian offshore arrangements are mature, which means the failure modes are well documented. What follows are engagements where somebody discovered the obligation travelled with the work.
A Melbourne insurer runs claims processing from Manila. Its contract requires APP compliance expressly, because a generic confidentiality clause would not amount to reasonable steps under APP 8.
A Sydney telecommunications provider offshores billing support. When an offshore agent misused account data, the Australian entity answered for it — section 16C gave the regulator a direct route.
A superannuation fund moves member servicing to a Philippine partner. Sensitivity raises the bar, so the fund audits access controls rather than relying on the partner’s self-assessment.
A retailer’s marketing agency sends customer lists to an overseas analytics firm. The retailer is the disclosing entity, and the agency’s convenience does not relocate the accountability.
Related terms
Australian privacy language differs from the European and Asian regimes buyers also encounter. Each entry below answers a different question, even where the vocabulary looks identical.
- GDPR outsourcing: the European processor contract, prescriptive where APP 8 is principle based.
- PDPA outsourcing: the Singapore regime, with a different transfer test.
- ISO 27001 outsourcing: the certification Australian buyers most often request as evidence.
- Philippines BPO: the destination most Australian offshore disclosure involves.
- Business process outsourcing (BPO): the delivery model that creates the disclosure.
- Data centre outsourcing: hosting decisions that can constitute cross-border disclosure.
- Compliance outsourcing: contracting the compliance function rather than the processing.
FAQ
Does APP 8 prohibit offshoring?
No. It requires reasonable steps before disclosure and makes you accountable afterwards, which is a governance burden rather than a ban.
Is a confidentiality clause enough?
Usually not. Reasonable steps ordinarily means an enforceable contract requiring the recipient to comply with the Australian Privacy Principles specifically.
What if the recipient breaches despite our precautions?
Section 16C still applies. The recipient’s conduct is treated as yours, which is why the choice of recipient matters as much as the paperwork.
Does the small business exemption help?
It exempts some operators from the Act, but the statutory tort for serious invasions of privacy applies regardless of that exemption.
What changed in 2024 and 2025?
Legislation assented in December 2024 amended the Act, and the statutory tort commenced in June 2025. Further reforms remain proposed rather than enacted.
Who regulates this?
The Office of the Australian Information Commissioner administers the Act and publishes the APP guidelines organisations rely on.
Review Outsource Accelerator and shortlist firms whose contracts already carry the clauses you need.







Independent




