Running the business

Offshore Staff and APP 8: Cross-Border Privacy Explained

Looking for VA work yourself? Apply at staffingsolutions.ph — this article is written for businesses hiring.
The short answer

Yes, an offshore team member can work with your clients' personal information. What does not move offshore is the responsibility for it. If that person mishandles it, your business is the one answering for it. So the question worth asking is not whether you are allowed to, but how you set the access up: inside your own systems, on their own named login, with nothing able to be downloaded or saved anywhere else.

The question is usually simpler than the legislation: can a team member in Manila see our clients' personal information? Generally yes, and Australian businesses do it every day. The Privacy Act 1988 (Cth) keeps you accountable for what happens to that information, and Australian Privacy Principle 8 is where that accountability is written down.

The mistake is treating APP 8 as a yes-or-no gate. It is a set of obligations whose shape depends on how you build the arrangement.

This is general information, not legal or financial advice. Every instrument below is named so you can check it against the source.

What APP 8 actually says

APP 8 sits in Schedule 1 to the Privacy Act. APP 8.1 says that before an APP entity discloses personal information to an overseas recipient, it must take such steps as are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, other than APP 1, in relation to that information. An overseas recipient is a person who is not in Australia or an external Territory, and who is neither you nor the individual concerned.

Then the part people skip. Section 16C provides that where APP 8.1 applied to a disclosure, the APPs do not otherwise apply to the overseas recipient, and the recipient does something that would have breached the APPs, that act is taken to have been done by you, and to be your breach. Accountability does not travel with the data.

APP 8.2 sets out exceptions, and two matter here. APP 8.2(a) lets you rely on a reasonable belief that the recipient is subject to a law or binding scheme substantially similar to the APPs, with mechanisms the individual can access to enforce it. APP 8.2(b) lets you rely on consent, but only where you expressly told the individual first that APP 8.1 would not apply. The Philippines has a general data protection statute, the Data Privacy Act of 2012 (Republic Act No. 10173), administered by the National Privacy Commission. Whether that satisfies APP 8.2(a) for you is a legal judgement, not one a staffing provider should make on your behalf.

Settle one thing first: whether the Act applies to you. Under section 6D, small business operators with an annual turnover of A$3 million or less are generally exempt, with carve-outs including health service providers holding health information, businesses that trade in personal information, and Commonwealth contractors. That exemption has been under review as part of Privacy Act reform, so confirm the current position.

Disclosure, or access to something you still control?

The APPs distinguish using personal information from disclosing it. Broadly, you use information when you handle it within your effective control and disclose it when you release it from that control. The OAIC's APP Guidelines work through when providing information to an overseas service provider is a use rather than a disclosure, and the factors turn on control: a binding contract limiting the provider to your purposes, your say over how it is secured, and your right to retrieve it or require its destruction.

Two arrangements can look identical from outside and land differently.

Looks like disclosure overseasLooks like access to what you hold
Emailing a client file to a personal addressA named user in your tenancy, on your licence seat
A provider holding your data on its systemsA provider that stores nothing on its side

This is not a badge you award yourself. Where there is real doubt, treat it as a disclosure and take the steps APP 8.1 asks for. Build it the second way regardless: it makes APP 11 easier to meet too.

What stays yours regardless

APP 11 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. That does not change because a team member sits in Manila rather than Melbourne. The Notifiable Data Breaches scheme in Part IIIC is yours too: a breach starting with an overseas account is still yours to assess, and if it is an eligible data breach, yours to notify to the OAIC and the individuals affected.

So is the regulated act. Privacy sits alongside the licensing boundary rather than replacing it, and we have mapped that boundary profession by profession in what you legally cannot delegate offshore. Preparation travels. The lodgement, the advice and the signature do not.

Your own contracts stay yours as well. Licensee agreements, aggregator policies and funding contracts often carry data-location clauses stricter than the Privacy Act, and where they do, they are the binding constraint. What you cannot do is contract accountability away: an agreement gives you recourse, and section 16C is why it does not move the obligation off you.

The controls that actually do the work

Almost everything APP 11 asks of you here is access control. These are cheap, unglamorous, and apply equally to local staff.

  • Named accounts, never a shared login. Their own account in every system, with multi-factor authentication. Every action attributed, access revocable in seconds.
  • Least privilege, reviewed. Only the permissions the role needs. No owner accounts, no standing global admin, nothing reaching payment settings.
  • Nothing leaves the system. Work in your tenancy, in the browser. No downloads to personal devices, no personal email or cloud storage, no client details in messaging apps.
  • Money movement stays with you. They prepare the payment file, your authorised person releases it. No exceptions.
  • Audit logs on, and actually read. Check them in the first fortnight, then periodically. A log nobody opens is not a control.
  • One page of plain-language data rules. What they may open, what they must never download, who to ask when it is unclear. Escalating has to be the expected answer, not a failure.
  • Same-day offboarding. When someone leaves the role, access ends that day.

Confidentiality terms should be signed before day one, and no client data should sit on your provider's systems at all. That is how we set placements up, and it is fair to ask any provider to put it in writing. More in how to onboard a virtual assistant and is it safe to hire an offshore virtual assistant.

Say it in your privacy policy and at collection

APP 1.4 requires your privacy policy to state whether you are likely to disclose personal information to overseas recipients and, where practicable, the countries they are likely to be in. APP 5.2 requires the same notice to individuals at or before collection, or as soon as practicable after. If the arrangement is genuinely access to information under your control, you may conclude there is nothing to describe. Where there is any real prospect otherwise, say so plainly and name the country. Saying it up front is a far easier conversation than explaining it later.

The rules that sit on top of APP 8

The Privacy Act is the floor rather than the ceiling, and several overlays are stricter.

Health. New South Wales, Victoria and the ACT each have their own health records legislation operating alongside the Privacy Act, and the detail differs, so the answer for a Sydney clinic is not automatically the answer for one in Brisbane. If your practice uses the My Health Record system, section 77 of the My Health Records Act 2012 (Cth) restricts records being held or taken outside Australia, though it is directed at registered repository, portal and contracted service providers rather than at every practice. Whether it reaches you is a question for your adviser.

Tax and BAS agents. Item 6 of the Code of Professional Conduct in section 30-10 of the Tax Agent Services Act 2009 (Cth) restricts disclosing information about a client's affairs to a third party without the client's permission or a legal duty, and the Tax Practitioners Board publishes guidance on outsourcing and offshoring. Read the current version rather than a summary of it, including ours. A compliant handover looks like hand over BAS prep.

Credit, financial services, legal and NDIS. Licensee agreements, aggregator policies, law society rules and NDIS funding contracts routinely add their own data-location, notification or approval requirements. Ask before you build the arrangement, not after someone asks you for it. For NDIS, start with what an NDIS provider should delegate first.

What to do next

  1. Confirm whether you are an APP entity, and note any sector rules that apply regardless of turnover.
  2. Write down what personal information the role will touch, and whether it stays inside your systems. If it moves outside them, ask whether it needs to.
  3. Check your client agreements, licensee rules and funding contracts for data-location clauses before you hire, not after.
  4. Update your privacy policy and collection notice so they describe the arrangement you actually run.

Design the access before the first day, not in month three. Our process is in how it works, and the security questions we get asked most are on the FAQ page.

To work through it against your own systems and your own regulator, book a discovery call. Bring your licensee's outsourcing policy if you have one, and we will build the arrangement around it.

General information only, current as at 10 August 2026, and not legal or financial advice. Confirm the current position with the OAIC, the relevant regulator, or your own adviser.

How we would staff this

How we would staff this without your client data leaving your systems

This article is really about access design, and that is the part we set up with you before anyone starts. We hire the person in the Philippines on your behalf, they work inside your systems as their own named user, and no client data sits on our systems at any point. Confidentiality terms are signed before day one, and the access map (what they can open, what they must never download, who releases payments) is agreed before the first day rather than in month three.

Administration assistant working inside your systems
What they do
  • Works in your systems on their own named login with multi-factor authentication and only the permissions the role needs, so every action is attributable and access can be cut the same day
  • Handles client records, correspondence and document chasing in the browser, with nothing downloaded to a personal device and nothing moved into personal email, chat or cloud storage
  • Prepares the payment file, claim or reconciliation and stops at the authorisation step, so money only moves when your authorised person releases it
  • Keeps the access and document register current, so when you run a permissions review or the role changes hands you are working from a live list rather than reconstructing one
  • Works to your one-page data rules and hands back anything outside them, so a client asking for a file to be sent somewhere unusual comes to you instead of being answered on the spot
What stays with you
  • The judgement about whether your arrangement is a disclosure overseas, and what reasonable steps are enough, which sits with you and your adviser rather than with us
  • Your privacy policy and collection notice wording, including whether you name the country in them
  • Assessing a suspected breach, and notifying the Australian Information Commissioner and the people affected
  • Owner and administrator accounts, reading the audit logs, and the regulated act itself: the advice, the signature, the lodgement and the release of any payment
From A$14/hr + GST · full-time and dedicated · about two weeks from brief to first day · no placement or exit fees
See the role →

Frequently asked questions

Do I need my clients' consent before an offshore assistant can access their information?
Consent is one lawful route, not a precondition. It only counts if you told the person beforehand that the cross-border protection would fall away once they agreed, which is an awkward sentence to put in front of a client. The other route, and the one the rule is built around, is to take reasonable steps to make sure the overseas person handles the information properly, and to say in your privacy policy and collection notice that overseas recipients are likely, naming the country where you can.
Does the Philippines have privacy laws like Australia's?
The Philippines has its own general data protection law, the Data Privacy Act of 2012, overseen by the National Privacy Commission. That does not automatically satisfy the Australian rules. Australian law lets you rely on an overseas regime being substantially similar to our privacy principles, with enforcement the individual can actually reach, but whether the Philippine regime meets that test for your particular arrangement is a legal judgement for your own adviser, not something a staffing provider should decide for you.
What happens if my offshore assistant causes a data breach?
It is treated as your breach. Where the cross-border rule applied to the disclosure and the Australian privacy principles do not otherwise apply to the overseas person, an act by them that would have breached those principles is taken to have been done by your business. Practically: cut the account off, pull the audit logs, work out exactly what was reachable, and assess whether serious harm is likely. If it is an eligible data breach, you notify the Australian Information Commissioner and the individuals affected.
Does the Privacy Act apply to my small business?
It may not. A business with an annual turnover of A$3 million or less is generally exempt on turnover alone. The carve-outs are the part to check: health service providers that hold health information, businesses that trade in personal information, and contracted service providers under a Commonwealth contract are covered regardless of turnover. That exemption has been under review, so confirm the current position. Client agreements, licensee rules and funding contracts can impose data obligations whether or not the Privacy Act reaches you.
Should offshore staff use a VPN or a remote desktop to access our systems?
Focus first on whether data can leave your systems at all. A hosted desktop or browser-only access with downloads, copy-out and local saving switched off does the real work, because the file never lands on a personal machine. A VPN alone does not; it moves the connection, not the control. Then layer the basics: their own account with multi-factor authentication, permissions limited to the role, no owner or global admin rights, and audit logs someone actually reads.
Do I need a confidentiality agreement with an offshore virtual assistant?
Yes, and signed before the first day. It should set out what they may access and why, that nothing is copied to personal devices, personal email or personal cloud storage, that material is returned or destroyed when the role ends, and the security standards they work to. What it cannot do is shift responsibility. Under Australian privacy law you remain accountable for what happens to the information overseas, so the agreement gives you recourse rather than an exit.
Sources & further reading
  • Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principle 8 (cross-border disclosure of personal information); Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines, Chapters B and 8 — The reasonable steps required before personal information is disclosed to an overseas recipient, the two exceptions the article relies on, and the distinction between using information within your effective control and disclosing it
  • Privacy Act 1988 (Cth) s 16C — That where the cross-border rule applied and the privacy principles do not otherwise apply to the overseas recipient, that recipient's act is taken to be your business's breach
  • Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principles 1.4, 5.2 and 11 — The security obligation, and what your privacy policy and collection notice must say about overseas recipients
  • Privacy Act 1988 (Cth) s 6D — The small business turnover exemption and the carve-outs that defeat it
  • Privacy Act 1988 (Cth) Part IIIC (Notifiable Data Breaches scheme) — Assessing and notifying an eligible data breach that begins in an offshore account
  • Republic Act No. 10173 (Philippines), the Data Privacy Act of 2012, administered by the National Privacy Commission — That the Philippines has its own general data protection law and regulator, which the article does not treat as automatically meeting the Australian test
  • Health Records and Information Privacy Act 2002 (NSW); Health Records Act 2001 (Vic); Health Records (Privacy and Access) Act 1997 (ACT) — That health privacy obligations are state and territory law as well as federal, and differ between jurisdictions
  • Tax Agent Services Act 2009 (Cth) s 30-10(6) (Code of Professional Conduct item 6); Tax Practitioners Board guidance on outsourcing and offshoring — The confidentiality restriction on a registered tax or BAS agent disclosing client information to a third party
Alfie Quiming
Alfie QuimingAccount manager, Manila

Alfie is a natural facilitator with a passion for building meaningful relationships. A true people person, he thrives on creating genuine connections and bringing people and businesses together, and he excels at fostering collaboration and teamwork. At StaffingSolutions.io he is usually the first person you speak to: he maps the role, writes the brief the recruiters work from, and stays on the account long after the placement.

Meet the team