WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Privacy Act 1988 — cross-border disclosure of personal information

APP 8 / s. 16C

Australia · March 12, 2014

Australia does not restrict WHERE you send data; it makes you answer for what happens to it there. APP 8.1 requires taking reasonable steps to ensure an overseas recipient does not breach the APPs, and s. 16C then deems any such breach by the recipient to be a breach BY YOU — the accountability does not transfer with the data, and no contractual allocation of risk changes that as against the regulator. The practical consequences are that vendor due diligence and contractual APP flow-downs are the compliance artefact, and that a SOC 2 report or similar assurance is evidence toward reasonable steps rather than a substitute for them. APP 8.2 carves out exceptions, including where the recipient is subject to a substantially similar law the individual can enforce, or where the individual consents after being expressly told that APP 8.1 will not apply.

Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principle 8; s. 16CRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.