Contract clause
Cross border data transfer clause
A cross border data transfer clause states whether personal information handled under a contract may be stored, accessed or disclosed outside the country, and on what conditions. In Australia it gives effect to APP 8, which requires reasonable steps before disclosing personal information to an overseas recipient and leaves the discloser accountable for that recipient.
Data crosses borders far more often than contracts admit, through offshore support desks, cloud regions and subcontractors in other time zones. The clause makes the supplier say where the data will actually go, so the customer can decide whether that is acceptable.
Nuwan Madhusanka · Co-founder
4 min read · Published
Sample clause
a customer support outsourcing agreement between Bilby Connect and Illawarra Solar Co, a fictional installer whose customer records include addresses and payment histories
11. Location of Customer Personal Information 11.1 Bilby Connect must not store, process, access or disclose Customer Personal Information outside Australia without Illawarra Solar's prior written consent. 11.2 If Illawarra Solar consents to a disclosure outside Australia, Bilby Connect must, before the disclosure: (a) identify in writing each overseas recipient, the country, and the purpose of the disclosure; (b) ensure each overseas recipient is bound by a written contract requiring it to handle the information in accordance with the Australian Privacy Principles, other than APP 1; and (c) give Illawarra Solar a copy of the relevant terms on request. 11.3 Access to Customer Personal Information by Bilby Connect's personnel while temporarily travelling overseas is a disclosure outside Australia for the purposes of this clause. 11.4 Bilby Connect is liable to Illawarra Solar for any act of an overseas recipient that would breach the Australian Privacy Principles if done by Bilby Connect.
Sample wording, not legal advice.
Variants
Named countries allowed
The supplier has a known offshore team or data centre and the customer is comfortable with those locations only.
The Supplier may store and process Customer Personal Information in Australia and New Zealand, and may allow its support personnel in the Philippines to access it remotely for the purpose of responding to customer enquiries, but not to store it there. The Supplier must not add a country to this list without 30 days written notice to the Customer, and the Customer may terminate the affected Services without charge if it does not agree.
UK and EU transfer safeguards
The data is subject to the UK GDPR or the EU GDPR and will be sent to a country without an adequacy decision.
The Processor must not transfer Personal Data to a country outside the United Kingdom or the European Economic Area unless the transfer is covered by adequacy regulations or an adequacy decision, or the parties have put in place appropriate safeguards under Article 46, such as standard data protection clauses approved for that transfer, together with any supplementary measures needed to make those safeguards effective. The Processor must give the Controller a copy of the safeguards on request.
No restriction
The information is low risk and the supplier's global platform cannot commit to one location.
The Customer acknowledges that the Supplier provides the Services using facilities in several countries, listed on the Supplier's published subprocessor page, and that Customer Personal Information may be stored or accessed in any of them. The Supplier must handle Customer Personal Information in accordance with this agreement wherever it is located, and must keep the published list current and notify the Customer of any change.
What to negotiate
Storage versus access
Suppliers often promise onshore storage while support staff overseas can view the same records. Customers now ask whether remote access counts, and increasingly insist that it does. Separating storage from access in the clause, with each location named, gives an accurate picture and lets the customer tell its own customers the truth in its privacy policy.
Consent in advance or case by case
A ban with consent required for each transfer gives the customer control but can stall a supplier that changes providers. A list of approved countries with notice and a right to object is easier to run. Customers with sensitive information usually keep case by case consent for anything outside the list.
Who carries the risk of the overseas recipient
Because APP 8 and section 16C can leave the Australian discloser accountable for what an overseas recipient does, customers want the supplier to bear that risk contractually. Suppliers accept liability for their own subcontractors but resist unlimited exposure, so this point usually ends up tied to the data protection sub cap in the liability clause.
The risk of leaving it out
Without the clause the supplier can move data to any country it chooses, and the customer may not find out until an incident. Under section 16C the customer can be treated as accountable for an overseas recipient's mishandling even though it never approved the transfer.
What APP 8 actually asks for
Before an entity covered by the Privacy Act discloses personal information to an overseas recipient, APP 8.1 requires it to take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, other than APP 1. Section 16C then makes the entity accountable for acts of the overseas recipient that would breach the principles. There are exceptions, including where the recipient is subject to a law or binding scheme substantially similar to the principles that the individual can enforce, and where the individual consents after being expressly told that APP 8.1 will not apply. For most commercial arrangements, a contract binding the recipient to the principles is the practical reasonable step.
Disclosure or use
The OAIC guidelines distinguish a disclosure to an overseas recipient from a use, where the entity does not release the later handling of the information from its effective control. Providing information to an overseas cloud provider only to store it, under a binding contract that limits the provider to that purpose, may be a use rather than a disclosure, and APP 8 would then not apply. A support centre whose staff read and act on customer records looks very different. This is why the sample treats even temporary overseas access by the supplier's own personnel as a transfer for contract purposes: the contract can be stricter than the statute, and a clear rule avoids arguing about which category an arrangement falls into.
Where it sits in a generated document
A generated outsourcing agreement can hold this clause beside the data protection and security clauses, with approved countries set out in a schedule table. The generator writes every location as content, so the named countries should be confirmed with the supplier before signing. An attached supplier questionnaire gives the draft facts to work from, since research runs only when no file is attached.
Documents that carry this clause
UK data processing agreement template with sub-processorsA data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.
Privacy policy template written to the Australian Privacy PrinciplesA privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.
IT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.Questions people ask
Does storing data in an overseas cloud count as a cross border disclosure?
Not always. The OAIC guidelines say that giving information to an overseas cloud provider only to store it, under a binding contract that keeps the handling within the entity's effective control, may be a use rather than a disclosure. The detail matters, which is why many contracts take a simpler position and control both storage location and access.
What are reasonable steps under APP 8?
Usually a written contract requiring the overseas recipient to handle the information in accordance with the Australian Privacy Principles, other than APP 1, backed by some ability to check compliance. What is reasonable depends on the sensitivity of the information, the recipient and the country. Health or financial information calls for more than contact details.
Can consent replace the APP 8 obligations?
In limited cases. The exception requires the individual to be expressly informed that, if they consent, APP 8.1 will not apply, and then to consent. Buried or bundled consent is unlikely to meet that standard. Most businesses find a contractual approach more reliable than trying to obtain informed consent from every customer.
What about data coming from the UK or the EU?
Personal data leaving the United Kingdom or the European Economic Area needs a lawful transfer route, such as an adequacy decision or appropriate safeguards under Article 46, commonly standard data protection clauses. An Australian supplier receiving that data will usually be asked to sign those clauses in addition to any Australian terms.
Should the clause cover staff travelling overseas?
Many customers now ask for it, because a laptop logged into customer systems from overseas produces the same exposure as an offshore office. The clause can treat temporary access as a transfer that needs consent, or permit it for named purposes with security conditions such as multi factor authentication and no local downloads.
How does the clause relate to the privacy policy?
A business covered by the Privacy Act must say in its privacy policy whether it is likely to disclose personal information overseas and, where practicable, which countries. If a supplier contract permits transfers to countries the policy does not mention, one of the two is wrong. Updating both whenever the approved country list changes keeps them aligned.
Put the clause in a finished document
The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.
Create a document with OneCraftRelated clauses
- Data processing clause under UK GDPR Article 28A UK data processing clause gives the controller to processor terms UK GDPR Article 28 requires. Sample for a marketing agency, the mandatory points, variants.
- Data protection clauseA data protection clause sets how a supplier handles personal information under the contract. Australian Privacy Act sample, UK GDPR and US variants.
- Data breach notification clauseA data breach notification clause sets when a supplier must tell the customer about a breach. Australian sample with 24 and 72 hour steps, and UK and US timing.
- Marketing consent clause and opt in wordingA marketing consent clause records permission to send marketing messages. Australian Spam Act sample for an event form, with UK PECR and US CAN-SPAM points.
For everything the document generator can do, see the document maker.
Step by step in the builder: Create a document with AI, then Document builder components.
Written and checked by the OneCraft team. Last checked .