Contract clause

Cross border data transfer clause

A cross border data transfer clause states whether personal information handled under a contract may be stored, accessed or disclosed outside the country, and on what conditions. In Australia it gives effect to APP 8, which requires reasonable steps before disclosing personal information to an overseas recipient and leaves the discloser accountable for that recipient.

Data crosses borders far more often than contracts admit, through offshore support desks, cloud regions and subcontractors in other time zones. The clause makes the supplier say where the data will actually go, so the customer can decide whether that is acceptable.

· Co-founder

4 min read · Published

Sample clause

a customer support outsourcing agreement between Bilby Connect and Illawarra Solar Co, a fictional installer whose customer records include addresses and payment histories

11. Location of Customer Personal Information 11.1 Bilby Connect must not store, process, access or disclose Customer Personal Information outside Australia without Illawarra Solar's prior written consent. 11.2 If Illawarra Solar consents to a disclosure outside Australia, Bilby Connect must, before the disclosure: (a) identify in writing each overseas recipient, the country, and the purpose of the disclosure; (b) ensure each overseas recipient is bound by a written contract requiring it to handle the information in accordance with the Australian Privacy Principles, other than APP 1; and (c) give Illawarra Solar a copy of the relevant terms on request. 11.3 Access to Customer Personal Information by Bilby Connect's personnel while temporarily travelling overseas is a disclosure outside Australia for the purposes of this clause. 11.4 Bilby Connect is liable to Illawarra Solar for any act of an overseas recipient that would breach the Australian Privacy Principles if done by Bilby Connect.

Sample wording, not legal advice.

Variants

Named countries allowed

The supplier has a known offshore team or data centre and the customer is comfortable with those locations only.

The Supplier may store and process Customer Personal Information in Australia and New Zealand, and may allow its support personnel in the Philippines to access it remotely for the purpose of responding to customer enquiries, but not to store it there. The Supplier must not add a country to this list without 30 days written notice to the Customer, and the Customer may terminate the affected Services without charge if it does not agree.

UK and EU transfer safeguards

The data is subject to the UK GDPR or the EU GDPR and will be sent to a country without an adequacy decision.

The Processor must not transfer Personal Data to a country outside the United Kingdom or the European Economic Area unless the transfer is covered by adequacy regulations or an adequacy decision, or the parties have put in place appropriate safeguards under Article 46, such as standard data protection clauses approved for that transfer, together with any supplementary measures needed to make those safeguards effective. The Processor must give the Controller a copy of the safeguards on request.

No restriction

The information is low risk and the supplier's global platform cannot commit to one location.

The Customer acknowledges that the Supplier provides the Services using facilities in several countries, listed on the Supplier's published subprocessor page, and that Customer Personal Information may be stored or accessed in any of them. The Supplier must handle Customer Personal Information in accordance with this agreement wherever it is located, and must keep the published list current and notify the Customer of any change.

What to negotiate

The risk of leaving it out

Without the clause the supplier can move data to any country it chooses, and the customer may not find out until an incident. Under section 16C the customer can be treated as accountable for an overseas recipient's mishandling even though it never approved the transfer.

What APP 8 actually asks for

Before an entity covered by the Privacy Act discloses personal information to an overseas recipient, APP 8.1 requires it to take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, other than APP 1. Section 16C then makes the entity accountable for acts of the overseas recipient that would breach the principles. There are exceptions, including where the recipient is subject to a law or binding scheme substantially similar to the principles that the individual can enforce, and where the individual consents after being expressly told that APP 8.1 will not apply. For most commercial arrangements, a contract binding the recipient to the principles is the practical reasonable step.

Disclosure or use

The OAIC guidelines distinguish a disclosure to an overseas recipient from a use, where the entity does not release the later handling of the information from its effective control. Providing information to an overseas cloud provider only to store it, under a binding contract that limits the provider to that purpose, may be a use rather than a disclosure, and APP 8 would then not apply. A support centre whose staff read and act on customer records looks very different. This is why the sample treats even temporary overseas access by the supplier's own personnel as a transfer for contract purposes: the contract can be stricter than the statute, and a clear rule avoids arguing about which category an arrangement falls into.

Where it sits in a generated document

A generated outsourcing agreement can hold this clause beside the data protection and security clauses, with approved countries set out in a schedule table. The generator writes every location as content, so the named countries should be confirmed with the supplier before signing. An attached supplier questionnaire gives the draft facts to work from, since research runs only when no file is attached.

Documents that carry this clause

Questions people ask

Does storing data in an overseas cloud count as a cross border disclosure?

Not always. The OAIC guidelines say that giving information to an overseas cloud provider only to store it, under a binding contract that keeps the handling within the entity's effective control, may be a use rather than a disclosure. The detail matters, which is why many contracts take a simpler position and control both storage location and access.

What are reasonable steps under APP 8?

Usually a written contract requiring the overseas recipient to handle the information in accordance with the Australian Privacy Principles, other than APP 1, backed by some ability to check compliance. What is reasonable depends on the sensitivity of the information, the recipient and the country. Health or financial information calls for more than contact details.

Can consent replace the APP 8 obligations?

In limited cases. The exception requires the individual to be expressly informed that, if they consent, APP 8.1 will not apply, and then to consent. Buried or bundled consent is unlikely to meet that standard. Most businesses find a contractual approach more reliable than trying to obtain informed consent from every customer.

What about data coming from the UK or the EU?

Personal data leaving the United Kingdom or the European Economic Area needs a lawful transfer route, such as an adequacy decision or appropriate safeguards under Article 46, commonly standard data protection clauses. An Australian supplier receiving that data will usually be asked to sign those clauses in addition to any Australian terms.

Should the clause cover staff travelling overseas?

Many customers now ask for it, because a laptop logged into customer systems from overseas produces the same exposure as an offshore office. The clause can treat temporary access as a transfer that needs consent, or permit it for named purposes with security conditions such as multi factor authentication and no local downloads.

How does the clause relate to the privacy policy?

A business covered by the Privacy Act must say in its privacy policy whether it is likely to disclose personal information overseas and, where practicable, which countries. If a supplier contract permits transfers to countries the policy does not mention, one of the two is wrong. Updating both whenever the approved country list changes keeps them aligned.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .