What should a data clause cover in an Australian supplier contract?
The important point is not in the contract, it is in the Privacy Act. If you hand personal information to a supplier who stores it overseas, you can remain accountable for their handling of it. That is what makes the data clause worth reading properly.
Last checked 2026-08-02. Australian law changes, and this page states the position as at that date.
You do not outsource the obligation
Australian Privacy Principle 8 deals with sending personal information overseas. Before disclosing personal information to an overseas recipient, you have to take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles.
Section 16C then goes further. In the relevant circumstances, an act by the overseas recipient that would breach the APPs is taken to have been done by you, and to be a breach by you. So if your supplier mishandles data in another country, that can be your breach, not only theirs.
There is an exception. You do not need to take those steps under APP 8.1 where you reasonably believe the recipient is subject to a law or binding scheme that protects the information in a way substantially similar to the APPs, and there are mechanisms the individual can access to enforce it.
This is why the data clause matters commercially rather than as boilerplate. The contract is one of the main ways you take those reasonable steps.
What the clause should cover
- Where the data is stored
- Named countries, not a general right to process anywhere. If the supplier can move hosting without telling you, your APP 8 position can change without your knowledge.
- Who else touches it
- Sub-processors, and whether you get notice before a new one is added. A supplier's sub-processor is still an overseas recipient as far as your obligations are concerned.
- Breach notification timing
- Australia's Notifiable Data Breaches scheme requires eligible breaches to be notified to the OAIC and affected individuals. You cannot meet that obligation if your supplier takes weeks to tell you. Ask for a defined period, in hours or days.
- Who owns the data
- It should be you. Watch for clauses granting the supplier broad rights to use your data for their own purposes, including model training.
- What happens on exit
- Return in a usable format, within a defined period, followed by deletion with confirmation. A clause that only promises deletion leaves you without your own records.
- Security commitments
- Specific and testable is better than a promise of industry standard measures. Certifications, encryption at rest and in transit, and access controls are worth naming.
What has changed recently
The Privacy and Other Legislation Amendment Act 2024 passed on 29 November 2024 and is being implemented in stages.
A statutory tort for serious invasions of privacy commenced on 10 June 2025. It gives an individual a direct right to sue, with two limbs covering intrusion upon seclusion and misuse of information. That is a route to liability that sits outside the regulator.
A further obligation on transparency about automated decision-making in privacy policies takes effect on 10 December 2026. If a supplier's product makes automated decisions about individuals using your data, this is worth raising now rather than close to the date.
Common questions
- Am I responsible if my supplier leaks data overseas?
- Potentially yes. Under APP 8 you must take reasonable steps before disclosing personal information to an overseas recipient, and under section 16C an act by that recipient which would breach the Australian Privacy Principles can be taken to be a breach by you. An exception applies where you reasonably believe the recipient is subject to a law or binding scheme substantially similar to the APPs.
- Can an Australian business use an overseas cloud supplier?
- Yes. APP 8 does not prohibit overseas disclosure, it regulates it. You need to take reasonable steps to ensure the recipient handles the information in line with the Australian Privacy Principles, and the supplier contract is one of the main ways you do that.
- How quickly does a supplier need to tell me about a data breach?
- The Privacy Act sets your obligations under the Notifiable Data Breaches scheme, not the supplier's timing to you. That is why the contract should specify a defined notification period. If your supplier takes weeks to tell you, you cannot meet your own obligation to notify the OAIC and affected individuals.
Sources
Check your own contract
Citrus reads a supplier contract and flags the clauses that sit outside the market or lean heavily one way, in plain English. One contract, no card.
More guides
- Unfair contract terms in Australia: what businesses need to check
- Supplier contract review checklist for Australian businesses
- What counts as a standard form contract in Australia?
- Can a supplier limit its liability under Australian law?
- Does a foreign governing law clause avoid Australian law?
- Can a supplier contract automatically renew in Australia?
- What should you check in an indemnity clause?
- What can AI contract review actually do, and what can it not?
- How do you choose contract review software?
- How do you review a supplier contract without a legal team?
General information about Australian law, not legal advice. Citrus is not a law firm. See our disclaimer.