Clear Picture Logo

Latest News

Key Considerations When Sharing Personal Information with Overseas Contractors

Engaging overseas contractors can be an effective way for businesses to respond to their business needs. However, while there are many advantages to hiring overseas contractors, you must consider this against legal risks, such as the risk of sharing the personal information of Australian individuals with overseas parties.

.

This article considers how you can comply with your privacy obligations under the Australian Privacy Principles outlined in the Privacy Act 1988 (Cth) when disclosing information with overseas contractors.

Are You an APP Entity?

Before sharing information with an overseas contractor, you must determine if you are an APP entity. This distinction is important because if an APP entity shares information overseas and that overseas party breaches the APPs, that breach will be taken to be a breach by the APP entity itself.

For example, suppose your business generates more than $3 million in annual turnover. In that case, it will likely be considered an APP entity and will have obligations under the Privacy Act, including concerning the disclosure of personal information overseas.

Sharing Information With Overseas Contractors

Suppose you are an APP entity. If so, let us explore several precautionary measures you can take when sharing information with your overseas contractors.

1. Privacy Policy

Before sharing information with any third party (including overseas contractors), you should review the terms of your privacy policy to ensure that you have informed your customers that you will share their personal information with overseas contractors.

If you have yet to inform customers of this intended use, you can update your privacy policy and provide notice of this to your customers. You should aim to give your customers at least 30 days’ notice before the privacy policy comes into effect. Accordingly, this will allow your customers to inform you of any issues with your intended use of their personal information before you disclose it.

2. Risk Mitigation

As a best practice, you should only share information essential for your overseas contractors to be able to deliver the services.

When engaging an overseas contractor, consider the following questions.

1. Whether the volume of information you are sharing with the contractor is necessary to enable them to perform the services?

  • Tip: As a rule, do not provide the contractor with more personal information than is necessary. The more information you share, the higher the risk of individuals using data in a way that breaches the APPs.

2. What is the nature of the information?

  • Tip: You should consider the nature of the information, and whether it is personal or sensitive information. Sensitive data requires a higher level of confidentiality due to its delicate nature.

3. How much access does the contractor have to my existing databases?

  • Tip: Ensure that you only provide access to the databases that the contractor needs to perform their services. All other access should be limited or subject to your approval.

3. Contractual Terms

You should ensure that the terms of your contractor agreement impose strong privacy obligations on the contractor, particularly concerning any personal information they receive or have access to during the term.

You can include clauses addressing the following:

  • an acknowledgement by the contractor that you are required to comply with the APPs;
  • a warranty that the contractor will not breach the APPs;
  • an indemnity by the overseas contractor if it breaches the APPs (for example, by disclosing personal information to an unauthorised party); and
  • a data breach response plan that includes a straightforward process for reporting a data breach.

 

 

 

Saya Hussain
April 18
legalvision.com.au

Hot Issues

Craig Byron

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Fusce efficitur ligula id justo blandit, sit amet accumsan magna scelerisque. Phasellus tincidunt ipsum nec semper sagittis. Suspendisse suscipit, orci sed gravida dapibus, elit est porta ligula, vel convallis metus urna et ante. Pellentesque aliquam erat sodales sem blandit, ac facilisis magna mattis. Aliquam id lorem eu mauris bibendum facilisis in sit amet leo.

Morbi non ante vitae velit vehicula vehicula vitae euismod ex. Ut pretium rhoncus lacus in tincidunt. Suspendisse vulputate, diam eget viverra feugiat, magna velit scelerisque velit, vel posuere eros sem ut felis. Sed pellentesque justo in eros iaculis, et consequat nibh sollicitudin. Ut facilisis sit amet turpis sed cursus. Sed tincidunt neque arcu, a rutrum lectus elementum quis.

Vivamus nisi lectus, malesuada vel maximus a, lobortis in justo. Donec turpis diam, consectetur eu justo ut, accumsan malesuada nisl.

Service 1

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris eget pulvinar velit. Pellentesque condimentum felis enim, vitae mollis felis feugiat sed. Fusce quis eros rutrum, blandit sem ut, pharetra felis. Aenean pulvinar et risus et rhoncus. Maecenas feugiat consectetur risus, eu lobortis erat viverra vitae. Nam tempor tellus bibendum, tempus elit a, laoreet metus.

Sed consectetur quam quis purus lobortis, sed rhoncus enim finibus. Sed fringilla eu lectus sit amet pretium. Ut tempus aliquam iaculis. Nulla enim elit, pellentesque ut maximus a, efficitur eu risus. Praesent finibus interdum finibus. Pellentesque et maximus dui. Maecenas consequat suscipit eleifend. Curabitur placerat quam nulla, et fringilla nisl consectetur eu. Proin posuere, nisl in viverra egestas, leo urna consequat risus, at euismod orci est quis sem. Praesent convallis viverra elit eu lacinia.

  • Lorem ipsum dolor sit amet, consectetur adipiscing elit.
  • Nulla commodo ex eu blandit maximus.
  • Cras vulputate libero vel felis mattis, a ultricies arcu pellentesque.
  • Etiam suscipit turpis a mauris fermentum, quis accumsan est dapibus.
Contact Us

Tax Diary

General Calculators

 

Accounting Videos

Secure File Transfer

Secure File Transfer is a facility that allows the safe and secure exchange of confidential files or documents between you and us.

Email is very convenient in our business world, there is no doubting that. However email messages and attachments can be intercepted by third parties, putting your privacy and identity at risk if used to send confidential files or documents. Secure File Transfer eliminates this risk.

Login to Secure File Transfer, or contact us if you require a username and password.